Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Focus-Virus
[Top] [All Lists]

Re: Strange Spyware or virus or processes

Subject: Re: Strange Spyware or virus or processes
Date: Fri, 26 Nov 2004 09:48:20 +0530
I'd like to add a few more tools:

Windows XP SP2 comes with a Add-Ons manager that basically can turn
individual BHO's On or Off.
Spybot (www.spybot.info) is also a good tool to identify and
selectively disable/remove BHo's.




On Thu, 25 Nov 2004 14:41:13 -0500, GuidoZ <uberguidoz@gmail.com> wrote:
OR look for any BHO remover. No need for system restore :-)

I completely agree. If you're like me and use some NICE 3rd part
browser extensions (Google toolbar for example) when you do use IE,
then you'll want to find an alternative to killing them all off with a
checkbox.

Expanding on what Babar Shafiq Nazmi said (quoted above), here are my
fav programs for working with BHOs:
- BHODemon (http://www.definitivesolutions.com/bhodemon.htm)
- HijackThis (http://www.tomcoyote.org/hjt/)
- BHOList (http://www.spywareinfo.com/~merijn/downloads.html)

They are listed in the order I like to use them as well. BHODemon is
awesome - it lists them out for you and makes it easy to uninstall
them or disable them. Excellent for spyware/viruses alike. HijackThis
is good for everything else (run keys, startup locations, etc). It has
very popular forums where they will help out any n00b that's able to
run it and figure out how to post. ;) Finally, if I simply don't know
what something is, BHOList is a nice front end for Tony's list of all
known BHOs. Check out the program for more info (scroll down a bit on
the linked page).

Educate yourself on how BHOs work (use Google when necessary) and
you'll soon laugh at the thought of using System Restore to fix such a
problem.

--
Peace. ~G

On Wed, 24 Nov 2004 20:52:07 +0500, Babar Shafiq Nazmi
<babarnazmi@gmail.com> wrote:
I think there is a easy solution, Those things are mostly attach with
Internet Explorer to work and run again with IE startup, so just goto
Tools->Internet Options->Advance-> and remove a check from
"Enable Third party browser extensions (Require restart)" (of IE).
by default it is checked and close all the IE windows, re-open it will
not run again with IE. also winpatrol is a good tool to remove BHOs
and other spyware from startups. try it frm http://www.winpatrol.com
OR look for any BHO remover. No need for system restore :-)

Babar Shafiq Nazmi.

On Wed, 03 Nov 2004 15:22:38 -0700, Matthew Wheeler <wheeler@lanl.gov> 
wrote:
Darren
The restore points are located in the hidden system volume information 
folder.
MS KB 307545 is a starting point for what you want to do

http://support.microsoft.com/default.aspx?scid=kb;en-us;307545

Cheers
Matthew
Los Alamos National Laboratory, USA



At 12:43 PM 11/3/2004, Darren Schilberg wrote:
I have System Restore on for a reason and it has saved me many times in 
the
past but disabling and then enabling System Restore loses all of the 
restore
points I've created and need.  Is there any way to "save" or "export" 
these
restore points in any way, scan them when System Restore is off, then
re-acquire them somehow so they can once again be used?

--Darren Schilberg
dschilberg@spamcop.net


-----Original Message-----
From: Mark Haney [mailto:mhaney@interactsys.com]
Sent: Tuesday, November 02, 2004 11:39

And for the record, if you need to boot to Safe Mode to get rid of that
cruft, you probably should also turn off System Restore (in XP), just in
case it's also hiding in there and restores itself on the next reboot.



--
God is a great Programmer



<Prev in Thread] Current Thread [Next in Thread>