<?xml version="1.0" ?>
<rss version="2.0">
	<channel>
		<title>Keith's Weblog: Comments on &quot;Spyware, adware, crappy-ware removal software&quot;</title>
		<description>Keith's Weblog: Comments on &quot;Spyware, adware, crappy-ware removal software&quot;, posted on February 1, 2004</description>
		<link>http://keithdevens.com/weblog/archive/2004/Feb/01/spyware</link>
		<language>en-us</language>
		<image>
			<link>http://keithdevens.com/weblog</link>
			<title>Keith Devens .com</title>
			<url>http://keithdevens.com/images/kbd.gif</url>
		</image>

		<item>
			<title>by Kayode Okeyode</title>
			<link>http://keithdevens.com/weblog/archive/2004/Feb/01/spyware#comment3855</link>
			<guid isPermaLink="false">http://keithdevens.com/weblog/4689#comment3855</guid>
			<pubDate>Sun, 01 Feb 2004 09:47:54 +0000</pubDate>
			<description>&lt;p class=&quot;st-markup&quot;&gt;I recently cleaned out a family friend's PC and was going to blog about it since there are some lessons to be learned.&lt;/p&gt;

&lt;p class=&quot;st-markup&quot;&gt;In addition to Ad Aware and Spybot Search and Destroy, you want the following:&lt;/p&gt;

&lt;ul class=&quot;st-markup&quot;&gt;
	&lt;li&gt;&lt;a href=&quot;http://www.spywareinfo.com/~merijn/cwschronicles.html&quot;&gt;CWShredder&lt;/a&gt; to catch the Cool Web Search Spyware. Ad Aware and Spybot are unable to keep up with this kind of Spyware and I suggest running it first (it fits onto a floppy) - scroll down for the download information.&lt;/li&gt;
	&lt;li&gt;&lt;a href=&quot;http://mjc1.com/mirror/hjt/&quot;&gt;HijackThis&lt;/a&gt; gives a log of all spyware on the PC - should give you a starting reference - runs in seconds and fits onto a floppy.&lt;/li&gt;
	&lt;li&gt;If your friend is using Windows NT/2000/XP, then have a look at some of the tools from &lt;a href=&quot;http://www.sysinternals.com/ntw2k/utilities.shtml&quot;&gt;sysinternals&lt;/a&gt; I would start with &lt;a href=&quot;http://www.sysinternals.com/ntw2k/freeware/autoruns.shtml&quot;&gt;autoruns&lt;/a&gt; which should give you a list of all applications starting up on the PC, then have a look at the following, if you wish: Process Explorer, File Monitor, Registory Monitor and TCPView which is GUI version of Netstat -ano&lt;/li&gt;
	&lt;li&gt;You also need an anti-trojan and an anti-virus, but I won't bore you with the details except to say that the &lt;a href=&quot;http://tds.diamondcs.com.au/&quot;&gt;Trojan Defence Suite&lt;/a&gt; can be tried for 30 days so you may wish to try it out on your friends PC and remove any trojans. For AV, I tend to use Avast which is free and auto-updates since the PCs owners are not willing to pay for an AV, but you can use AVG, EZ if they suite you (all free). By the way, I use F-Prot on my Home PC.&lt;/li&gt;
	&lt;li&gt;For a Firewall, I tend to use Kerio 2.1.5 (which is a rules-based firewall) because I think it is the best of the bunch, unfortunately, the last PC I cleaned, I just received an email telling me they had to uninstall it, it was too strict for them because I set it to allow IE to talk to the outside world on Ports 80, 8080 and 443 only - it seems IE needed to go somewhere outside those ports! - obviously, I wasn't allowed to install another browser so I locked down IE as best as I could.&lt;/li&gt;
	&lt;li&gt;Once the PC is clean, you may wish to look at &lt;a href=&quot;http://www.wilderssecurity.net/spywareguard.html&quot;&gt;Spyware Guard&lt;/a&gt; which alerts when IE's Home Page is changed and &lt;a href=&quot;http://www.javacoolsoftware.com/spywareblaster.html&quot;&gt;Spyware Blaster&lt;/a&gt; which prevents Spyware from being installed by setting killbits in the registry&lt;/li&gt;
&lt;/ul&gt;

&lt;p class=&quot;st-markup&quot;&gt;Unfortunately, I cannot comment on WinPatrol, I have seen it discussed in the Security Newsgroups where I hang out but the tools I mentioned above are really the cool ones to have.&lt;/p&gt;

&lt;p class=&quot;st-markup&quot;&gt;If your friend insists on IE, unfortunately, you will need to lock it down too - the PC I cleaned had those buttons on the keyboard for &amp;quot;Internet&amp;quot; and &amp;quot;Email&amp;quot; so I had to stick with IE (I locked it down without mentioning it though.)&lt;/p&gt;

&lt;p class=&quot;st-markup&quot;&gt;You could also use the Hosts File to block some of the nasties - I have some URLs but I haven't shared them here, because I wanted to focus on tools I have used and can vouch for.&lt;/p&gt;

&lt;p class=&quot;st-markup&quot;&gt;Hope the above helps.&lt;/p&gt;

</description>
		</item>
		<item>
			<title>by Keith</title>
			<link>http://keithdevens.com/weblog/archive/2004/Feb/01/spyware#comment3857</link>
			<guid isPermaLink="false">http://keithdevens.com/weblog/4689#comment3857</guid>
			<pubDate>Sun, 01 Feb 2004 20:15:36 +0000</pubDate>
			<description>&lt;p class=&quot;st-markup&quot;&gt;Whoa, thanks a lot.&lt;/p&gt;

</description>
		</item>
		<item>
			<title>by Sparticus</title>
			<link>http://keithdevens.com/weblog/archive/2004/Feb/01/spyware#comment3864</link>
			<guid isPermaLink="false">http://keithdevens.com/weblog/4689#comment3864</guid>
			<pubDate>Tue, 03 Feb 2004 11:17:45 +0000</pubDate>
			<description>&lt;p class=&quot;st-markup&quot;&gt;Lock down ie? That sounds like a good idea. How?&lt;/p&gt;

</description>
		</item>
		<item>
			<title>by Brian</title>
			<link>http://keithdevens.com/weblog/archive/2004/Feb/01/spyware#comment3865</link>
			<guid isPermaLink="false">http://keithdevens.com/weblog/4689#comment3865</guid>
			<pubDate>Tue, 03 Feb 2004 14:44:31 +0000</pubDate>
			<description>&lt;p class=&quot;st-markup&quot;&gt;I've found that some of the best software to use is the following:&lt;/p&gt;

&lt;p class=&quot;st-markup&quot;&gt;- WebSweeper (use first)&lt;br /&gt;
- Search &amp;amp; Destroy SpyBot (use second to remove everything the sweeper missed.. this is a great program because it will ask to load at system start up before other utilities to remove any programs still in memory)&lt;br /&gt;
- Hijack this (this is great because it will scan all of your memory and report everything - most of the time it reports good things as bad but it's very powerful.)&lt;/p&gt;

&lt;p class=&quot;st-markup&quot;&gt;With those three you shouldn't have any problems getting the system up and running as it was before. Good luck.&lt;/p&gt;

</description>
		</item>
		<item>
			<title>by Kayode Okeyode</title>
			<link>http://keithdevens.com/weblog/archive/2004/Feb/01/spyware#comment3866</link>
			<guid isPermaLink="false">http://keithdevens.com/weblog/4689#comment3866</guid>
			<pubDate>Tue, 03 Feb 2004 15:23:24 +0000</pubDate>
			<description>&lt;blockquote class=&quot;st-markup&quot;&gt;&lt;p&gt;Lock down ie? That sounds like a good idea. How?&lt;/p&gt;&lt;/blockquote&gt;

&lt;p class=&quot;st-markup&quot;&gt;I don't have access to my usual resources because I am not at home at the moment, but you may wish to have a look at the &amp;quot;Related Reading&amp;quot; section of an article I wrote over the weekend:&lt;/p&gt;

&lt;p class=&quot;st-markup&quot;&gt;&lt;a href=&quot;http://www.kayodeok.co.uk/weblog/200402/01/hack_ie_my_computer_zone.html&quot;&gt;Hacking Internet Explorer's My Computer Zone&lt;/a&gt;&lt;/p&gt;

&lt;p class=&quot;st-markup&quot;&gt;Basically, you lock down IE by tweaking the IE Security Zones and also the options on the &amp;quot;Advanced&amp;quot; Tab.&lt;/p&gt;

&lt;p class=&quot;st-markup&quot;&gt;If you are not comfortable doing this, then you may wish to install &lt;a href=&quot;http://www.staff.uiuc.edu/~ehowes/resource6.htm&quot;&gt;Eric Howes' Enough is Enough&lt;/a&gt; or look at his &lt;a href=&quot;http://www.staff.uiuc.edu/~ehowes/resource.htm#IESPYAD&quot;&gt;IESPYAD&lt;/a&gt;&lt;/p&gt;

</description>
		</item>
		<item>
			<title>by Bruno Bord</title>
			<link>http://keithdevens.com/weblog/archive/2004/Feb/01/spyware#comment3868</link>
			<guid isPermaLink="false">http://keithdevens.com/weblog/4689#comment3868</guid>
			<pubDate>Wed, 04 Feb 2004 00:48:40 +0000</pubDate>
			<description>&lt;p class=&quot;st-markup&quot;&gt;I read somewhere that the &amp;quot;Ad aware&amp;quot; engine was in fact, stolen to  SpyBot.&lt;br /&gt;
The Bulletproof Inc. did the same...&lt;/p&gt;

&lt;p class=&quot;st-markup&quot;&gt;The genuine Spybot engine can be found at &lt;a href=&quot;http://security.kolla.de/&quot;&gt;http://security.kolla.de/&lt;/a&gt;&lt;/p&gt;

</description>
		</item>
		<item>
			<title>by Sparticus</title>
			<link>http://keithdevens.com/weblog/archive/2004/Feb/01/spyware#comment3876</link>
			<guid isPermaLink="false">http://keithdevens.com/weblog/4689#comment3876</guid>
			<pubDate>Wed, 04 Feb 2004 10:12:43 +0000</pubDate>
			<description>&lt;p class=&quot;st-markup&quot;&gt;Sweet! Thanks very much&lt;/p&gt;

</description>
		</item>
		<item>
			<title>by Paddy</title>
			<link>http://keithdevens.com/weblog/archive/2004/Feb/01/spyware#comment4158</link>
			<guid isPermaLink="false">http://keithdevens.com/weblog/4689#comment4158</guid>
			<pubDate>Wed, 17 Mar 2004 05:56:29 +0000</pubDate>
			<description>&lt;p class=&quot;st-markup&quot;&gt;How do you feel about Spyhunter?   I use Spybot S&amp;amp;D,  but a friend suggests this is better... &lt;/p&gt;

&lt;p class=&quot;st-markup&quot;&gt;Paddy&lt;/p&gt;

</description>
		</item>
		<item>
			<title>by Keith</title>
			<link>http://keithdevens.com/weblog/archive/2004/Feb/01/spyware#comment4159</link>
			<guid isPermaLink="false">http://keithdevens.com/weblog/4689#comment4159</guid>
			<pubDate>Wed, 17 Mar 2004 06:06:43 +0000</pubDate>
			<description>&lt;p class=&quot;st-markup&quot;&gt;I think both Spy Hunter and Spy Killer are &lt;em&gt;themselves&lt;/em&gt; spyware. I was pretty surprised when I found that out. I'm not &lt;em&gt;completely&lt;/em&gt; sure that they are, but I don't trust them.&lt;/p&gt;

</description>
		</item>
		<item>
			<title>by Mark Henly</title>
			<link>http://keithdevens.com/weblog/archive/2004/Feb/01/spyware#comment4764</link>
			<guid isPermaLink="false">http://keithdevens.com/weblog/4689#comment4764</guid>
			<pubDate>Mon, 14 Jun 2004 06:11:33 +0000</pubDate>
			<description>&lt;p class=&quot;st-markup&quot;&gt;We have added a removal feature for some of the symptoms you mentioned &lt;a href=&quot;http://spyware.removal.nospyx.com/free/spyware-scan/&quot;&gt;http://spyware.removal.nospyx.com/free/spyware-scan/&lt;/a&gt; If anyone wants a free scan. This is a new product but its catching tons of spyware. I would love a review guys&lt;/p&gt;

</description>
		</item>
	</channel>
</rss>
