Security Basics mailing list archives

Re: Removing xupiter, spyware, malware


From: "Morton B. Maser" <MBMaser () msn com>
Date: Thu, 31 Jul 2003 15:44:45 -0700

Check out http://www.spywareinfo.com and http://www.wilders.org.
SpuwareBlaster and SpywarewareGuard are a nice little pair of freeware
utilities that will prevent them from installing in the first place, and -
if already installed - can usually disable them.

AdAware and SpyBot Search and Destroy are two other file scanners that do a
good job at removing both.  You also might want to download PestPatrol
(http://www.pestpatrol.com) for a 30 day free trial and try that.

All the above are small downloads and use minimal system resources.  Spybot
has an immunize feature similar to SpywareBlaster, but not as granular.
SpyBot also contains a feature (it's host list), that will send output from
known spyware to the local loop (127.0.0.1) rather than the intended URL.

Most of the current generation spyware/adware share many characteristics of
trojans and worms, and embed themselves in such a way that every time you
reboot they reload.  (lop has even gone so far as to install just an initial
installer on the first exposure, then it gradually "trickles" in the
necessary files over subsequent online sessions, making it very hard to
detect and eradicate early.

Hope this helps

M
----- Original Message ----- 
From: "Bill Hardstone" <rhardstone () eudoramail com>
To: <security-basics () securityfocus com>
Sent: Tuesday, July 29, 2003 3:14 AM
Subject: Removing xupiter, spyware, malware



Greetings,

Anyone has positively removed spyware/ adware/ malware/parasites i.e.
xupiters and other apps as memory meter, calender, etc. completely without
reinstalling the OS?


I have cleaned up the registry and and cleaned up the directory but it
shows up again. It even piggybacks on another process. So, the user can't
even see PID's in the task manager.

Any suggestions?


Need a new email address that people can remember
Check out the new EudoraMail at
http://www.eudoramail.com

--------------------------------------------------------------------------
-
--------------------------------------------------------------------------
--



---------------------------------------------------------------------------
----------------------------------------------------------------------------


Current thread: