The MASM Forum Archive 2004 to 2012

Miscellaneous Forums => The Orphanage => Topic started by: shankle on September 11, 2006, 11:48:56 PM

Title: Spyware Software
Post by: shankle on September 11, 2006, 11:48:56 PM
I have been running Ad-Aware by Lavasoft for quite awhile. Lately it found
a trojan "Win32.Trojandownloader.Zlob". I ran Ad-Aware and quarantined
the offending Trojan. Being the skeptic that I am, I ran it again and the same
trojan showed up as if I never quarantined it.
It seems to reside in 2 places:
  HKEY_CLASSES_ROOT: clsid\(202a961f-23ae-42b1-9505-ffe3c818d717)
  HKEY_LOCAL_MACHINE:software\microsoft\windows\current version\explorer\browser helper
    objects\(202a961f-23ae-42b1-9505-ffe3c818d717)
I know next to nothing about the Registry and would be very reluctamt to change
anything there. That's why I have Registry Mechanic.

So now I'm out shopping for a new spyware program.
The ones I am looking at are as follows:
    Spyware Detector
    Stopzilla
    Spyware Doctor

I really don't want one that does half the job.
I looked on this site but was unable to find anything pertinent.

Regards,
JPS







Title: Re: Spyware Software
Post by: hutch-- on September 12, 2006, 06:23:17 AM
Jack,

It means the spyware/malware app is rewriting the registry key each time it is deleted. Its being detected OK but you need to find where the key is being rewritten from.
Title: Re: Spyware Software
Post by: drhowarddrfine on September 12, 2006, 12:11:20 PM
I'm surprised adaware detected it at all since it is not an anti-virus program.  You need to use AVG from grisoft.com.  Just a few days ago I started using the free one from AOL, of all people.  It detected five sleeping trojans in some old zip files I had in my archive folders which AVG never knew about.
Title: Re: Spyware Software
Post by: Ghirai on September 12, 2006, 12:28:29 PM
You're using IE, right?
Title: Re: Spyware Software
Post by: pro3carp3 on September 12, 2006, 01:54:05 PM
An article in PC Magazine that a read recently suggests using two spy-ware removal programs- One commercial and one free.  Each kind is designed from a different perspective and with the two, you will have better protection than using one or the other.
Title: Re: Spyware Software
Post by: shankle on September 12, 2006, 01:59:47 PM
DrHowarddrfine - It's a different program called Ad-Adware by Lavasoft.

Ghirai - I'm using Mozilla's FireFox.

Thanks for responding,
JPS
Title: Re: Spyware Software
Post by: drhowarddrfine on September 12, 2006, 06:13:39 PM
Yes, I'm familiar with Ad-Aware and that's what I meant.  I do not believe Ad-Aware is designed for trojans, viruses, and the like.  That is why I'm surprised when you say it caught a trojan.  Still, I recommend the two programs above.  Symantec also has virus removal tools and methods you can find for free on their site.
Title: Re: Spyware Software
Post by: skywalker on September 12, 2006, 09:44:26 PM
Spybot is real good. Been using it for 5+ years. Freeware and it has command line options as well.

Title: Re: Spyware Software
Post by: Vortex on September 13, 2006, 05:42:26 AM
Anyone who tried MS Windows Defender?
Title: Re: Spyware Software
Post by: sinsi on September 13, 2006, 05:44:52 AM
Windows Defender, AVG free and the Windows firewall - no problems in ~ 2 years.
Title: Re: Spyware Software
Post by: drhowarddrfine on September 13, 2006, 12:14:50 PM
But, again, Spybot isn't anti-virus, is it?  Spyware and virii are not always the same thing.
Title: Re: Spyware Software
Post by: Ghirai on September 13, 2006, 03:03:23 PM
I'm asking if you use IE because that think looks like a BHO.

And you shouldn't rely on Windows Firewall, trust me :bg
Title: Re: Spyware Software
Post by: Vortex on September 13, 2006, 04:59:15 PM
Quote from: Ghirai on September 13, 2006, 03:03:23 PM
And you shouldn't rely on Windows Firewall, trust me :bg

That's true. If I am not wrong, Windows Firewall is responsible only for outgoing connections.
Title: Re: Spyware Software
Post by: Ghirai on September 13, 2006, 06:00:45 PM
Even so, it's very easy to bypass it, so do not rely on it.
Title: Re: Spyware Software
Post by: DarkWolf on October 19, 2006, 01:10:35 AM
For Spyware Trojans etc..

Ad-aware     lavasoft.com or lavasoft.de
A2     emsisoft.com
Spybot Search and Destroy     spybot.info
AVG Anti-Spyware     free.grisoft.com

For Virus
AVG     free.grisoft.com
Avast (sorry, i can't remember)

You should run Ad-aware and other spyware removers from 'safe mode' where most software has not been started and can be removed before it rewrite. Ad-aware also has settings to remove software on a reboot, before the system restarts and the spyware rewrites files or registry.