|
|
Learn how to track and find spyware - Your best defense!
Become famaliar with your system startup. System startup is the list of programs that run everytime your computer is rebooted. It is more complex then
just a simple list, as many system related things startup in the background also, but if you click "start" then "run", then type "msconfig" in the box
and click ok to run it, you will see a window open. Click the startup tab on that window and it will show a list of programs that are running. These
run automatically whenever you reboot your system. This is a good thing to monitor, as if you get spyware, adware, or viruses, often they will
suddenly appear in this list. That's because if the programs have no way to automatically start after you shutdown, then they become useless once
you reboot. If they are in this list, they will run instantly (and therefore continue running) when you reboot your computer. You may see normal programs
here like AIM instant messenger, Yahoo messenger, hardware related programs, and other programs like this that automatically appear in your system tray when you boot up. That
is how the programs automatically run and show in your system tray. As I mentioned it is more complex then this, as there are services and BHO's that
can run separately from this list, but this is a good start becoming familiar with this. You can also uncheck and make it so the programs do not run
when your reboot. If you are someone that makes alot of changes on your computer, or installs
and runs alot of software programs, then I suggest using a program like
Disk and Registry Alert which will show you everything that is installed on your
computer. Basically you scan your system immediately before installing software, then immediately after, and it shows you all the differences on
your hard drive and registry both. It's not necessarily a cleanup program, but is a must for those who install any software on their system.
It will give you ease of mind, and it show you exactly which programs were put on your pc, and where they are located. It also works good to make sure
program uninstalls have really removed everything that was installed, and helps keep your system clean.
Become familiar with your task list and task manager. When you press CTRL-ALT-DELETE your task list appears, this is the tab named
"Processes". It shows everything currently running in the background on your computer. For example, if you open Internet Explorer, you will
see a process appear in your list named "iexplore.exe". Close Internet Explorer and this task will disappear. Although the list may be fairly
large, it is good to become familiar with this and at least look at it at times. You can also check your performance under the performance tab.
If your cpu usage or memory suddenly is maxed out, then thats not a good sign as something may be now running in the background that is causing
this. If you want to lookup what the task names are to see if they are spyware or virus related, look them up on this
task list page.
Learn what booting your computer in safe mode means, as there will come a time when you need to reboot into safe mode due to a virus or spyware.
Safe mode is a state on your computer where only the very basic programs run during bootup. This means that you will be able to delete those virus
or spyware modules that automatically replace themselves. If you ever had one of these rogue programs (Zlob, VirusBurst, etc), you know how frustrating
it is. To boot into safe mode, press and hold down the F8 key during bootup. A dos menu will appear and safe mode can be chosen. Your screen will
be ugly when it boots up, as many drivers will not run, but this is just a temporary measure until you delete the rogue software that you want to get
rid of. Once gone just reboot and your computer is back to normal. It is also better to run your virus
scanner or spyware cleaner in safe mode, as that way they will also have full access to delete the necessary viruses. Files like the Zlob virus
and VirusBurst are 2 that need cleaning in safe mode, and many others are like them. I intentionally installed the Zlob virus to learn about it,
and it put files at C:\WINDOWS\system32\kdrzg.exe and C:\WINDOWS\system32\kdid.exe, but these names can change. You cannot delete them and cannot
remove them from the registry as they immediately reappear. Safemode is your savior here! There is also various reports on rootkit viruses
withe the Zlob virus.
Some spyware and adware becomes a hidden "add on" when you install free software. Remember that free software (called freeware, freeware is different
from shareware, as shareware usually costs money) is usually free for a reason. Most companies will not spend all their time supporting and writing
something to give away free, unless they have a way to get some money in return (can't blame them, it makes business sense), so they get paid to embed
hidden programs in with your free programs. These programs (called spyware or adware) track you, display ads to you, create pop up windows, or use
your machine resources, among other things.
Become familiar with system restore! This is automatically done for you in Windows. System restore means you can move your system registry back to
a previous state (for example the day before you got the pc virus). This is a great thing that allows you to automatically reset back, so that any
virus changes made to your regsitry are simply gone. No reason to do any cleanup, just eliminate it and go back. This is as easy as selecting the option
on which day you want. Booting your computer in safe mode and using system restore are 2 of your best secrets to getting rid of a pesky virus or spyware
program!
Note that with your latest Windows systems, like Vista, 7, or later .... viruses and spyware are almost always places in the users - owner folder path.
This is because Windows doesn't allow access to much of the hard drive, unlike earlier systems. So it is much easier to indentify and find viruses today.
Other help pages and tips:
Get help - ask or post your questions
Security and privacy tips homepage
|