# Advanced spyware removal help needed

**URL:** <https://boards.straightdope.com/t/advanced-spyware-removal-help-needed/308150>\
**Category:** In My Humble Opinion\
**Created:** [June 13, 2005, 10:30pm UTC](https://boards.straightdope.com/t/advanced-spyware-removal-help-needed/308150 "2005-06-13T22:30:39Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![kanicbird](https://avatars.discourse-cdn.com/v4/letter/k/5f8ce5/32.png) [@kanicbird](https://boards.straightdope.com/u/kanicbird)\
**Post date:** [June 13, 2005, 10:30pm UTC](https://boards.straightdope.com/t/advanced-spyware-removal-help-needed/308150/1 "2005-06-13T22:30:39Z")

</div>

For most computers running several antispyware programs seems to do it, but on a few it doesn’t help as things seem to come back. Random registry keys seem to load BHO’s on startup.

Programs like Hijack this allow me to remove them, but they come back, MS Anitspware allows me to block them on startup, but I have to reblock them each startup.

What is the next step? Any good sites on how to go about getting these nasties off the system?

---

<div class="post-metadata">

**Author:** ![Alien](https://avatars.discourse-cdn.com/v4/letter/a/57b2e6/32.png) [@Alien](https://boards.straightdope.com/u/Alien)\
**Post date:** [June 13, 2005, 11:43pm UTC](https://boards.straightdope.com/t/advanced-spyware-removal-help-needed/308150/2 "2005-06-13T23:43:39Z")

</div>

The next step is to identify the program, then find (google) a program written to remove said program, or simply hunt down the details and remove it manually from disk and registry (registry backup recommended beforehand).

What you have (?) is one or more instances of an installer (exe program, activex, etc) stored on our harddrive. Usuall, registry keys reinstalls them. I hardly ever get infected, but a family member’s computer had one with 6 identical secret installers, all with different file names and extensions and spread out in various loations on c-disk.

---

<div class="post-metadata">

**Author:** ![Giraffe](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/giraffe/32/129_2.png) [@Giraffe](https://boards.straightdope.com/u/Giraffe)\
**Post date:** [June 14, 2005, 12:06am UTC](https://boards.straightdope.com/t/advanced-spyware-removal-help-needed/308150/3 "2005-06-14T00:06:12Z")

</div>

I recently got a spyware infection. After two days of trying every remedy Google could throw at me, I still had at least one hidden installer that no one seemed to know how to get rid of. (My searches seemed to indicate that this was a very recent flavor.)

I finally decided it was quicker and easier to just reformat the hard drive and reinstall, rather than try to comb through the registry and ferret it out manually. And not to turn off ZoneAlarm any more.

---

<div class="post-metadata">

**Author:** ![Fear\_Itself](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/fear_itself/32/19637_2.png) [@Fear\_Itself](https://boards.straightdope.com/u/Fear_Itself)\
**Post date:** [June 14, 2005, 12:21am UTC](https://boards.straightdope.com/t/advanced-spyware-removal-help-needed/308150/4 "2005-06-14T00:21:36Z")

</div>

> [@kanicbird](#):
>
> Any good sites on how to go about getting these nasties off the system?

I normally recommend the [SpywareInfo removal forum](http://www.spywareinfo.com/forumsdown.php), but it has recently suffered a meltdown, with no estimate on repair time. The next best option is [BleepingCompute](http://www.bleepingcomputer.com/)r, post your HJT log in their forum and a crackerjack volunteer will guide you through the removal process.

That being said, if you have what is known as a ‘rootkit’ variety of spyware, you might as well reformat and reinstall. I just attended a Microsoft webcast on rootkit removal, and they basically said if you have a rootkit, you have to reformat. This may change as the arms race between the white hats and the black hats continues, but at this time we are SOL against rootkits.

---

<div class="post-metadata">

**Author:** ![Dewey\_Finn](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dewey_finn/32/4222_2.png) [@Dewey\_Finn](https://boards.straightdope.com/u/Dewey_Finn)\
**Post date:** [June 14, 2005, 1:20am UTC](https://boards.straightdope.com/t/advanced-spyware-removal-help-needed/308150/5 "2005-06-14T01:20:57Z")

</div>

What’s a rootkit variety, and how can you tell if the system is infected with one?

---

<div class="post-metadata">

**Author:** ![carnivorousplant](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/carnivorousplant/32/3563_2.png) [@carnivorousplant](https://boards.straightdope.com/u/carnivorousplant)\
**Post date:** [June 14, 2005, 1:47am UTC](https://boards.straightdope.com/t/advanced-spyware-removal-help-needed/308150/6 "2005-06-14T01:47:09Z")

</div>

> [@Giraffe](#):
>
> I finally decided it was quicker and easier to just reformat the hard drive and reinstall,

Amen, Brother.  
Especially when you do it for a living.  
🙂

---

<div class="post-metadata">

**Author:** ![Giraffe](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/giraffe/32/129_2.png) [@Giraffe](https://boards.straightdope.com/u/Giraffe)\
**Post date:** [June 14, 2005, 2:12am UTC](https://boards.straightdope.com/t/advanced-spyware-removal-help-needed/308150/7 "2005-06-14T02:12:00Z")

</div>

> [@carnivorousplant](#):
>
> Amen, Brother.  
> Especially when you do it for a living.  
> 🙂

It wasn’t easy, either. I fancy myself to be quite handy with computers, so it was hard to admit defeat. But once I got past that, it was obviously the right decision, as my intense desire to punch the computer abated almost immediately. 🙂

---

<div class="post-metadata">

**Author:** ![carnivorousplant](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/carnivorousplant/32/3563_2.png) [@carnivorousplant](https://boards.straightdope.com/u/carnivorousplant)\
**Post date:** [June 14, 2005, 3:12am UTC](https://boards.straightdope.com/t/advanced-spyware-removal-help-needed/308150/8 "2005-06-14T03:12:48Z")

</div>

How much anti spyware are most folks running? I have an anti virus program of course. I’ve never gotten spyware, but then I run as a limited user and don’t [shoot the duck](http://www.ucomics.com/boondocks/2005/06/07/) .  
Warning: There’s probably a duck to shoot on that page.  
I run anti spyware to clean up an infected client, but I don’t leave it active. That’s just fewer resources available for the PC, particularly Win 98 machines.

---

<div class="post-metadata">

**Author:** ![Fear\_Itself](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/fear_itself/32/19637_2.png) [@Fear\_Itself](https://boards.straightdope.com/u/Fear_Itself)\
**Post date:** [June 14, 2005, 3:40am UTC](https://boards.straightdope.com/t/advanced-spyware-removal-help-needed/308150/9 "2005-06-14T03:40:55Z")

</div>

> [@Dewey Finn](#):
>
> What’s a rootkit variety, and how can you tell if the system is infected with one?

You can use [Rootkit Revealer from Sysinternals](http://www.sysinternals.com/Utilities/RootkitRevealer.html) to determine if you have one, but note this does nothing to remove it. Even this tool isn’t foolproof:

> [@](#):
>
> Is there a sure-fire way to know of a rootkit’s presence?
> 
> In general, not from within a running system. A kernel-mode rootkit can control any aspect of a system’s behavior so information returned by any API, including the raw reads of Registry hive and file system data performed by RootkitRevealer, can be compromised. While comparing an on-line scan of a system and an off-line scan from a secure environment such as a boot into an CD-based operating system installation is more reliable, rootkits can target such tools to evade detection by even them.
> 
> **The bottom line is that there will never be a universal rootkit scanner** , but the most powerful scanners will be on-line/off-line comparison scanners that integrate with antivirus.

Also, it only works on WinXP, Win2K, and WinNT.

---

<div class="post-metadata">

**Author:** ![romansperson](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/romansperson/32/17100_2.png) [@romansperson](https://boards.straightdope.com/u/romansperson)\
**Post date:** [June 14, 2005, 3:04pm UTC](https://boards.straightdope.com/t/advanced-spyware-removal-help-needed/308150/10 "2005-06-14T15:04:20Z")

</div>

It’s easier to do what **Giraffe** suggests and just wipe your system clean, but if you really want to play sleuth, here’s what we recommend here:

1. Download Ewido Security Suite at [http://www.ewido.net/en/download/](http://www.ewido.net/en/download/) and install it. Update to the newest definitions. Do NOT run it yet.

2. Download nailfix at [http://andymanchesta.com/Downloads/nailfix.zip](http://andymanchesta.com/Downloads/nailfix.zip) (for Windows XP) or [http://andymanchesta.com/Downloads/nailfix2k.zip](http://andymanchesta.com/Downloads/nailfix2k.zip) (for Windows 2000) Unzip it to the desktop but do NOT run it yet.

3. Download KillBox [http://www.greyknight17.com/spy/KillBox.exe](http://www.greyknight17.com/spy/KillBox.exe). Don’t run it yet.

4. Download HijackThis [http://www.majorgeeks.com/downloadget.php?id=3155&file=11&evp=3304750663b552982a8baee6434cfc13](http://www.majorgeeks.com/downloadget.php?id=3155&file=11&evp=3304750663b552982a8baee6434cfc13). Don’t run it yet.

5. Download Adaware [http://www.download.com/Ad-Aware-SE-Personal-Edition/3000-8022\_4-10399602.html?tag=lst-0-1](http://www.download.com/Ad-Aware-SE-Personal-Edition/3000-8022_4-10399602.html?tag=lst-0-1) and install it. Update to the newest definitions. Don’t run it yet.

6. Download Spybot [http://www.download.com/Spybot-Search-Destroy/3000-8022\_4-10401314.html?tag=lst-0-1](http://www.download.com/Spybot-Search-Destroy/3000-8022_4-10401314.html?tag=lst-0-1) and install it. Update to the newest definitions. Don’t run it yet.

7. Download Spysweeper [http://www.download.com/Webroot-Spy-Sweeper/3000-8022\_4-10373771.html](http://www.download.com/Webroot-Spy-Sweeper/3000-8022_4-10373771.html) and install it. Update to the newest definitions. Don’t run it yet.

8. Update your anti-virus program to the newest definitions. Don’t run it yet.

9. Reboot into Safe Mode by hitting the F8 key repeatedly until a menu shows up (and choose Safe Mode from the list). In some systems, this may be the F5 key, so try that if F8 doesn’t work.

10. Once in Safe Mode, please double-click on nailfix.cmd (or nailfix2k.bat if you have Windows 2000). Your desktop and icons will disappear and reappear, and a window should open and close very quickly — this is normal.

11. Next run a full scan in Ewido.

12. Run a scan in HijackThis. Check each of the following and hit ‘Fix checked’ (after checking them) if they still exist (make sure not to miss any):

**these are not the only files to delete, remove any other suspicious files (i.e. mediaaccess, abetterinternet, aurora)**

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default\_Search\_URL = about:blank  
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [http://www.onet.pl/](http://www.onet.pl/)  
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page\_bak = [http://www.onet.pl/](http://www.onet.pl/)  
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =  
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe  
O2 - BHO: BolgerObj Class - {302A3240-4805-4a34-97D7-1645A0B08410} - C:\WINDOWS\Bolger.dll  
O4 - HKLM…\Run: [tustkk] c:\windows\system32\benbqpb.exe  
O9 - Extra button: (no name) - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates\_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)  
O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) - [http://bezpieczenstwo.onet.pl/skaner/SkanerOnline.cab](http://bezpieczenstwo.onet.pl/skaner/SkanerOnline.cab)  
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe

1. Close all open windows except for HijackThis and click Fix Checked.

2. Run KillBox and check the box that says ‘End Explorer Shell While Killing File’. Next click on ‘Delete on Reboot’. For each of the following files below, check the box that says ‘Unregister .dll Before Deleting’ if it’s not grayed out. Copy and paste each of the following into KillBox (hitting the X button for each file - choose NO when it asks if you want to reboot):

c:\windows\system32\benbqpb.exe  
C:\WINDOWS\Nail.exe  
C:\WINDOWS\Bolger.dll  
C:\Program Files\Ebates\_MoeMoneyMaker  
C:\WINDOWS\svcproc.exe

1. Run a full scan of Adaware and remove any spyware found.

2. Run a full scan of Spybot and remove any spyware found.

3. Run a full scan of Spysweeper and remove any spyware found.

4. Search the registry (start-\>run-\>regedit) for any spyware programs found in hkey\_local\_machine\software\microsoft\windows\currentversion\run or hkey\_current\_user\software\microsoft\windows\currentversion\run

5. Run msconfig (start-\>run-\>msconfig) and remove any spyware programs found in startup.

6. Do a search on the computer for any remanents of spyware on the computer and delete them. Examples of things to search for (but not limited to):

benbqpb.exe  
nail.exe  
bolger.dll  
ebates\_moemoneymaker  
svcproc.exe  
mediaaccess

1. Run a full virus scan and remove any viruses found according to instructions found on your anti-virus program’s web site.

2. Reboot into normal mode.

This takes about 3 or 4 hours to do.

---

<div class="post-metadata">

**Author:** ![Marley23](https://avatars.discourse-cdn.com/v4/letter/m/45deac/32.png) [@Marley23](https://boards.straightdope.com/u/Marley23)\
**Post date:** [June 14, 2005, 3:41pm UTC](https://boards.straightdope.com/t/advanced-spyware-removal-help-needed/308150/11 "2005-06-14T15:41:44Z")

</div>

I had a similar problem with a virus and spyware this past weekend. I ran Norton, AdAware and Spybot, and none of them worked. After I tried downloading and running a few other programs to no effect, a friend advised me to get SpySearch, restart the computer in Safe Mode, then run Norton and SpySearch again. That worked, and after I restarted the computer again in regular mode, everything was fine. Somebody else could probably talk you through the details of how to do that better than I can.

---

<div class="post-metadata">

**Author:** ![kanicbird](https://avatars.discourse-cdn.com/v4/letter/k/5f8ce5/32.png) [@kanicbird](https://boards.straightdope.com/u/kanicbird)\
**Post date:** [June 15, 2005, 10:42pm UTC](https://boards.straightdope.com/t/advanced-spyware-removal-help-needed/308150/12 "2005-06-15T22:42:00Z")

</div>

Update, it does not seem to be a rootkit. So I think it’s an installer. What is the best way to find it and getting rid of it? Just running all antispyware programs in safemode?

---

<div class="post-metadata">

**Author:** ![Fear\_Itself](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/fear_itself/32/19637_2.png) [@Fear\_Itself](https://boards.straightdope.com/u/Fear_Itself)\
**Post date:** [June 16, 2005, 2:03am UTC](https://boards.straightdope.com/t/advanced-spyware-removal-help-needed/308150/13 "2005-06-16T02:03:52Z")

</div>

> [@kanicbird](#):
>
> Update, it does not seem to be a rootkit. So I think it’s an installer. What is the best way to find it and getting rid of it? Just running all antispyware programs in safemode?

**romansperson** ’s advice seems pretty complete. If that doesn’t remove it, nothing will.

---

<div class="post-metadata">

**Author:** ![Mama\_Zappa](https://avatars.discourse-cdn.com/v4/letter/m/71e660/32.png) [@Mama\_Zappa](https://boards.straightdope.com/u/Mama_Zappa)\
**Post date:** [June 16, 2005, 2:28pm UTC](https://boards.straightdope.com/t/advanced-spyware-removal-help-needed/308150/14 "2005-06-16T14:28:13Z")

</div>

A slight hijack here: What’s a good way to tell whether your computer may have picked up spyware if you don’t see any obvious unusual behavior? No browser hijacks or unusual popups.

We run ZoneAlarm Pro. We also periodically update and run Ad-Aware and Spybot and all they ever turn up is tracking cookies. However Ad-Aware hasn’t succeeded in finding an updated definitions file since _October_ so it may be missing things.

Should I routinely run Hijack This and/or some of the other tools mentioned here, “just in case”? or should I be reasonably confident that “no odd behavior” + “ZoneAlarm” = safe computer? We recently got broadband (cable modem) so I know our risk is higher than it used to be.

---

<div class="post-metadata">

**Author:** ![Marley23](https://avatars.discourse-cdn.com/v4/letter/m/45deac/32.png) [@Marley23](https://boards.straightdope.com/u/Marley23)\
**Post date:** [June 16, 2005, 2:33pm UTC](https://boards.straightdope.com/t/advanced-spyware-removal-help-needed/308150/15 "2005-06-16T14:33:31Z")

</div>

> [@Mama Zappa](#):
>
> We run ZoneAlarm Pro. We also periodically update and run Ad-Aware and Spybot and all they ever turn up is tracking cookies. However Ad-Aware hasn’t succeeded in finding an updated definitions file since _October_ so it may be missing things.

Are you running the full scan or the smart scan?

> [@](#):
>
> Should I routinely run Hijack This and/or some of the other tools mentioned here, “just in case”?

During the crisis I described, the friend who got me through it offered Hijack This only as a last resort and called it “the sledgehammer of the spyware toolkit.” It’s indiscriminate and picks up more than just spyware. It warns you of this fact. So if you run it and don’t know exactly what everything is, you can end up deleting things you really need. So with my limited knowledge I’d recommend against using that thing.

---

<div class="post-metadata">

**Author:** ![Fear\_Itself](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/fear_itself/32/19637_2.png) [@Fear\_Itself](https://boards.straightdope.com/u/Fear_Itself)\
**Post date:** [June 16, 2005, 2:35pm UTC](https://boards.straightdope.com/t/advanced-spyware-removal-help-needed/308150/16 "2005-06-16T14:35:31Z")

</div>

> [@Mama Zappa](#):
>
> However Ad-Aware hasn’t succeeded in finding an updated definitions file since _October_ so it may be missing things.

Download the current version of [AdAware SE Personal v.106](http://www.download.com/Ad-Aware-SE-Personal-Edition/3000-8022_4-10045910.html?part=dl-ad-aware&subj=dl&tag=top5). It is a new program that came out on 5/27; the older versions are not upgradable anymore.
