Categories Menu
Repair Center
24 hours online support we repair all types of laptops and relating to LCD screen,motherboard, DC adapter, power supplies and so much more! The shop reliable laptop repair in Ottawa area since 1995. Repair your laptop as easy as 1-2-3 !
computer_25
Services for your location
How to Clean Up a Windows Spyware Infestation
print
report error
add to favorites
write a review
send to friends
suggest a topic
register
anning for blank Publishers, or any Publisher you don't recognize. If you see anything that's suspect, delete it! In a default Windows install, 99.5% of the entries will have "Microsoft Corporation" as the Publisher. Any reputable vendor will have no problem attaching their name to their work, so it's generally only the blank entries you need to worry about.

Now reboot the system. We've removed most of the spyware infestation, but there's a certain much more virulent class of spyware that can survive this treatment. We'll deal with them next.

After rebooting, check Process Explorer and Autoruns for anything suspicious, exactly as we did before. The first thing I noticed that "came back" in Autoruns was a suspicious driver, core.sys, that didn't have a Publisher. I used the powerful Find | Find Handle or DLL menu in Process Explorer to locate any active references to this file.

spyware: process explorer find

Unfortunately I didn't capture the right screenshot at the time, so I'm showing a generic search result above. Anyway, there was exactly one open handle to the core.sys file. I selected the result, which highlights the corresponding handle in the lower pane of the Process Explorer view. Right-click the handle entry in the lower pane and click "Close Handle".

spyware: process explorer, close handle

After I closed the handle, I could physically delete the rogue core.sys file from the filesystem, along with the Autoruns entry for it. Problem solved!

The other item that reappeared in Autor
Other newly Articles from the Security and BIOS updates - Anti-virus /anti-Spyware Category:
  1. Solved: Trojan named AppInit.dll
  2. How to Secure Your PC from Hackers, Virus and other Online Threats
  3. Remove Antivirus Soft. Description and removal instructions
  4. Kill viruses under Windows safe mode
  5. Fix an Unbootable Windows XP or Vista, Remove Boot Virus from Startup
  6. Google Hijack Virus - How to Remove the Google Hijack Virus
  7. Enable or Disable UAC From the Windows 7 / Vista Command Line
  8. How To Remove Security Tool and other Rogue/Fake Antivirus Malware
  9. AppInit Dlls - How do I remove a resident .dll? Help!
  10. Tips to defend PHP Trojan attack effectively
  11. How to kill the running exe and dll viruses?
  12. Solution for the virus drwtsn32.exe
  13. Check up—whether hackers invaded your computer?
  14. Disable "Your computer might be at risk" Popup in Windows XP SP2
  15. infected by: Trojan-Spy.Win32.Agent.azpj - please help
Custom Search
Examples: HP,laptop Rapair,LCD,DC Backlight,Inverter,solder
Article Comment:Replies(0)Views
Name(required):        Email(required):  
Verify: key
Use the above information at your own risk
Loading ... Loading ...