g-smooth2k
08-17-2004, 01:54 PM
Information provided by Bleeping Computer (http://www.bleepingcomputer.com/forums/index.php?showtutorial=43)
Table of Contents
Introduction
Installing Spybot - Search & Destroy
Starting Spybot - Search & Destroy for the first time
Using Spybot - Search & Destroy
Using Spybot - Search & Destroy's Immunize Feature
Restoring fixed entries with Spybot - Search & Destroy
Introduction
If you suspect that you have spyware installed on your computer, then an excellent tool called Spybot - Search and Destroy can be used to remove them. Follow the instructions below to learn how to use Spybot - S&D to remove these programs from your computer. Word of warning, though, Spyware can sometimes be integrated tightly into software that you use, and if you remove the spyware, that software may not function correctly. So be careful as to what you remove.
Installing Spybot - Search & Destroy
The first step for spyware/hijacker removal is to download and install Spybot - S&D from the link below. After it is installed, continue with the following steps.
You can download Spybot - S&D from the following link: Spybot - Search and Destroy (http://www.safer-networking.org/index.php?page=spybotsd)
When you have downloaded the program, double click on the downloaded file to start the installation. Follow the default selections, agreeing to the user agreements, and pressing the Next button until you get to the Select Additional Tasks screen shown below in Figure 1.
http://img.photobucket.com/albums/v314/g-smooth2k/Spybot%20Search%20N%20Destroy%2013/installadd.gif
Figure 1: Installing Additional Tasks
Make sure you put a checkmark in the last checkbox labeled "Use system settings protection (Tea Timer)". After you place a checkmark in that box all checkboxes should have a check in them. Before you continue with the next step, let me explain what the permanent protection settings do.
SDHelper - This program will integrate into your Internet Explorer browser and block your browser from downloading "bad" programs from known malware sites.
TeaTimer - This program will constantly run on your computer in the background and notify you of any changes to system settings on your computer before they are allowed to happen.
NOTE: If you install TeaTimer and have another program that does a similar task, like SpywareGuard, they will both work, but you will get notifications from both of the programs. If you do not want double notifications, and you choose to use Spybot - S&D's TeaTimer, make sure you uninstall any other program that will do a similar task.
When you are ready you can now press the Next button and then the Install button to start the installation process. When the installation process is complete you will see an screen similar to Figure 2 below.
http://img.photobucket.com/albums/v314/g-smooth2k/Spybot%20Search%20N%20Destroy%2013/installend.gif
Figure 2: End of Installation.
Make sure there are checkmarks in both boxes as shown in Figure 2 above and then press Finish. Spybot - S&D will now start and TeaTimer will load into memory as a background application.
Starting Spybot - Search & Destroy for the first time
Step 1: Launch Spybot - S&D
If you told Spybot to launch when it was done installing, the program should now be open. Otherwise find the icon on your desktop and double-click on it. When you use Spybot - S&D for the first time, it will prompt you for certain tasks to complete. You should complete all tasks as described below.
Step 2: Backup your Registry
The first screen, similar to Figure 3 below, is to backup your registry in order to be able to restore from it in the future. This can cause no harm, so it is a worthwhile task to do.
http://img.photobucket.com/albums/v314/g-smooth2k/Spybot%20Search%20N%20Destroy%2013/regbackup.gif
Figure 3. Backup your Registry
You should click on the Create registry backup button, designated by the red box in Figure 3 above. This will create a backup of your registry and may take a few minutes so do not be alarmed if you feel the program is hanging. When it is completed, you should then click on the Next button.
Step 3: Update Spybot - S&D
The next screen you should see will be similar to figure 4 below.
http://img.photobucket.com/albums/v314/g-smooth2k/Spybot%20Search%20N%20Destroy%2013/instupdate.gif
Figure 4: Update Spybot - S&D
Click on the Search for updates button, as shown in the red box in figure 4 above. This will make Spybot connect to a server on the Internet and determine if there are any available updates for Spybot. If there are no updates available it will tell you so, and then you can click on the Next button.
If updates are available then the Download all available updates button will become available and you should click on that following the prompts. Unfortunately there are no new updates as I am writing this tutorial so I can not show you what it looks like.
When the updates are installed click on the Next button.
Step 3: Immunize Internet Explorer
You will now see a screen similar to figure 5 below.
http://img.photobucket.com/albums/v314/g-smooth2k/Spybot%20Search%20N%20Destroy%2013/installimu.gif
Figure 5: Immunize Internet Explorer
You should now click on the Immunize this system button designated by the red box in figure 5. This will immunize Internet Explorer so that you will not be allowed to download and run known malware or other malicious programs. After you click this button you should see an image similar to Figure 6 below which will show you that Spybot successfully immunized Internet Explorer.
http://img.photobucket.com/albums/v314/g-smooth2k/Spybot%20Search%20N%20Destroy%2013/installimm2.gif
Figure 6: Successful Immunization
You should now click on the Next button and then click on then click on the button labeled Start using this program to begin using Spybot - Search & Destroy. To learn how to use this program continue reading the next section.
Important Note: For people using the new version 1.3, it is ignoring a few malware products by mistake so it will not find them. To fix this click on the Mode menu option at the top and click on Advanced Mode. Reply Yes to the confirmation when it asks you. This will change the screen and give you different options. Click on Settings on the left hand side and then click on the Ignore Products section. Click on the All Products tab, and scroll through all the listed products and make sure there are no checkmarks in any of them. If there are, remove the check marks. Then click on the Mode menu option and switch back to Default Mode again.
Table of Contents
Introduction
Installing Spybot - Search & Destroy
Starting Spybot - Search & Destroy for the first time
Using Spybot - Search & Destroy
Using Spybot - Search & Destroy's Immunize Feature
Restoring fixed entries with Spybot - Search & Destroy
Introduction
If you suspect that you have spyware installed on your computer, then an excellent tool called Spybot - Search and Destroy can be used to remove them. Follow the instructions below to learn how to use Spybot - S&D to remove these programs from your computer. Word of warning, though, Spyware can sometimes be integrated tightly into software that you use, and if you remove the spyware, that software may not function correctly. So be careful as to what you remove.
Installing Spybot - Search & Destroy
The first step for spyware/hijacker removal is to download and install Spybot - S&D from the link below. After it is installed, continue with the following steps.
You can download Spybot - S&D from the following link: Spybot - Search and Destroy (http://www.safer-networking.org/index.php?page=spybotsd)
When you have downloaded the program, double click on the downloaded file to start the installation. Follow the default selections, agreeing to the user agreements, and pressing the Next button until you get to the Select Additional Tasks screen shown below in Figure 1.
http://img.photobucket.com/albums/v314/g-smooth2k/Spybot%20Search%20N%20Destroy%2013/installadd.gif
Figure 1: Installing Additional Tasks
Make sure you put a checkmark in the last checkbox labeled "Use system settings protection (Tea Timer)". After you place a checkmark in that box all checkboxes should have a check in them. Before you continue with the next step, let me explain what the permanent protection settings do.
SDHelper - This program will integrate into your Internet Explorer browser and block your browser from downloading "bad" programs from known malware sites.
TeaTimer - This program will constantly run on your computer in the background and notify you of any changes to system settings on your computer before they are allowed to happen.
NOTE: If you install TeaTimer and have another program that does a similar task, like SpywareGuard, they will both work, but you will get notifications from both of the programs. If you do not want double notifications, and you choose to use Spybot - S&D's TeaTimer, make sure you uninstall any other program that will do a similar task.
When you are ready you can now press the Next button and then the Install button to start the installation process. When the installation process is complete you will see an screen similar to Figure 2 below.
http://img.photobucket.com/albums/v314/g-smooth2k/Spybot%20Search%20N%20Destroy%2013/installend.gif
Figure 2: End of Installation.
Make sure there are checkmarks in both boxes as shown in Figure 2 above and then press Finish. Spybot - S&D will now start and TeaTimer will load into memory as a background application.
Starting Spybot - Search & Destroy for the first time
Step 1: Launch Spybot - S&D
If you told Spybot to launch when it was done installing, the program should now be open. Otherwise find the icon on your desktop and double-click on it. When you use Spybot - S&D for the first time, it will prompt you for certain tasks to complete. You should complete all tasks as described below.
Step 2: Backup your Registry
The first screen, similar to Figure 3 below, is to backup your registry in order to be able to restore from it in the future. This can cause no harm, so it is a worthwhile task to do.
http://img.photobucket.com/albums/v314/g-smooth2k/Spybot%20Search%20N%20Destroy%2013/regbackup.gif
Figure 3. Backup your Registry
You should click on the Create registry backup button, designated by the red box in Figure 3 above. This will create a backup of your registry and may take a few minutes so do not be alarmed if you feel the program is hanging. When it is completed, you should then click on the Next button.
Step 3: Update Spybot - S&D
The next screen you should see will be similar to figure 4 below.
http://img.photobucket.com/albums/v314/g-smooth2k/Spybot%20Search%20N%20Destroy%2013/instupdate.gif
Figure 4: Update Spybot - S&D
Click on the Search for updates button, as shown in the red box in figure 4 above. This will make Spybot connect to a server on the Internet and determine if there are any available updates for Spybot. If there are no updates available it will tell you so, and then you can click on the Next button.
If updates are available then the Download all available updates button will become available and you should click on that following the prompts. Unfortunately there are no new updates as I am writing this tutorial so I can not show you what it looks like.
When the updates are installed click on the Next button.
Step 3: Immunize Internet Explorer
You will now see a screen similar to figure 5 below.
http://img.photobucket.com/albums/v314/g-smooth2k/Spybot%20Search%20N%20Destroy%2013/installimu.gif
Figure 5: Immunize Internet Explorer
You should now click on the Immunize this system button designated by the red box in figure 5. This will immunize Internet Explorer so that you will not be allowed to download and run known malware or other malicious programs. After you click this button you should see an image similar to Figure 6 below which will show you that Spybot successfully immunized Internet Explorer.
http://img.photobucket.com/albums/v314/g-smooth2k/Spybot%20Search%20N%20Destroy%2013/installimm2.gif
Figure 6: Successful Immunization
You should now click on the Next button and then click on then click on the button labeled Start using this program to begin using Spybot - Search & Destroy. To learn how to use this program continue reading the next section.
Important Note: For people using the new version 1.3, it is ignoring a few malware products by mistake so it will not find them. To fix this click on the Mode menu option at the top and click on Advanced Mode. Reply Yes to the confirmation when it asks you. This will change the screen and give you different options. Click on Settings on the left hand side and then click on the Ignore Products section. Click on the All Products tab, and scroll through all the listed products and make sure there are no checkmarks in any of them. If there are, remove the check marks. Then click on the Mode menu option and switch back to Default Mode again.