Prevention or Cure?

  • Thread starter Thread starter Chris
  • Start date Start date
C

Chris

Is the Antispyware product supposed to prevent spyware or
cure it?

Having loaded the software, I was casually browsing some
web pages and I was suddenly hit by a number of spyware
messages. I told the application to block them, and my
virus scanner also started picking up one or two bits.
Having thought I had overted the problem, I closed all
browsers and was asked to do a full scan, which I did. I
was then confrunted with a report that my system had 14
different bits of spyware installed and would i like to
get rid of it. All my IE settings (default home, default
search, favourites) had been changed. As far as I can
tell I had been hijacked and nither the MS Antispyware,
or the antivirus could stop it.

I have since cleaned all traces from my machine, but
still get annoying popups which I am sure are a result of
the attack (I am running XP SP2 with firewall and popup
blocker turned on.)

Does anyone have any advice (my view is to rebuild my
machine, I could be keylogged or anything!)???
 
If you have a trojan in place, rebuilding the machine is not an unreasonable
option, although this statement evokes controversy among folks who repair
this kind of thing for a living.

It isn't the first thing I would think of in the situation you describe,
however--a sudden inundation due to clearly commercial adware. I would
recommend that you restart in safe mode and scan twice. Also check add or
remove programs for anything new listed there that you do not recognize.

Microsoft Antispyware is intended to provide active protection against new
installations, as well as cleaning functionality, so it looks like this
failed in your particular situation.
 
Hi,

Yeah, I'm getting the same. If I am having the option to
block, why does it still install itself onto the PC?

The actual program does appear good at present and could
be great once all the issues are addressed.
 
I have seen an issue where the option to block appears "late"--i.e. well
after the action you are blocking has taken place. I believe this is a
performance issue in the product--I hadn't seen it with an actual
installation issue such as both of you are describing. This is a serious
bug. I'll see what I can do about documenting it well.
 
Back
Top