Repeating spyware infections...

Soldato
Joined
26 Feb 2004
Posts
4,800
Location
Hampshire, England.
Hi guys,

A friend has got a vista desktop that at least 4 family members use on a regular basis: two adults and two children under 15...

Basically, every couple of months or so I get call asking to come and sort out numerous issues they are having as a result (usually) of a spyware infection. Sometimes from general web use, but mainly because they've (the unders 15's…) installed a dodgy app or web plugin!

They've all got their own accounts (but all are set as admin iirc) but the infections are usually always system-wide. I know there is no definitive answer for this kind of scenario, and I've tried all the usual; install av/spyware scanners, told them to be careful where they download from, keep windows up to date etc, but I always end up back to square one again with them :(

When I pick up there machine tomorrow to fix (re-install windows probably!) their latest infestation, what else is there I can do when I get it back to them; so far I've got two new things lined up...

1. Firefox with adblock+ and noscript - since using these two plugins, I have dramatically reduced the spyware on all of my machines.

2. Limit their local accounts - would this actually make any difference on a non-network controlled os? Sorry, I'm a bit ignorant here :)

What else can I do to stop this happening again, or at least reduce the frequency a bit? I use spybot, ccleaner, super-antispyware and anti-malware. All are run once/twice a month and I never get any problems. All of which are installed on their machine, but I don't think they run them regularly. Are there any real time protection apps out there that might do them?

Any thoughts?

Cheers.
 
i hope you get paid everytime you go to fix it ?

if you start charging them (like you should be) then they might take more effort in looking after and running the antispyware apps themselves
 
Make their accounts limited and make sure UAC is turned on, that should stop the infection spreading further than their own account.

Is Windows Defender turned on? That might stop a few of them getting through. Also, install a decent anti virus such as ESET NOD32.

I trust you're turning off system restore when removing spyware? Some spyware is designed to re-infect a system by restoring itself using system restore.
 
Without doubt number 2 would drastically reduce your callouts.

Unfortunately, unless you can actually keep the admin password secret (at least from the kids) then it's going to be hard work changing their habits. But even then, if they download a dodgy piece of software and say "dad, can you put in the password so I can install this" / "sure thing son" / bang then there is not a lot you can do. :rolleyes:
 
1. Firefox with adblock+ and noscript - since using these two plugins, I have dramatically reduced the spyware on all of my machines.

This will help a lot! BUT,if they are just going to carry on as usual,then nothing much will change! If they were paying to have the computer sorted out regularly,then they might think a bit more about how they use it.
Rather than saying :This ****** computers broken AGAIN! fix it fix it fix it fix it :D
 
Limit accounts - yes.

I put Threatfire on newly sorted systems as it does a good job of curtailing all sorts of malware.

If they really are as shambolic as you suggest then the next step would be some form of virtualization, such as Returnil. Good luck!

;)
 
Thanks for the responses guys; there's plenty for me to go through there :D

I always get paid, that's never been the issue. It's just the hassle of being the 'guy that knows about pc's etc' - it's a legacy I can't seem to shake off! I haven't really been into the 'fix my pc scene' since I was about 16. Back then the cash came in handy admittedly, but things change don't they, and I have a separate career now... I think I need to start being a firmer with people ;)

Cheers guys.
 
Just had a look at threatfire and it seems to only be available for x86...

Strange considering the last release was on May 27th, I was under the impression most developers catered for both platform these days :)
 
Back
Top Bottom