|
Computing Safety Center:
The BlueCollarPC.Net website and Web Group are dedicated to Computing Safety. A few years ago it seemed the biggest Security decision was too add Anti-Virus Software to the Computer. This was recommended and probably included with purchase. In recent time, and now the 21st Century, it is recommended now to have at least three basic Security softwares in place - installed on your Computer, active and in constant use. These absolute neccessities are now: Anti-Virus Software, a Firewall, and Anti - Spy/AdWare Software. Without these, you are at risk concerning ID and Peronal Data theft - and also loosing your Computer to misusing persons in various ways.
Search Engines  Spy/Adware, .DLL, Malware, etc. Search for and Identify Files and Processes
BleepingComputer.com  http://www.bleepingcomputer.com/startups/ Search engine.
CA Spyware Information Center  http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453072738 CA Spyware Information Center search engine.
File Research Center - Free File and Process Information  http://www.fileresearchcenter.com/ The File Research Center provides a free scanning service to identify what is running on your computer. We also provide free information about safe and unsafe files, processes, services, spyware, adware, malware, trojans, and other programs that may be on your computer.
I Am Not A Geek - Start Up  http://startup.iamnotageek.com/srch-Backdoor.NuAgent.html Online search engine.
Kephyr.com  http://www.kephyr.com/filedb/index.php Search engine.
ProcessLibrary.com - Search  http://www.processlibrary.com/notfound/index.php Search engine.
WinTasks DLL Library  http://www.liutilities.com/products/wintaskspro/dlllibrary/winsock/ Search engine is about mid-page. Look up .dll information - whether valid .dll files.
Spyware-net http://www.fbmsoftware.com/spyware-net/index.html .... your Internet security resource for all things spyware, bringing you the latest spyware trends, updating you on the latest security vulnerabilities, and serving as a one-stop spyware information guide. (Online Search Engine for threats).
Information / Help / Removal:

Definition and Explanation of a .DLL file http://support.microsoft.com/kb/q87934/
Microsoft: Bugbusting, Spyware Removal http://www.microsoft.com/windows/IE/community/columns/bugbusting.mspx
OnGuardOnline.Gov (USA Government website): OnGuardOnline.gov provides practical tips from the federal government and the technology industry to help you be on guard against Internet fraud, secure your computer, and protect your personal information. http://onguardonline.gov/index.html
ScamBusters.org Internet ScamBusters Helps You Protect Yourself From Clever Scams -- Online and Offline... http://www.scambusters.org/
a-squared Process List http://www.hijackfree.com/en/processlist/
AuditMyPC.com http://www.auditmypc.com/ Firewall Test, Port Scan, Spy Ware and Security Audit Choices, and a whole lot more.
CastleCops - CLSID / BHO List / Toolbar Master List http://castlecops.com/bhonew.html This is the Master BHO and Toolbar list copyrighted by Tony Klein and CastleCops. For expert assistance, please post here. The information is collected across the Internet by the CastleCops Team. The CLSID list is free for personal use. If the information is intended to be used for commercial gain, please consider donating to the site to help cover bandwidth and hardware costs so that these and other services can continue. In all cases, please ensure that proper credit is given for the information.
CastleCops ActiveX Objects List (Downloaded Program Files) aka O16 http://castlecops.com/atx-925.html Currently 1167 activex entries and growing...Last updated on 2005-10-05 08:06:01 Eastern.
Introduction to Spyware Keyloggers http://www.securityfocus.com/infocus/1829
Trojans - myths & facts http://www.emsisoft.com/en/kb/articles/tec021007/
ProcessLibrary.com http://www.processlibrary.com/ ProcessLibrary.com: Free Process Information. Find the latest information about spywares, adwares, trojans, viruses, system processes and common applications.
TestMyFirewall.com - DLL Files http://www.testmyfirewall.com/dll-files.html DLL Files are Dynamic Link Library files, a way of writing modular programs that can be shared among several tasks at the same time. This is in comparison to individual programs containing a copy of every module. A DLL file is often considered an essential component without which the relevant application program or device driver would not function.Just what your particular dll files do can be a mystery, so we offer you a list of .dll, .exe, .com and other files with their associated functions..DLL Files - Security Risk: Some of .dll files can be a security risk and often include viruses, Trojans, Spyware, Adware and more. To find out if we have a description or information on your dll file, simply click on the filename or type your dll files into the search above.
WinTasks Process Library http://www.liutilities.com/products/wintaskspro/processlibrary/ In the recesses of your computer, 20-30 invisible processes run silently in the background. Some hog system resources, turning your PC into a sluggish computer. Worse yet, other useless processes harbour spyware and Trojans - violating your privacy and giving hackers free reign on your computer. WinTasks Process Library is an invaluable resource for anyone who wants to know the exact purpose of every single process. The categories available online are: * Top Security Risks * Top System Processes * Top Applications* Other Processes.
How to Identify Files (file extensions Search Engine) (example: . exe , . dll) FILExt Home Page, The File Extension Source http://filext.com/ Welcome to FILExt, the file extension source. FILExt is a detailed database of file extensions and programs that use them. A file extension is simply the end characters after the period in a file name (see here for a detailed description). A search in the database here might result in multiple possibilities. Use the context of where you got the file to help you figure out exactly what it is if there are multiple possibilities. To help, many of the links on this site will open a new browser window so you have constant reference to the FILExt data.
gdargaud dot net http://www.gdargaud.net/Hack/NoSpam.html Information site.
PCHell.Com http://www.pchell.com/ Everyone has been to PC Hell at one time or another. It's that place you visit when your personal computer is driving you insane with problems, glitches, and so on. To try to soothe the frustration, we'll provide some tips, hints, and troubleshooting remedies to help you get out of PC Hell. Be warned however, sometimes there is no exit....
Diagnostics Tools Downloads http://www.majorgeeks.com/downloads7.html
Spyware Tools http://www.majorgeeks.com/downloads31.html
Blocking Unwanted Parasites with a Hosts File (Thanks to Randy Knobloch (aka: Siljaline) Microsoft MVP for providing the update notices for the HOSTS file.) This article provides details on blocking Ads, Banners, Parasites, and Hijackers, web bugs, etc. with a custom HOSTS file. http://www.mvps.org/winhelp2002/hosts.htm
AntiSpywareCoalition.Org http://www.antispywarecoalition.org/
Trend Micro Bookmarks HOME AND HOME OFFICE >Free Virus Scan - http://housecall.trendmicro.com/ >Free Spyware Scan - http://www.trendmicro.com/spyware-scan/ >Browser Hijacking - http://www.trendmicro.com/cwshredder/ >Security Newsletters - http://www.trendmicro.com/subscriptions/default.asp
LEGAL REASONS TO HAVE PROTECTION IN PLACE The Legal Risks of Computer Pests and Hacker Tools Jiffy Lube International, 4 CCH Computer Cases para. 46845 (US Dist. Ct. Md. 1993), a corporate telecommunications customer, Jiffy Lube International, ... http://research.pestpatrol.com/KnowledgeBase/Whitepapers/LiabilityofPests.asp The Legal Risks of Computer Pests and Hacker Tools http://www.pestpatrol.com/Whitepapers/LiabilityofPests.asp
Download.com Tutorials / How To 
How to use AVG (AntiVirus) http://www.download.com/How-to-use-AVG/1200-2023-5158759.html?tag=morehowto
How to clean your PC with HijackThis http://www.download.com/1200-2023_4-5157522.html
How to destroy spyware using SpyBot http://www.download.com/1200-2023_4-5157526.html
How to use ZoneAlarm (Firewall) http://www.download.com/1200-2023_4-5157528.html
How to lock down your hosts file http://www.download.com/1200-2023_4-5157524.html
Software Utilities:
A Very Important Message about anti-spyware software:
It is very sad to mention that this sector of Computing Security is a jungle. Not like others, anti-virus or firewalls. There are many bad or fake anti-spyware softwares out here that actually hi-jack your web browsers for one to try to force purchase to get your PC back. This is a must website to view before purchasing any anti-spyware software ! Note that there are legal liabilities for professionals in reporting bad software and this is a compliant website and very known at forums and groups:
Title: The Spyware Warrior List of Rogue/Suspect Anti-Spyware Products & Web Sites Description: Bad, False, Fake products URL: http://www.spywarewarrior.com/rogue_anti-spyware.htm
NOTE: Shareware is generally at a price. Freeware can come with bundles added with various adware offered at risk to user by people who do that. The freeware here has none of these and is called "Working Freeware". I give the term 'working freeware' noting that it is not "Trialware" which is usually a limited version software that expires, or ceases to function, after a set time - usually 15 or thirty days. Working freeware means just that - it is a fully operational software authored, in the case here, by various community help oriented persons that are very talented - I use them myself. These are offered by some as free who also have other softwares for sale - and are not bundled with adware. Some may also have a "premium version" (meaning for sale) activating a proactive version - running in background like anit-virus protectection. Generally, the working freewares have manual updates and manual scans - although some may also contain scheduled scans.

AVG Anti-Virus Free Edition (need anti-virus ?) [working-freeware] Download, Information at this website : http://www.download.com/AVG-Anti-Virus-Free-Edition/3000-2239_4-10320142.html http://www.grisoft.com/ AVG Free Edition is the well-known antivirus protection tool. AVG Free is available free of charge to home users for the life of the product. Rapid virus database updates are available for the lifetime of the product, thereby providing the high level of detection capability that millions of users around the world trust to protect their computers. AVG Free is easy to use and will not slow your system down (low system resource requirements). Highlights include automatic update functionality, the AVG Resident Shield, which provides real-time protection as files are opened and programs are run, free Virus Database Updates for the lifetime of the product, and AVG Virus Vault for safe handling of infected files.
ClamWin Free Antivirus [Open Source - working freeware] http://www.clamwin.com/ ClamWin is a Free Antivirus for Microsoft Windows 98/Me/2000/XP and 2003. ClamWin Free Antivirus comes with an easy installer (and open source code). You may download and use it absolutely free of charge. It features: High detection rates for viruses and spyware; Scanning Scheduler; Automatic downloads of regularly updated Virus Database. Standalone virus scanner and right-click menu integration to Microsoft Windows Explorer; Addin to Microsoft Outlook to remove virus-infected attachments automatically. The latest version of Clamwin Free Antivirus is 0.88.2.3 . Please note that ClamWin Free Antivirus does not include an on-access real-time scanner. You need to manually scan a file in order to detect a virus or spyware.
a-squared trojan remover (Free Working Version for life and Proactive Premium Version) http://www.emsisoft.com/en/software/free/ a-squared (a-squared) is a complementary product to antivirus software and desktop firewalls on MS Windows computers. Antivirus software specializes in detecting classic viruses. Many available products have weaknesses in detecting other malicious software (Malware) like Trojans, Dialers, Worms and Spyware (Adware). a-squared fills the gap that malware writers exploit. Automatic updates: In a-squared Free the updater must be run manually. The auto-update feature of a-squared Personal checks hourly for new available updates and installs them automatically. a-squared Free is freeware! You can download and use it completely for free. You are also allowed to distribute it to third parties. To be able to use it, you only must set up a free a-squared Account, to get access to the update server.
Microsoft AntiSpyware is now Windows Defender [working-freeware from Microsoft] http://www.microsoft.com/athome/security/spyware/software/default.mspx Windows Defender (Beta 2) is a free program that helps protect your computer against pop-ups, slow performance, and security threats caused by spyware and other unwanted software. It features Real-Time Protection, a monitoring system that recommends actions against spyware when it's detected, and a new streamlined interface that minimizes interruptions and helps you stay productive.
a-squared HiJackFree [working-freeware] http://www.hijackfree.com/en/ Publisher: http://www.emsisoft.com/en/ a-squared HiJackFree is a detailed system analysis tool which helps advanced users to detect and remove all types of HiJackers, Spyware, Adware, Trojans and Worms. (The superior alternative to "Hi JackThis" logs, gives extensive information and instant analysis of results online).
HijackThis Tutorial & Guide A guide and tutorial on using HijackThis to remove Browser Hijackers & Spyware http://www.bleepingcomputer.com/forums/index.php?showtutorial=42
HijackThis (Download.com) [working-freeware utility] http://www.download.com/HijackThis/3000-8022_4-10227353.html (Note: This utility will automatically scan and display running processes and also Browser Help Objects {BHO} - Toolbars, which also allows you to copy/paste results that can be posted for analysis by the experienced for removal of BHO's that are unwanted installations that are usually without knowledge or permission. This can also help in identifying unknown processes running in the background. There are several features as well that enable deletion and 'fix' - but not at all recommended for beginners or even intermediate users. We accept these "HiJackThis Logs' at our Web Group membership here at the website for help in safe removals. There are several websites accepting them now for help. )
CWShredder http://www.intermute.com/spysubtract/cwshredder_download.html CWShredder finds and destroys traces of CoolWebSearch. CoolWebSearch is a name given to a wide range of different browser hijackers. Though the code is very different between variants, they are all used to redirect users to coolwebsearch.com and other sites affiliated with its operators. Learn More: http://www.intermute.com/cwshredder/learn_more_cwshredder.html (Note: CoolWebSearch has been reported as the worst, and the CWShredder is the only known true remover for all traces, variants - and is constantly updated. CWSredder has been aquired by Trend Micro AntiSpyware now but is still free as a stand alone program from them. Take a look at the extensive variants list of the CoolWebSearch toolbar browser hijacker at CA Spyware Information Center......): CA Spyware Information Center (List of CWS variants) http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453076035
a-squared HiJackFree [working-freeware/no ads] http://www.hijackfree.com/en/ a-squared Home: http://www.emsisoft.com/en/ a-squared HiJackFree is a detailed system analysis tool which helps advanced users to detect and remove all types of HiJackers, Spyware, Adware, Trojans and Worms. (Note this is the superior alternative to HiJackThis for advanced users with instant analysis online)
a-squared trojan remover (Free Working Version for life and Proactive Premium Version) http://www.emsisoft.com/en/software/free/ a-squared (a-squared) is a complementary product to antivirus software and desktop firewalls on MS Windows computers. Antivirus software specializes in detecting classic viruses. Many available products have weaknesses in detecting other malicious software (Malware) like Trojans, Dialers, Worms and Spyware (Adware). a-squared fills the gap that malware writers exploit. Automatic updates: In a-squared Free the updater must be run manually. The auto-update feature of a-squared Personal checks hourly for new available updates and installs them automatically. a-squared Free is freeware! You can download and use it completely for free. You are also allowed to distribute it to third parties. To be able to use it, you only must set up a free a-squared Account, to get access to the update server.
Spybot - Search & Destroy [working-freeware] http://www.safer-networking.org/en/spybotsd/index.html Overview: Spybot - Search & Destroy can detect and remove spyware of different kinds from your computer. Spyware is a relatively new kind of threat that common anti-virus applications do not yet cover. If you see new toolbars in your Internet Explorer that you didn't intentionally install, if your browser crashes, or if you browser start page has changed without your knowing, you most probably have spyware. But even if you don't see anything, you may be infected, because more and more spyware is emerging that is silently tracking your surfing behaviour to create a marketing profile of you that will be sold to advertisement companies. Spybot-S&D is free, so there's no harm in trying to see if something snooped into your computer, too :)
Ad-Aware [working-freeware, personal use] http://www.lavasoftusa.com/software/adaware/ Ad-Aware Personal provides advanced protection from known data-mining, aggressive advertising, Trojans, dialers, malware, browser hijackers, and tracking components. This software is downloadable free of charge.
SpywareBlaster [working-freeware] http://www.javacoolsoftware.com/spywareblaster.html Prevent the installation of spyware and other potentially unwanted software! Spyware, adware, browser hijackers, and dialers are some of the fastest-growing threats on the Internet today. By simply browsing to a web page, you could find your computer to be the brand-new host of one of these unwanted fiends! SpywareBlaster is freeware. Please consider donating to further our cause! Click here for more information.
BHODemon - utility [working-freeware] http://www.pcworld.com/downloads/file_description/0,fid,23611,00.asp Internet Explorer has a nasty habit of allowing so-called Browser Helper Objects (or BHOs) to install themselves into IE. Some BHOs are helpful, like the Google Toolbar, but others (especially those planted by viruses or spyware) can be malicious and harmful. BHODemon gives you a quick look at the BHOs installed on your PC, tells you whether a specific BHO is known to be safe or harmful, and gives you the ability to enable or disable individual BHOs with a single mouse click.
Browser Hijack Blaster [working-freeware] http://www.wilderssecurity.net/bhblaster.html Browser Hijack Blaster protects your system from browser hijackers and spyware that alters your Internet Explorer settings. Running silently in the background, Browser Hijack Blaster only springs into action when an attempt is made. It watches and protects the following items: IE Homepage, IE Default Page, IE Search Page, BHOs
Cookie Spy Version 3.0 [working-freeware] (This is the cookie manager that you wish Internet Explorer had) http://camtech2000.net/Pages/Cookie_Spy_SE.htm Cookie Spy SE is the complete manager for all those Cookies installed by web sites you visit. An easy to use interface lets you delete and permanently block Spyware Cookies or allow the ones you want to keep such as those that remember who you are when you log in to a site. Once a site is blocked you will never receive a Cookie from that site again. The Filters Lists makes it easy to change and/or remove those you've blocked or allowed. Some Cookies are harmless and in fact helpful but more sites and programs are using them now to get your email address, shopping habits and other personal details. It's not uncommon for computers to have hundreds and even thousands of Spy Cookies installed and most often when you delete them they're installed again when you revisit the site. Cookie Spy SE allows you to permanently block those you don't want. Camtech 2000 offers many quality programs, freeware and trial for Desktop Enhancement, Internet and System Utilities such as SpySites Plus, XP Icons, SpySites, Meta Tag Enterprise, The Html Directory, CleanEm, T5, MemCheck Pro, DunStats, PopUp Master, IE Logos, DunSpeed, CT Cookie Spy, SpyChaser, Toolbar Wallpaper, Toolbar Skins, Icons, IcoFolder, Clear Desktop, Screen Savers, Themes, and most all the Windows Startup Logos.
SiteAdvisor.Com Information and Download [working-freeware, Internet Explorer and Firefox browsers] http://www.siteadvisor.com/preview/ We test the Web to help keep you safe from spyware, spam, viruses and online scams. SiteAdvisor's safety ratings are based on automated safety tests of Web sites (including of our own site) and are enhanced with user feedback from our users and our own manual analysis. We do not accept payment from sites to be rated, so we have no conflict of interest. We also document our safety tests for every site we analyze. About SiteAdvisor SiteAdvisor is a consumer software company founded in April 2005 by a group of MIT engineers who wanted to make the Web safer for their family and friends. Having spent one too many holiday breaks trying to clean a mess of spam, adware, and spyware from our families' computers, we decided to take action. We realized there was a gaping hole in existing Web security products. While traditional security companies had gotten relatively good at addressing technical threats like viruses, they were failing to prevent a new breed of "social engineering" tricks like spyware infections, identity theft scams, and sites which send excessive e-mail. To address this challenge, we built a system of automated testers which continually patrol the Web to browse sites, download files, and enter information on sign-up forms. We document all these results and supplement them with feedback from our users, comments from Web site owners, and analysis from our own employees. Our easy to use software for Internet Explorer and Firefox summarizes our safety results into intuitive red, yellow and green ratings to help Web users stay safe as they search, browse and transact online. Our goal is to pioneer a new approach to Web safety and make the Internet safer for everyone.
IE-SPYAD - How To (How to Update this product) http://forums.neoplanet.co.uk/index.php?showtopic=6640 How to Install and Update IE Spyad for Internet Explorer.
IE-SPYAD: Restricted Sites List for Internet Explorer [working-freeware] https://netfiles.uiuc.edu/ehowes/www/resource.htm IE-SPYAD adds a long list of sites and domains associated with known advertisers, marketers, and crapware pushers to the Restricted sites zone of Internet Explorer. Once you merge this list of sites and domains into the Registry, the web sites for these companies will not be able to use cookies, ActiveX controls, Java applets, or scripting to compromise your privacy or your PC while you surf the Net. Nor will they be able to use your browser to push unwanted pop-ups, cookies, or auto-installing programs on your PC. (NOTE: Example: Open Explorer >click Tools, click > Internet Options, > click Security, > click Restricted Sites. There you may manually (normally) add any website you wish to restrict Explorer from accessing by clicking > Sites and typing in the web address. This utility adds hundreds almost instantaneously - do the math on the time you save !)
Microsoft Baseline Security Analyzer V1.2.1 [working-freeware, works on home PC]  http://www.microsoft.com/technet/security/tools/mbsahome.mspx MBSA 1.2.1 is the free, best practices vulnerability assessment tool for the Microsoft platform the tool helps with the assessment phase of an overall security management strategy. MBSA Version 1.2.1 includes a graphical and command line interface that can perform local or remote scans of Windows systems. MBSA 1.2.1 runs on: Windows 2000, Windows XP, and Windows Server 2003 systems.
SSA-KeyLogger Clean [working-freeware] http://majorgeeks.com/_SSA-KeyLogger_Clean_d4725.html Cleans the spyware keylogger, named Srv.SSA-KeyLogger, secretly steals data from users' Internet sessions, including logins and passwords from online banking sessions, eBay, PayPal, and other programs that use html forms to collect personal information. NOTE: Since the SSA-KeyLogger spyware cannot be installed on the following platforms, it is not necessary to run the SSA-KeyLogger Clean software: Windows 95-98-98SE-ME-NT4
Startup Control Panel [working freeware] http://www.mlin.net/StartupCPL.shtml Screenshot - picture: http://www.mlin.net/media/StartupCPL.png Startup Control Panel (working freeware, prevents malicious start-ups) Startup Control Panel is a nifty control panel applet that allows you to easily configure which programs run when your computer starts. It's simple to use and, like all my programs, is very small and won't burden your system. A valuable tool for system administrators! Startup Control Panel is compatible with all modern versions of Windows, including Windows 95, 98, 98SE, ME, NT 4.0, 2000, and XP. (GroupOwnerNote: Most excellent, catches all start up executable programs - and option to allow or deny. Stop malicious programs from start up.)
EarthLink Free Software & Tools For All Internet Users [working-freeware security toolbar] http://www.earthlink.net/software/nmfree/ EarthLink Toolbar: Surf safer and easier with our exclusive ScamBlocker and Pop-Up BlockerSM, plus a convenient Google search added to your browser toolbar. Free download. EarthLink Tools for the Firefox Browser, featuring ScamBlocker: Now you can use the popular Firefox Web browser with our customized EarthLink theme and our own extension—the EarthLink Toolbar featuring ScamBlocker! EarthLink Spy Audit: Do you have spyware on your machine? Find out now—FREE!
EULAlyzer 1.1 http://www.javacoolsoftware.com/eulalyzer.html EULAlyzer can analyze license agreements in seconds, and provide a detailed listing of potentially interesting words and phrases. Discover if the software you're about to install displays pop-up ads, transmits personally identifiable information, uses unique identifiers to track you, or much much more.
Some Free Spyware Scans: discover threats... 
New ? Have a look - orientation demo.....  Malware Threats - View Demo http://www.trendmicro.com/en/products/global/malware-demo.htm "Phishing", "Trojans", "Spyware"... Worried about the threat of computer attack but confused about the terms? View this fun multimedia presentation for an introductory overview of some of the many types of malware and how they can affect you. View Presentation (click at website to see).
Free Spyware Scans Free ad-spyware scans offered by reputable companies. These are generally offered for two reasons. One, if you are new to detection and protection you can discover what threats are present on your Computer that you are unaware of. Two, in finding defined threats you will most likely decide on purchasing protection software. NOTE that some software in trial downloads may give "false positives" just to sell their product. You can thoroughly examine results and your Computer to validate a "positive" (ad-spyware found) generally by file look-up of any 'positive' (ad/spyware item present in your PC).
EarthLink Spy Audit http://www.earthlink.net/software/nmfree/spyaudit/ When you browse the Web, spyware programs can sneak onto your computer. As a result, Web sites can track your browsing habits, corrupt your data, or even steal your identity. To scan your PC for spyware, just run a quick EarthLink Spy Audit.* This free service examines your computer and lists spyware results in minutes. It will not change or harm your system in any way.
Trend Micro AntiSpyware Scan Free Scan http://www.trendmicro.com/spyware-scan/ Trend Micro Anti-Spyware for the Web is a free online tool that checks computers for spyware, and helps remove any infections found. When the detection process is complete, the tool will display a report describing the result including which if any, spyware were detected, and prompt you before the removal process.
Webroot Spy Audit http://www.webroot.com/services/spyaudit_03.htm Quickly scan your PC for spyware - It's free! At no cost or obligation to you, Spy Audit scans your system registry and hard drive space for thousands of known spyware programs. Spy Audit shows you what spyware is on your system. It will not remove or modify any files. Webroot Software respects your privacy - after all, that's our business. Running Spy Audit will not add cookies or harm your computer in any way. Spy Audit takes only seconds to run. Try it now.
Pest Patrol Free Spyscan http://www.pestpatrol.com/
Windows Live Safety Center - free safety scan for your computer http://www.microsoft.com/athome/security/update/windows_live_safety_center.mspx Get a free safety scan for your computer. Windows Live Safety Center helps tune up your computer. Windows Live Safety Center is a new service that lets you scan your computer to help protect, clean, and keep it running at its best. The service is free and available directly from the Internet at http://safety.live.com. You can revisit the Windows Live Safety Center for subsequent tune ups as often as you like.
Panda (free scan) http://www.pandasoftware.com/products/activescan.htm Scans, viruses, worms and Trojans from all system devices, hard disks, compressed file and all your email.
Visit: Anti-Spyware Software comparisons... 
Title: CastleCops - Compare Description: Comparison for Reviewed Anti-Spyware Products (charts) URL: http://www.castlecops.com/compare-3
|
Free Spyware Scans... Detection: Some Free Spyware Scans: discover threats...
New ? Have a look - orientation demo:  Malware Threats - View Demo http://www.trendmicro.com/en/products/global/malware-demo.htm "Phishing", "Trojans", "Spyware"... Worried about the threat of computer attack but confused about the terms? View this fun multimedia presentation for an introductory overview of some of the many types of malware and how they can affect you. View Presentation (click at website to see).
Free Spyware Scans  Free ad-spyware scans offered by reputable companies. These are generally offered for two reasons. One, if you are new to detection and protection you can discover what threats are present on your Computer that you are unaware of. Two, in finding defined threats you will most likely decide on purchasing protection software. NOTE that some software in trial downloads may give "false positives" just to sell their product. You can thoroughly examine results and your Computer to validate a "positive" (ad-spyware found) generally by file look-up of any 'positive' (ad/spyware item present in your PC).

EarthLink Spy Audit http://www.earthlink.net/software/nmfree/spyaudit/ When you browse the Web, spyware programs can sneak onto your computer. As a result, Web sites can track your browsing habits, corrupt your data, or even steal your identity. To scan your PC for spyware, just run a quick EarthLink Spy Audit.* This free service examines your computer and lists spyware results in minutes. It will not change or harm your system in any way.
Trend Micro AntiSpyware Scan Free Scan http://www.trendmicro.com/spyware-scan/ Trend Micro Anti-Spyware for the Web is a free online tool that checks computers for spyware, and helps remove any infections found. When the detection process is complete, the tool will display a report describing the result including which if any, spyware were detected, and prompt you before the removal process.
Webroot Spy Audit http://www.webroot.com/services/spyaudit_03.htm Quickly scan your PC for spyware - It's free! At no cost or obligation to you, Spy Audit scans your system registry and hard drive space for thousands of known spyware programs. Spy Audit shows you what spyware is on your system. It will not remove or modify any files. Webroot Software respects your privacy - after all, that's our business. Running Spy Audit will not add cookies or harm your computer in any way. Spy Audit takes only seconds to run. Try it now.
Pest Patrol Free Spyscan http://www.pestpatrol.com/
Windows Live Safety Center - free safety scan for your computer http://www.microsoft.com/athome/security/update/windows_live_safety_center.mspx Get a free safety scan for your computer. Windows Live Safety Center helps tune up your computer. Windows Live Safety Center is a new service that lets you scan your computer to help protect, clean, and keep it running at its best. The service is free and available directly from the Internet at http://safety.live.com. You can revisit the Windows Live Safety Center for subsequent tune ups as often as you like.
Panda (free scan) http://www.pandasoftware.com/products/activescan.htm Scans, viruses, worms and Trojans from all system devices, hard disks, compressed file and all your email.
How do I know if my PC is infected ? 
Most likely one or both things can start to happen or more. Your Computer slows down browsing - sluggish, bloated, slow. Also, you may suddenly find new tool bars. There may be new links in your Favorites that you certainly did not bookmark. You may even see some new desktop shortcut icons. Checking the search engines or news stories about sluggish computers you might go down the avenue that you may need to increase your computer memory which is like a $100.00 memory addition - from 256K to 512K. Most likely you have a variety of events occurring from various types of adware, spyware, or other data miners or even trojans and worms, and other little 'badwares' called scumware, parasites, and malware of various kinds. You may start out going to help forums about getting rid of that stupid toolbar you did not install and wondered how it got there. Other weird things may be occurring like hitting your homepage and it is going somewhere else. Your browser has been hi-jacked ! (BHO Browser Help Objects). That is what this webpage is all about - because once you do enter the community of help and information about these operational and confidential intrusions you are going to find that you are probably going to end up doing a complete spring cleaning of your Computer. The more items you find you back track in your mind about I wonder what that leaked and to who - according to the severity of the "badware" found. It is possible to find up to 100 items, even more, which kind of constitutes your Computer to be what is called "infested". There is now great types of software that will get rid of practically everything. But the industry and consumers have found some items that need "manual removal". This involves many times of going into the computer Registry to delete items and also deletion of certain individual associated files. This is a second phase that needs some real investigation. There is always the warning here about registry deletions - if you delete a Registry item you are unsure of you may render your Computer completely inoperable or software programs installed. So, it takes a little homework to know what you are looking at when deleting files or Registry items for confidence in "clean removals". Welcome to the road of "Computer Health" .
My Own Story ?: In first becoming aware of an extra toolbar all of a sudden (the notorious and worst "CoolWebSearch) I attempted to find out how to remove it. In becoming an Earthlink.net customer, I began using the free Webroot anti-spyware scanner included. This all lead finally to trying the top ten trial anti-spyware softwares - "trialware". My result was that both Webroot Spysweeper (over 120,000 definitions) and Trend Micro AntiSpyware tied as finding the most items with no false positives. These two actually found up to ten times as many badware items as ALL others !!! I decided on both - and they both have shields running at all times like a firewall. Note that a "false positive" is actual safe software or registry items that the bad software often reports in a scan just to get you to buy their software, common tactic and SEE:
The Spyware Warrior List of Rogue/Suspect Anti-Spyware Products & Web Sites  Bad, False, Fake products http://www.spywarewarrior.com/rogue_anti-spyware.htm
ALL good anti-spyware is known for virtually no false positives.
Advanced Users: 
About Remote Access Service  http://windowssdk.msdn.microsoft.com/library/default.asp?url=/library/en-us/rras/rras/about_remote_access_service.asp
RAS AutoDial (clean dialers out of windows registry)  http://windowssdk.msdn.microsoft.com/library/default.asp?url=/library/en-us/rras/rras/ras_autodial.asp
Examples: RAS Autodial (my own finds Jan/Feb 2006 - and I believe I have discovered these first in spyworld, would like the credit mentioned, and found all software does not ! I am trying my best to get software developed immediately so I can copyright the invention, but I need a writer. For more check out the unknown "anti-dialer softwares available, and I doubt if they stop these). (There were actually 10-20 different ones of these examples) HKEY_CURRENT_USER\Software\Microsoft\RASAutodial\Addresses\bannerserver.gator.com HKEY_CURRENT_USER\Software\Microsoft\RASAutodial\Addresses\fm2.imesh.com
For IP number Look-Up, use a DNS service. The one below is handy and fast with Reverse Look Up - which means you can look up the IP number to find out the domain involved with the RASautodial present in your registry: Web Based DNS Lookup (NSLookup) (ZoneEdit.com) DNS Network Information via nslookup, yet another free service from ZoneEdit. http://www.zoneedit.com/lookup.html
EXAMPLE: HKEY_CURRENT_USER\Software\Microsoft\RAS Autodial\Addresses\207.46.106.123 is a typical Microsoft key for apparently hotmail or msn.com. NOTE: If you find something strange that may be a porn dialer or spyware - make sure you really search out exactly what domain is associated and why before considering deleting one of these keys !
More Examples of RASAutodial entries:
HKEY_CURRENT_USER\Software\Microsoft\RAS Autodial\Addresses\www.clickspring.net HKEY_CURRENT_USER\Software\Microsoft\RAS Autodial\Addresses\gatorcme.gator.com HKEY_CURRENT_USER\Software\Microsoft\RAS Autodial\Addresses\gs.gator.com HKEY_CURRENT_USER\Software\Microsoft\RAS Autodial\Addresses\ss.gator.com HKEY_CURRENT_USER\Software\Microsoft\RAS Autodial\Addresses\www.clickthebutton.com HKEY_CURRENT_USER\Software\Microsoft\RAS Autodial\Addresses\www.imesh.com HKEY_CURRENT_USER\Software\Microsoft\RAS Autodial\Addresses\www.imesh.net HKEY_CURRENT_USER\Software\Microsoft\RAS Autodial\Addresses\www.vcatch.com HKEY_CURRENT_USER\Software\Microsoft\RAS Autodial\Addresses\istechno.com HKEY_CURRENT_USER\Software\Microsoft\RAS Autodial\Addresses\www.mediacharger.com HKEY_CURRENT_USER\Software\Microsoft\RAS Autodial\Addresses\www.musicex.com HKEY_CURRENT_USER\Software\Microsoft\RAS Autodial\Addresses\www.tbrpr.com HKEY_CURRENT_USER\Software\Microsoft\RAS Autodial\Addresses\www.zdnet.com HKEY_CURRENT_USER\Software\Microsoft\RAS Autodial\Addresses\localhost HKEY_CURRENT_USER\Software\Microsoft\RAS Autodial\Addresses\istechno.com HKEY_CURRENT_USER\Software\Microsoft\RAS Autodial\Addresses\upgrade.newdotnet.net
ARP Cache (clean windows registry arp cache items)  http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/arp.mspx
|
|
Enter a search term and press Go! | |
PC Maintenance:
Macromedia Flash Global Storage Security Settings  (Note: This is only place to adjust these settings - online for your PC. Wait for the Panel to load - it does take a long moment). Macromedia Flash Global Storage Security Settings Panel http://www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager03.html Cookies and PIE (Secure Settings - MacroMedia Flash)..... Source: http://www.pcmag.com/article2/0,1759,1879765,00.asp
Disk C and D Defragmentation: 

Disk Defragmenter in Windows 2000: http://www.microsoft.com/windows2000/techinfo/administration/fileandprint/defrag.asp
Fragmentation and Defragmentation: http://www.pcguide.com/ref/hdd/file/ntfs/relFrag-c.html
Perform a Disk Defragmentation: http://www.theeldergeek.com/disk_defragmenter_utility.htm
Perform a Disk Volume Check For Errors on a regular basis: http://support.microsoft.com/default.aspx?scid=kb;en-us;315265
Restore Your Computer's Performance with Windows XP: http://www.microsoft.com/windowsxp/using/setup/expert/northrup_restoreperf.mspx
How to Defragment Your Hard Disk http://www.earthlink.net/elink/issue13/tech.html
Additional Forums, Message Boards - Compare Results
Online Help Forums 
Note: every forum has its own rules. Be sure to read the forum rules before posting.
Spywareinfo Forums: http://forums.spywareinfo.com/
Cexx Forums: http://boards.cexx.org/
D-A-L forums: http://www.d-a-l.com/index.php
CastleCops Forums (formerly ComputerCops): http://castlecops.com/
SpyWare BeWare!: http://forums.maddoktor2.com/index.php
BleepingComputer.com: http://www.bleepingcomputer.com/forums/
TechMonkeys: http://www.techmonkeys.co.uk/
PCHelp Forum: http://pchelpforum.com/
WilkonsonPC (Spanish): http://www.wilkinsonpc.com.co/cgi-bin/foros/index.cgi?board=HijackThis A support forum for Spanish-speaking users of South America and Central America.
PCPitstop Forum: http://pcpitstop.ibforums.com/
Tech with dk (dknoppix): http://dknoppix.com/forums/
InfoSpyware (Spanish): http://www.forospyware.com/
CyberTechHelp: http://www.cybertechhelp.com/
AntiSpywareOffensief.nl (English + Dutch): http://www.antispywareoffensief.nl/
Subratam.org: http://www.subratam.org/
BestTechie: http://www.besttechie.net/forums/
GeeksToGo: http://www.geekstogo.com/forum/index.php
"Pro" Sites to post HiJackThis Logs: 
[NOTE: Observe all Posting Rules first at each/any website accepting these.]
http://aumha.net/viewforum.php?f=30 http://www.bleepingcomputer.com/forums/forum22.html http://www.dslreports.com/forum/security http://castlecops.com/forum67.html http://www.cybertechhelp.com/forums/forumdisplay.php?f=25 http://www.geekstogo.com/forum/Malware_Removal_HiJackThis_Logs_Go_Here-f37.html http://gladiator-antivirus.com/forum/index.php?showforum=170 http://forum.networktechs.com/forumdisplay.php?f=130 http://forums.maddoktor2.com/index.php?showforum=17 http://www.spywarewarrior.com/viewforum.php?f=5 http://forums.spywareinfo.com/index.php?showforum=18 http://forums.techguy.org/f54-s.html http://forums.tomcoyote.org/index.php?showforum=27 http://forums.subratam.org/index.php?showforum=7 http://www.5starsupport.com/ipboard/index.php?showforum=18 http://www.malwarebytes.org/forums/index.php?showforum=7
Horror stories ? "SVKP.sys"
NOTE: Software hackers and pirates might re-write legitimate monitoring software to produce threatwares.
The SVKP.sys LEGACY_SVKP mystery... Created at every start up in my incidence, and I am trying to discover that culprit - whether program or malware or worm or rootkit - or valid program. Any help will be appreciated, and you may have cracked this. Manual Removal with all reports of trojans or viruses reveal nothing present as reported, except the actual C:\WINDOWS\system32\SVKP.sys mention. HiJackThis reveals nothing. (NOTE That it is not found anywhere at Microsoft.com which raises a real question of the forged entry in Properties of SVKP.sys in windows system32 >>> Copyright (C) Microsoft Corp. 1981-1999 as/ SVKP driver for NT) See: Photo:

Identified as TSPY_Joiner.AV (Trend Micro AntiSpyware)
Obscure: If purchased as a valid software, it may be employed as "trialware protection" for various products: SEE: "The presence of SVKP.SYS does not necessarily mean that this trojan is installed. SVKP.SYS is part of SVK Protector, which this trojan is packed with. SVK Protector is used in innocent programs as well. http://vil.nai.com/vil/content/v_101134.htm"
Apparent related websites selling "AntiCracking" or "SVK Protector" or related:
SVKP Website - [ Translate this page ] www.svkp.ch/
AntiCracking Software Protecion Systems: Copy protection, Software ... Software security protection solutions for software corporations, distributors and developers. Software and Hardware based copy licensing protection via SVK ... http://www.anticracking.sk/ shows : "© 2001 AntiCracking. All Rights Reserved" (which could be a clue as to the date of any download - and shows 2003-08-17 New Distributor for Serbia and Montenegro - Relikon d.o.o.).
SVKP SVK Protector. SVK Protector is suitable for all companies and professional software developers, who need easy, fast, and efficient protection for their ... www.anticracking.sk/products_svkp.html
CD Media World - Commercial CD/DVD Protections: SVK Protector Protection, :, SVK Protector (SVKP) - Slovak Protector. Versions, :, 1.43. How to Detect, :, Use Protection ID. Backup Solution, :, Unknown as of yet! ... www.cdmediaworld.com/hardware/ cdrom/cd_protections_svkp.shtml
SVK Protector http://www.anticracking.sk/products_svkp.html "SVK Protector is suitable for all companies and professional software developers, who need easy, fast, and efficient protection for their products. SVK Protector was designed with ease of protection implementation into your product as a basic feature. All users, also the less experienced, can do it in just couple of minutes. Despite the ease of use, programs are protected with the highest level of security and this protection will stop software pirates from unauthorized copying and distribution of your work...... " .
Help offered websites: (google results)
File.Net - How to remove SVKP.sys error problem SVKP.sys file information on Windows XP. If you have a SVKP.sys problem or error or want to remove this file, check it out. www.file.net/process/svkp.sys.html "How to remove SVKP error The free File.Network forum can help you find out if SVKP.sys is a virus, trojan, spyware, adware which you can remove, or a file belonging to a Windows system or an application you can trust. SVKP.sys file information The process SVKP driver for NT [ http://www.google.com/search?q=% 22SVKP driver for NT%22 ] belongs to the software SVKP driver for NT [ http://www.google.com/search?q=%22SVKP driver for NT%22 ] by AntiCracking [ http://www.google.com/search?q=%22AntiCracking%22 ] . Description: SVKP.sys is located in the folder C:\Windows\System32. The file size on Windows XP is 2368 bytes. The driver can be started or stopped from Services in the Control Panel or by other programs. The program has no visible window. There is no detailed description of this service. File SVKP.sys is not a Windows system file. SVKP.sys seems to be a compressed file. Therefore the technical security rating is 6% dangerous, however also read the users reviews. Important: Some malware camouflage themselves as SVKP.sys, particularly if they are located in c:\windows or c:\windows\system32 folder. Thus check the SVKP.sys process on your pc whether it is pest. We recommend Security Task Manager for verifying your computer's security. It is one of the Top Download Picks of 2005 of The Washington Post and PC World...... Other processes odhost.exe btwdins.exe tcpsvcs.exe SVKP.sys idrivert.exe gearaspiwdm.sys photoshopelementsfileagent.exe hplun.dll pchbutton.exe pqntdrv.sys support.exe [all] " .
SVKP that wont go away - TechSpot Troubleshooting Still everytime on startup i get a svkp that is found in my system32. I attached my most recent hijackthis results if anyone can help ... www.techspot.com/vb/all/windows/ t-35824-SVKP-that-wont-go-away.html
CastleCops.com Described as from malware / worms: W32/Rbot-AGP http://www.sophos.com/virusinfo/analyses/w32rbotagp.html W32/Spybot-FB http://www.sophos.com/virusinfo/analyses/w32spybotfb.html W32/Rbot-AJR http://www.sophos.com/virusinfo/analyses/w32rbotajr.html http://castlecops.com/o23list-852.html
McAfee AntiVirus: defines as- IRC-Deport trojan http://vil.nai.com/vil/content/v_101134.htm
Sophos virus analysis: W32/Rbot-AJR http://www.sophos.com/virusinfo/analyses/w32rbotajr.html When W32/Rbot-AJR is installed it creates the file <Windows system folder>\svkp.sys.
Symantec Security Response - W32.Loxbot.A Service Name: SVKP Display Name: SVKP. Creates the following registry subkeys for the two ... HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SVKP ... securityresponse.symantec.com/ avcenter/venc/data/w32.loxbot.a.html Symantec Security Response - W32.Spybot.RDW www.sarc.com/avcenter/venc/data/w32.spybot.rdw.html
Viruslist.com - Email-Worm.Win32.Wurmark.a www.viruslist.com/en/viruses/encyclopedia?virusid=66726 "Workstation Service Buffer Overrun (Microsoft Security Bulletin MS03- 049) DCOM RPC (Microsoft Security Bulletin MS03-026) Microsoft SQL Server 2000 or MSDE 2000 audit (Microsoft Security Bulletin MS02-061) Microsoft Windows LSASS (Microsoft Security Bulletin MS04-011)."
Microsoft searches ; no such thing, as the SVKP.sys file in Windows system32 properties claim it is copyrighted by Microsoft (Copyright (C) Microsoft Corp. 1981-1999 )
microsoft.public.security.virus: Re: hacktool.rootkit SVKP.sys file - sometimes it is good and sometimes not. I am using TweakUI ... file C:\wimdows\system32\SVKP.sys is infected with the Hacktool.Rootkit ... www.derkeiler.com/Newsgroups/microsoft. public.security.virus/2005- 10/0310.html
Additional Registry entries found concerning: TSPY_Joiner.AV (Trend Micro AntiSpyware)
If you are having trouble finding these, simply download the adware/ads free fully working freeware RegSeeker which has multiple functions and searches entire Windows Registry very quickly. Keyword Search: SVKP
C:\WINDOWS\system32 SYKP.sys (((PROPERTIES))): Company Name: AntiCracking File Version 4.0.1381.1 Description: SVKP driver for NT Copyright (C) Microsoft Corp. 1981-1999 Other Version Information: Value: 4.00 Internal Name: SVKP.sys Language English Original File Name: SVKP.sys Product Name: SVKP driver for NT Product Version: Value 1.00 (NOTE That it is not found anywhere at Microsoft.com which raises a real question of the forged entry in Properties)
Additional Registry entries found concerning: TSPY_Joiner.AV (Trend Micro AntiSpyware) Additional Registry Entries: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SVKP HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SVKP\0000 (Service SVKP) HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SVKP\0000 (DeviceDesc SVKP) HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SVKP HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SVKP\0000 \Control (Active Service SVKP) HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SVKP HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SVKP]\?? \C:\WINDOWS\system32\SVKP.sys (ab ImagePath) HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SVKP (Display Name SVKP) HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001 \Services\SVKP\EnumRoot\LEGACY_SVKP\0000 ( ab 0 ) HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SVKP HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SVKP (Service SVKP) HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SVKP (DeviceDesc SVKP) HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\StillCam\Security (Note RegSeeker displays this as: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SYMIDSCO\SVKP - with the backwards letter P and extra line | in it ) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SVKP HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SVKP\0000 (Service SVKP) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SVKP (DeviceDesc SVKP) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SVKP\0000 \Contol (Active Service SVKP) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SVKP HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SVKP\?? \C:\WINDOWS\system32\SVKP.sys (image path) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SVKP (DisplayNameSVKP) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SVKP\EnumRoot\LEG ACY_SVKP\0000 (ab 0)
NOTE: The "StillCam" is in the "Sparrow" registry folder which lends to possible system snapshot ?
Possible files to search for: [from product information at AntiCracking: http://www.anticracking.sk/ SVKP_DLL.DLL SVK Protector SVKP_GetHWInfo in Visual Basic SVKP_KillDebugger function against kernel debuggers (like VC debugger,W32Dasm ...)
File.Net - How to remove SVKP.sys error problem http://www.file.net/process/svkp.sys.html Other processes odhost.exe btwdins.exe tcpsvcs.exe SVKP.sys idrivert.exe gearaspiwdm.sys photoshopelementsfileagent.exe hplun.dll pchbutton.exe pqntdrv.sys support.exe
Free Microsoft Knowledge Base Articles by E-mail
|
Privacy Policy |
KB Alertz.com monitors the Microsoft Knowledge Base and emails subscribers informing them of updates and additions. Enter your e-mail addres and click [Sign Up], to recieve [Insert Technology Here] related articles in the Micrsoft Knowledge Base.
|
|
| |
Sign Up for the Alerts to your Inbox:
|