re: Temporarily Disable Real Time Monitoring Programs

gillianbrown

Posts: 141   +0
Hi Kimsland, just a quick couple of points.

In the UPDATED 8-step Viruses/Spyware/Malware Preliminary Removal Instructions I believe it's important to tell users to rename HijackThis.exe to Crusty.exe or some other such name. This is because some malware can actually hide from the HijackThis.exe filename.

GillianBrown said:
[center]Very Important.[/center]

You need to rename HijackThis.exe to Crusty.exe. This is because some malware can hide from HijackThis.exe. Follow these instructions in order to do so.

Go to the C:\Program Files\Trend Micro\HijackThis\HijackThis.exe file and right click on HijackThis.exe. Choose rename. Click in the title box and hit the enter key to clear what`s there.

Now type Crusty.exe into the title box and hit the enter key. Right click on the Crusty.exe file and choose "Send to desktop Create Shortcut".

You can now close the HJT directory.

Also, you may not be aware, but the CastleCops website is no more and therefore the link for instructions to disable real time monitoring programmes no longer works.

Feel free to add these instructions if you wish.

GillianBrown said:
Malware Removal: Temporarily Disable Real Time Monitoring Programs.

The reason we do this is because real time protection programmes can interfere with any fixes we are trying to run.

Instructions on how to disable the real time monitoring of some of the more common antispyware programmes can be found below.


AD-AWARE AD-WATCH

* Right click on the Ad-Watch icon in the system tray.
* At the bottom of the screen there will be two checkable items called "Active" and "Automatic".
o Active: This will turn Ad-Watch On\Off without closing it.
o Automatic: Suspicious activity will be blocked automatically.
* Uncheck both of those boxes.
* (When done, you can re-enable it using the same steps but this time check both boxes.)

AVG ANTI-SPYWARE

* Launch AVG Anti-Spyware.
* From the "Status" menu, select "Change state" to inactivate 'Resident Shield' and 'Automatic Updates'.
* Then right click on AVG Anti-Spyware in the system tray and uncheck "Start with Windows".

COMODO BO CLEAN

* Right-click the System Tray Icon.
* Select Shut down BO Clean button.
* Restarts on reboot or open from Program Menu.

COUNTERSPY

* Right-click on the running CounterSpy icon in the sytem tray.
* Hover your mouse over "Active protection".
* A menu will slide out and then you need to left click on "Disable Active Protection".
* Disabling CS Active Protection should cause the systray icon to turn orange/red and hovering your mousing over the icon will then state "Active protection is disabled".

(When we are done, re-enable Counterspy by launching the program from Start > Programs, click on the Active Protection. It will either say Active Protection enabled or disabled. On the right side, you can select each of the tasks (scroll down to see all of them) individually, then either enable or disable them on the bottom right, individually. If you have a problem doing that then click on help, choose run setup wizard, click next 2 times, make sure automatic updates is set to yes, click next, make sure enable active protection is set to yes, click next, then click finish, then exit. Then open CounterSpy to make sure that the active protection has been enabled.)

PREVX

* Right click on the Prevx icon in your system tray and choose Show Management Console.
* On the Management Console click the Protection Level drop-down menu.
* You will see three levels:
o Maximum
o Off
o User Defined
* To disable all protection set the level to Off.
* You will receive a prompt asking "You are about to change your security settings. Do you wish to continue?" Click Yes.
* Click the X on the upper right hand corner to exit the Management console.

PROCESS GUARD

* Right-click the blue lock ProcessGuard icon located in the system tray.
* Uncheck 'protection enabled'.
* Click yes.

REG DEFEND
Right click the icon for RegDefend in the systray and select Exit.

SPYBOT TEATIMER

* Launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
* On the left hand side, click on Tools, then click on the Resident Icon in the list.
* Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box.
* Click on the "System Startup" icon in the List
* Uncheck the "TeaTimer" box and "OK" any prompts.
* If Teatimer gives you a warning that changes were made, click the "Allow Change" box when prompted.
* Exit Spybot S&D when done.
* (When we are done, you can re-enable Teatimer using the same steps but this time place a check next to "Resident TeaTimer" and check the "TeaTimer" box in System Startup.]

SPY SWEEPER

* Open Spy Sweeper and click on Options > Program Options and uncheck "load at windows startup".
* On the left click "shields" and then uncheck everything there.
* Uncheck "home page shield".
* Uncheck "automatically restore default without notification".
* Exit the program.
* (When we are done, you can re-enable it using the same steps but this time reverse them.)

SPYWARE DOCTOR

* Click the Spyware Doctor icon in the System Tray.
* Click Settings.
* Click Startup Settings under Pick a Category.
* Uncheck "Run at Windows startup".
* Click Apply and Exit Spyware Doctor.
* From within Spyware Doctor, click the "OnGuard" button on the left side.
* Uncheck "Activate OnGuard".
* (When we are done, you can reenable Spyware Doctor)

SPYWARE GUARD

* Right click the running icon of Spywareguard in the system tray to open the program.
* Then go to Menu, File, and choose Exit.

TROJAN HUNTER

* Go to TrojanHunter Guard in the the system tray. It is a light blue icon with a magnifying glass and red handle.
* Right click on it and select settings.
* Uncheck "Load at startup" and "Enabled". Make sure that the program, TrojanHunter itself, is also closed/not running.

WINDOWS DEFENDER

* Click Start > Programs > Windows Defender or launch from the system tray icon.
* Click on Tools & Settings > Options.
* Under Real-time protection options, uncheck the "Real-time protection" check box.
* Click Save.
* Go to Start > Control Panel > Security > Windows Defender, at the bottom of the Window Defenders page uncheck under Administrator Options "use Windows Defender" and then Save.
* (When we are done, you can re-enable Defender using the same steps but this time place a check next to "Turn on real-time protection" check box.)

WINDOWS ONECARE

* To Disable Antivirus: Open the Windows OneCare user interface.
* Click View or Change Settings > Antivirus Tab.
* Click the radio button to turn the anti-virus off.
* To Disable Firewall: Open the Windows OneCare user interface.
* Click View or Change Settings > Firewall Tab.
* Drag down the slider to turn the firewall off.

WINPATROL
Right-click the running icon of Winpatrol in the sytem tray and choose exit.

Once we are finished with the cleaning process you are advised to turn the protection back on

I hope this proves useful. ;)

Sorry for posting this here, but I couldn't send it via a pm due to length restrictions. I also couldn't post in the main thread as it is closed.
 
Re: UPDATED 8-step Viruses/Spyware/Malware Preliminary Removal Instructions
Thanks gillianbrown
There's a cached page here: http://209.85.173.132/search?q=cach...l_Time_Monitoring_Programs&hl=en&ct=clnk&cd=1
But it's not ideal ie internal links broken
Actually I'll move these posts to the meeting spot to discuss it further ;)

Edit:
I'm going to post link to the Norton Removal Tool (seeming I quote it nearly everyday!)
http://service1.symantec.com/Support/tsgeninfo.nsf/docid/2005033108162039

May as well provide the AVG Removal Tool, whilst I'm at it: (seeming that generally corrupts under virus infection too)
http://www.grisoft.cz/filedir/util/avg_arm_sup_____.dir/avgremover.exe
.
 
Thanks for posting the full programs disable instructions. As you may have seen, I mentioned the Castlecops closing on a thread and printed out the instructions for Teatimer, which was all we were dealing with at the time.

Any news on the Castlecops closing? Is it a permanent thing? I even set up a tab for that site on Firefox to have it handy when checking logs. Can't imagine what we'll do without that fine site to help out.
 
As far as I'm aware, the closing of CastleCops is permanent, though I wouldn't be surprised if it resurfaced at some point in the future.
 
CastleCops was a great asset. I don't know of any other site that had the search abilities found there. BleepingComputer has some features, but not all.

Maybe someone will pick it up again. Robert Graham wrote "Firewall Forensics- What am I seeing" that is THE information for firewalls- much like the Black Viper site is for Services. When Graham left the site, it was frequently quoted and the information was available from other sites with credits to Mr. Graham.

Same for BV. When he left the site for a while, it was frequently referred to and the information was available, I hope this works for CastleCops. But the thing is that the nature of the information calls for frequent updating, so someone would have to support the site for updates.
 
Why doesn't somebody just write our own comprehensive guide to disabling real time monitoring - we could update it constantly with the latest instructions.

I have on my other computer, saved canns for 15 - 20 different programs in detail. How to disable, uninstall, update, ect.

If I have time I will contribute to the guide.
 
As Howard I mean gillianbrown has now been banned (same user - how strange!)
I'll try to organize a "comprehensive guide" but I'd prefer you do it Blind Dragon, I really think it's your area, possibly Bobbye would be best suited to creating a guide too.
Really I'm not the best for this.
I'm hoping one of you will reply saying you will create one...
 
that's unfortunate - I knew it was him from his posting style but wasn't going to say anything. Guess it's back to watching the newbies give bad advice.
 
Yes he was pretty verbally abusive, without cause
Anyway, I PMd Julio (who agreed to the ban), and in the process of banning, I went... hang on!... Ooohh it's you.
I wish I had known this, even before banning him, but oh well. Hey he was quick too, no wonder. It all seems clear now.
 
Back