Thoughts about everything

How to install and set up Spybot Search & Destroy

, , ,

If you have it installed but didn’t use it for a long time (Current version is 1.6.0.30) uninstall it than reboot the computer.

Now Delete Spybot folder (Spybot - Search & Destroy) at
c:\Documents and Settings\All Users\Application Data\


Go to security.kolla.de - it will redirect to Spybot's main site. Why using this? - Simple – there are false sites which has “safer networking” or similar names spreading viruses –so it is easier to use this – or you can download it from

Here

Select your language (English) than READ the license - accept it than click on next.
Select directory - click on next.


If you don't want all language to be installed unselect additional languages.

Skins are useless - so unselect it
Downloading updates immediately – unselect it - you gonna do it later.

The Secure Shredder is useless mainly - you probably have a similar or better software already (it can delete crap in a way that it is gonna be harder to recover them)
The file scan plug-in is useless - if you wanna have an invidual file-scanner leave it - otherwise unselect it.
My adviced setup is this:




Click next
If you don't want a start menu group select Don't create A Start Menu Folder.

Now the "big deal"

SDHelper and TeaTimer are both slow and TOTALLY USELESS. Also RARELY THEY CAN CAUSE BSOD-S (BLUE SCREEN OF DEATH)
Since you are (hopefully) not using Internet Explorer - or if you do, quit using it IMMEDIATELY. It can slow down browsing anyways.
TeaTimer also slows down the computer and it is useless for normal users - its gonna keep nagging you if something changes - like when you are updating your system - so totally useless.


Click next when you made up your mind smile - install it.


Click on finish so it will start the software - it might bring up a small window telling you that it wants to delete temporary files - click on yes.

Now it will bring up the “legal stuff".

Read if you'd like to than click on Don't show this message again than to ok.

If you have Ad-Aware it will bring up a window telling you that Ad-aware may find spyware in Spybot's backup directory.
Click on Ignore.

Creating a registry backup is pretty useless - since you'll rather uninstall 1 software what you've prevented from working by removing its spyware components - rather than setting and installing tons of other if you rever changes. Click on next.

Click on next till you can click on Start Using the program - gonna tell you later why.
Now click on search for Updates - click on Continue

You should select everything - you might need the Description files later - especially if you are concerned what is going on on your computer - right now it should look like this :



Click on download - Spybot will restart itself - you'll have to do the legal stuff and warning steps again - click on ok, and then click on exit on the updater.
Close Spybot

Open it again

Click on Mode menu than to Advanced Mode - it will bring up a warning telling you that you might screw your computer if you are not sure what you are doing.
Click on yes

On the left now you'll have 3 another popping menus - Settings, Tools and Info & License

Click on Settings than to File Sets - select everything - it should look like this:




Now click on Settings.
Since the main reason why we are using this software is to eliminate all possible threats you should unselect all "Create Backup" crap - you don't wanna have backups - thrust me.
Also you should unselect "Display confirmation dialogs" since it just nags you - of course you wanna remove crap from your computer and you won't need confirmations for that
Other settings are not important for normal users - other may want to select "Show Expert buttons..." under Expert settings. It should look like this :




The next step is very important and you'll have to do it after EVERY update - especially if you wanna find all threats.
Go to Ignore products right click in the product list, than left click on Deselect all.



The Tools Section is for advanced users - a normal user won't know what it does - so do not bother it.
Now lets go to immunization - click on Mode Menu than to default menu.
Now click on immunize.
Too bad that you'll have to wait for it because you'll have to undo the changes by clicking on undo. Why?
Because it screws up the cookies and you won't be able to log into various sites and we are going to exclude cookies.

So now we've undone everything.
You have o extend the Profile column till you can see all names - here it is how:




Now unselect everything which has Cookies in its name
Keep in mind that if you visit "attacking sites" you might not be able to do it if you have Global (Host) selected - if you don't leave it selected
It should look like this : (Please note that every user has its own settings here so there might be waay more for you)



Now click on Immunize smile

Now we can start Looking for stuff. Click on Search & Destroy - than to Check for Problems. If it finds any click on Select all than to Fix Selected problems - that's all - have fun - for further questions feel free to contact me

On next restart it will remove stuffs what it cannot during the normal removal - so it will bring up command prompt - don't be afraid - it’s ok smile smile


© by Stomyr

DisclaimerWas on meeting - tired now

Comments

Cleanclean Wednesday, December 10, 2008 11:42:01 AM

Hey, Stormyr - I never knew you were such a massive expert on Spybot! You've come up in the first page of results when I was Googling for answers to a problem I was having lately:

Just downloaded the latest beta (1.6.1.38). For some reason, though, I end up with a problem on the HitsLink site (most Opera bloggers will know what I'm on about - I'm sure you do).

Regardless of whether I'm logged in on Opera or not, whenever I try to login to HitsLink, I get the following (which I've never seen before):

Problem - No Cookie Support

This product requires support for cookies to log in.

If you have installed security or privacy software, cookies are likely being blocked for this site. Programs that block cookies include:

SpyBot
Norton Firewall
Norton Internet Security
SpyBlocker
Ad Annihilator

These programs can block cookies from our site.

Another possibility is that your privacy setting on your browser is set too high. This setting should be set to 'Medium' or set to always allow session cookies or our site must be explicitly set to allow cookies. This setting can be found in Internet Explorer under the Tools/Internet Options/Privacy menu.

In order to use our product, you must configure your cookie-blocking software to allow cookies from us.



Now (obviously wink ) I'm using Opera (9.62). Also, Spybot is the only one of the abovementioned products I have on my computer (OS - Vista Home Basic). I updated to the new Spybot beta and immunized before I even knew I had a problem that may have been caused by the update (so I'm not sure if undoing the immunization will work for me somehow).

I've looked at what you've written above (skimmed, really, for the moment - it's hugely comprehensive! yes ) and tried unticking the cookies, etc. No change, though. I've also checked individual site preferences through Opera and allowed cookies from HitsLink, but, stilllo ... no dice.

Any thoughts? smile

Stomyr Wednesday, December 10, 2008 5:42:55 PM

Ok, first leave everything selected and do an undo - because if you do it w/o selecting back Opera it won't change it.
So once everything is selected do an undo changes - make sure that the "protected" coulumn is 0 everywhere -and on the right it says that 0 is protected.
Now unselect the cookies and click on immunize.

(Btw, you shouldn't install any kind of beta if you haven't got a big experience in how the software works smile )

Cleanclean Wednesday, December 10, 2008 9:50:04 PM

sad Didn't work.

Oh, well ... I'm sure the Safer Networking people will sort somthing out in the future. But thank you for the help, though! cheers

(Btw, you shouldn't install any kind of beta if you haven't got a big experience in how the software works smile



lol True! I read in a computer mag that betas were fairly safe to use nowadays ... rolleyes lol

Stomyr Thursday, December 11, 2008 11:35:27 AM

Than you might have to disable sd helper and Tea Timer, located under Advanced mode / tools / resident as well.

Whet you read in magazines are not always true - in my opinion a normal user should use only stable versions - so the person won't get problems like you smile

Cleanclean Thursday, December 11, 2008 8:47:51 PM

Hmm ... they're off, too (now).

Regarding the mags: true, true, very true! lol

Stomyr Thursday, December 11, 2008 10:04:46 PM

still doesn't work?

Cleanclean Thursday, December 11, 2008 10:15:17 PM

Nope.

Oh, well ... next time I'll leave the betas be! rolleyeslol

Stomyr Thursday, December 11, 2008 10:28:51 PM

Try clearing everything under tools/advanced/content/blocked content if you are using Opera smile

Cleanclean Friday, December 12, 2008 4:47:04 AM

Done. Still no dice.

I wonder if the HitsLink people are doing it? If Spybot's blocking HitsLink cookies, there must be a reason ...

Stomyr Friday, December 12, 2008 1:43:29 PM

Hitslink is considered a "data collector" (not in the original meaning) since it track you and the place where you cam and where you go.

Stomyr Friday, December 12, 2008 1:54:48 PM

It should look something like this - of course with the STABLE version

Cleanclean Saturday, December 13, 2008 2:00:00 AM

Umm ...

Unprotected 93411
Protected 0
Total 93411

And also in protected total underneath, it's 328, 192 ...

I think I'm going to simply uninstall the beta and go back to the previous stable version.

Stomyr Saturday, December 13, 2008 3:40:46 PM

The protected column should be 0 everywhere smile

Switching back is a good idea. smile

Cleanclean Sunday, December 14, 2008 8:47:11 AM

Now on my To Do list wink

Thanks, Stomyr! cheers

Stomyr Sunday, December 14, 2008 4:31:21 PM

You are welcome smile

jar konzungul Wednesday, July 15, 2009 2:41:17 PM

Hi

I just find U and right away I have a question.
I did everything to set up properly my Spybot....
and after immunization I've got:
Unprotected 166860
Protected 0
Total 166860

It's good or bad because I've got a little confuse after last post. I never have this problems with Windows XP and now I have Ultimate Windows Vista x64 I've got lost

P.S.
Thank you so much for your manual !!!

Stomyr Thursday, July 16, 2009 5:20:18 PM

Hi, you are welcome smile

Few things changed since this post was made. The developer didn't update the installer, thus after the first update computers can simply hang up. Probably - (I'm not sure though), the same happened in your case thus immunization actually didn't happen.
If you try to immunize while any of your browsers are open, it will notify you to close them.

Anyways, If you want to immunize your system , first close all browsers you have, (IE,FF,O,CH,ECT) than click on Immunize, and wait till it is done. If it doesn't start right away (it should) than there is an Immunize button on the "top" of the window.

The need of Immunization varies from person to person - for example if you aren't an experienced user or just simply want to be kinda overprotected, you'll need it. With it you can get rid of some popups if you aren't using any "advanced" blockers, and also it will block some random philishing / attacking site aswell. However if you are protected with a good security suite, and can spot an attacking site in like a second, you probably don't need it.
In case you have a kid and you want to protect his/her computer it than it is definitely a "must have"

jar konzungul Friday, July 17, 2009 2:09:45 AM

Thanks for explanation. I reinstall and I think everything now is OK. What I did else ( somebody told me), I run Spybot as Administrator. I don't know if this thing changed something but I did it.

Stomyr Friday, July 17, 2009 4:47:34 PM

You are welcome smile

Yep - forgot to tell you that. (thought you installed it as Admin already)

helpkid2010ineedhelp Saturday, April 3, 2010 5:50:31 PM

hey stomyr i got a question, i keep getting pop ups from internet explorer and i have the pop up blocker but it is not working will this help stop them? i got the pop ups after downloading something.....and i try to find it so i can delete it but i can't remember the name so will this delete this thing? i don't want to say what i downloaded but i think all the men know..... most likely they have done this when they first got a computer ...something you dont want to get caught with on your comp...........

Stomyr Sunday, April 11, 2010 10:36:54 AM

First things first, welcome to my blog!

Most likely you got a mutation of Virtumonde - or something similar. First of all FORGET IE FOR GOD SAKES! Get either Firefox or Opera or Chrome, or anything else just not IE.
Now that you hopefully have a decent browser disable System Restore.


(In Win XP :
Click Start, right-click My Computer, and then click Properties.
In the System Properties dialog box, click the System Restore tab.
Click to select the Turn off System Restore on all drives check box.
Click OK.
When you receive the following message, click Yes to confirm that you want to turn off System Restore)

(Win Vista:
Right-click on the Computer icon, and choose Properties
Click on the System Protection link on the left-hand side
Once you’ve clicked the System Protection link in Control Panel, you’ll see the checkboxes next to your different disks
Once you uncheck the drive, click the “Turn System Restore Off” button
Confirm in the dialog box.)
(Do this for all drives)

(Win 7:
Right-click on the Computer icon, and choose Properties
Click on the System Protection link on the left-hand side
Click the Configure button below the list of drives
Select Turn off System Protection.
Click OK)





Than download Spybot Search & Destroy from here and read this guide.

Than download Ad-Aware from Here

I also have a full guide for it here

Several things are not updated in these 2 guides (I think the e-mail scanner is the only missing part, but it is not necessary most of the times)

Also download Malwarebytes Anti-Malware Here
I don't have a full tutorial for it as I didn't see the point of making one for a 3 click software smile

So now you have all 3.
Update all of them, run full scans, remove threats, reboot if required. Once you're done, run another round to check if everything had been removed.
After nothing shows up, you can turn back on System restore if you wish the way you disabled it. If you are stuck or a scanner can't update / fails to load / fails to scan (hopefully won't happen)
than I'll need certain logs. I'll tell you more when it is needed.


Regards,

Stomyr

Write a comment

New comments have been disabled for this post.