Windows BBS The Place for Microsoft Windows Support! Windows, Support, Help Site

Go Back   Windows BBS > Security > General Security


General Security Post any general questions related to security, viruses or spyware here.

Register your FREE account to unlock additional features at WindowsBBS.com
Register
Welcome to WindowsBBS.com
Microsoft Windows Support

Mission Statement

WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.

Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.


Discussion Forums
Operating Systems
Windows 7 Windows 7
Windows Vista Windows Vista
Windows XP Windows XP
Windows Server System Windows Server System
Windows 2000 Windows 2000
Windows 95/98/Me/NT Windows 95/98/Me/NT
Internet & Networking
Networking
Internet Explorer
Microsoft Mail
Firefox, Thunderbird
      & SeaMonkey

General Internet
Security
General Security
Malware and Virus
     Removal

Other
Other Software
Hardware
Test Posts
Community
Introductions
General Discussions
Comments
      & Suggestions

News @ WindowsBBS

Forum Sponsor
 Image

Closed Thread
 
LinkBack Thread Tools
Old 19th October 2004   #1
Senior Member
 
Profile:
Join Date: Dec 2003
Posts: 163
Computer Experience:
intermediate
silverwork Reputation Level


Can't run Virus or Spyware programs

I have been called to a friends to rescue their PC as they detected downloader.small and are having a a problem with a dialer.
I have been successful in the past at fixing many such problems, but this is a bit wierd.
I have deleted some suspiscious exe files with GIPO@MOVEONBOOT that kept appearing in MSCONFIG/STARTUP. The dial up box keeps autostarting even though it has been removed from start up.

Here is the problem.

The PC runs OK, until you run AVG or Spyware removal (including Search and destroy and many others I ogt from computercops.biz.

Then the PC reboots every single time during these scans. Is this a very clever virus? I can't find the name as the scans don't finish. I have run about 5 recommended spyware removal tools - they all cause a reboot half way through, or a cpl that don't detect anything finish but discover nothing (and ask for money to upgrade).

Any ideas?
TiA

silverwork is offline  
Didn't find the information you thought to find?
Check out these Similar Threads
Old 19th October 2004   #2
WindowsBBS Team Member
 
TonyT's Avatar
 
Profile:
Join Date: Jan 2002
Location: Fairfax, VA
Posts: 5,162
Computer Experience:
echo $experienced;
TonyT Reputation LevelTonyT Reputation LevelTonyT Reputation LevelTonyT Reputation LevelTonyT Reputation LevelTonyT Reputation LevelTonyT Reputation LevelTonyT Reputation LevelTonyT Reputation LevelTonyT Reputation Level


boot in safe mode.
use task manager to cl;ose all non-windows processes, then scan.

TonyT is offline  
Old 20th October 2004   #3
Senior Member
 
Profile:
Join Date: Dec 2003
Posts: 163
Computer Experience:
intermediate
silverwork Reputation Level


Hi thanks for the tip, I close all applications, but I don't know what processes I should close and which I should leave open?
Is there a basic list of what i should leave on before the scan?

Many Thanks

silverwork is offline  
Old 20th October 2004   #4
Senior Member
 
alboy's Avatar
 
Profile:
Join Date: Jan 2002
Location: uk
Posts: 331
Computer Experience:
Always Learning
alboy Reputation Level


I don't know what processes I should close

This may help to give some idea what processes are doing and if they can be disabled, scroll down to service configurations.
hope it helps

alboy is offline  
Old 20th October 2004   #5
WindowsBBS Team Member
 
TonyT's Avatar
 
Profile:
Join Date: Jan 2002
Location: Fairfax, VA
Posts: 5,162
Computer Experience:
echo $experienced;
TonyT Reputation LevelTonyT Reputation LevelTonyT Reputation LevelTonyT Reputation LevelTonyT Reputation LevelTonyT Reputation LevelTonyT Reputation LevelTonyT Reputation LevelTonyT Reputation LevelTonyT Reputation Level


What operasting system?
If XP or 2k you can close everything except windows will not let you end a system process. Just use task manager to end everything one by one and if a process can't be ended windows will tell you.

TonyT is offline  
Old 20th October 2004   #6
Senior Member
 
Profile:
Join Date: Dec 2003
Posts: 163
Computer Experience:
intermediate
silverwork Reputation Level


Unhappy

Thanks TonyT - it is XP Professional. So I iwll follow that advice.

I have noticed that these maliscious spyware, hijackers and diallers are getting out of hand - they seem harder to deal with than the "traditional viruses" and they are costing ppl a lot of time to fix.
I have also noticed that all the different spyware removal tools find totally different things. Even Adaware seems to miss loads of stuff other programs find and they miss stuff adaware finds - it's getting so difficult to control

silverwork is offline  
Old 26th October 2004   #7
Senior Member
 
Profile:
Join Date: Dec 2003
Posts: 163
Computer Experience:
intermediate
silverwork Reputation Level


In case anyone finds my results useful for future reference - here you go:

I booted into Safe Mode and ran SpySweepr, a program I am new to, but seems really good (it finds lots more than adaware does on my PC). The program ran and removed a few things. I then tried to run AVG (free edition) and it would not run in SafeMode - I even re-installed it and got the same error.

However, the SpySweeper run had cleared whatever it was that stopped me runnning AVG in normal mode, so I ran AVG that way and found a couple of viruses and removed to the vault.

I then scanned the secondary hard drive and found another group of viruses that AVG could not seem to deal with. They were in a hidden folder called Windows System Information (this disc used to be a system disk). I removed the viruses by deleting with Gipo@moveonboot as I could not delete them the normal method - access denied (Windows thinking they are in use).

System now seems clean

Anyone got a good recomendation for a Spyware program the stops these pests getting on the system in the first place? As opposed to cleaning once infected. I will try SpySweeper - but would appreciate some advice from the experts!

silverwork is offline  
Old 26th October 2004   #8
SuperGeek
 
Bmoore1129's Avatar
 
Profile:
Join Date: Jun 2002
Location: Angelina County Texas
Posts: 1,583
Computer Experience:
1995
Bmoore1129 has disabled reputation

My System

I use Spywareblaster with auto updates (paid version) and my Spy Sweeper, Ad-Aware or SpyBot never finds anything when I run the scans.
Bmoore1129 is offline  
Old 26th October 2004   #9
Inactive
 
Profile:
Join Date: Oct 2004
Posts: 8
Computer Experience:
Experienced
eprom Reputation Level


www.spywarewarrior.com is a good place to start when looking for recommendations. You might also note that some of the removal and preventions programs have to be run for each user or you risk reinfections.
eprom is offline  
Old 26th October 2004   #10
Senior Member
 
Profile:
Join Date: Dec 2003
Posts: 163
Computer Experience:
intermediate
silverwork Reputation Level


Thanks for the replies - I will check them out. Need a free version really

I forgot to mention - I turned system restore off - as I suspect this may have had something to do with the re-infection. Is it safe to turn back on once system appears clean?

silverwork is offline  
Old 26th October 2004   #11
Inactive
 
Profile:
Join Date: Oct 2004
Posts: 8
Computer Experience:
Experienced
eprom Reputation Level


If you are sure that your clean. A program that I use to backup the registry at different points during a disinfections is ERUNT found here http://home.t-online.de/home/lars.hederer/erunt/ you might want to check it out. It is an emergency registry recover tool. Very simple, very helpful.
eprom is offline  
Old 26th October 2004   #12
Senior Member
 
Profile:
Join Date: Dec 2003
Posts: 163
Computer Experience:
intermediate
silverwork Reputation Level


I just realised - you have to pay to update the definitions on SpySweeper - guess I'll have to try something else as I can't afford more software bills!!!

Shame - it's a nice program.

silverwork is offline  
Old 26th October 2004   #13
WindowsBBS Team Member
 
TonyT's Avatar
 
Profile:
Join Date: Jan 2002
Location: Fairfax, VA
Posts: 5,162
Computer Experience:
echo $experienced;
TonyT Reputation LevelTonyT Reputation LevelTonyT Reputation LevelTonyT Reputation LevelTonyT Reputation LevelTonyT Reputation LevelTonyT Reputation LevelTonyT Reputation LevelTonyT Reputation LevelTonyT Reputation Level


I clean my kids systems and clients systems using these free apps:
1. SpywareBlaster (makes an extensive list of IE Restricted Sites)
2. Spybot S&D
3. Adaware
4. CWShredder
5. Autoruns (by sysinternals.com shows ALL things that load at boot)
6. HijackThis (if necessary)
7. Regedit

First thing I do is kill all unneeded processes, then I delete unnecessary files in: (usually using command prompt after killing explorer.exe)
c:\windows\temp
c:\windows\downloaded program files
docs&settings\user\local settings\temp
docs&settings\user\local settings\tif
docs&settings\user\cookies

Then I run autoruns and use regedit to get rid of the startup items. Then run antispy apps as needed. AFTER all spyware has been cleaned I then run antivirus.

TonyT is offline  



Closed Thread

Thread Tools


Similar Threads
Thread Thread Starter Forum Replies Last Post
rundll32.exe has my computer running very slowly Kreem Malware and Virus Removal 12 28th September 2004 01:47
Need help with yet another HJT log BillB Malware and Virus Removal 12 27th September 2004 01:11
Adware and Spyware problems mstakenforstars General Security 5 22nd August 2004 08:51
More of the same... Regenerating Spyware MikeXsells General Security 22 18th August 2004 23:36
Computer very slow... Kimberlee Windows 95/98/Me/NT 49 5th May 2004 03:35


All times are GMT +1. The time now is 20:58.






Advertisements do not imply our endorsement of the product or service advertised.
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.3.2
Copyright © 2002 - 2009 WindowsBBS.com. All rights reserved.
Terms of Use, Legal Information & Privacy Policy
[]