1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

very sick comp.

Discussion in 'Security and Privacy' started by Gasolene, 2004/01/31.

Thread Status:
Not open for further replies.
  1. 2004/01/31
    Gasolene

    Gasolene Inactive Thread Starter

    Joined:
    2002/01/17
    Messages:
    210
    Likes Received:
    0
    I was cleaning a computer that was very sik

    It had no virus or firewall software, and the XP firewall was disabled.

    The browser was hijacked so I had no real internet access, it would not let me open "msconfig, taskmanager, or regedit ", they would close instantly.

    I had no access to network adapters, it said the service wasn't running but I did have internet.

    I installed Adaware in safemode, it found 780+ entries.
    I ran the online virus scan at symentac, it found 101 viruses,

    among them were the blaster worm, and the W32.Spybot.Worm which counted for about 95% of the files.
    There was no virus software so I removed all startup entries from rededit and system.ini. It must hav been more places because all spyware and virus services started up again. about 50 unwanted services running.

    the problem is that Adaware won't remove any of the spyware entries, it crashes when you select "clean ".

    and I can't install norton2003, it also crashes on install.

    i hav some control in safemode, non of the unwanted services startup and I have proper internet access.

    any suggestions??
     
  2. 2004/01/31
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I think, the only logical solution in this case, would be:
    -fdisk
    -format
    -reinstall XP
    Then the very first thing would be to get AV program, and a good firewall (both available out there for free)
     

  3. to hide this advert.

  4. 2004/01/31
    Hugh Jarss

    Hugh Jarss Inactive

    Joined:
    2002/07/22
    Messages:
    908
    Likes Received:
    6
    perhaps PepiMK's CoolWWWSearch.SmartKiller removal tool followed by CWShredder might help?

    from the CWShredder download page , re the removal tool:
    but from what it says you may get blown off course trying to get to the downloads page, so the link for CWShredder given above is the "direct" link - it says to use if having trouble accessing the normal ones.

    good luck with it & best wishes, HJ.
     
    Last edited: 2004/01/31
  5. 2004/01/31
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    the problem is that Adaware won't remove any of the spyware entries, it crashes when you select "clean ".
    ===============

    Try it in safe mode and only fix one thing at a time,, also install update and run SpyBot S&D,,But first take care of any viruses

    as a supplement to the online you did
    well get another from one of the other companies if possible and install one of the free av programs
    an get and run stinger
    McAfee AVERT Stinger 2.0.0
    http://www.majorgeeks.com/download4063.html
    Theres a list of free on-lines and programs in the pinned topics

    are you using the recommended settings for Adaware ?
    Adaware 6 How To Perform a Full Scan: http://www.lavahelp.com/howto/fullscan/

    about the same thing here
    Lavasoft - Basic Settings - Configuration: http://www.lavasoftsupport.com/index.php?showtopic=2933


    Let us know what happens
     
  6. 2004/02/02
    Newt

    Newt Inactive

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    Gasoline - the system can probably be made to work and maybe even completely cleaned up including dumping all the bad stuff and fixing what was broken.

    But unless there is a compelling reason to do so, I tend to agree with broni. Wipe the thing completely out and start over.

    I would also suggest having AV software of some kind on a local removable media so you could install and update it before ever letting the system anywhere near the internet.
     
    Newt,
    #5
  7. 2004/02/04
    Johanna

    Johanna Inactive Alumni

    Joined:
    2003/03/08
    Messages:
    2,402
    Likes Received:
    2
    I'm with Newt and Broni. Reinstall after wiping -too much of a mess to clean up. A few word about the owner- first, he deserves the idiot surcharge on your bill. Second, he needs education. If he won't agree to a reasonable security policy, he has no business being online. There's no tactful way to tell someone they are clueless, and he may not care what a menace his computer is to cyberspace. If that is the case, how will you handle it?

    Johanna
     
  8. 2004/02/04
    Gasolene

    Gasolene Inactive Thread Starter

    Joined:
    2002/01/17
    Messages:
    210
    Likes Received:
    0
    thnx for the replies,

    O'v got a couple tools that I'm goin to try, but if I can't run any spyware or virus software then it will definately be a wipe.

    as for the idiot charge, I aggree exept this is for a friend of the family.

    She had no idea what a firewall was, and their virus software expired 2 years ago. They thought if they just uninstalled it, the cpu would run faster.
    She also has a 16y old son who is probably the cause of most of the spyware/viruses. Lot's of kazaa files and game cracks, not to mention the ****.

    infact, one of the spyware files was a "popup ad blocker ". (irony)

    They actually called me because they got an email from their ISP saying they were in violation (repeat offence) of their terms of service, as mass amounts of unsolicited emails were being sent from that IP.

    They had no idea what the even meant. had their ISP not informed them, they would probably still not have a clue.
     
  9. 2004/02/04
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    You could also try this online scanner, which can also fix what it finds. Good luck!
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.