1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Can't run Virus or Spyware programs

Discussion in 'Security and Privacy' started by silverwork, 2004/10/19.

Thread Status:
Not open for further replies.
  1. 2004/10/19
    silverwork

    silverwork Inactive Thread Starter

    Joined:
    2003/12/15
    Messages:
    163
    Likes Received:
    0
    I have been called to a friends to rescue their PC as they detected downloader.small and are having a a problem with a dialer.
    I have been successful in the past at fixing many such problems, but this is a bit wierd.
    I have deleted some suspiscious exe files with GIPO@MOVEONBOOT that kept appearing in MSCONFIG/STARTUP. The dial up box keeps autostarting even though it has been removed from start up.

    Here is the problem.

    The PC runs OK, until you run AVG or Spyware removal (including Search and destroy and many others I ogt from computercops.biz.

    Then the PC reboots every single time during these scans. Is this a very clever virus? I can't find the name as the scans don't finish. I have run about 5 recommended spyware removal tools - they all cause a reboot half way through, or a cpl that don't detect anything finish but discover nothing (and ask for money to upgrade).

    Any ideas?
    TiA
     
  2. 2004/10/19
    TonyT

    TonyT SuperGeek Staff

    Joined:
    2002/01/18
    Messages:
    9,072
    Likes Received:
    400
    boot in safe mode.
    use task manager to cl;ose all non-windows processes, then scan.
     

  3. to hide this advert.

  4. 2004/10/20
    silverwork

    silverwork Inactive Thread Starter

    Joined:
    2003/12/15
    Messages:
    163
    Likes Received:
    0
    Hi thanks for the tip, I close all applications, but I don't know what processes I should close and which I should leave open?
    Is there a basic list of what i should leave on before the scan?

    Many Thanks
     
  5. 2004/10/20
    alboy

    alboy Well-Known Member

    Joined:
    2002/01/09
    Messages:
    538
    Likes Received:
    4
    I don't know what processes I should close

    This may help to give some idea what processes are doing and if they can be disabled, scroll down to service configurations.
    hope it helps
     
  6. 2004/10/20
    TonyT

    TonyT SuperGeek Staff

    Joined:
    2002/01/18
    Messages:
    9,072
    Likes Received:
    400
    What operasting system?
    If XP or 2k you can close everything except windows will not let you end a system process. Just use task manager to end everything one by one and if a process can't be ended windows will tell you.
     
  7. 2004/10/20
    silverwork

    silverwork Inactive Thread Starter

    Joined:
    2003/12/15
    Messages:
    163
    Likes Received:
    0
    Thanks TonyT - it is XP Professional. So I iwll follow that advice.

    I have noticed that these maliscious spyware, hijackers and diallers are getting out of hand - they seem harder to deal with than the "traditional viruses" and they are costing ppl a lot of time to fix.
    I have also noticed that all the different spyware removal tools find totally different things. Even Adaware seems to miss loads of stuff other programs find and they miss stuff adaware finds - it's getting so difficult to control
     
  8. 2004/10/26
    silverwork

    silverwork Inactive Thread Starter

    Joined:
    2003/12/15
    Messages:
    163
    Likes Received:
    0
    In case anyone finds my results useful for future reference - here you go:

    I booted into Safe Mode and ran SpySweepr, a program I am new to, but seems really good (it finds lots more than adaware does on my PC). The program ran and removed a few things. I then tried to run AVG (free edition) and it would not run in SafeMode - I even re-installed it and got the same error.

    However, the SpySweeper run had cleared whatever it was that stopped me runnning AVG in normal mode, so I ran AVG that way and found a couple of viruses and removed to the vault.

    I then scanned the secondary hard drive and found another group of viruses that AVG could not seem to deal with. They were in a hidden folder called Windows System Information (this disc used to be a system disk). I removed the viruses by deleting with Gipo@moveonboot as I could not delete them the normal method - access denied (Windows thinking they are in use).

    System now seems clean :D

    Anyone got a good recomendation for a Spyware program the stops these pests getting on the system in the first place? As opposed to cleaning once infected. I will try SpySweeper - but would appreciate some advice from the experts!
     
  9. 2004/10/26
    Bmoore1129

    Bmoore1129 Geek Member

    Joined:
    2002/06/11
    Messages:
    1,675
    Likes Received:
    3
    I use Spywareblaster with auto updates (paid version) and my Spy Sweeper, Ad-Aware or SpyBot never finds anything when I run the scans.
     
  10. 2004/10/26
    eprom

    eprom Inactive

    Joined:
    2004/10/26
    Messages:
    8
    Likes Received:
    0
    www.spywarewarrior.com is a good place to start when looking for recommendations. You might also note that some of the removal and preventions programs have to be run for each user or you risk reinfections.
     
  11. 2004/10/26
    silverwork

    silverwork Inactive Thread Starter

    Joined:
    2003/12/15
    Messages:
    163
    Likes Received:
    0
    Thanks for the replies - I will check them out. Need a free version really :)

    I forgot to mention - I turned system restore off - as I suspect this may have had something to do with the re-infection. Is it safe to turn back on once system appears clean?
     
  12. 2004/10/26
    eprom

    eprom Inactive

    Joined:
    2004/10/26
    Messages:
    8
    Likes Received:
    0
    If you are sure that your clean. A program that I use to backup the registry at different points during a disinfections is ERUNT found here http://home.t-online.de/home/lars.hederer/erunt/ you might want to check it out. It is an emergency registry recover tool. Very simple, very helpful.
     
  13. 2004/10/26
    silverwork

    silverwork Inactive Thread Starter

    Joined:
    2003/12/15
    Messages:
    163
    Likes Received:
    0
    I just realised - you have to pay to update the definitions on SpySweeper - guess I'll have to try something else as I can't afford more software bills!!!

    Shame - it's a nice program.
     
  14. 2004/10/26
    TonyT

    TonyT SuperGeek Staff

    Joined:
    2002/01/18
    Messages:
    9,072
    Likes Received:
    400
    I clean my kids systems and clients systems using these free apps:
    1. SpywareBlaster (makes an extensive list of IE Restricted Sites)
    2. Spybot S&D
    3. Adaware
    4. CWShredder
    5. Autoruns (by sysinternals.com shows ALL things that load at boot)
    6. HijackThis (if necessary)
    7. Regedit

    First thing I do is kill all unneeded processes, then I delete unnecessary files in: (usually using command prompt after killing explorer.exe)
    c:\windows\temp
    c:\windows\downloaded program files
    docs&settings\user\local settings\temp
    docs&settings\user\local settings\tif
    docs&settings\user\cookies

    Then I run autoruns and use regedit to get rid of the startup items. Then run antispy apps as needed. AFTER all spyware has been cleaned I then run antivirus.
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.