Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Disposing of hard drives

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion
Register FAQ Community Calendar

Friend's computer is virused up to the max
Reply
 
Thread Tools
Old 13-09-2006, 11:07   #1
McGraw
Inactive
 
Join Date: Dec 2003
Location: Manchester
Posts: 993
McGraw has a spectacular aura about themMcGraw has a spectacular aura about themMcGraw has a spectacular aura about themMcGraw has a spectacular aura about them
Friend's computer is virused up to the max

So I'm going round there to sort it out.

I've sorted quite a few people's PCs out before and it's usually the trick of turning system restore offthat gets rid of the little blighters.

However, this infection sounds quite bad. Although I built the machine and set her up with Spybot, AVG and made sure the Windows firewall was on, she has backdoor trojans, w32.myzor and various malware threats. This is down to all the dodgy "game of the day" sites she goes on as well as less as not updating and immunising Spybot for at least 6 months.

She says her internet connection has now dropped so there's a small chance I won't be able to fix it without having some general purpose virus removal tools.

So, whilst I've got the chance, what does anyone recommend I burn to CD and take round?

Cheers.
McGraw is offline   Reply With Quote
Advertisement
Old 13-09-2006, 11:09   #2
zing_deleted
Guest
 
Posts: n/a
Re: Friend's computer is virused up to the max

if its that bad reformat and take a ghost image once the machine is up and running.
I have very little time for customers of mine that allow their system to get virused up to the max as it were and unless there prepared to pay 15 quid an hour for me to sit there watching a boot time virus scan then id just format and tell them off for downloading garbage

Dude its obvious you put yourself accross as a system builder you should know what to do
  Reply With Quote
Old 13-09-2006, 11:11   #3
gazzae
Inactive
 
gazzae's Avatar
 
Join Date: Jun 2003
Location: Belfast
Age: 45
Posts: 4,594
gazzae is cast in bronzegazzae is cast in bronzegazzae is cast in bronzegazzae is cast in bronze
gazzae is cast in bronzegazzae is cast in bronzegazzae is cast in bronzegazzae is cast in bronzegazzae is cast in bronzegazzae is cast in bronzegazzae is cast in bronzegazzae is cast in bronzegazzae is cast in bronzegazzae is cast in bronzegazzae is cast in bronzegazzae is cast in bronzegazzae is cast in bronzegazzae is cast in bronzegazzae is cast in bronzegazzae is cast in bronzegazzae is cast in bronzegazzae is cast in bronzegazzae is cast in bronze
Re: Friend's computer is virused up to the max

format c:\

Seriously. If a PC is that bad esp with some of the nasty spyware about then I find it far quicker just to do a clean reinstall.
gazzae is offline   Reply With Quote
Old 13-09-2006, 11:12   #4
zing_deleted
Guest
 
Posts: n/a
Re: Friend's computer is virused up to the max

Quote:
Originally Posted by gazzae View Post
format c:\

Seriously. If a PC is that bad esp with some of the nasty spyware about then I find it far quicker just to do a clean reinstall.
who uses that command often nowadays lol lol
  Reply With Quote
Old 13-09-2006, 11:14   #5
Stuart
-
 
Stuart's Avatar
 
Join Date: Jun 2003
Location: Somewhere
Services: Virgin for TV and Internet, BT for phone
Posts: 26,546
Stuart has a lot of silver blingStuart has a lot of silver blingStuart has a lot of silver blingStuart has a lot of silver blingStuart has a lot of silver bling
Stuart has a lot of silver blingStuart has a lot of silver blingStuart has a lot of silver blingStuart has a lot of silver blingStuart has a lot of silver blingStuart has a lot of silver blingStuart has a lot of silver blingStuart has a lot of silver bling
Re: Friend's computer is virused up to the max

Assuming you have your XP or Server 2003 disks, you can use Bart PE to build a bootable windows CD. This includes a plug in and instructions to enable you to download a McAfee virus scanner from the web. You can then run this from the CD.

Note: The plug in doesn't seem to require a McAfee licence.
Stuart is offline   Reply With Quote
Old 13-09-2006, 11:14   #6
dilli-theclaw
R.I.P.
 
dilli-theclaw's Avatar
 
Join Date: Jun 2003
Location: Near Sandy Heath transmitter
Services: BT
Posts: 19,325
dilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden aura
dilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden aura
Re: Friend's computer is virused up to the max

Quote:
Originally Posted by zinglebarb View Post
who uses that command often nowadays lol lol
Well not without the /u switch anyway
dilli-theclaw is offline   Reply With Quote
Old 13-09-2006, 11:15   #7
Aragorn
Inactive
 
Aragorn's Avatar
 
Join Date: Apr 2004
Location: Minas Tirith, Gondor
Age: 60
Posts: 3,458
Aragorn has a nice shiny star
Aragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny star
Re: Friend's computer is virused up to the max

I'm with the Zing on this - you could spend days trying to get rid of stuff and still not be certain there isn't a hidden rootkit.
Nuke it and tell her not to be so careless!
Aragorn is offline   Reply With Quote
Old 13-09-2006, 11:17   #8
zing_deleted
Guest
 
Posts: n/a
Re: Friend's computer is virused up to the max

Quote:
Originally Posted by Stuart C View Post
Assuming you have your XP or Server 2003 disks, you can use Bart PE to build a bootable windows CD. This includes a plug in and instructions to enable you to download a McAfee virus scanner from the web. You can then run this from the CD.

Note: The plug in doesn't seem to require a McAfee licence.
or you can follow my instructions for modifying bart pe to have full shell access allowing you to run apps off the hard drive its all posted here somewhere
  Reply With Quote
Old 13-09-2006, 11:22   #9
Gareth
cf.mega poster
 
Gareth's Avatar
 
Join Date: Dec 2003
Age: 50
Posts: 7,101
Gareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny stars
Gareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny stars
Re: Friend's computer is virused up to the max

Yeah, like it says here... http://www.eweek.com/article2/0,1895,1945782,00.asp
Quote:
In a rare discussion about the severity of the Windows malware scourge, a Microsoft security official said businesses should consider investing in an automated process to wipe hard drives and reinstall operating systems as a practical way to recover from malware infestation.

"When you are dealing with rootkits and some advanced spyware programs, the only solution is to rebuild from scratch. In some cases, there really is no way to recover without nuking the systems from orbit," Mike Danseglio, program manager in the Security Solutions group at Microsoft, said in a presentation at the InfoSec World conference here.
Gareth is offline   Reply With Quote
Old 13-09-2006, 11:24   #10
Stuart
-
 
Stuart's Avatar
 
Join Date: Jun 2003
Location: Somewhere
Services: Virgin for TV and Internet, BT for phone
Posts: 26,546
Stuart has a lot of silver blingStuart has a lot of silver blingStuart has a lot of silver blingStuart has a lot of silver blingStuart has a lot of silver bling
Stuart has a lot of silver blingStuart has a lot of silver blingStuart has a lot of silver blingStuart has a lot of silver blingStuart has a lot of silver blingStuart has a lot of silver blingStuart has a lot of silver blingStuart has a lot of silver bling
Re: Friend's computer is virused up to the max

Quote:
Originally Posted by zinglebarb View Post
or you can follow my instructions for modifying bart pe to have full shell access allowing you to run apps off the hard drive its all posted here somewhere
TBH, I was thinking more along the lines of copying important data somewhere then nuking the system. The Virus scanner was to make sure you don't copy any viruses.
Stuart is offline   Reply With Quote
Old 13-09-2006, 11:27   #11
zing_deleted
Guest
 
Posts: n/a
Re: Friend's computer is virused up to the max

http://www.cableforum.co.uk/board/sh...7&postcount=12 here is my link it shows you how you can use nero(you can run this from program files as long as its installed on the drive ) also so you can burn and saved files to cd/dvd without running from the hdd.
Having full shell access allows for easier copy and paste options
  Reply With Quote
Old 13-09-2006, 11:39   #12
punky
Inactive
 
Join Date: Jun 2003
Age: 44
Posts: 14,750
punky has a golden aurapunky has a golden aura
punky has a golden aurapunky has a golden aurapunky has a golden aurapunky has a golden aurapunky has a golden aurapunky has a golden aurapunky has a golden aurapunky has a golden aurapunky has a golden aurapunky has a golden aurapunky has a golden aurapunky has a golden aurapunky has a golden aurapunky has a golden aurapunky has a golden aura
Re: Friend's computer is virused up to the max

Quote:
Originally Posted by McGraw View Post
So I'm going round there to sort it out.

I've sorted quite a few people's PCs out before and it's usually the trick of turning system restore offthat gets rid of the little blighters.

However, this infection sounds quite bad. Although I built the machine and set her up with Spybot, AVG and made sure the Windows firewall was on, she has backdoor trojans, w32.myzor and various malware threats. This is down to all the dodgy "game of the day" sites she goes on as well as less as not updating and immunising Spybot for at least 6 months.

She says her internet connection has now dropped so there's a small chance I won't be able to fix it without having some general purpose virus removal tools.

So, whilst I've got the chance, what does anyone recommend I burn to CD and take round?

Cheers.
Easiest thing to do is take a Linux live CD round. You insert the disk, and it boots into Linux giving you a complete operating system without making any changes to your HD. I have good success with Mandriva lately.

I'm with everyone else though, just nuke it and start afresh. Much easier in the long run.
punky is offline   Reply With Quote
Old 13-09-2006, 12:16   #13
McGraw
Inactive
 
Join Date: Dec 2003
Location: Manchester
Posts: 993
McGraw has a spectacular aura about themMcGraw has a spectacular aura about themMcGraw has a spectacular aura about themMcGraw has a spectacular aura about them
Re: Friend's computer is virused up to the max

Ok, thanks for the advice.
McGraw is offline   Reply With Quote
Old 13-09-2006, 19:46   #14
greencreeper
Inactive
 
Join Date: Nov 2003
Location: Leeds - the dog house
Age: 48
Services: Email me for a current price list
Posts: 8,270
greencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny star
greencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny star
Re: Friend's computer is virused up to the max

I usually go for a once over with Stinger, then Windows Update, AV install/config, and Spybot/SpywareBlaster.
greencreeper is offline   Reply With Quote
Old 14-09-2006, 00:50   #15
ADd
Inactive
 
ADd's Avatar
 
Join Date: Apr 2006
Location: Land of the free
Posts: 308
ADd has a reputation beyond reputeADd has a reputation beyond reputeADd has a reputation beyond reputeADd has a reputation beyond reputeADd has a reputation beyond reputeADd has a reputation beyond reputeADd has a reputation beyond reputeADd has a reputation beyond reputeADd has a reputation beyond reputeADd has a reputation beyond reputeADd has a reputation beyond reputeADd has a reputation beyond reputeADd has a reputation beyond repute
Re: Friend's computer is virused up to the max

Hi McGraw, you mention backdoor trojams, which is by far one of the worst infections a user could have. This is because of their backdoor capabilities, which means the attacker could have installed almost anything on the sysytem, indeed many backdoor trojans/worms allow the attack to have so much control they could be sitting at the desk using the computer in question, thus you are never really able to trust that system fully again. So the decision to re-format and reinstall depends upon the infection, and also what the pc is used for.
The w32.myzor infection isn't a real problem, you should be able to remove it using the info at this link:
http://www.bleepingcomputer.com/forums/topic63896.html

Good tools are as follows:
Anti-Spyware/Adware
Adaware SE Personnal:
http://www.lavasoft.de/software/adaware/
(Free, manual update)

Anti-Malware:
Ewido Anti-spyware:
http://www.ewido.net/en/download/
14 day full trial then on demand scanner have to update manually after trial(very good piece of software!) download setup files for ewido, and the separate full signature manual update to cd.

Trojan Hunter:
http://www.misec.net/
another free trial thinks it's 30 days.

It is best to run all these scans in safe mode, as many malware files will not be deleted in normal mode, and [b]disconnect the infected PC from the internet [b](pull the plug)

CCleaner:
http://www.ccleaner.com/ccdownload.asp (I would run this first)

Very good, but be careful of using the 'Issues' part of program, as it has been known to delete needed registry entries. The 'Cleaner' section which you need is completely safe, however it will remove cookies from your system so make sure you have all your passwords for forums hotmail etc witten down before using, and perhaps bookmarked (in Firefox,or put in favourites if you use IE) pages you visit regularily.

Without knowing exactly what infections you have, I cannot help more, but I would strongly advise you to visit one of these ASAP forums:

http://www.malwareremoval.com/a-sap.html

and post a HijackThis log. This link may help you decide if a reformat is necessary:

http://www.dslreports.com/faq/10063

In addition if you have been infected by backdoor trojans, there is the possibility of rootkit infected, which are often very hard to detect and remove, hence the previous reply to boot with a linux cd is a good idea, as most modern rootkits hide at the kernel level.

Above all goodluck
ADd is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 00:47.


Server: osmium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
All Posts and Content are © Cable Forum