Tilted Forum Project Discussion Community  

Go Back   Tilted Forum Project Discussion Community > Interests > Tilted Technology


 
 
LinkBack Thread Tools
Old 01-13-2009, 06:52 PM   #1 (permalink)
I'm a family man - I run a family business.
 
Redjake's Avatar
 
Location: Wilson, NC
Mega Virus/Malware/Adware/Spyware Issue!

Hey guys,

Normally I can fix stuff like this very easily. But this one beats anything I've seen.

It's a coworker's personal computer. It's infected with spyware, adware, and viruses - all of this confirmed.

The issue is, the PC won't let me run anything! Whenever I double click on anything, it doesn't come up. It's in Task Manager, but won't show up. I've tried "ending process" and restarting the applications, but no go.

I need to run AVG, Ad-Aware, Spybot etc. but I can't!

Even worse, whenever I go online (and can get through the pop-ups), the browser (FF and IE) redirects to ads whenever I go to online scanner sites like Pandasoftware and stuff.

Tried booting into Safe Mode, no dice. Programs still won't run. Won't even run HijackThis.

Booted into selective startup/diagnostic startup (where all services and startup apps are disabled) and STILL can't run any applications.

Does anyone have any suggestions besides wiping? There is about 5 GB of iTunes songs and pictures I would have to backup if I format, and I really don't want to have to trudge around the DRM-fest with iTunes.

She has had the computer for 4 years but there are mysteriously on "restore points" for System Restore - says "no restore points available."

Tried creating new user account, no dice there either - can't run any applications or .exes.

Windows XP Home w/ SP3
Dell

Thanks everyone!

EDIT - when I say "applications won't run" I mean fixer-apps, such as Ad-Aware, Spybot, AVG, Hijack This, CWShredder, Malwarebytes, etc. Browsers will load, I can go through system files "My Computer" etc. Seems like only the programs that would get rid of the issue won't load.
__________________
Off the record, on the q.t., and very hush-hush.

Last edited by Redjake; 01-13-2009 at 06:54 PM..
Redjake is offline  
Old 01-14-2009, 11:53 AM   #2 (permalink)
Junkie
 
MontanaXVI's Avatar
 
Location: Go A's!!!!
If you cannot boot into safe mode and run your apps I really don't see any other choice but to wipe it out.

Maybe just take the drive out and see if you can use it in another PC to copy the data off that you want to keep before you wipe it out?
__________________
Spank you very much
MontanaXVI is offline  
Old 01-14-2009, 12:39 PM   #3 (permalink)
Tone.
 
shakran's Avatar
 
Some of the commercial antivirus programs, such as Norton, come with a CD that you can use as an emergency recovery CD. You boot off the CD, it does a virus scan without running windows, and therefore without triggering the virii to stop everything from working.

Also, try installing a skeletal OS + AVG/spybot on a portable hard drive and booting off of that drive, then run the scans on your system drive from it.
shakran is offline  
Old 01-14-2009, 12:49 PM   #4 (permalink)
Winter is Coming
 
Frosstbyte's Avatar
 
Location: The North
Quote:
Originally Posted by shakran View Post
Some of the commercial antivirus programs, such as Norton, come with a CD that you can use as an emergency recovery CD. You boot off the CD, it does a virus scan without running windows, and therefore without triggering the virii to stop everything from working.

Also, try installing a skeletal OS + AVG/spybot on a portable hard drive and booting off of that drive, then run the scans on your system drive from it.
That's what I was going to recommend. Hope that works!
Frosstbyte is offline  
Old 01-14-2009, 03:10 PM   #5 (permalink)
Invisible
 
yournamehere's Avatar
 
Location: tentative, at best
If all else fails and your only recourse is to wipe the drive, here's a suggestion. Pretty much the same as MontanaXVI's but you won't have to detach, change the jumper settings, and re-install the HDD.

Get an IDE-to-USB adapter cable (and possibly a USB cable extension) - here's a suggestion where - Newegg.com - GWC AD2200/AD2210 USB2.0 Hi-Speed to IDE Adapter
This is assuming, of course, it's an IDE drive.

Then disconnect the the infected drive from its controller cable.

Using another computer, hook up your co-worker's hard drive via the adaptor into a USB port, and salvage whatever files you can before wiping it.
It's not a perfect solution, but at least you can save all the songs by copying them to another drive.

ps - now that you have the adaptor, download WinMFS and use it to put a much larger hard drive in your TiVo.

2 birds/1 stone.
__________________
If you want to avoid 95% of internet spelling errors:
"If your ridiculous pants are too loose, you're definitely going to lose them. Tell your two loser friends over there that they're going to lose theirs, too."
It won't hurt your fashion sense, either.
yournamehere is offline  
Old 01-14-2009, 04:27 PM   #6 (permalink)
Just here for the beer.
 
Wyodiver33's Avatar
 
Location: Ft. Lauderdale, Floriduh
You could also boot from a Linux Live CD. That would allow you to view the hard drive and delete / move files.
__________________
I like stuff.
Wyodiver33 is offline  
Old 01-14-2009, 05:00 PM   #7 (permalink)
Insane
 
Location: at home
Quote:
Originally Posted by yournamehere View Post
If all else fails and your only recourse is to wipe the drive, here's a suggestion. Pretty much the same as MontanaXVI's but you won't have to detach, change the jumper settings, and re-install the HDD.

Get an IDE-to-USB adapter cable (and possibly a USB cable extension) - here's a suggestion where - Newegg.com - GWC AD2200/AD2210 USB2.0 Hi-Speed to IDE Adapter
This is assuming, of course, it's an IDE drive.

Then disconnect the the infected drive from its controller cable.

Using another computer, hook up your co-worker's hard drive via the adaptor into a USB port, and salvage whatever files you can before wiping it.
It's not a perfect solution, but at least you can save all the songs by copying them to another drive.

ps - now that you have the adaptor, download WinMFS and use it to put a much larger hard drive in your TiVo.

2 birds/1 stone.
Good advice there, but I would recomend something like this Newegg.com - Nippon Labs USB-SATA USB to IDE/SATA Adapter w/ power - Adapters & Gender Changers as it has SATA and IDE (2.5" and 3.5"). The link is just the first I found. I have a Vantec version of the same thing, it has already paid for itself.

Yours
Zweiblumen
__________________
Sodomy non sapiens. : I'm buggered if I know
Zweiblumen is offline  
Old 01-15-2009, 10:08 AM   #8 (permalink)
I'm a family man - I run a family business.
 
Redjake's Avatar
 
Location: Wilson, NC
thanks for the suggestions everyone! I ended up formatting & reinstalling windows. this was the worst case of this shit I've ever seen. I used an ext usb hd to backup files. computer is so much faster now!!!
Redjake is offline  
 

Tags
issue, mega


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -8. The time now is 04:24 PM.

Tilted Forum Project

Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0 PL2
© 2002-2012 Tilted Forum Project

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360