• The Forums are now open to new registrations, adverts are also being de-tuned.

Help needed

glojo

Hardcore MB Enthusiast
Joined
Sep 15, 2004
Messages
14,652
Location
Torquay
Car
S211 Sprinter 213CDI, & the new T-class
My brother has very recently emigrated to New Zealand and his main form of communication with friends and relatives is via the computer, be it Skype or e-mail.

This morning I received the following message:

Hi I’m having to write this from my laptop. The main pc has somehow caught a terminal virus. I updated it today with the latest windows updates. After I restarted it every thing was ok until tonight when Norton went to run its routine virus scan. I got the message Norton could not run because its out of date I thought this strange as its only about 4 months old. I thought I would restore the computer in case something had happened when I had updated it this morning. I got the message that restore is disabled and am unable to switch it back on. I then found that the registry mechanic program would not run. I ran my anti spyware programme which found 56 problems. There were 4 Trojans on the PC one of them apparently disables all security programs that try to remove it. So far it has disabled Norton Security, Killbox, MSCONFIG.exe, System restore, Hijack this and Registry Mechanic. Spyware Doctor can not remove it. The other Trojans send data to third parties, Hijack intertnet backing and so on. The list of antivirus programs that have been disabled on my pc came up and seemed pretty exhaustive. I’ve switched it off so don’t have them infront of me. Any advice would be most welcome I don’t have all the install disc’s to put the pc back together. The main thing I want to know is how on earth the things got onto the system in the first place when all my software is up to date?

************************************************************************************
Now I know that he has an extremely SLOW connection I believe the fastest connection they can allegedly get is 56k, but in reality it is less than half that, so there is no way they will be downloading music or any other software.

I would be grateful if anyone can offer any advice.

Bye for now,
John
 
False MICROSOFT update links by E-MAIL

There are numerous "False Updates" EMAILS on the go at the moment purporting to be from MICROSOFT. If he received an update "link " via e-mail and used it, his pseudo security update or windows update will have downloaded all these problems from a rogue site. :crazy: IS THERE A POSSIBLITY HE DID THIS ???
Having identified the main problems, he will have to download security fix progs from symantec or similar sites on to bootable floppy or CD via his laptop and use them to clean his system (read the symantec notes carefully also about disabling certain windows features while he does this). Hopefully he can concentrate on getting his anti virus/spyware progs to work and then maybe use them to clean up the rest. Caution him also about rogue dialers if he is back on the old 56k modem technology!
 
Last edited:
grober said:
he will have to download security fix progs from symantec or similar sites on to bootable floppy or CD via his laptop and use them to clean his system (read the symantec notes carefully also about disabling certain windows features while he does this).

Hi Grober,
Thanks very much for the quick response, I had already suggested getting a rescue floppy disc, but I was certainly not aware of the rogue updates... Ouch, that is certainly something I will have to be on my guard against.

I have never been a fan of Norton Anti-Virus, but should it have picked this up? What's the point in paying for anti-virus software?

I'll pass on your warning to him, thanks again.

John
 
There is a new raft of Microsoft security fixes, Windows upgrades and malware removal tools. I did them last night.

Has he tried this?

Otherwise may be a case of buying a new copy of Windows XP (which is not that expensive if you get an OEM version from the right place) formatting the hard disk (or maybe get another?) and reinstall.

I had to do this last year after a triumph by No 2 son that resulted in all manner of nasties. Advised that these simply could not be made to go away other than at a cost in terms of time & effort that was likely to be in excess of a format/reinstall. A real pain.

Took the opportunity to upgrade to XP Professional and put a second drive in
 
You can do an online scan here
 
Thanks Satch and PJH,
The problem is he cannot log on. Not even in safe mode.

He lost his sense of humour when I suggested he might have picked up the virus by logging onto sites of 'ill repute' :o So it looks like it might have been caused by Grobers suggestion.

When I upgraded my computer I also took the oppurtunity to upgrade to Windows XP Pro.

John
 
PJH said:
You can do an online scan here

Over dial-up? I dont think so.

His best bet is to use any of the major antivirus companies boot floppy's. That said, when a PC gets this badly infected you can be really up against it.

If he knows anyone else locally with a PC, he could attach his HDD to another PC as a slave and clean it thius way. Ideally, connect it to a PC with a fast connection so he can perform online scans. He could also purchase a USB 3.5" disk caddy or use one from a external CD/DVD burner and connect it to his laptop and clean it this way.

Whichever route he takes, its likely to be a very time consuming excersise.

The reason for all the problems is likely due to not being up to date at some point with his antivirus dats, coupled with the fact that over dial-up you have a publicly accessible IP address rather than being sheilded behind a router using NAT. If you have no firewall or have any non protected shares you are going to get infected pretty quickly.

FWIW, IMO, Norton antivirus doesnt cut the mustard being intrusive and slow to get the updates which should be checked daily - most people on dial-up find daily updates nigh on impossible.
 
Sp!ke said:
FWIW, IMO, Norton antivirus doesnt cut the mustard being intrusive and slow to get the updates which should be checked daily - most people on dial-up find daily updates nigh on impossible.

Hi Spike,
Thanks very much for your most informative post. I do know he is a stickler for keeping his anti-virus software uptodate, so I doubt if that was the cause. Like you say it certainly appears to be a big problem, and a 'fast connection' is a non starter. Only the larger towns have broadband and my brother is 9km away from the nearest town so that rules that one out. Your other suggestions are definitely worthy of consideration.

He is thirteen hours ahead of us and no doubt fast asleep at present. I will collate all the very constructive messages, copy and paste them into one message, then post them all along with a 10 megabyte Mp3 :D

Thanks very much
 
glojo said:
I will collate all the very constructive messages, copy and paste them into one message, then post them all along with a 10 megabyte Mp3 :D

Thanks very much
John, you are a very cruel man................but I like your style :D
 

Users who are viewing this thread

Back
Top Bottom