Forum Moderators: open

Message Too Old, No Replies

Any spyware experts out there?

Neighbors PC totally infested

         

innocbystr

5:42 am on Aug 16, 2005 (gmt 0)

10+ Year Member



My neighbors seen to think that since I have I a website that I'm an Internet expert. Went to see what their problem was and best I can determine their PC is totaly infested. Cannot download any spyware programs. If I tried and pressed the install button and then nothing happened. On of their most serious problems was that once they started an app or just email they were suddenly deluged with IE popup windows. Downloaded Firefox on CD thinking that if I could get around IE that I could download and run something like Spybot. No Luck. Tried numerous anti-spyware programs to no avail, nothing would even load up. System Restore just listed todays date and that was it, nothing previous, no help there. Anyone have any ideas?

Only solution I can think of is format C:

Blair

BeeDeeDubbleU

6:29 am on Aug 16, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



I have an idea - format c: or you may end up spending days on this. How much time do you like to spend with your neighbour?

Actually there is an opportunity here for some of the whiz kids. Anyone know how to develop and market a program that will deal with and clear all known viruses and spyware?

If you build it they will come.

innocbystr

8:46 am on Aug 16, 2005 (gmt 0)

10+ Year Member



Not that much time. Just trying to be a good neigbhor and, oh well...

Good advice on someone out there putting together some software for spybot prevention, need a bootable CD to take it out.

Perhaps we can share a Dos Eqis sometime.

Blair

Essex_boy

12:11 pm on Aug 16, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Have you tried panda softwares anti virus prohram? you dont have to download, this works well on mine when I have a problem.

Mike12345

1:08 pm on Aug 16, 2005 (gmt 0)

10+ Year Member



Also, have you tried killing all non-windows processes?

Then try installing any software, make sure you turn off system restore, and you could mooch through the registry to find anything untoward an kill it.

Also may seem a bit obvious, but sometimes it helps, but have you tried to use safe mode? ifnot try this first.

Leosghost

11:28 am on Aug 17, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Open the Bios while its booting ..change the boot order to cd first ..run knoppix from cd ..use it to look at the win .ini .sys config files etc ..check them against known good ones from another box that runs the same OS ....find the last known registry that was clean and compare with the current one ( once you get into doing this stuff you might find afreeware ..clean ..no spyware or "helpers" called "Regshot 1.61e5 Final" usefull to compare reg before and after cahnges ..)...usually you can shut down whatever is loading up at the beginning and start your clean up that way ..

Oh and when you have got it running again ..cancel the doze splash screen on load up ..then you have a chance to see what is maybe hijacking the system during bootup if your neighbour manages to get infected again sometime ...

You can selectively change bits of the registry to cure some of your ills as you go along ...if you arent' used to this I would suggest downloading to another machine a copy of " Xteq systems X setup" it can still be found in the free version ..it comes shipped with the lockergnome newsletter ..between them they allow for changing a gerat many things on adoze box ( the guy at lockergnome does think that MS is all that glistens tho ..but he's a good reg hacker with easy to follow instructions ..Xq itself is a gui ..but if you play around with it ( watch out when it tells you something might harm your system it usally will ...you can get it back ..but if you knew how you wouldn't be here asking ..so listen to it ) ...watch what and where in the registry ( on a second machine ) it makes it's changes ...particularly in the run on start area ..than you can import clean reg values over the top of the currently corrupted ones on your friends machine ..

If you have trouble finding your way to certain values in the registry on the second machine ( the one where you are discovering about registries ) ..try looking for "REGISTRY JUMPER"..or "RegSeeker" ..again both freeware ..if you have trouble finding them sticky me ..they are harder to find than they were ...

One last thing ..if you can find the older version of BCwipe that was freeware ..it comes shipped with a destroy or wipefile option ...you can use this on anything doze and totally kill your computer...BUT! just before you kill the file ..such as winini or sysconfig ( tread warily here!) it will let you "veiw" inside the file ( even ones in use such as index.dat etc ) and any attachments with suspect contents ..it's "veiw" is not like "quickview" ..I mean it doesn't actually run the file to see it ..which can be way dangerous ..It looks without running ..thereby allowing you to see what the file is "calling" by way of .dlls ..what the command sequence is ..wether the file actually has two suffixes ..( like a hidden .pif ) ...

You do have to recognise what the lurking nasties are ..it takes time to learn to identify them ..but most virii /scum etc tries to get hook on the same sequence of things in doze to create it's own brand of havoc ...experience will come

When you' discoverd how usefull that "veiw" can be you can stop relying on just an AV to protect yourself ...

Oh yeah ..install a regmoniter on your and their machine as soon as you get control back ....

As some of this stuff and other utilities that you may find usefull are now no longer freeware I can't give you their links here ..however I'm putting together a list of links to some of the better ones ( sticky me ..I'll get back ASAP ) ..The list will soon be a site ..( yeah I know there are others out there ..but clean machines are good for all of us ..and some of the sites that exist are a bit too techy and intimidating ..or push one AV as the total solution ...) ....

S'cuse the spelling ..french keyboard ..and I don't have the time today to "proofread"..

Leosghost

12:22 pm on Aug 17, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



As some of this stuff and other utilities that you may find usefull are now no longer freeware I can't give you their links here

What I mean is they used to be freeware ..some of the freeware versions no longer exist on the "parent sites" of some of the apps and they are now shareware "TBYB" or similar ..hence I shouldn't link to them from here ..howver some of the old abandonware ones I am putting up space for ..and some are still hosted on other freeware providers archive pages ( but again these latter also offer payware or shareware either versions of the same or alternatives .."donc" I cant link to them from here ...)...

Hopefully that doesnt count as "disputing the TOS" ..meant to be "explaining why it's important to be respecting it"...always was catch 22 that one ;)

Got back to the keyboard too late ( the "editable window" delay did get shorter I swear it ) to edit to make the previous post clear and to correct my spelling which was even worse than I thought ( french keyboard layout "AZERTY" ..Irish/English education make for mistakes at speed ...

Lawman usually correct my more horrendous blunders ..in between naps

Leosghost

12:28 pm on Aug 17, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Have you tried panda softwares anti virus program
..

Living dangerously there Delboy ...rather it be your reliant robin than mine if thats your "spare tyre" ;)

It's not the only "kojak tyre" of the AV world ..but it's up there in the top of the hacked , cracked , spoofed and compromised league ..still if you never go near the dangerous parts of the information highway maybe it's nearly safe enough ....

reaper

8:30 am on Aug 22, 2005 (gmt 0)

10+ Year Member



I would try pandasoft its free. This scumbag software that will not allow you to install even a scumbag cleaner is just so wrong.
I read a news article a few weeks ago about the throw away PC. It appears than many execs that use PCs for email and basic offic software hooked up to the internet will throw/buy a new basic pc every 4-6 months because it is not cost effective 4 them to rid thier systems of parasite ware.
I can deal with spam much more effectively than spyware. The feds really need to legislate this type of intrusion/privacy onto personal property.

Essex_boy

10:32 am on Aug 22, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Delboy indeed!

I didnt know that about Panda software ive always found them to effective.

.....Rodney wheres Damien?