Austech  


Go Back   Austech > Technology > Security and Privacy
Register Forum RulesiTrader Mark Forums Read

Security and Privacy Spyware , Proxies , all security and privacy issues and software.

Reply
 
LinkBack Thread Tools Display Modes
Old 30-12-09, 09:57 PM   #21 (permalink)
Super Moderator
 
Sanity's Avatar
 
Join Date: Jan 2008
Location: Victoria
Age: 43
Posts: 7,809
Thanks: 527
Thanked 1,551 Times in 683 Posts
Rep Power: 25
Sanity has a reputation beyond reputeSanity has a reputation beyond reputeSanity has a reputation beyond reputeSanity has a reputation beyond reputeSanity has a reputation beyond reputeSanity has a reputation beyond reputeSanity has a reputation beyond reputeSanity has a reputation beyond reputeSanity has a reputation beyond reputeSanity has a reputation beyond reputeSanity has a reputation beyond repute
Default

He may be referring to the XP repair function ? Put the XP install disc in the drive and reboot the PC. Follow the instructions on the screen should get you to it I think.
Sanity is offline   Reply With Quote
Old 30-12-09, 10:13 PM   #22
Premium Member
 
checkitout's Avatar
 
Join Date: Jan 2008
Posts: 812
Thanks: 12
Thanked 15 Times in 13 Posts
Rep Power: 19
checkitout will become famous soon enough
Default

Thanks - I would call this a re-install "repair" .

Believe it or not it is not my day.

Have been trying to do this but it looks like the original XP install disc has a scratch enough to be unreliable. I am trying to source an exact copy... really need WIN XP SP2 as a minimum.

Not my day...
checkitout is offline   Reply With Quote
Old 30-12-09, 10:18 PM   #23
I'am Not a Bloody Joke
 
best4less's Avatar
 
Join Date: Jan 2008
Location: Australia
Age: 44
Posts: 5,098
Thanks: 1,034
Thanked 545 Times in 296 Posts
Rep Power: 127
best4less has a reputation beyond reputebest4less has a reputation beyond reputebest4less has a reputation beyond reputebest4less has a reputation beyond reputebest4less has a reputation beyond reputebest4less has a reputation beyond reputebest4less has a reputation beyond reputebest4less has a reputation beyond reputebest4less has a reputation beyond reputebest4less has a reputation beyond reputebest4less has a reputation beyond repute
Default

Do a search for " BartPE rapidshare " should be able to find a complete iso image ready to go
__________________
Shut Up I Hack You
best4less is offline   Reply With Quote
Old 30-12-09, 10:33 PM   #24
Premium Member
 
joezep's Avatar
 
Join Date: Jan 2008
Location: SE Melbourne
Posts: 358
Thanks: 54
Thanked 45 Times in 27 Posts
Rep Power: 12
joezep has a spectacular aura aboutjoezep has a spectacular aura aboutjoezep has a spectacular aura about
Default

OMG these virus are getting smarter everyday. A mate of a mate asked me if i could get rid of all the nasties off his laptop. First look at notebook, Norton's expired omg!!, had no control of INTERNET it always went to their antivirius homepage. First thing i did was uninstall Norton's and went out and bought Kaspersky thats when the trouble began.

Tried to activate Kaspersky no go, installed spybot search and destroy could not update and malwarebytes still could not update.

These are the steps that fixed it

Disable system restore

Go into safe mode with network

Only then i could activate Kaspersky and update programs

Ran full scan with all three programs still in safe mode

Rebooted and spybot did one more scan then able system restore all sweet.

The key is to disable system restore first and then run everything in safemode

Hope that helps.
joezep is online now   Reply With Quote
The Following 2 Users Say Thank You to joezep For This Useful Post:
dan22 (02-01-10), osci (31-12-09)
Old 31-12-09, 03:12 PM   #25
Member
 
Join Date: May 2008
Age: 30
Posts: 33
Thanks: 0
Thanked 1 Time in 1 Post
Rep Power: 3
grizu34 is on a distinguished road
Default

i have just relized that along with myself and others the problem/virus what the thing is effects WIN XP

all the hijackthis reports logged in are XP?

must upgrade to vista or 7
grizu34 is offline   Reply With Quote
Old 31-12-09, 03:12 PM   #26
Premium Member
 
checkitout's Avatar
 
Join Date: Jan 2008
Posts: 812
Thanks: 12
Thanked 15 Times in 13 Posts
Rep Power: 19
checkitout will become famous soon enough
Default

Quote:
Originally Posted by best4less View Post
Do a search for " BartPE rapidshare " should be able to find a complete iso image ready to go
Searched the internet last nigh and downloaded 2 versions of which both are corrupted and are of no use. what a waste of time.

Does anyone have a reputable URL or location I can get a working BartPE ISO image from ??
checkitout is offline   Reply With Quote
Old 01-01-10, 01:38 PM   #27
Premium Member
 
checkitout's Avatar
 
Join Date: Jan 2008
Posts: 812
Thanks: 12
Thanked 15 Times in 13 Posts
Rep Power: 19
checkitout will become famous soon enough
Default

OK I have just been able to get a HawkePE 37 ISO image successfully downloaded and am about to try that.

Pointers anyone??
checkitout is offline   Reply With Quote
Old 02-01-10, 02:26 AM   #28
Premium Member
 
checkitout's Avatar
 
Join Date: Jan 2008
Posts: 812
Thanks: 12
Thanked 15 Times in 13 Posts
Rep Power: 19
checkitout will become famous soon enough
Default

I am making some progress.

To tell you the truth the Hawke/Bart PE Disk did not help much apart from proving that the hardware was OK.

A combination of scanning for Virus and Spyware with a Windows repair install has brought the machine back to life with original programs intact. I still have the problem of not being able to connect to the internet.

I will do more Virus and Spyware scans tomorrow and then do another windows repair install and see what happens.

Also I have noticed I can improve the performance of the machine by changing settings within msconfig to different settings (basic gives better shart down and startup times)
checkitout is offline   Reply With Quote
Old 02-01-10, 03:28 AM   #29
I'am Not a Bloody Joke
 
best4less's Avatar
 
Join Date: Jan 2008
Location: Australia
Age: 44
Posts: 5,098
Thanks: 1,034
Thanked 545 Times in 296 Posts
Rep Power: 127
best4less has a reputation beyond reputebest4less has a reputation beyond reputebest4less has a reputation beyond reputebest4less has a reputation beyond reputebest4less has a reputation beyond reputebest4less has a reputation beyond reputebest4less has a reputation beyond reputebest4less has a reputation beyond reputebest4less has a reputation beyond reputebest4less has a reputation beyond reputebest4less has a reputation beyond repute
Default

Quote:
Originally Posted by checkitout View Post
I am making some progress.

To tell you the truth the Hawke/Bart PE Disk did not help much apart from proving that the hardware was OK.
That's true but you do have to use other programs like registry restore LOL
and that way you can restore your computer to before the Trojan was installed and that way you can start your computer and run Malawarebytes

Trust me, done 100's of them mate


__________________
Shut Up I Hack You
best4less is offline   Reply With Quote
The Following 3 Users Say Thank You to best4less For This Useful Post:
bigfella08 (03-01-10), osci (02-01-10), OSIRUS (02-01-10)
Old 02-01-10, 12:44 PM   #30
Premium Member
 
checkitout's Avatar
 
Join Date: Jan 2008
Posts: 812
Thanks: 12
Thanked 15 Times in 13 Posts
Rep Power: 19
checkitout will become famous soon enough
Default

Thanks Best... luv your work and help mate.

Unfortunately Registry Restore will not work as once I did the XP install repair restore points back in time are no longer available...

Also I did not realise that I could have done registry restore once I placed the HDD into another working computer

Live and learn I suppose...

I am still finding Viruses and Spyware since I have done the XP install repair (not sure what happened here) .. some I am cleaning the HDD again now and starting again.... it takes forever with the scans I need to be patient
checkitout is offline   Reply With Quote
Old 02-01-10, 12:59 PM   #31
Super Moderator
 
WhiteOx's Avatar
 
Join Date: Jan 2008
Location: Newcastle, Nsw
Posts: 1,474
Thanks: 102
Thanked 422 Times in 139 Posts
Rep Power: 25
WhiteOx has a brilliant futureWhiteOx has a brilliant futureWhiteOx has a brilliant futureWhiteOx has a brilliant futureWhiteOx has a brilliant futureWhiteOx has a brilliant futureWhiteOx has a brilliant futureWhiteOx has a brilliant futureWhiteOx has a brilliant futureWhiteOx has a brilliant futureWhiteOx has a brilliant future
Default

My wife keeps getting a similar fake virus scanner ..... it comes from dodgy places like underground.mn and katzforums

Malwarebytes usually gets rid of it.
Boot into safe mode and use Malwarebytes portable from a usb stick, make sure you update it first.
There's a link to it in the premium section.
WhiteOx is offline   Reply With Quote
Old 02-01-10, 02:14 PM   #32
Senior Member
 
Philquad's Avatar
 
Join Date: Jan 2008
Location: nelson bay
Age: 42
Posts: 1,373
Thanks: 17
Thanked 215 Times in 103 Posts
Rep Power: 40
Philquad has much to be proud ofPhilquad has much to be proud ofPhilquad has much to be proud ofPhilquad has much to be proud ofPhilquad has much to be proud ofPhilquad has much to be proud ofPhilquad has much to be proud ofPhilquad has much to be proud of
Default

yes malwarebytes
i would check msconfig 1st, make sure nothing is in the startup
in ie, go tools, internet options,connections,lan settings
make sure its on automatic detect and not proxy.
Philquad is offline   Reply With Quote
Old 02-01-10, 02:17 PM   #33
Super Moderator
 
WhiteOx's Avatar
 
Join Date: Jan 2008
Location: Newcastle, Nsw
Posts: 1,474
Thanks: 102
Thanked 422 Times in 139 Posts
Rep Power: 25
WhiteOx has a brilliant futureWhiteOx has a brilliant futureWhiteOx has a brilliant futureWhiteOx has a brilliant futureWhiteOx has a brilliant futureWhiteOx has a brilliant futureWhiteOx has a brilliant futureWhiteOx has a brilliant futureWhiteOx has a brilliant futureWhiteOx has a brilliant futureWhiteOx has a brilliant future
Default

Quote:
Originally Posted by PhillTheQuad View Post
yes malwarebytes
i would check msconfig 1st, make sure nothing is in the startup
in ie, go tools, internet options,connections,lan settings
make sure its on automatic detect and not proxy.
Sounds like you have dealt with this bugger before too.
WhiteOx is offline   Reply With Quote
Old 02-01-10, 02:25 PM   #34
Premium Member
 
checkitout's Avatar
 
Join Date: Jan 2008
Posts: 812
Thanks: 12
Thanked 15 Times in 13 Posts
Rep Power: 19
checkitout will become famous soon enough
Default

Quote:
Originally Posted by WhiteOx View Post
My wife keeps getting a similar fake virus scanner ..... it comes from dodgy places like underground.mn and katzforums

Malwarebytes usually gets rid of it.
Boot into safe mode and use Malwarebytes portable from a usb stick, make sure you update it first.
There's a link to it in the premium section.
Thanks

One main problem I have is that I get locked out of having network and internet access... hence I am never able to get a latest update of the internet

Any chance of having a Malware update via a downloaded file from another computer?
checkitout is offline   Reply With Quote
Old 02-01-10, 02:51 PM   #35
Senior Member
 
Philquad's Avatar
 
Join Date: Jan 2008
Location: nelson bay
Age: 42
Posts: 1,373
Thanks: 17
Thanked 215 Times in 103 Posts
Rep Power: 40
Philquad has much to be proud ofPhilquad has much to be proud ofPhilquad has much to be proud ofPhilquad has much to be proud ofPhilquad has much to be proud ofPhilquad has much to be proud ofPhilquad has much to be proud ofPhilquad has much to be proud of
Default

you need to stop this thing running 1st
do the above msconfig trick,reboot
run mwbytes if you have it, even if its not updated
check ie settings as i said above
Philquad is offline   Reply With Quote
Old 02-01-10, 07:38 PM   #36
Premium Member
 
checkitout's Avatar
 
Join Date: Jan 2008
Posts: 812
Thanks: 12
Thanked 15 Times in 13 Posts
Rep Power: 19
checkitout will become famous soon enough
Default

Quote:
Originally Posted by PhillTheQuad View Post
you need to stop this thing running 1st
do the above msconfig trick,reboot
run mwbytes if you have it, even if its not updated
check ie settings as i said above
I have pulled the HDD out and run Malware bytes via another computer. I have also used CA Antivirus and Anti Spyware. The hard drive is surely clean now.

Also re-installed XP as a repair install.

I am getting the following error "Spoolker Subsystem App has encountered a problem and needs to close...etc" which seems to co-incide with the network connection failures.

Phil.. I will try with your instructions but I have lost faith... if the HDD is clean now and I am not getting access to the internet the Malware Bytes is not going to help... it is a catch 22 ??

BTW now apart from the lack of access to the internet the machine appears to work fine...

I know a fix will be a full HDD format and new install but this loses the key programs we do not have a backup for...
checkitout is offline   Reply With Quote
Old 02-01-10, 07:53 PM   #37
Premium Member
 
checkitout's Avatar
 
Join Date: Jan 2008
Posts: 812
Thanks: 12
Thanked 15 Times in 13 Posts
Rep Power: 19
checkitout will become famous soon enough
Default

Before someone states this suggestion again I must also say I now do not have access to restore, Registry Restore Wizard or otherwise.

Once I did the XP Install/Repair there are no restore points available (looks like a fresh install.. but actually is not)

I am running Malware now on the machine to see if anytthing found... my gut feeling is that it will be clean
checkitout is offline   Reply With Quote
Old 02-01-10, 09:22 PM   #38
Premium Member
 
OSIRUS's Avatar
 
Join Date: Jul 2008
Location: NSW
Posts: 1,351
Thanks: 992
Thanked 176 Times in 111 Posts
Rep Power: 37
OSIRUS is a splendid one to beholdOSIRUS is a splendid one to beholdOSIRUS is a splendid one to beholdOSIRUS is a splendid one to beholdOSIRUS is a splendid one to beholdOSIRUS is a splendid one to beholdOSIRUS is a splendid one to behold
Default

Looks like you are getting there,

Hope your nearly done

Good Luck
__________________
Become a Premium Member and support the Austech Forum

Last edited by OSIRUS; 02-01-10 at 09:28 PM.
OSIRUS is offline   Reply With Quote
Old 02-01-10, 10:25 PM   #39
Senior Member
 
Philquad's Avatar
 
Join Date: Jan 2008
Location: nelson bay
Age: 42
Posts: 1,373
Thanks: 17
Thanked 215 Times in 103 Posts
Rep Power: 40
Philquad has much to be proud ofPhilquad has much to be proud ofPhilquad has much to be proud ofPhilquad has much to be proud ofPhilquad has much to be proud ofPhilquad has much to be proud ofPhilquad has much to be proud ofPhilquad has much to be proud of
Default

unplug the printer
Philquad is offline   Reply With Quote
Old 02-01-10, 11:46 PM   #40
Premium Member
 
checkitout's Avatar
 
Join Date: Jan 2008
Posts: 812
Thanks: 12
Thanked 15 Times in 13 Posts
Rep Power: 19
checkitout will become famous soon enough
Default

Quote:
Originally Posted by PhillTheQuad View Post
unplug the printer
No Printer has been connected... I have managed to get Malware bytes going on the same machine with MS config set with nothing in startup now

It takes ages for a full scan. I will let you know how this goes
checkitout is offline   Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Malware bytes won't run osci Security and Privacy 10 05-10-09 09:00 PM
Malware osci Security and Privacy 6 28-03-09 11:47 AM
Viral/malware nasty mandc Operating Systems 8 20-02-09 07:13 PM
NoAdware - is it malware? Studio1 PC Software 3 19-04-08 12:34 PM


All times are GMT +11. The time now is 04:24 AM.


Powered by vBulletin™
Copyright © vBulletin Solutions, Inc. All rights reserved.
Ad Management plugin by RedTyger