Results 1 to 8 of 8

Thread: virus clean up, pull out hd and put in a clean system to clean up?

  1. #1
    Junior Member
    Join Date
    Jan 2008
    Posts
    231
    Thanks
    24
    Thanked 5 Times in 5 Posts
    Rep Power
    206
    Reputation
    26

    Default virus clean up, pull out hd and put in a clean system to clean up?

    I've been given a machine to clean up. Its been infected with a virus after playing a network game. Now it just shuts down when the computer is turned on.

    Can I simply pull the HD out (Win XP) and plug it into my system (VISTA) and run Avat, Search & destroy etc etc?

    Will I break anything on the WinXP system? ... might be a bit late now i've started. what I'm worried about is file premissions etc.

    what else should I do?



Look Here ->
  • #2
    Junior Member
    Join Date
    Jan 2008
    Posts
    231
    Thanks
    24
    Thanked 5 Times in 5 Posts
    Rep Power
    206
    Reputation
    26

    Default

    Avast has found VBS.Solow but its not able to delete it/repair it/move to chest. I think its got to do with file permissions

    Is there a boot cd that has antivirus software that can clean this up?

  • #3
    Junior Member
    Join Date
    Jan 2008
    Posts
    231
    Thanks
    24
    Thanked 5 Times in 5 Posts
    Rep Power
    206
    Reputation
    26

    Default

    hmm the boot cd will probably have the same problem with file permissions...

  • #4
    Senior Member tagg's Avatar
    Join Date
    Jan 2008
    Location
    In a Tin Can
    Posts
    2,203
    Thanks
    872
    Thanked 378 Times in 221 Posts
    Rep Power
    309
    Reputation
    1897

    Default

    VBS.Solow.B propagates on computers via removable media drives. It modifies Web Browser title to "Taga Lipa Are"



    Technical Name: VBS.Solow.B



    Threat Level: Low



    Type: Worm



    Systems Affected: Windows All


    Tagg

  • #5
    Senior Member tagg's Avatar
    Join Date
    Jan 2008
    Location
    In a Tin Can
    Posts
    2,203
    Thanks
    872
    Thanked 378 Times in 221 Posts
    Rep Power
    309
    Reputation
    1897

    Default

    HOW TO REMOVE VBS.Solow.B :

    1. Temporarily Disable System Restore (Windows Me/XP).
    2. Update the virus definitions.
    3. Reboot computer in SafeMode

    4. Run a full system scan and clean/delete all infected files

    5. Delete related files:

    a) Open My Computer -> Tools Menu -> Folder Options -> View Tab:
    b) Select: Show hidden Files and Folders
    c) Uncheck: Hide Extensions for known file type and Hide Protected operating system
    d) Click Yes Then OK.
    e) Delete autorun.inf and FS6519.dll.vbs in all your hard drive. Commonly found in root of Drive C. Use your Windows "Search" function to find all.


    6. Delete any values added to the registry.
    Navigate to and delete the following registry entries:
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run\"FS6519" = "%Windir%\FS6519.dll.vbs"
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\"Window Title" = "TAGA LIPA ARE!"



    7. Exit registry editor and restart the computer.
    8. In order to make sure that the threat is completely eliminated from your computer, carry out a full scan of your computer using AntiVirus and Antispyware Software. Another way to delete the virus using various Antivirus Program without the need to install can be done with Online Virus Scanner.

    Tagg

  • #6
    Junior Member
    Join Date
    Jan 2008
    Posts
    231
    Thanks
    24
    Thanked 5 Times in 5 Posts
    Rep Power
    206
    Reputation
    26

    Default

    Thanks Tagg, will take the drive out and put it back in.

    That doesnt explain why the computer's rebooting on start up. i'll see how it goes in safe mode.

  • #7
    Senior Member tagg's Avatar
    Join Date
    Jan 2008
    Location
    In a Tin Can
    Posts
    2,203
    Thanks
    872
    Thanked 378 Times in 221 Posts
    Rep Power
    309
    Reputation
    1897

    Default

    you may have a power supply or memory problem


    Tagg

  • #8
    Senior Member BCNZ's Avatar
    Join Date
    Jan 2008
    Location
    In the back of a 50 kW AM broadcast transmitter
    Posts
    1,697
    Thanks
    235
    Thanked 292 Times in 190 Posts
    Rep Power
    305
    Reputation
    2546

    Default

    It wasn't running Norton's by any chance was it?

  • Bookmarks

    Posting Permissions

    • You may not post new threads
    • You may not post replies
    • You may not post attachments
    • You may not edit your posts
    •