Computer Geeks, Need Help - Bad Malware/Spyware

BLACK6PACK

1 sec reaction King
Joined
May 24, 2001
IE opens up on its own, that's the most obvious problem. I go to a bunch of malware/spyware sites and they're blocked by the virus. Even a bunch of pages on microsoft.com are blocked. Short of a complete reinstallation of xp any advice. If its a complete reinstall. How do I go about that. I don't have disks just a sticker on the side of the computer with the code key. It was bought from the computer store with all the software installed. XP and windows 2003.
 
Malwarebytes.org

Download and try this. It cleans up all kinds of junk. If you have a hotmail/live messenger account, I can remote in and fix it for you.
 
Thanks Killer! I was hoping you would pop in on this thread. Hope you didn't take offense to the "computer geek" title. Anymore its a badge of honor that comes with a good paycheck. I'm a graphic artist, with enough IT knowledge to be IT's worste nightmare. I know enough to be dangerous! :D

It found several trojans, but several of my other virus stuff found trojans only to be back the next time I booted up the computer. I ran the scan and deleted all the crap, then it took me 4 times to get it to reboot. Every time I tried to boot into safe mode the video card failed. :confused: finally worked on the 5th try.

I opened up AVG and it was actually able to get the updates. AVG, Lavasoft and most of microsoft virus pages were blocked by the trojans. I'm running AVG right now.

Oh, and IE hasn't popped up in the background and started running videos (yet). :)
 
Make sure you don't have remote access enabled. Download "Hijack This" (free) and get rid of everything you don't want. Also use ZoneAlarm(free).
 
Thanks, SFI. Been fighting it for a month or so. :( I can always count on my buick clan to point me in the right direction. I've ran Killer's program again and eliminated the problems, but I'm afraid that another reboot will cause the issues to come back. I'll try your advice on top of the 6 other things I'm doing to get rid of this HIV COMPUTER virus.

Thanks again!
 
And... download firefox so you can at least hit the web. You should be running IE7 not 6 anything. XP SP3? Turn off all the browser add ons in IE.

start > run > msconfig >Enter
go to startup and uncheck anything that is just a blank line or you don't know which program it is. I have seen machines with 30 or so entries. When I'm done, it may have five or six still checked.
 
And... download firefox so you can at least hit the web. You should be running IE7 not 6 anything. XP SP3? Turn off all the browser add ons in IE.

start > run > msconfig >Enter
go to startup and uncheck anything that is just a blank line or you don't know which program it is. I have seen machines with 30 or so entries. When I'm done, it may have five or six still checked.

Funny mine had exactly 30 as well. How do I know which ones to uncheck? Does it speed the computer up??
 
Funny mine had exactly 30 as well. How do I know which ones to uncheck? Does it speed the computer up??

You can expand the location by dragging or double clicking the bars at the top of the list. Follow each of those program paths to see what it's loading. I'll post instructions later on how to export those entries from the registry so you can post the text here. Sorry, have to run to work now...
 
Try this one

SUPERAntiSpyware.com - AntiAdware, AntiSpyware, AntiMalware!

After running the program:

Turn off system restore before rebooting because some programs dont clean all the registry files. If you reboot with system restore on, it will re-install the bug. After rebooting, turn system restore back on!

Be very careful if you use "hijack this", you really have to know what you are doing!
 
Some of these are real nasty, I had a customer that I had to remove the hard drive put it in a usb enclosure and clean it with another computer. I've also used Ultimate Boot CD before you clean the system by booting the system on another os mounting the NTFS partion and running virus scanners on it. Another great program is CCleaner but I'd use it once it's back up and running. Also fireforx on a flash disk can be a live saver.
 
I ran the malware program that killer suggested again and it seemed to clean things up. I haven't opened IE yet, been using Netscape. I did have a warning pop up in the lower right corner last night, but haven't had time to run the program again.

Like I said, I'm not sure how I'm supposed to reformat the computer since I have no disks.
 
It helps to run all those programs in "safe mode" as well. That keeps some of them from coming back when you reboot.
 
Top