Boat Drinks  

Go Back   Boat Drinks > General > Computer and Consoles

Reply
 
Thread Tools Display Modes
Old 22-03-2008, 12:26   #1
Joe 90
Absinthe
 
Joe 90's Avatar
 
Join Date: Jan 2007
Location: Chester
Posts: 2,345
Default Need to rid myself of some nasty Malware

oh noes - gots some nasty adware/spyware.

It would appear my brother/mother have cocked up this laptop whilst i've been at uni.
I got back last week and it had some 'Win AntiVirus 2007' installed so i'm guessing things started with an IE popup saying 'youre computer is not protected, install this now!!'

so i've ran spybot/ccleaner/avast scans which all claim to do their job but still this thing seems to have a couple of startup scripts which shouldn't rund, and i also get two rundll32 errors because i've removed two files that this nasty stuff obviously wanted.

now, one thing we've got is definately this Vundo Trojan which spybot says its removed a few times, but it keeps coming back alongside some others.
Anyway, if these apps can't get rid, can anyone advise what i do?
i tried to run through regedit with symantec's advise from that site, but some of the reg keys didn't exist, but those that did, got removed. not sure what else to do really.

*edit*
don't know if its related, but Windows update just failed, twice to install office sp1 and a security patch. And facebook keeps failing to upload any photos (even just a sinlge 30kb image!)
__________________
360 Blog | Join GiffGaff | Twitter

Last edited by Joe 90; 22-03-2008 at 12:55.
Joe 90 is offline   Reply With Quote
Old 22-03-2008, 13:02   #2
Justsomebloke
The Night Worker
 
Justsomebloke's Avatar
 
Join Date: Jul 2006
Posts: 5,228
Default

Did you turn Off system restore prior to running scans etc ?
__________________



Justsomebloke is offline   Reply With Quote
Old 22-03-2008, 13:09   #3
Joe 90
Absinthe
 
Joe 90's Avatar
 
Join Date: Jan 2007
Location: Chester
Posts: 2,345
Default

/digs up sys restore.

looks like its still turned on.

do these things create restore points and restore themselves silently after removal?

how'd you turn off sys restore? been ages since i've used XP
__________________
360 Blog | Join GiffGaff | Twitter
Joe 90 is offline   Reply With Quote
Old 22-03-2008, 13:16   #4
Justsomebloke
The Night Worker
 
Justsomebloke's Avatar
 
Join Date: Jul 2006
Posts: 5,228
Default

Control panel/ System / Top left tab then Tick the box to Turn it Off.

Yes mate that is how they keep popping back, Turn Off system restore then Run all your Scans, I use Ad aware, S&D & Avast & you can also download a few from Microsoft like the malicous whatever remover. Then use CCleaner & then clear out your Start menu using MSconfig.
Then reboot, Defrag, turn on System restore & Bobs the Uncle who had sex with his dog in the public toilets.
__________________



Justsomebloke is offline   Reply With Quote
Old 22-03-2008, 13:36   #5
Joe 90
Absinthe
 
Joe 90's Avatar
 
Join Date: Jan 2007
Location: Chester
Posts: 2,345
Default

fantastic - cheers
__________________
360 Blog | Join GiffGaff | Twitter
Joe 90 is offline   Reply With Quote
Old 22-03-2008, 14:39   #6
Stan_Lite
Stan, Stan the FLASHER MAN!
 
Stan_Lite's Avatar
 
Join Date: Jul 2006
Location: In bed with your sister
Posts: 5,483
Default

Running the spyware removers with Windows in safe mode can help too.
__________________

Just because I have a short attention span doesn't mean I...
Stan_Lite is offline   Reply With Quote
Old 22-03-2008, 15:39   #7
Desmo
The Last Airbender
 
Desmo's Avatar
 
Join Date: Jun 2006
Location: Pigmopad
Posts: 11,915
Default

I had to sort out this load of crap a week or so ago for a lady who works for us. Her laptop was streaming with stuff after her daughter used it. I downloaded VundoFix whic hgto rid of that and then run S&D, Ad Aware and AVG free after that. Took a good few goes to get it clear but it's fine now.
__________________
Desmo is offline   Reply With Quote
Old 23-03-2008, 14:14   #8
Stan_Lite
Stan, Stan the FLASHER MAN!
 
Stan_Lite's Avatar
 
Join Date: Jul 2006
Location: In bed with your sister
Posts: 5,483
Default

I had an old laptop to look at yesterday as IE and Windows update weren't working. Re-installed IE7 and it was fine so ran adaware whilst I was at it and it found 500 infections - 123 of which, Adaware classed as malicious. I decided I'd best run a virus scan too and when I opened AVG, it was out of date and not activated. Uninstalled it and installed Avast and ran a boot scan - it found 3 trojans and 2 spyware things which Adaware missed.
What a mess. All seems to be fine now, though.
__________________

Just because I have a short attention span doesn't mean I...
Stan_Lite is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT +1. The time now is 23:09.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.