Click Here



Post New Topic  Post A Reply
my profile | register | search | faq | forum home
  next oldest topic   next newest topic
»  :[ Q3Arena.com Message Board ]:   » The Lounge   » shitload of problems!

UBBFriend: Email this page to someone!    
Author Topic: shitload of problems!
Zippy
Sarge
Member # 3027

Rate Member

posted 07-23-2004 02:48 AM     Profile for Zippy   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
just working on a friends computer(sony viao) and holy crap!
-269 windows problems detected by windoctor
-422 spyware products
-4 virus's
-282 progies at risk
-and a shitload of dust bunnies!
jez, when are people going to learn how to use computers properly!

--------------------


Posts: 94 | From: Canada | Registered: Dec 2003  |  IP: Logged
outrider
Sarge
Member # 41

Member Rated:

posted 07-23-2004 08:58 AM     Profile for outrider   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
Sounds like a dell 4300 I worked on last week.
Posts: 2426 | From: nc | Registered: Jun 1999  |  IP: Logged
Cacophonous
Sarge
Member # 19

Member Rated:

posted 07-23-2004 09:17 AM     Profile for Cacophonous   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
And a generic one I just finished last night. This one was only dial-up but had:

No antivirus software
No anti-ad program
XP had no updates (no SP1 or anything)

It only had 8 instances of a worm. But tons of other junk.

The browser hijack took the longest to correct since I needed to patch out windows, etc.

--------------------

...


Posts: 5571 | From: Yes | Registered: Jun 1999  |  IP: Logged
dAm
Sarge
Member # 2600

Member Rated:

posted 07-23-2004 09:51 AM     Profile for dAm   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
Here's one I worked on last year. Only had one virus but a shitload of infected files.

--------------------

Shut-up and fish


Posts: 577 | From: Calgary | Registered: Nov 2001  |  IP: Logged
Cacophonous
Sarge
Member # 19

Member Rated:

posted 07-23-2004 10:30 AM     Profile for Cacophonous   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
Our email server at work had 35,000 infected files (messages) once. It took me days to clean it up because the antivirus software had to read all that data. I thought the antivirus software was corrupt but it was just so slow due to that number.

--------------------

...


Posts: 5571 | From: Yes | Registered: Jun 1999  |  IP: Logged
AcidWarp
Sarge
Member # 997

Member Rated:

posted 07-23-2004 11:02 AM     Profile for AcidWarp   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
I didn't personally see it, but at work apparently one came into the shop that had 30,000 infected files, that weren't email. The virus had just kept replicating. I think the average amount of spyware that I see is around 700-800 objects per scan. We use Ad-Aware and Spybot for that. Coupled with Hijack This and several other utilities.

Oh, and as for dustbunnies, nothing, and I mean NOTHING beats the ones with spider webs, complete with eaten bugs, and the spider itself.

Cac, that browser hijack sounds suspiciously like CoolWebSearch. Might be a good idea to go back and re-check the machine in a day or two. It's a NASTY peice of spyware that some AV vendors now consider a trojan. It's a bitch to get rid of. I've had to do a few manual removals, and it's not easy.

--------------------

“I have noticed even people who claim everything is predestined, and that we can do nothing to change it, look before they cross the road.”

“Intelligence is the ability to adapt to change.”

--Dr. Stephen Hawking.


Posts: 4363 | From: Waterloo, Ontario | Registered: Nov 1999  |  IP: Logged
Cyborg6
Sarge
Member # 1382

posted 07-23-2004 12:14 PM     Profile for Cyborg6   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
When building a person a computer go:

AVG Virus (Free Updates)
Zone Alarm (Firewall)

Then leave and say "You are now on your own, don't call me for support"

Do I sound bitter?


Posts: 2869 | From: | Registered: Dec 1999  |  IP: Logged
J0SH
Sarge
Member # 103

Rate Member

posted 07-23-2004 12:36 PM     Profile for J0SH   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
hehe, no, you install zone alarm and avg and then say "if you call me for support it will be $45 for the first hour and $30 each additional hour

--------------------

I am.


Posts: 1591 | From: buffalo new york | Registered: Jun 1999  |  IP: Logged
Cacophonous
Sarge
Member # 19

Member Rated:

posted 07-23-2004 02:59 PM     Profile for Cacophonous   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
AW - I think it may be CoolWebSearch. I still have the machine so I'll take your advice and check it in a few days. Thanks...

--------------------

...


Posts: 5571 | From: Yes | Registered: Jun 1999  |  IP: Logged
Cacophonous
Sarge
Member # 19

Member Rated:

posted 07-23-2004 06:59 PM     Profile for Cacophonous   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
Nope it's god damn Home Search and it's baccccck.

--------------------

...


Posts: 5571 | From: Yes | Registered: Jun 1999  |  IP: Logged
Acid
Sarge
Member # 758

Member Rated:

posted 07-23-2004 09:31 PM     Profile for Acid   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
AVG is awesome.
Posts: 1306 | From: | Registered: Sep 1999  |  IP: Logged
Cyrus
Sarge
Member # 344

Rate Member

posted 07-24-2004 12:56 AM     Profile for Cyrus   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
When I had a whole lot of junk on my computer after using Internet Explorer, I had to use several programs to fully clean my computer.

Some that come to mind are:

CWSShredder
Stinger
Ad-Aware
AVG
Norton Trial Version
SpyBot - Search & Destroy
Zone Alarm

This is why I now use FireFox

--------------------

Shiny.


Posts: 205 | From: Winnipeg, Manitoba, Canada | Registered: Jul 1999  |  IP: Logged
Cacophonous
Sarge
Member # 19

Member Rated:

posted 07-24-2004 01:00 AM     Profile for Cacophonous   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
I'm suprised that AW is the only person who mentioned 'hijack this'.

Great program...

--------------------

...


Posts: 5571 | From: Yes | Registered: Jun 1999  |  IP: Logged
jondster
Sarge
Member # 109

Member Rated:

posted 07-24-2004 10:33 AM     Profile for jondster   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
Where do you get AVG ?

--------------------

No Sig


Posts: 2128 | From: Cascade MI USA | Registered: Jun 1999  |  IP: Logged
AcidWarp
Sarge
Member # 997

Member Rated:

posted 07-24-2004 11:09 AM     Profile for AcidWarp   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
www.grisoft.com there's a free version, it's very popular right now.

I don't have a high opinion of AVG. I've seen it mess up, break, and even miss things. I'll stick with Norton. I use Norton AV 2004, and while admittedly it's suppose to be buggy I haven't had a problem yet *knocks on wood* and it's got a smaller memory footprint than 2003 did.

Recently I've seen a anti-virus scanner called Nod32 that seemed pretty nice. It's VERY fast at scanning, and doesn't appear to miss anything. Haven't had much of a chance to use it though.

Oh, Cac, there's a couple of really neat utils for removing spyware. There's AboutBlaster and BHODemon, they seem to work pretty well. Autoruns is another good one too. Home Search is a variant of CWS iirc. But try those, they wipe out Browser Helper Objects etc. You have to treat CWS like a virus. Do all of your scans etc in safe mode with no networking support.

Oh, and about CWShredder. Just so you guys know, it is no longer being updated. The guy who was putting it out just can't keep up to the rate of changes that CoolWebSearch goes through. It's still a good idea to run it, because the computer could be infected with more than one variant, and CWS might help.

[ 07-24-2004: Message edited by: AcidWarp ]

[ 07-24-2004: Message edited by: AcidWarp ]

--------------------

“I have noticed even people who claim everything is predestined, and that we can do nothing to change it, look before they cross the road.”

“Intelligence is the ability to adapt to change.”

--Dr. Stephen Hawking.


Posts: 4363 | From: Waterloo, Ontario | Registered: Nov 1999  |  IP: Logged
Flux
Sarge
Member # 3052

posted 07-24-2004 12:47 PM     Profile for Flux   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
There's always HijackThis. Lists BHOs, registry entries for anything that runs on startup as well as stuff hooked into the browser, etc. It gives you a list of things that you can delete.

--------------------


Posts: 794 | From: | Registered: Jan 2004  |  IP: Logged
Cacophonous
Sarge
Member # 19

Member Rated:

posted 07-24-2004 03:07 PM     Profile for Cacophonous   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
quote:
Originally posted by Cacophonous:
I'm suprised that AW is the only person who mentioned 'hijack this'.

Great program...


Pay attention [josh]Flux[/josh]

--------------------

...


Posts: 5571 | From: Yes | Registered: Jun 1999  |  IP: Logged
AcidWarp
Sarge
Member # 997

Member Rated:

posted 07-24-2004 03:13 PM     Profile for AcidWarp   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
Yeah flux, pay attention

Autoruns goes further than HijackThis for startup items, and even further than msconfig does. Check it out.

[edit]
Just thought of something Cac. If the VAIO machine is Win98/Me and CWS just keeps coming back, you can try using IEeradicator as well. It kinda breaks things in WinXP (like windows update) but you can use it to strip out IE and then reinstall it fresh from CD if you have it. If you don't have the full redistributal IE installer on hand, you can download it from MS. You absolutely NEED IE for windows update. So it's wise to put it back in.

[ 07-24-2004: Message edited by: AcidWarp ]

--------------------

“I have noticed even people who claim everything is predestined, and that we can do nothing to change it, look before they cross the road.”

“Intelligence is the ability to adapt to change.”

--Dr. Stephen Hawking.


Posts: 4363 | From: Waterloo, Ontario | Registered: Nov 1999  |  IP: Logged
Cacophonous
Sarge
Member # 19

Member Rated:

posted 07-24-2004 03:19 PM     Profile for Cacophonous   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
I meant to respond back to you AW but I was waiting for the flood control police to go get a donut or something.

Yeah thanks for the tips. I will try what you are recommending.

--------------------

...


Posts: 5571 | From: Yes | Registered: Jun 1999  |  IP: Logged
AcidWarp
Sarge
Member # 997

Member Rated:

posted 07-24-2004 03:32 PM     Profile for AcidWarp   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
*bump*

Edited my post.

--------------------

“I have noticed even people who claim everything is predestined, and that we can do nothing to change it, look before they cross the road.”

“Intelligence is the ability to adapt to change.”

--Dr. Stephen Hawking.


Posts: 4363 | From: Waterloo, Ontario | Registered: Nov 1999  |  IP: Logged
J0SH
Sarge
Member # 103

Rate Member

posted 07-26-2004 09:13 AM     Profile for J0SH   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
i need not pay attention - i already use hijack this!

--------------------

I am.


Posts: 1591 | From: buffalo new york | Registered: Jun 1999  |  IP: Logged
Serengeti
Sarge
Member # 51

Rate Member

posted 07-27-2004 09:52 AM     Profile for Serengeti   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
Has anyone actually ever been able to successfulyl remove CoolWebSearch? I tried for about a week on the kids' PC and gave up and reinstalled everything.

I tend to consider myself extremely windows savvy, and I couldn't find all the places where that shit stuck itself.

That really should be illegal, and the creators should be shot!


Posts: 1045 | From: your grocer's freezer | Registered: Jun 1999  |  IP: Logged
J0SH
Sarge
Member # 103

Rate Member

posted 07-27-2004 10:07 AM     Profile for J0SH   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
i've had the same problem om my GF's computer, Ser. I ran every utility I could think of and checked the registry manually and still have the problem.

--------------------

I am.


Posts: 1591 | From: buffalo new york | Registered: Jun 1999  |  IP: Logged
Cacophonous
Sarge
Member # 19

Member Rated:

posted 07-27-2004 10:58 AM     Profile for Cacophonous   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
I still can't get rid of Home Search.

--------------------

...


Posts: 5571 | From: Yes | Registered: Jun 1999  |  IP: Logged
outrider
Sarge
Member # 41

Member Rated:

posted 07-27-2004 11:10 AM     Profile for outrider   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
Cac, maybe this thread will help?
http://www.computing.net/security/wwwboard/forum/12346.html

Posts: 2426 | From: nc | Registered: Jun 1999  |  IP: Logged
AcidWarp
Sarge
Member # 997

Member Rated:

posted 07-27-2004 02:12 PM     Profile for AcidWarp   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
I've gotten rid of it, manually, on at least two different machines. It took patience though.

Safe mode is the key. If there are multiple user accounts, you have to remove it in EACH account. It gets into the HKEY_Current_User section of the registry. Use Autoruns and Hijack this. Don't just remove BHOs and ActiveX stuff. Remove any HKLM..Run stuff you are even remotely suspicious of. Also CWS Hides in Windows\system32 as a bunch of .dat files that all have the same date, and are usually just random letters as the file name. When it doubt, google it. Adaware and Spybot DON'T delete those dat files, you have to do it manually.

Hope some of that helps.

As for the creators of CWS, shooting them is too kind, I propose bashing their fingers with a sledgehammer.

--------------------

“I have noticed even people who claim everything is predestined, and that we can do nothing to change it, look before they cross the road.”

“Intelligence is the ability to adapt to change.”

--Dr. Stephen Hawking.


Posts: 4363 | From: Waterloo, Ontario | Registered: Nov 1999  |  IP: Logged
Cacophonous
Sarge
Member # 19

Member Rated:

posted 07-27-2004 03:01 PM     Profile for Cacophonous   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
Thanks a bunch outrider and Acidwarp. I will try it again tonight.

--------------------

...


Posts: 5571 | From: Yes | Registered: Jun 1999  |  IP: Logged
J0SH
Sarge
Member # 103

Rate Member

posted 07-28-2004 09:17 AM     Profile for J0SH   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
ahhhh - never thought it could be the user thing...there are multiple users setup on her computer and i bet that's the prob

--------------------

I am.


Posts: 1591 | From: buffalo new york | Registered: Jun 1999  |  IP: Logged
Snag
Sarge
Member # 992

Member Rated:

posted 07-28-2004 09:40 PM     Profile for Snag   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
quote:
Originally posted by Zippy:
jez, when are people going to learn how to use computers properly!

Hmmmm...that doesn't sound very entrepreneurial


Posts: 2606 | From: Canada | Registered: Nov 1999  |  IP: Logged
AcidWarp
Sarge
Member # 997

Member Rated:

posted 07-29-2004 01:33 AM     Profile for AcidWarp   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
Heh. . . it's a catch 22 snag

Cac, there's another good utility. AboutBuster. Might help you.

If, in the end, you can't get rid of it, back up the persons data, and format/reinstall. Sometimes it's the only way.

--------------------

“I have noticed even people who claim everything is predestined, and that we can do nothing to change it, look before they cross the road.”

“Intelligence is the ability to adapt to change.”

--Dr. Stephen Hawking.


Posts: 4363 | From: Waterloo, Ontario | Registered: Nov 1999  |  IP: Logged
Zippy
Sarge
Member # 3027

Rate Member

posted 07-30-2004 01:58 AM     Profile for Zippy   Author's Homepage     Send New Private Message   Edit/Delete Post   Reply With Quote
true enough snag, but i still have ta bitch about something

[ 07-30-2004: Message edited by: Zippy ]

--------------------


Posts: 94 | From: Canada | Registered: Dec 2003  |  IP: Logged

All times are ET (US)  

Post New Topic  Post A Reply Close Topic    Move Topic    Delete Topic next oldest topic   next newest topic
Hop To:

Contact Us | Q3Arena.Com

Powered by Infopop Corporation
Ultimate Bulletin Board 6.04d