De-Screwing my bro's PC

robphelan

Diamond Member
Aug 28, 2003
4,084
17
81
Running WinXP SP2.

Well, my brother called and said he was having a bunch of issues.. being the family geek, I was obliged to try to fix it.

turns out there are numerous viruses running around in there.

I've begun by running a2(squared), AdAware, & SpyBot S&D several times.

things were looking really good while in safe mode, but appear to start up again when I reboot to normal mode - which indicates not ALL of the viruses/malware are gone.

One thing I did notice is that it created an "Administrator" user that does NOT show up on the log on screen (his 2 users, brother & niece, do show up).

I found this "Administrator" user only in the safe mode login screen - I go to User Groups to delete it, but that user does not show up there.

I think this is the key - i need to get rid of that user somehow but can't seem to do it. Any ideas?

thanks.
 

bsobel

Moderator Emeritus<br>Elite Member
Dec 9, 2001
13,346
0
0
Since you obviously have a system as well, slave the drive to yours and run a real av/as tool and just clean the system up.
 

John

Moderator Emeritus<br>Elite Member
Oct 9, 1999
33,944
1
0
1) The "hidden" Administrator account is by design and perfectly legit.
http://windowsxp.mvps.org/admins.htm

2) See my sig for malware removal advice. Do not slave the drive since you will need the tools to clean rogue registry entries.

3) Some malware attaches to Windows system files. One example is a spambot that infects ndis.sys so that when you delete the offending files the ndis.sys drops them back in place.
 

robphelan

Diamond Member
Aug 28, 2003
4,084
17
81
Originally posted by: John
1) The "hidden" Administrator account is by design and perfectly legit.
http://windowsxp.mvps.org/admins.htm

2) See my sig for malware removal advice. Do not slave the drive since you will need the tools to clean rogue registry entries.

3) Some malware attaches to Windows system files. One example is a spambot that infects ndis.sys so that when you delete the offending files the ndis.sys drops them back in place.

thanks for the info on the admin account. that was worrisome.

i was going through your guide yesterday.. excellent info. i'm going to give it a go tonight (tomorrow night's the spurs game so i'll be busy then:thumbsup.
 

robphelan

Diamond Member
Aug 28, 2003
4,084
17
81
Originally posted by: John
Any luck?

unfortunately, I didn't have any time last night to do anything other than to d/l all the software onto a thumb drive.

hopefully tonight i can find the time during timeouts and halftime of Game1!!!!!!
 

robphelan

Diamond Member
Aug 28, 2003
4,084
17
81
gave up... the PC kept closing down all my windows before I could get to the folders to install the anti-spyware software.

i went ahead and formatted/re-installed. since it wasn't my PC, i was a little less willing to spend the time trying to recover.

thanks for the input.
rp.
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Originally posted by: robphelan
gave up... the PC kept closing down all my windows before I could get to the folders to install the anti-spyware software.

i went ahead and formatted/re-installed. since it wasn't my PC, i was a little less willing to spend the time trying to recover.

thanks for the input.
rp.
security ideas for the future :light:
 

robphelan

Diamond Member
Aug 28, 2003
4,084
17
81
thanks for the link.. i went ahead and setup a limited account - my bro only uses it to stream NPR & play music.. and my niece uses it for IM/school work.. it should work fine for them.

 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Originally posted by: robphelan
thanks for the link.. i went ahead and setup a limited account - my bro only uses it to stream NPR & play music.. and my niece uses it for IM/school work.. it should work fine for them.
sweet :thumbsup:
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |