Need help with BAD infection

ghoti

Member
Apr 12, 2004
106
0
0
I am in desperate need of help. Although I can occasionally reach my desktop (WinXP Pro SP3) -- most of the time, the computer shows a perpetual hour glass before I reach the desktop. Even when I do reach the desktop, I can do nothing from there. The machine simply shows a perpetual hour glass no matter what I try to do.

I am occasionally able to boot up in Safe Mode and have run scans with Avira AntiVir (freeware) and SpyBot, finding Trojans and other nasties, which I have quarantined. Nonetheless, the machine has gotten worse in how quickly it becomes useless.

I thought I might try SuperAntiSpyware which John recommends in this Security thread, but John seems to say that it must be installed on the machine to be scanned (I cannot run it from a CD). I am dubious of my chances of installing it on my infected machine. Is this something I might be able to do in Safe Mode?

If I MUST reformat my hard drive, there are some files I would like to save first (assuming I can then get them back onto the reformatted computer. Where is the 'favorites' info (showing favorite web sites) stored (what is the file name)? I run Outlook 2000 which I use for e-mail. Where are the address book and previously received (not archived) e-mail messages stored? Can I simply copy those files onto a disk from Safe Mode and then copy them back onto the computer after I have done a clean install of WinXP? Will I be able to run Roxio in Safe Mode so as to burn a CD with these files, or must I run out and get a flash drive (with its very limited capacity)?

I confess my ignorance. Like certain famous literary figures, I must "rely upon the kindness of strangers." Your help will be greatly appreciated!
 

ghoti

Member
Apr 12, 2004
106
0
0
Thanks Law.

Sorry, but I do not know about HJT -- I'm gonna take a guess: Hijack This? Even if that's right, I don't really know about it (where to find it, how to use it, etc.).

I guess I had the naive hope that there was one (perhaps two) prieces of software I could run in safe mode (e.g., Malwarebytes and/ or SuperAntiSpyware) that would purge the malware.

BTW, I found that I was able (just now) to boot up in Safe Mode w/ Networking, despite the earlier 'refusal' of my machine to do so. So, I guess I will be able to download Malwarebytes free version, update, and then run it (all in Safe Mode + Networking).

Thanks again in anticipation of your further input and help.
 

ghoti

Member
Apr 12, 2004
106
0
0
Interesting! The infected computer will not allow me to connect to either of the sites to which you posted links. This clean computer will connect to both sites and the infected computer will connect to other sites (e.g., Google). I guess the malware is preventing the connections to these sites?

I can download the programs to the desktop of the clean computer, burn a CD with the downloaded files, then use the CD to install the programs on the infected computer (unless the malware prevents that, also, which seems a real possiblity judging from John's guide posted in this Security thread), BUT even if all that works, how am I going to get to the malwarebytes site to update the definitions on the infected computer?

Is there any software I can use (download to the clean copmuter) and run from a CD?

Thanks again Law.
 

ghoti

Member
Apr 12, 2004
106
0
0
Law,

Nope, mbam-setup.exe will not run off the CD in the infected computer. It will run on this clean computer.

MAN, this d#*n malware is TOUGH!

I'll try HijackThis -- though I doubt I'll get any further than I have with mbam.

Salud!
 

ghoti

Member
Apr 12, 2004
106
0
0
Well, I was able to run HijackThis.exe from CD on the infected machine. (I could not install HijackThis on the infected machine). I posted the log to pitstop. (I hope that is the right place to post in order to get the best advice.)

I could not reach housecall.trendmicro from the infected computer.

Thanks.
 

law9933

Senior member
Sep 11, 2006
394
0
0
Great!!!!
You are now in good hands, they give great/friendly advice, but there are other very good HJT sites.
Only post at one, your turn for help will come. You gave them a great description of the problem.
They will probably have you install MBytes when you can or do install it later, it is a good program.

You can post & check your HJT log here, but do nothing-it is not really safe! One extreme nasty, there could be more.

http://www.hijackthis.de/en

 

Chapbass

Diamond Member
May 31, 2004
3,148
89
91
grab a copy of bartPE, boot into it and do manual removals from a remote OS? BPE also has some built in scanners as well.


Usually a good start if you cant get into safe mode.
 

law9933

Senior member
Sep 11, 2006
394
0
0
ghoti,
It lookes like the adviser has you running again. It took 40+ posts from you two, I did not say it was easy, only that they are good. He would not give up when you thought you wanted to. I saw that another great adviser was watching the progress (may have assisted Aflac) I am not allowed to post in their HJT forum. Job well done!!!
 

ghoti

Member
Apr 12, 2004
106
0
0
Amen to that, Law! I was impressed.

I do still have some residuals (you can see from my last post), but I am hopeful I'll soon (with help) have them cleared. And the machine is running normally again (at least at the moment).

Thanks again for your recommendations! I'm going over to TrendMicro Housecall now to see what it finds.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |