You have commented 339 times on Rantburg.

Your Name
Your e-mail (optional)
Website (optional)
My Original Nic        Pic-a-Nic        Sorry. Comments have been closed on this article.
Bold Italic Underline Strike Bullet Blockquote Small Big Link Squish Foto Photo
Moderator needs tech help
2005-08-13
Help! If you have mad Windoze98 skillz, please send me a note.

My computer caught a passel of nasty viruses a week or so ago, and shockingly, the "wait and see if it goes away" method doesn't seem to be working very well.

I was trolling thru Google Images for a smashing new graphic for your enjoyment, and ended up at some stupid gamer site.

Farking gamers.

So now I've got some trojans running loose reporting allan-knows-what back to the mother ship, annoying pop-ups, and endless offers to install "WinFix 2005." No pr0n as far as I can tell, but a lot of system instability and periodic "new" icons in my system tray. I admit the puppy dog icon was cute, but I had to put him down uninstall program "rebate retriever."

I ran out and got Norton Antivirus 2005, but the damn viri disabled the CD.

HELP!

Thanks, Emily
"Seafarious"
seafarious@yahoo.com

PS Send me email or leave a note here, I may be busy tomorrow, but I'll get back to you, promise! Assuming the haxors haven't eaten my OS by then.
1. If it's a laptop or you feel like lugging a desktop up to my place, bring it by and we'll try and kill the virii.

2. If you've still got internet, McAfee has an online virus scan. See if it'll get a bite on the bustards.
I have a spare Mac if you're interested ...
Posted by:Seafarious

#23  Ayatollah Windowsa - want a working tar-ball of the blasphemy?
Posted by: 3dc   2005-08-13 23:55  

#22  If the pop-ups have "Aurora" at the on the left of the top bar, then its about the hardest to clean there is.
I've been cleaning it for people, but none of the cleaner apps will do it. Its manual hacking and slashing in the registry and system folder.
I can't even write down the directions because I still haven't fully understood how I'm finally getting rid of it.
Googling for Aurora Nail should get you some real experts who have developed directions for removal. Good Luck with it.
Posted by: LastMall   2005-08-13 22:54  

#21  3dc: You have committed blasphemy, infidel!
Posted by: Ayatollah Windowsa   2005-08-13 19:24  

#20  Emily:
I run Windows 98 and got a virus. Nothing worked. I could'nt access the internet and had to have my hard drive rebuilt.
Posted by: Deacon Blues   2005-08-13 19:09  

#19  I use Panda AV. Saved me from viruses today, when I was trying to find a game hack for my daughter. Farking gamers indeed!
Posted by: phil_b   2005-08-13 18:32  

#18  Emily

http://www.winehq.org/
Posted by: 3dc   2005-08-13 18:23  

#17  Seafarious
I used to run a script on a linux router/gateway I had that would send commands to the offending windows box to shutdown.

I quit doing it as many viri restart from where they left off after a shutdown. I got a serious DOS (denial of service) effect from all the windows machines returning to service. I modified it to get myself a new ppp address every 25 attacks but even that got too frequent.
If you put a machine on to the internet with a packet sniffer and appache web server... you will be amazed at the number of attacks per minute you will quickly get.
Posted by: 3dc   2005-08-13 13:48  

#16  Carl-
Thanks for suggesting Avast! - it pulled 277 diffeternt viruses and adwares out of my trusty old Emachine! I owe you one.

Mike
Posted by: Mike Kozlowski   2005-08-13 11:47  

#15  Okay, my 2 cents worth. Norton/Symantec, MacAfee and Trend (maybe others too, but I have not seen myself yet) can all be compromised by certain viruses that attack and corrupt their kernels. AdAware and SpyBot Search and Destroy etc. don't dig deeply enough. These are all half measures. So much for what NOT to count on.

Tenbril SpyCatcher (www.tenebril.com) is the most thorough spyware excavator - best by far. It has a free trial. I use it now, after having used all of the others mentioned in the other comments plus some not mentioned for years. Their ghostsurf ( a step up) contains spycatcher and allows you to surf the web through a third party protected server - you are invisible. Panda AV PlatinumIS at www.pandasoftware.com is the AV of choice; updates several times a day (on some days), has a good firewall. All antivirus programs are mostly reactive - they prevent infection from KNOWN viruses. PlatIS can catch brand new, as yet unknown viruses. Their free online scanner is good too. I think they have a free trial for platis.

Get a router - $50. - with stateful packet inspection (spi). Most routers are firewalls. I suggest a Linksys WRT54G.

The suggestions about bootable linux cd's are worth doing.

At dead worst, reformat and reinstall. DON'T connect to the internet until you get the the AV and spyware programs loaded. Plan ahead. Scan everything at least once a day.
Posted by: Whiskey Mike   2005-08-13 09:16  

#14  Emily,

Before you go all crazy with the others try this.
Go to:
Major Geeks
and download CWshredder.
That should get rid of most of the popups and the recurring reinfestation.

Then get Spybot and Adaware and clean out the system.

Good Luck
Dan

p.s. Went through same thing in Spring looking for graphics of an Easter bunny for the wife.
Posted by: DanNY   2005-08-13 07:33  

#13  Emily check out this page for lotsa very good information from a pro.... who is a frequent RantBurg contributor.
Posted by: Shipman   2005-08-13 06:33  

#12  try HijackThis to check registry hacking. Also install Sypywareblaster for pre-protection(not for cleaning), both are free.
Posted by: Hupomoque Spoluter7949   2005-08-13 04:24  

#11  Emily, like gromky #10 is suggesting; if you have deep registry corruption because of the many tentacles of the spyware and adware; reformatting is the quickest and easiest choice! I'm also assuming you have tried system restoral to an earlier date or trying a repair with your windows cd. In any event, after that's done, protect your pc with the many software freebees you've read about in the previous entries. I keep my machine clean with Counterspy (for the spyware and adware), Norton AntiVirus 2005 and like the others are saying FireFox as your browser version 1.0.6! Good luck.
Posted by: smn   2005-08-13 03:48  

#10  Windows 98?!? Are you kidding?

Modern worms are mostly unkillable, due to Windows' crappy features. If you're really infected, there's nothing to do but gather your important data, and reformat. And don't connect to the internet while you do so, your computer is highly vulnerable in an unpatched state.
Posted by: gromky   2005-08-13 01:55  

#9  Oh, and Rafael is right too: for antivirus-from-within-windows, I have found f-prot to be useful in the past.
Posted by: Phil Fraering   2005-08-13 01:01  

#8  The thing I like about Norton Internet Security is that it notifies you if any program (or inconspicuous file) attempts to access the internet. You can even configure it so that it checks if specific program modules attempt internet access. So you know if you've "got some trojans running loose reporting allan-knows-what back to the mother ship". Theoretically at least.
I'd also recommend a router even if you're not sharing an internet connection (preferably not the wireless kind, because it brings in other security issues).
For all your anti-virus needs, I recommend F-Prot (www.f-prot.com)

With these 3 things, I've never had a problem with ads,spies,younameit, though after having said this, I probably will this morning.

/2cents(2.394canadian)
Posted by: Rafael   2005-08-13 00:44  

#7  Emily, if you have a non-infected computer capable of accessing the internet and downloading a CD, I would suggest downloading something like knoppix, gnoppix, or ubuntu (three linux distributions that run from CD without installing to the hard drive), and running a program called "clamav" (which can be easily downloaded/installed) on the computer.

Now not to get involved in the OS wars, the neat thing about this trick is that afaik there are no viruses that can infect both windows and linux. Not to mention the fact that it's hard to infect a CD.

(Oh, I just noticed about the CD.)

IF it didn't disable that in the BIOS the CD should boot anyway.

IF it modified the BIOS, you might try rearranging the cabling so the CD drive is "located" somewhere else. (So that, where it was originally (for instance) the slave on the first bus, it would be the master on the second bus. Or vice-versa...) Although I'm a little fuzzy on whether it can be used to boot with if it's a slave...

Anyway, you can usually use "apt" to download optional packages, which is how you'll get clamav... which is meant to screen windows files and partitions for viruses.
Posted by: Phil Fraering   2005-08-13 00:39  

#6  Emily, PC Magazine has a webpage aimed at duffers like me -- that's where I found the AdAware and Spybot downloads that Frank recommends, plus a whole lot more. The programs are rated, too, and most of them are free or trials. Good luck -- when the virus ate my ability to get onto the computer, my friend the expert said I had the cleanest computer he'd ever seen ... except for that nasty little infection. ;-)
Posted by: trailing wife   2005-08-13 00:25  

#5  Oh yeah, and what Zhang said: use Firefox (or Mozilla) -- and Thunderbird
Posted by: Carl in N.H.   2005-08-13 00:16  

#4  Go with freeware. I'm as close to a Luddite as you can be and still manage to get online, yet I swear by the following:

1. Antivirus:

Avast


2. Firewall:

ZoneAlarm

3. anti-Spyware/Pop-ups/etc:

Spybot Search and Destroy

Ad Aware
Posted by: Carl in N.H.   2005-08-13 00:15  

#3  Go to google. Look up "housecall". Click on the Trend Micro website. Run the Trend Micro virus scan on your computer. Zap any viruses and spyware it detects. Run the virus scan again to catch anything that may not have been detected on the first go round. Each scan will take a few hours, so be forewarned.

Go to download.com. Download Spy Sweeper. Install the program and let it run through a scan. Delete any spyware items it detects. Buy a subscription and spare yourself a lot of headaches.

Go to google. Look up Firefox. Download and install Firefox. Use it as your default browser. It's slower than Internet Explorer but it exposes you to far fewer items of spyware.
Posted by: Zhang Fei   2005-08-13 00:10  

#2  winfix is a spyware popup - run Adaware and Spybot (both free) then the antivirus.
Posted by: Frank G   2005-08-13 00:10  

#1  Thank you, Fred & Steve. I've tried the Symantec online scan; it found plenty of beasties but was unhelpful in eradicating them. Will try McAfee next but not tonite.
Posted by: Seafarious   2005-08-13 00:06  

00:00