Computer Forums

Member Login

Remember Me? Sign Up! | Forgot Password
 
Slogan
 
Closed Thread
Old 01-31-2005, 11:44 PM   #1 (permalink)
billiegirl's Avatar
 
Junior Techie

Join Date: Jan 2005

Posts: 44

billiegirl is on a distinguished road

Default Virus Problem please help!

My friend has a virus on her computer and we dont know how to get rid of it's a trojan virus called backdoor.small and is lodged in the hidden folder of c:\_restore which is protected and won't allow any access to remove the file or anything. The virus managed to get through her fully updated AVG anti virus.

She has have tried all the usual ways,and have also tried tp manually removing the file in MS-DOS...her last resort is to format the computer, which is a pain in the a$$ so any ideas appreciated.

Thank you in advance

Cheers
__________________
A aussie mum to three little rug rats
With a bad warcraft addiction lol
billiegirl is offline  
Old 02-01-2005, 08:32 PM   #2 (permalink)
 
True Techie

Join Date: May 2003

Posts: 221

mobo

Default

Go to Start>Run and type msconfig Press enter.

When msconfig opens, click the Launch System Restore Button.
On the next page, click the System Restore Settings Link on the left.

Check the box labeled Turn off System restore on all Drives.


Reboot. Go back in and Turn System Restore Back on. A new Restore Point will be created.

Then to make sure the system is clean elsewhere:

Get The latest version of Adaware
You can download the free version here:
http://www.lavasoftusa.com/support/download/

or here (alternate download location)
http://www.majorgeeks.com/download506.html

You need to be logged on as Adminstrator through the installation.
For ease in installation and operation, view the tutorial here http://www.spyware911.net/adaware.htm

Just download it to your desktop and then to install click on the file you just downloaded (aawsepersonal.exe). You will be guided through the installation. It is recommended to use the default setting of "Protect anyone who uses this computer".

On the main screen of Adaware please look for the *check for updates now* link, just above the start button in the bottom right corner or you can click on the Webupdate button that looks like a globe icon at the top. Press * connect* to let it check for any recent updates. If any are found, please let it download and install them.

Now, configure your settings. Click the gear icon at the top. These are the recommended settings:

AAW SE settings

General Button
Safety:
Check (Green) all three.

Advanced Button
Logfile Detail Level:
All options under this should be checked (Green).

Tweak Button
Check (Green) the following:
Log Files
Include basic Ad-Aware settings in logfile:
Include additional Ad-Aware settings in logfile:
Please do not check (Green): Include Module list in logfile:

On your first scan, use the Full Scan (Perform full system scan) mode.

Let Adaware remove any *bad* objects found. Reboot your PC and scan again. Repeat this process until no more bad items are found. It may take several scans to clean everything, depending on the type of infections found.
________________________
Download Spybot - Search & Destroy, from here http://security.kolla.de/: if you haven't already got the program.
For ease in installation and operation you can opt to view the tutorial here http://www.spyware911.net/spybots&d.htm

Click on Settings, and Settings again. Go to the Webupdate section, and check Display also available beta versions.

Now press Online, and search for, and put a check mark next to all updates, and install following the prompts.

Next, close all Internet Explorer windows, and click Check for Problems. Once the scan is complete, have SpyBot remove all it finds marked in RED.
__________________________________________________ _________________
Create a directory on your hardrive to save HijackThis.exe. A directory like c:\hijackthis. If you do not do this, you will not be able to use the backup/restore features.

Download HijackThis from:

http://www.spywareinfo.com/~merijn/files/hijackthis.zip

Save this file into the directory you made previously and then run the program named hijackthis.exe. When the program opens click on the Config button, then click on the Misc Tools button, and click on the Check for update online button. When it completes checking/applying updates press the back button.

Now click on the Scan button and when it is finished click on the Save Log button. A Notepad window will open with the contents of this log. Click on Edit then click on Select all. Then click on Edit and then Click on Copy.

Create a reply to this post here and right click in message area and select paste to paste the log into the post.
__________________
Security Tools | Spyware Scan | Prevention 101
mobo is offline  
Old 02-01-2005, 08:38 PM   #3 (permalink)
billiegirl's Avatar
 
Junior Techie

Join Date: Jan 2005

Posts: 44

billiegirl is on a distinguished road

Default

Wow thanks mobo I let her know.

Cheers
__________________
A aussie mum to three little rug rats
With a bad warcraft addiction lol
billiegirl is offline  
Old 02-01-2005, 08:40 PM   #4 (permalink)
 
True Techie

Join Date: May 2003

Posts: 221

mobo

Default

Your welcome.
__________________
Security Tools | Spyware Scan | Prevention 101
mobo is offline  
 
Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On