AudioMasters
User Info & Key Stats
Welcome,
Guest
. Please
login
or
register
.
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
February 01, 2012, 11:36:19 PM
73736
Posts in
7768
Topics by
2597
Members
Latest Member:
miskaudio
News:
Buy Adobe Audition:
Pick Your Region
Austria
Australia
Belgium
Brazil
Bulgaria
Canada
Cyprus
Czech Republic
Denmark
Estonia
Finland
France
Germany
Greece
Hong Kong
Hungary
Ireland
Italy
Japan
Korea
Latvia
Lithuania
Luxembourg
Malta
Mexico
Netherlands
New Zealand
Norway
Poland
Portugal
Romania
Singapore
Slovakia
Slovenia
South Africa
Spain
Switzerland (Dutch)
Switzerland (French)
Sweden
United Kingdom
United States
AudioMasters
Off Topic
OT Posts
the horse is in the city
« previous
next »
Pages:
[
1
]
Author
Topic: the horse is in the city (Read 371 times)
«
on:
August 27, 2011, 06:40:55 AM »
AndyH
Member
Posts: 1769
the horse is in the city
I'm trying to help a friend who is running a WinXP system (service pack 3), AVG free anti-virus, and Comodo free firewall. The internet connection is a cable modem, and Mozilla Firefox. I'm trying, not because I know very much, but because he is totally clueless.
The basic question, is there some on-line service that might have a good chance of interactively scanning and fixing his system, without causing more problems in the process? Just getting to that service will require letting something(s) on the computer out through the firewall.
HISTORY
Last week he was suddenly blocked from doing almost anything by a nasty program that put up a screen screaming that his system was infected with various malware, and demanding $79 paid to somewhere online to clear the problems. Almost nothing on his system could start, not the firewall, the browser, the anti-virus, or most other programs.
I followed the breadcrumbs and found a recently dated application in his download folder. Once I deleted that and rebooted, their front-end interference was gone. I updated the anti-virus, firewall, and browser. The (latest) AVG scan said it found a trojan and took care of it. Everything seemed good for a week.
CURRENT
Now suddenly something from the AVG start up process put up a screen saying it found four instances of a different trojan, each instance associated with some Windows service. Attempts to deal with it were unsuccessful -- access denied.
A regular AVG scan of the computer system failed to locate that or anything else, either in user mode or admin mode, and restarting the system does not bring up the messages again. However, according to the firewall, attempts to get on-line with the browser, the AVG program, or the firewall itself, find all sorts of services that are "new" and need permission to communicate. These are mostly, or entirely, modules that were fine the day before, so either the firewall itself, or who knows how many other programs, have been modified by whatever is causing the problem.
Of course this trojan may be communicating with the outside just fine, but making it difficult for anything else to be done with the system. Regardless, the options seems to be
try to give permission to the firewall to get out and get somewhere that may be able to help, if I knew where to go once on-line
or
download something on another system that can be installed on a USB flash drive or (preferably) a CD-R, perhaps that can boot independently of the Windows OS, and might have a good chance of cleaning and repairing the system.
or
(a very distant third) throw out the two hard drives and start over. This will still require doing something useful about the problem because he has years of data that would be hard to give up. Maybe the experience will get him to finally make the effort to do backups, but that is definitely a side issue at the moment.
Some of you probably have experience that could be helpful. Any suggestions?
Logged
Reply #1
«
on:
August 27, 2011, 09:56:36 AM »
emmrecs
Member
Posts: 47
Re: the horse is in the city
This sounds very suspiciously like something that happened to my Brother-in-Law. He suddenly found he could not access any programs or the net; he'd become infected by a "program" called "MS Removal Tool", yes, it did claim to be from Microsoft.
Since he lives on the other side of the country to me and despite my best attempts to help him via the telephone (he's also not very computer-literate) he eventually had to take his computer to a local shop and have them sort it out for him!
However, on the positive side for you, if your friend's computer has become infected by that particular nasty (and it appears it may well have "left its calling card behind" despite your attempts to remove it) if you Google "MS Removal Tool" you will find there are a number of web sites, many at least apparently genuine, which will give detailed instructions on how to remove the infection.
My commiserations to you and your Friend!
Logged
Reply #2
«
on:
August 27, 2011, 11:02:07 AM »
AndyH
Member
Posts: 1769
Re: the horse is in the city
I don't know if the current problem is a left over from the original problem of a week ago or he just has a tenancy to blunder into the wrong places. The current symptoms are rather different from last week's problem.
I'm pretty sure last week's nasty program that dominated the screen, and prevented almost anything else from loading, was Defender.exe. The trojan that AVG reported found and eliminated, after I updated everything, had some other name, involving the word trojan, some number, and possibly some alpha prefix or suffix.
The current symptoms don't prevent anything from running locally but any attempt to reach any web page is blocked by the firewall, pending the user's approval of a "new" application or service "attempting to communicate with the internet." Most, or all of these "new" things have the same name as legitimate parts of the anti-virus program, the browser, the firewall program, the Windows OS, etc..
That makes fighting the thing from his system difficult. If we allow these components to communicate, in order to access the internet and seek help, do we really just increase the problem by allowing the trojan to have greater access?
In the meantime, I might as well see what the "MS Removal Tool" removal instructions say. Maybe there will be something useful there.
Logged
Reply #3
«
on:
August 27, 2011, 11:10:49 AM »
ryclark
Member
Posts: 650
Re: the horse is in the city
Malwarebytes has a free version is excellent at sorting these sort of problems.
http://www.malwarebytes.org/products/malwarebytes_free
Logged
Reply #4
«
on:
August 27, 2011, 11:25:53 AM »
YogiBoar
Member
Posts: 10
Re: the horse is in the city
Have you tried booting in safe mode then running AV progs.
Often solves the problem of access denied.
Logged
Thunder Bolt
Strikes where least expected!
Reply #5
«
on:
August 27, 2011, 05:19:03 PM »
runaway
Member
Posts: 655
Re: the horse is in the city
As ryclark suggests malwarebytes as well as YogiBoar's safe-mode suggestion are certainly worth a try.
I would suggest getting hold of an 'Avira rescue disk'
http://www.avira.com/en/support-download-avira-antivir-rescue-system
I would also suggest that your friend uses Avira rather than AVG.
I have the Premium version (I was so impressed with the free one that I bought 5 licences) and I have found Avira to be the best free AV going around.
Logged
www.aatranslator.com.au
www.mediasweeper.com.au
Reply #6
«
on:
August 27, 2011, 08:32:18 PM »
AndyH
Member
Posts: 1769
Re: the horse is in the city
Thanks. Now I'm going to have to try to get access to some other broadband connection to download these tools before I visit him again. Downloading here would tie up my phone line for days, but at least I now have a starting point.
Logged
Reply #7
«
on:
August 27, 2011, 09:14:33 PM »
djwayne
Member
Posts: 1273
Re: the horse is in the city
I've had excellent luck with Microsoft's Security Essentials. It's free and does work with XP.
Not one virus have I had since installing it.
http://www.microsoft.com/en-us/security_essentials/Default.aspx
Logged
Reply #8
«
on:
August 28, 2011, 12:05:56 PM »
Havoc
Member
Posts: 1209
Re: the horse is in the city
While I feel like collaborating with the ememy, me to found Microsoft Security Essentials a better alternative for AVG. I have always used it on pc's for family members but beyond version 7.something it used so much cpu/hd that it became a nuisance.
Another thing you could do is to run msconfig.exe. It will give you a list of what starts at boot time. You might find something that looks suspicious and guve you a direction to search further. Also take a look in the registry for what is listed under the ../run and ../run_once keys. A lot of malware sits there often. Always take a look and use google (and read several responses) before taking any action.
Logged
Expert in non-working solutions.
Reply #9
«
on:
August 29, 2011, 11:17:37 AM »
runaway
Member
Posts: 655
Re: the horse is in the city
Malware/viruses also lurk in the 'restore' points - so turning off System Restore for a while also helps.
There is usually no one cure but rather a number of steps many of which have been suggested.
Logged
www.aatranslator.com.au
www.mediasweeper.com.au
Reply #10
«
on:
August 29, 2011, 01:15:49 PM »
MarkT
Guest
Re: the horse is in the city
Sorry I only just saw this post, but if I recommend you follow something like the script here:
http://www.dslreports.com/faq/8428
. I know it seems like a lot of steps, but this is the only way to be sure you have gotten rid of everything. A lot of malware plants software deep in your system and prevents normal AV software from getting rid of it.
If this doesn't help follow the link on the page for getting help - It isn't easy and it isn't fun, but it is worth it. The alternative is to reformat your freinds harddisk and reinstall the OS and software. Which is easier?
Good Luck!
Logged
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Forum Topics
-----------------------------
=> Forum Suggestions/Remarks
-----------------------------
Audio Software
-----------------------------
=> Adobe Audition 2.0, 3.0 & CS5.5
===> Audition CS5.5 AKA Audition 4
=====> Audition 4 Stickies and FAQs
===> Adobe Audition 3.0
=====> Audition 3.0 Stickies & FAQs
=====> MIDI
===> Adobe Audition 2.0
=====> Audition 2.0 Stickies & FAQs
=> Previous Versions
===> Cool Edit 96, 2000, 1.2a
===> Cool Edit 2.0 & 2.1, Audition 1.0 & 1.5
=====> CE 2.0 & 2.1, Audition 1.0 & 1.5 Stickies and FAQ's
=> Adobe Audition Wish List
=> Third-Party Plugins
-----------------------------
Audio Related
-----------------------------
=> General Audio
===> General Audio Stickies & FAQ's
=> Radio, TV and Video Production
=> Hardware and Soundcards
===> Hardware and Soundcards Stickies and FAQ's
=> Recordings Showcase
-----------------------------
Off Topic
-----------------------------
=> OT Posts
=> Polls
Loading...