Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Problem removing Virus/Spyware from Safe Made?

Status
Not open for further replies.

CraigHappy

Technical User
Jun 1, 2005
92
GB
Hi Guys

I have a friends system which is in a right mess, I know it has viruses and plenty of spyware on it!

Is there a way to get internet access via Ethernet to a router from within Safe Mode?

The problem I have is that when I boot normally, the system restarts seconds after getting to the desktop. I can boot to safe made, but have no internet access from there and need to update the spyware definitions for the software I've also installed from within safe mode.

I've tried going to msconfig and changing the start to disallow the start-up programs, but it still restarts?

They let their antivirus expire and hadn't updated any of the windows xp security updates! Just asking for trouble!

Any suggestions would be very helpful, as I'm up against a brick wall with this one at the mo!

Many thanks, Craig.
 
If yu cna get to safe mode run a hijakc this and psot it's log as it will be able to let us see what type of garbage he has!

Download hijack this from the link below.Please do this. Click here:


to download HijackThis. Click scan and save a logfile, then post it here so
we can take a look at it for you. Don't click fix on anything in hijack this
as most of the files are legitimate.


Member of ASAP Alliance of Security Analysis Professionals

under the name khazars
 
you can try knoppix (a live cd version of linux) to get the box running. check out this link:
from within knoppix you can do some antivirus stuff, or at least copy the files they want to save...
you could also try downloading the things you need and burning them to a cd or copying them to a usb key from another computer. i think ad-aware and ewido let you download the updates as separate packages. the windows updates are usually available as well. or you could check out auto-patcher for the windows updates (
"Maturity is a bitter disappointment for which no remedy exists, unless laughter can be said to remedy anything."
-Vonnegut
 
You should be able to use Ewido or Spybot in safe mode and put their updates on a CD or something that you can access in safe mode.

Ewido download:


Manually update it with these files that you download somewhere else:

Full:
Current:
Update it and run a complete scan.

Spybot:

Download it here:


Updates here:


Run these tools and then see if you can boot normally.

Regards.

Erik+
 
Hi Guys

Many thanks for all the help and support.
I was able to get internet access via the Safe Mode with Networking and I installed ad-aware and spybot, also Ewido (which I had never heard of before, but thought it was very good).

Tons of spyware found and removed! :)

Still no virus protection though, as something seems to be stopping it from updating and running correctly, system runs extremely slow as well, but as you all have helped me get back into a operating desktop and been able to backup all the important stuff, I've chatted with my friend that owns the system and we have decided to wipe the drive and start from scratch with a fresh OS. That way hopefully everything will be back to normal!

Also gave him some words of wisdom about backing up and keeping virus, spyware and os security up to date!

Many thanks again, very helpful!

Cheers, Craig.
 
check your hosts file to see if that is blocking the antivirus updates.

"Maturity is a bitter disappointment for which no remedy exists, unless laughter can be said to remedy anything."
-Vonnegut
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top