Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Spyware/Trojan Got Me Good! Locked out of my XP Pro user accounts

Status
Not open for further replies.

vince32837

Technical User
Sep 26, 2003
25
US
Sun night my IE home page was hijacked to web-search.com (not sure of exact spelling). The top border in windows explorer was modified too, casino, travel icons etc.

I shutdown the PC. Last night I powered the PC back up. I created 2 accounts on the PC both with admin privileges. When I enter my password for either account, XP states “loading settings”…then 5 sec later…states “logging off…I can’t get past the XP blue screen!!

How do I get out this mess??
Thanks Vince
 
Press F8 when Booting and try booting in the Safe Mode.
 
Mike,

When I press F8, do I want to boot up in safe mode and try to run cleaning tools like spybot etc.. or should I select last good windows config?

thanks for the quick reply,

Vince
 
You want Safe mode. :)

----------------------------
"Will work for bandwidth" - Thinkgeek T-shirt
 
Last night I could not logon through safe mode or admin account... I gave up and formatted the drive and re-installed XP PRO.

I was wondering what protection apps you guys were running, real-time monitoring and once a week/month inspection.

Across the board- firewall, antivirus, spyware, trojan?

Thanks for the help,
Vince
 
Here's my home setup...

Firewall
Windows XP Firewall enabled and customized to my needs.

Antivirus
Norton Antivirus

Spyware
Spybot (including Teatimer)

Microsoft Spyware Beta

Spyware Blaster

Hijack This!

The above setup, along with a biweekly scan for malware/virus' finds my system free 99.9% of the time. And this is with several friends and family members heavily utilizing my system to surf the web.

Other possible programs to use include

Antivirus (many others here beyond these two)
Mcafee

AVG (Grisoft)

Firewall
Zone Alarm

Spyware (many other options here as well)
Adaware

Webroot
 
Aquias,

Do you have XP firewall, Norton AV, Spybot,Microsoft Spyware Beta,Spyware Blaster, "Hijack This" all running at windows startup?


Thanks for the list,
Vince
 
Hijack This! is more of a diagnostic tool, used in conjuction with biweekly spyware scans.

Everything else boots with the system and stays running as long as my system is up. I don't see much/any slow down on most sites. Every now and again certain sites will give me a slow down, but that only seems to be ones laden with something that is trying to install itself to my system.

And you're welcome.
 
Oh and last thing, it is heavily recommended that you run two of any spyware programs that you choose.
 
Aquias,

I will go with your defense app set-up, except I have outpost firewall instead of XP. I made clean install of XP Pro, then installed all hardware drivers. 2nd, I made a clone of the drive with Norton ghost. This is the 2nd time I have been burnt!

Thanks again for the tips,
Vince
 
vince32837:

One other programme for you is SpywareGuard (follow the SpywareBlaster link), also do not forget all Windows Critical updates now that you have formatted and re-installed XP Pro.



Ted

"The difference between a misfortune and a calamity is this: If Gladstone fell into the Thames, it would be a misfortune. But if someone dragged him out again, that would be a calamity."
Benjamin Disraeli.
 
I use my linksys router firewall, I find it to be very effective as well.

I run pretty much everything stated above, do monthly scans of some things, bi-weekly of others.

I'd throw in some online virus scanners too, trend, panda software, symantec, mcafee, stuff like that.
 
SuaveRick,

I have an SMC router, right now there is just a password to get into the settings menu. What security features are you utilizing on the Linksys?

Thanks Vince
 
vince,

For my router I have the firewall active as well as the settings to not send an ack when someone pings my IP (I can't think of the setting off the top of my head).

But on yoru SMC router (which I used to have one) you have to turn on the firewall and there is an option call "disregard ping from wan". That will make your computer NOT send back an ACK when someone pings your ip. Make sure that DMZ is turned off.

I pretty much have every security feature turned on that I can. WEP, MAC Address filter, Firewall, all the other options too.

Just look at your manual or grab a copy from the SMC site, it'll explaine all that fun stuff for you :)
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top