•
•
•
•
What is DaniWeb IT Discussion Community?
You're currently browsing the Windows NT / 2000 / XP / 2003 section within the Tech Talk category of DaniWeb, a massive community of 456,558 software developers, web developers, Internet marketers, and tech gurus who are all enthusiastic about making contacts, networking, and learning from each other. In fact, there are 3,461 IT professionals currently interacting right now! Registration is free, only takes a minute and lets you enjoy all of the interactive features of the site.
Please support our Windows NT / 2000 / XP / 2003 advertiser: 64-bit Windows Community
Views: 704 | Replies: 8
![]() |
•
•
Join Date: Oct 2007
Posts: 8
Reputation:
Rep Power: 0
Solved Threads: 0
I have found many helpful solutions on this site, but this is my first post. so forgive me if im posting in the wrong section.
I'm a tech by profession and work mostly on virus/spywar. Normally that's no problem i can use various tools and edit them out of the registry no problem. however, yesterday i had an HP Pavilion a518x come in that was beyond my control. to the point even in safe mode with 512mb of ram it took ten minutes to get into the log in screen. that's fine i waited it out and plugged in my thumbdrive with a-squared2, avg antispy, and Analyze This on it. they all installed but i decided to run the Analyze This before the scans. i checked off 68 very obvious things that shouldn't be present and clicked fix. no luck, after 5 seconds i got an error from Analyze this not even "windows" and the program shut down. so i restarted and ran the other programs i had installed, got rid of a few thousand problems that way, but not enough. off the top of my head i know there was WINDOWS ANTIVIRUS 2006, WINDOWS ANTIVIRUS 2007, WINDOWS ANTISPYWARE 2007, ERROR CHECK, ROGUE SUSPECT(three diffrent downloads of smitfraud, that i have used on other machines would not run), STARWARE, and the fake windows security alert/notifier. many, many more to.
still after running those programs with system restore off i could not get into a regular log in and safe mode still took an eternity and wouldn't even let me into the administrator profile. there was no password it just shut down. so, as i normally do i ran a dell system C.D (the user didnt have his discs) on it and did a repair. i was prepaired to have to reactivate windows etc afterwords. now, it gets me to the regular log in page and when i click to log in sure enough i need to activate before i log in. ok, great except when you click yes to register the computer restarts itself. i have tried this numerous times with the same result. and you cannot register in safe mode.
so my question is "now what?" the customer has numerous costly programs.. word, quicken, picasa, photoshop and more and no disks. so a reformat is a definite last resort, even if i saved all of his data and found all of his outlook, quicken etc he would have to go out and buy all new disks or risk getting himself infected agian by trying to pirate them. which he proved he is not capable of. any help would be GREATLY appreciated.
reposted in virus/spyware forum, my bad
I'm a tech by profession and work mostly on virus/spywar. Normally that's no problem i can use various tools and edit them out of the registry no problem. however, yesterday i had an HP Pavilion a518x come in that was beyond my control. to the point even in safe mode with 512mb of ram it took ten minutes to get into the log in screen. that's fine i waited it out and plugged in my thumbdrive with a-squared2, avg antispy, and Analyze This on it. they all installed but i decided to run the Analyze This before the scans. i checked off 68 very obvious things that shouldn't be present and clicked fix. no luck, after 5 seconds i got an error from Analyze this not even "windows" and the program shut down. so i restarted and ran the other programs i had installed, got rid of a few thousand problems that way, but not enough. off the top of my head i know there was WINDOWS ANTIVIRUS 2006, WINDOWS ANTIVIRUS 2007, WINDOWS ANTISPYWARE 2007, ERROR CHECK, ROGUE SUSPECT(three diffrent downloads of smitfraud, that i have used on other machines would not run), STARWARE, and the fake windows security alert/notifier. many, many more to.
still after running those programs with system restore off i could not get into a regular log in and safe mode still took an eternity and wouldn't even let me into the administrator profile. there was no password it just shut down. so, as i normally do i ran a dell system C.D (the user didnt have his discs) on it and did a repair. i was prepaired to have to reactivate windows etc afterwords. now, it gets me to the regular log in page and when i click to log in sure enough i need to activate before i log in. ok, great except when you click yes to register the computer restarts itself. i have tried this numerous times with the same result. and you cannot register in safe mode.
so my question is "now what?" the customer has numerous costly programs.. word, quicken, picasa, photoshop and more and no disks. so a reformat is a definite last resort, even if i saved all of his data and found all of his outlook, quicken etc he would have to go out and buy all new disks or risk getting himself infected agian by trying to pirate them. which he proved he is not capable of. any help would be GREATLY appreciated.

reposted in virus/spyware forum, my bad
Last edited by Tabby8 : Oct 24th, 2007 at 5:56 pm. Reason: wrong forum
•
•
Join Date: Jul 2004
Location: Canada/Alberta/Fort McMurray
Posts: 61
Reputation:
Rep Power: 5
Solved Threads: 1
Wow, thats one hell of an infected system.
As a person interested in becoming a technician, does this kind of sever case happen often?
As a person interested in becoming a technician, does this kind of sever case happen often?
-Operating System: Windows XP Home Edition
-Console Model & Manufacturer: COMPAQ Presario SR1030NX
-Processor: AMD Athlon XP 3000 Processor (2.17Ghz)
-RAM: 1 gig (2x 512 DDR, PC2700 chips)
-Harddrive: 160GB (7200 RPM) Ultra DMA Hard drive
-Graphics Card: Radieon 9200 (128mb)
-Console Model & Manufacturer: COMPAQ Presario SR1030NX
-Processor: AMD Athlon XP 3000 Processor (2.17Ghz)
-RAM: 1 gig (2x 512 DDR, PC2700 chips)
-Harddrive: 160GB (7200 RPM) Ultra DMA Hard drive
-Graphics Card: Radieon 9200 (128mb)
•
•
Join Date: Aug 2007
Location: Berkshire, UK
Posts: 870
Reputation:
Rep Power: 3
Solved Threads: 55
It's prolly time to recognise that the system was given to you more-or-less beyond hope of recovery. Then the Dell recovery trick, the activation issues and so on only serve to muddy the already murky waters.
You could always slave the HDD and look arond on it in another PC for clusters of DLL/SYS/EXE/DAT files with strange names that appear with the same date and time of creation from around when infection might first have started. I posted a full methodology on this on around 25-Aug in the Spyware section. I guess you'll find the lurkers that way.
You could always slave the HDD and look arond on it in another PC for clusters of DLL/SYS/EXE/DAT files with strange names that appear with the same date and time of creation from around when infection might first have started. I posted a full methodology on this on around 25-Aug in the Spyware section. I guess you'll find the lurkers that way.
Suspishio
My advice is at your risk
(We saved the Frogs from the Krauts - twice!)
Dell XPS M1710; T7200 2GHz Core 2 Duo; 2GB RAM; XP Pro (32)
nForce 680i LT; Q6600 Quad Core 2.4GHz; 8GB RAM; XP Pro (64)
My advice is at your risk
(We saved the Frogs from the Krauts - twice!)
Dell XPS M1710; T7200 2GHz Core 2 Duo; 2GB RAM; XP Pro (32)
nForce 680i LT; Q6600 Quad Core 2.4GHz; 8GB RAM; XP Pro (64)
•
•
Join Date: Oct 2007
Posts: 706
Reputation:
Rep Power: 3
Solved Threads: 51
This seems to be a definite reformat. Even at my rate, the time spent to repair this machine would cost as much as new Dell.
If he doesn't have install disks, he almost certainly "borrowed" all his "costly" software.
I'd even be uncertain about saving the data, as it may contain the infection.
Copy the data, reformat and reinstall and let him know the data may be infected. A good scan should be run before installing the data.
I've had to give up on a few machines due to time/cost restraints, and it may be the best answer in many cases.
If he doesn't have install disks, he almost certainly "borrowed" all his "costly" software.
I'd even be uncertain about saving the data, as it may contain the infection.
Copy the data, reformat and reinstall and let him know the data may be infected. A good scan should be run before installing the data.
I've had to give up on a few machines due to time/cost restraints, and it may be the best answer in many cases.
•
•
Join Date: Aug 2007
Location: Berkshire, UK
Posts: 870
Reputation:
Rep Power: 3
Solved Threads: 55
•
•
•
•
This seems to be a definite reformat. Even at my rate, the time spent to repair this machine would cost as much as new Dell.
If he doesn't have install disks, he almost certainly "borrowed" all his "costly" software.
I'd even be uncertain about saving the data, as it may contain the infection.
Copy the data, reformat and reinstall and let him know the data may be infected. A good scan should be run before installing the data.
I've had to give up on a few machines due to time/cost restraints, and it may be the best answer in many cases.
Well said, though poor old Tabby8 is in the unenviable position of having to face the customer!
Suspishio
My advice is at your risk
(We saved the Frogs from the Krauts - twice!)
Dell XPS M1710; T7200 2GHz Core 2 Duo; 2GB RAM; XP Pro (32)
nForce 680i LT; Q6600 Quad Core 2.4GHz; 8GB RAM; XP Pro (64)
My advice is at your risk
(We saved the Frogs from the Krauts - twice!)
Dell XPS M1710; T7200 2GHz Core 2 Duo; 2GB RAM; XP Pro (32)
nForce 680i LT; Q6600 Quad Core 2.4GHz; 8GB RAM; XP Pro (64)
•
•
Join Date: Oct 2007
Posts: 8
Reputation:
Rep Power: 0
Solved Threads: 0
thanks for all the responses so far! normally when i get a computer that badly infected i'm able to go around in the registry and tweak it enough to be able and do a repair to continue on. if i had an hp c.d or an actual XP cd instead of just dell i probably would have been alright since i wouldnt have had to reactivate. but you do what you can right?
i saved his ended up having no choice but a reformat and saving the system files. even doing that i had to continue the cleaning afterwords but not to nearly the same extent.
i honestly don't think this guy was bright enough to find working versions of the programs he had to steal them. it takes a truly "special" person to be able to get THAT infected before realizing there was an issue or maybe that you should get your machine fixed. even in safe mode disconnected from the internet he had three diffrent security alerts going down in the corner and constant pop ups from games, spyware programs, you name it.
in response to Omni, in the last year i've only worked on hmm under 20 computers that were this badly infected, most of them can be fixed with a few scans and a little common sense. i'm sure the amount you get depends on where you live tho, i live in Hawaii and am one of 3 techs on the island so i get quiet a few from my small customer group.
dealing with the customer wasn't so bad because i explained what i did and what i could have done along with the charges for both. showing him he wouldve bought a brand new top of the line computer for the amount of hours it would've taken me to clean it. normally when a customer comes in they're just dumbstruck that a woman is going to fix their computer.
so no one knows anyway to get around activating huh? i know you get 30 days but what about when you dont have the ability to activate it? wont let you log in, no internet, etc?
i saved his ended up having no choice but a reformat and saving the system files. even doing that i had to continue the cleaning afterwords but not to nearly the same extent.
i honestly don't think this guy was bright enough to find working versions of the programs he had to steal them. it takes a truly "special" person to be able to get THAT infected before realizing there was an issue or maybe that you should get your machine fixed. even in safe mode disconnected from the internet he had three diffrent security alerts going down in the corner and constant pop ups from games, spyware programs, you name it.
in response to Omni, in the last year i've only worked on hmm under 20 computers that were this badly infected, most of them can be fixed with a few scans and a little common sense. i'm sure the amount you get depends on where you live tho, i live in Hawaii and am one of 3 techs on the island so i get quiet a few from my small customer group.
dealing with the customer wasn't so bad because i explained what i did and what i could have done along with the charges for both. showing him he wouldve bought a brand new top of the line computer for the amount of hours it would've taken me to clean it. normally when a customer comes in they're just dumbstruck that a woman is going to fix their computer.
so no one knows anyway to get around activating huh? i know you get 30 days but what about when you dont have the ability to activate it? wont let you log in, no internet, etc?
•
•
Join Date: Aug 2007
Location: Berkshire, UK
Posts: 870
Reputation:
Rep Power: 3
Solved Threads: 55
•
•
•
•
....i live in Hawaii and am one of 3 techs on the island so i get quiet a few from my small customer group.
.....so no one knows anyway to get around activating huh? i know you get 30 days but what about when you dont have the ability to activate it? wont let you log in, no internet, etc?
I'm hot footing it to Hawaii, with my system disks an' all!
As a professional, you should really have a set of disks for repair.
On the activation question, nobody here is gonna give you any advice on how to break Microsoft's rights. Your customer could contact Microsoft using the sticker that's on his machine and see what they say. But I reckon the customer is gonna have to buy a copy of Windows. You could have this in your terms & conditions as a last resort measure 'cos you wouldn't want Microsofty coming down on you.
Good luck and see ya there!
Suspishio
My advice is at your risk
(We saved the Frogs from the Krauts - twice!)
Dell XPS M1710; T7200 2GHz Core 2 Duo; 2GB RAM; XP Pro (32)
nForce 680i LT; Q6600 Quad Core 2.4GHz; 8GB RAM; XP Pro (64)
My advice is at your risk
(We saved the Frogs from the Krauts - twice!)
Dell XPS M1710; T7200 2GHz Core 2 Duo; 2GB RAM; XP Pro (32)
nForce 680i LT; Q6600 Quad Core 2.4GHz; 8GB RAM; XP Pro (64)
I too, find it strange that one of 3 tech's on the island doesn't have his /her own winxp cd install disks. I'am a backyard computer fixer and i have copies of legit xp pro and home,for just the problem you are having .
Last edited by caperjack : Oct 28th, 2007 at 1:21 pm.
Boo!!!!! Sarcastic Jack
Malwarebytes startUpLite Program Works wonders for me .
http://www.malwarebytes.org/startuplite.php
Malwarebytes startUpLite Program Works wonders for me .
http://www.malwarebytes.org/startuplite.php
![]() |
•
•
•
•
•
•
•
•
DaniWeb Windows NT / 2000 / XP / 2003 Marketplace
•
•
•
•
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
•
•
•
•
antivirus apple browser cd choose computer crack debian defender dell development download fiji hoax install internet it jargon language leopard linux microsoft mobile news office open operating opinions os photo registry research second security server software source spyware survey system torvalds tweaks ubuntu unix upgrade vista windows windows update windows vista xp
- Infected computer (Viruses, Spyware and other Nasties)
- Infected computer (Viruses, Spyware and other Nasties)
- Stupid Red X "Your Computer has been infected" (Viruses, Spyware and other Nasties)
- seriously infected computer (Viruses, Spyware and other Nasties)
- Cant see my hidden folders - "folder options" missing!! (Windows NT / 2000 / XP / 2003)
- Error message, posting HijackThis log (Viruses, Spyware and other Nasties)
- Crackers for Christmas (or, How Did My Brand New Computer Get Infected Already?) (Viruses, Spyware and other Nasties)
- On Internet Explorer, My Java does not work! (Web Browsers)
- computer turns off by itself (Windows NT / 2000 / XP / 2003)
Other Threads in the Windows NT / 2000 / XP / 2003 Forum
- Previous Thread: Allow Secondary Logon But Deny Interactive Logon
- Next Thread: getting ipconfig at command prompt



Linear Mode