Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie
Hi there,
There is an issue with role permissions that is being worked on at the moment.
If you are having trouble with access or permissions on regional forums please post here to get access: https://www.boards.ie/discussion/2058365403/you-do-not-have-permission-for-that#latest

got rid of bad spyware but it's killed a bunch of stuff

  • 05-10-2006 9:26pm
    #1
    Registered Users, Registered Users 2 Posts: 13,016 ✭✭✭✭


    had a bit of a bad spyware attack on a pc, and with the help of hijackthis!, spybot and ad-aware i've got rid of it, but it was a real hooer of a thing and has left untold damage in it's wake.

    the following things are now completely disabled:

    task manager
    regedit
    msconfig
    gpedit
    right click
    system restore

    and probably more besides, but that's pretty much bad enough.

    anyone have any ideas as to how i can un-fcuk this god aweful mess without a re-install?


Comments

  • Registered Users, Registered Users 2 Posts: 16,930 ✭✭✭✭challengemaster


    ehm... eh.. sorry, reinstall is all i can think of.. maybe some others will have better help.


  • Closed Accounts Posts: 36,634 ✭✭✭✭Ruu_Old


    Run an anti-virus scan in safe mode, also check the msconfig.exe Startup tab while you are there and see if theres anything unusual.


  • Registered Users, Registered Users 2 Posts: 14,012 ✭✭✭✭Cuddlesworth


    A reinstall would be quicker and less painless.


  • Closed Accounts Posts: 13,126 ✭✭✭✭calex71


    you could try and restore the files that got messed up from the scans from quarintine assuming your not like me and just get rid of them right after the scans, this will probably put you back in spyware central but after this you can scan to find out what you have and try and figure out hwat system file sare effected and maybe research manually fixing the issuses once you know exactly what your dealing with. Spybot would be my suspect with this problem, they dont show that when you start it up for nothing. Maybe try scanning with windows defender and ad-aware and your normal anti- virus and leave out spybot for this scan, (all assuming you can put back files the 1st round of scans altered/removed from quarintine.)

    As said though a rebuild would be best and would definately be the way id go about it.


  • Registered Users, Registered Users 2 Posts: 13,016 ✭✭✭✭vibe666


    haha!

    got it.

    smart as it was, it hadn't disabled remote regedit functionality.

    managed to get in and fix the reg entries stopping everything from working. figured it was messing with group policies to stop me from removing it, so i figured that was the best place to start and it paid off.

    all fine and dandy now. thanks anyway for the help. :)

    i have to say, i'm quite impressed with it's self preservation tricks from a professional/technical point of view anyway.

    from a BOFH point of view it'd almost be worth it to roll it out on-site to stop users from messing. :)


  • Advertisement
  • Closed Accounts Posts: 80 ✭✭realblackstuff


    Before you get in a mess like that next time, get Ewido now and install/run it. www.ewido.net
    It's amazing what that program can clean up for you.


  • Registered Users, Registered Users 2 Posts: 13,016 ✭✭✭✭vibe666


    ah, interesting. just noticed ewido has just become avg anti-spyware. might just be tempted to give it a go.

    oh, and i wouldn't have gotten into the mess in the first place if i'd been keeping my eye on the ball. i was installing nero in the background and took a popup for a reg entry allow/deny request as being from the nero installer but it seemingly wasn't.

    a schoolboy error that cost me quite a bit of time and effort to put right. :(

    note to self: read dialog boxes before clicking. ;)


Advertisement