My laptop has a bug.
Its a real bastard :
Can't browse to antivirus sites, in fact if you type in the name of any antivirus products into a search engine and hit submit, it closes the window.
It won't let me access the windows firewall or security center settings.
I can't access the firewall via the command prompt.
The processes window in the task manager comes up blank.
Won't let me install AVG.
I just installed windows on this machine a week ago and haven't installed any antivirus. Anyone know what it is? Anyone know an online scanner that might not be programmed into this little bastard?
Edit : After rolling XP back to SP1 Ad-Aware now picks up 31 objects. A bunch of Alexa trackers, two windows vulnerabilities listed as regedit access disablement. When the regedit disablement is removed, regedit is still unavailable. I'm pretty sure this is a virus rather than spyware.
Considering I have the latest windows updates, have not opened any email attachments, have been running the windows firewall every time I've been connected and have only been connected for short periods browsing fairly inoccuous sites, I'm going to have to assume its some sort of worm.. It seems made for SP2.
Its a real bastard :
Can't browse to antivirus sites, in fact if you type in the name of any antivirus products into a search engine and hit submit, it closes the window.
It won't let me access the windows firewall or security center settings.
I can't access the firewall via the command prompt.
The processes window in the task manager comes up blank.
Won't let me install AVG.
I just installed windows on this machine a week ago and haven't installed any antivirus. Anyone know what it is? Anyone know an online scanner that might not be programmed into this little bastard?
Edit : After rolling XP back to SP1 Ad-Aware now picks up 31 objects. A bunch of Alexa trackers, two windows vulnerabilities listed as regedit access disablement. When the regedit disablement is removed, regedit is still unavailable. I'm pretty sure this is a virus rather than spyware.
Considering I have the latest windows updates, have not opened any email attachments, have been running the windows firewall every time I've been connected and have only been connected for short periods browsing fairly inoccuous sites, I'm going to have to assume its some sort of worm.. It seems made for SP2.
no subject
Date: 2004-10-08 10:41 am (UTC)I couldn't network it with another machine, I think due to SP2 being installed. I just rolled that back and going to see if I can network and use one machine to scan the other. Wish me luck.
no subject
Date: 2004-10-08 10:20 am (UTC)Safe Mode - Control Panel - Internet Options. Under the programs tab, there SHOULD be a button that will let you see EVERY BHO and whatnot loading with your browser. Very neat little tool that Microsoft threw us in SP2. Also, I'd strongly reccomend that in safe mode you check your startup sequence via MSCONFIG, in particular your non-microsoft services, kill anything that shouldn't be there, kill any normal programs starting with the system that shouldn't be there, and pray that lets you get things going. You may or may not need to clean up the hosts file, it depends on HOW this thing is redirecting and killing your browser.
Failing that, you're going to be installing AVG from Safe Mode.
Failing THAT, well, I hope you like installing Windows. ^_^;;
I will NOT ask you what in the bloody hell you were doing operating with your pants down like that, as I really, really don't want an answer.
no subject
Date: 2004-10-08 10:30 am (UTC)no subject
Date: 2004-10-08 10:31 am (UTC)no subject
Date: 2004-10-08 10:38 am (UTC)Safe mode might let you run stinger. Barring that, like hereticorp said, a bootable A/V CD, and/or an AV program that the virus doesn't know of, is probably going to be your best bet.
no subject
Date: 2004-10-08 10:32 am (UTC)no subject
Date: 2004-10-08 10:39 am (UTC)no subject
Date: 2004-10-08 10:33 am (UTC)Use that to get your AV software or whatever you need.
Then proceed to use it forever because it's not prone to the exploits IE is.
Accept no substitutes. IE sucks.
no subject
Date: 2004-10-08 10:39 am (UTC)no subject
Date: 2004-10-08 10:47 am (UTC)*or, at least, lessen the chance considerably
no subject
Date: 2004-10-08 10:50 am (UTC)no subject
Date: 2004-10-08 11:18 am (UTC)no subject
Date: 2004-10-08 04:18 pm (UTC)no subject
Date: 2004-10-08 12:02 pm (UTC)(And, furthermore, what would be the point in regurgitating that which others have already covered?)
no subject
Date: 2004-10-08 12:05 pm (UTC)Stupid viruses.. They piss me off.
no subject
Date: 2004-10-08 12:25 pm (UTC)Amusingly, a friend (who doesnt work in this particular examples IT dept) tells me that their Co. (Win2K based) just got hit by Blaster. 900+ infected PC's.
You know, that one that has been out over a year now, and updating to SP4 + a few simple windows updates removes the vulnerability..
It's funny because we don't have to clear up *that* mess ;)
no subject
Date: 2004-10-08 12:27 pm (UTC)no subject
Date: 2004-10-08 03:51 pm (UTC)And anyway, I take every oppertunity I get to promote alternative browsers.
no subject
Date: 2004-10-08 03:52 pm (UTC)no subject
Date: 2004-10-09 02:14 am (UTC)Get your friends using it, your friends friends, your parents, their parents, everyone. Do not rest until no one you know uses IE.
...And if you can, get them to switch to Linux too. :P
no subject
Date: 2004-10-09 02:19 am (UTC)/Seriously hate microsoft
/Give me convenience or give me death
no subject
Date: 2004-10-09 05:20 am (UTC)I'd recommend trying the new SuSE 9.1 / 9.2 as I've heard that's pretty close to 'just works'.
I personally use Gentoo (http://www.gentoo.org)... I like it hard. ;)
no subject
Date: 2004-10-09 07:02 pm (UTC)I've got a girlfriend and things to get done, the linux OS sucks! Sorry to say it, but it does!
Want games, will windows... Also the networking/file-sharing capabilities of XP are something I actually like.. Home networking is easy as pie, but that is all I use it for.
Can you plug an ethernet cable into a linux box and have access to shared files at the click of a button?
no subject
Date: 2004-10-10 01:28 am (UTC)It's not as easy as plug'n'play to share files, but then again it isn't in Windows. If it is, it shouldn't be because then it turns into a security risk.
Linux networking - at least with NFS - is as simple as editing /etc/exports on your server, and /etc/fstab on your client. Now, that's simple as pie for me, but I do see where you're coming from.
Still, you should still try it before you knock it.
no subject
Date: 2004-10-08 10:40 am (UTC)no subject
Date: 2004-10-08 10:42 am (UTC)The location of this file on XP is,c:\i386 you will need to search for it on different systems.
# Copyright (c) 1993-1999 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
127.0.0.1 localhost
c:\i386
Date: 2004-10-08 10:47 am (UTC)...
Date: 2004-10-08 10:58 am (UTC)Try to browse to AV online scanners by IP?
Re: ...
Date: 2004-10-08 11:35 am (UTC)Re: ...
Date: 2004-10-08 11:43 am (UTC)Access to regedit is disabled also. Ad-Aware finds this hack and removes it but then I am told I do not have enough permission to run regedit.
Re: ...
Date: 2004-10-08 11:46 am (UTC)This time around, my only suggestions are - you put firefox on right after you run windows update, you get AVG running within one reboot of that, and better luck this pass around.
Re: ...
Date: 2004-10-08 11:49 am (UTC)I think I'm going to have to reinstall. What a crock. I brought my machine in to work to play starcraft on the LAN. I wanted fun and gaming, not frustration and geekery.
CASTRATE THE VIRII AUTHORS AND FEED THEIR GENITALS TO FLESH-EATING BACTERIA
Re: ...
Date: 2004-10-08 01:00 pm (UTC)And that machine, as of right now, would be where we'd be pronouncing it 'in need of rebuild.'
If required, take a large, blunt object, and strike the geek helping you. Not hard enough to kill, just hard enough to knock senseless. Then start the wipe and restore before he gets back up.
Re: ...
Date: 2004-10-08 01:03 pm (UTC)Re: ...
Date: 2004-10-08 01:09 pm (UTC)At the same time, have you EVER tried to clean spyware out of 98? It's insane. One invariably feels like a dentist trying to extract a few bad teeth, and accidentally taking the whole damn jaw - but somehow managing to leave some good teeth in there. They're pretty useless by that point, but they're there.
no subject
Date: 2004-10-08 04:20 pm (UTC)Definately 0wn3d
Date: 2004-10-08 12:01 pm (UTC)First, boot into safe mode.
Now at the run box, type 'notepad \windows\system32\drivers\etc\hosts'
take out all the lines redirecting variuos sites to 127.0.0.1
Next, run msconfig and turn off ALL startup items.
Boot normally and you should be able to get some sort of antivirus on there. Update it and do a full system scan before turning startups back on.
Re: Definately 0wn3d
Date: 2004-10-08 12:03 pm (UTC)I am so frustrated I want to scream.
Re: Definately 0wn3d
Date: 2004-10-08 05:39 pm (UTC)wow, that is in there deep.
do this
run > "cmd" to get a shell
cd \windows\system32
copy taskmgr.exe task.com
task.com
that should start the task manager as a differently named process, and you can kill it from there
it might also be in as a system service. run "services.msc" and look for suspicious ones.