BuckeyePlanet Ohio State Forums  

Go Back   BuckeyePlanet Ohio State Forums > Varied Interest > Open Discussion (Work-safe) > Computers, Home Theater & Technology

Computers, Home Theater & Technology Need help with your computer? Want to learn about the latest advances in technology? Are you an audio/videophile? Need help hooking up your home theater? This is the forum for you.

 
Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 05-24-2008, 11:18 PM
Muck's Avatar
The Lone Shenanigan
 

Join Date: Feb 2004
Posts: 4,378
Points: 539,132.17
Bank: 1.00
Total Points: 539,133.17
Muck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and Hayes
Muck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and Hayes
Cleaning a bad infestation of malware, virii, trojans, rootkits etc

Since I seem to be on a security kick lately I thought I might as well post some detailed directions I put together for a friend on another board who's having severe issues with all the little nasties...

(Feel free to comment, ask questions or add to the guide)



1. Update your anti-spyware & antivirus programs to the newest versions available.

2. Run Disk Cleanup (If you have a third party app like CCleaner, Clean Up!, ATF Cleaner or Advanced Windows Care run that instead).

3. Download HijackThis from Trend Micro.

- Run a scan and save the logfile (be sure to change the name from "hijackthis.log" something you will remember like "hijackthisbefore.log").

4. Open "Add/Remove Programs" and check to see if there is anything weird that needs to be uninstalled (unknown toolbars, search utilities etc)

5. Turn off the real time monitoring of all your security programs (any antispyware, antivirus, firewalls)

6. Download & run McAfee Stinger.

7. Download & run the newest version of Microsoft's Malicious Software Removal Tool

8. Go to eset Nod 32, F-Secure, BitDefender or TrendMicro and run an online scan (these all use ActiveX so you must use IE).

9. Reboot the computer and start up in safe mode.

10. Do a full scan with your primary anti-spyware program. Once the scan is complete & repairs made make sure the program is completely closed. If there is an icon in the system tray that means it is still running. Right click on the icon and select “exit” (or “close”, “shutdown” etc).

- Repeat with your secondary anti-spyware program.

- Finally do a full scan with your anti-virus program.

11. Reboot normally

12. Again turn of real time monitoring and completely close any of your antispy/virus programs that install on start up.

13. Run your anti-spyware scanners & anti-virus again as you did while in safe mode.

14. Run HijackThis a final time and again give the log file a unique name to distinguish it (ie “hijackthisafter.log”.

15. If you are still having problems you can copy & paste your HijackThis logfiles into the analyzer at I Am Not A Geek which will help you find files that may be causing problems. Google anything listed as bad to find specific methods of removing the problem files. (Be careful as the analyzer does give false positives at times.)

- You can also paste the logs at the Castle Cops, Hijack This Logs forum. Start a new thread with a title describing the problem you are having and then paste your logfiles into the main body of the post. The members of the forum will be happy to help you figure out what the problem is through your log file.
__________________

This post brought to you by the letters:

O H

Last edited by Muck; 05-25-2008 at 05:06 AM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble it!Reddit! Share on Facebook!Google bookmark it!Wong this Post!
Reply With Quote
Sponsored Links
  #2 (permalink)  
Old 05-26-2008, 08:11 PM
3074326's Avatar
MUSCLE
 

Join Date: Nov 2007
Location: West of the 315
Posts: 4,030
Points: 137.54
Bank: 0.00
Total Points: 137.54
Blog Entries: 3
3074326 is beyond Tressel and Hayes3074326 is beyond Tressel and Hayes3074326 is beyond Tressel and Hayes3074326 is beyond Tressel and Hayes3074326 is beyond Tressel and Hayes3074326 is beyond Tressel and Hayes3074326 is beyond Tressel and Hayes3074326 is beyond Tressel and Hayes3074326 is beyond Tressel and Hayes3074326 is beyond Tressel and Hayes3074326 is beyond Tressel and Hayes3074326 is beyond Tressel and Hayes3074326 is beyond Tressel and Hayes3074326 is beyond Tressel and Hayes3074326 is beyond Tressel and Hayes
3074326 is beyond Tressel and Hayes3074326 is beyond Tressel and Hayes3074326 is beyond Tressel and Hayes3074326 is beyond Tressel and Hayes3074326 is beyond Tressel and Hayes3074326 is beyond Tressel and Hayes3074326 is beyond Tressel and Hayes3074326 is beyond Tressel and Hayes3074326 is beyond Tressel and Hayes3074326 is beyond Tressel and Hayes3074326 is beyond Tressel and Hayes3074326 is beyond Tressel and Hayes3074326 is beyond Tressel and Hayes3074326 is beyond Tressel and Hayes3074326 is beyond Tressel and Hayes3074326 is beyond Tressel and Hayes3074326 is beyond Tressel and Hayes3074326 is beyond Tressel and Hayes3074326 is beyond Tressel and Hayes3074326 is beyond Tressel and Hayes3074326 is beyond Tressel and Hayes
Quite the list. Thanks for it. It'll help those of us who aren't great with things like this.
__________________


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble it!Reddit! Share on Facebook!Google bookmark it!Wong this Post!
Reply With Quote
  #3 (permalink)  
Old 05-27-2008, 04:57 PM
martinss01's Avatar
blissfully stupid
 
BP Donor

Join Date: Oct 2004
Location: cincy
Posts: 3,020
Points: 1,503,201.72
Bank: 1,486.13
Total Points: 1,504,687.85
martinss01 is Tresselesquemartinss01 is Tresselesquemartinss01 is Tresselesquemartinss01 is Tresselesque
martinss01 is Tresselesquemartinss01 is Tresselesquemartinss01 is Tresselesquemartinss01 is Tresselesquemartinss01 is Tresselesquemartinss01 is Tresselesquemartinss01 is Tresselesquemartinss01 is Tresselesquemartinss01 is Tresselesquemartinss01 is Tresselesquemartinss01 is Tresselesquemartinss01 is Tresselesquemartinss01 is Tresselesquemartinss01 is Tresselesquemartinss01 is Tresselesquemartinss01 is Tresselesquemartinss01 is Tresselesquemartinss01 is Tresselesquemartinss01 is Tresselesquemartinss01 is Tresselesquemartinss01 is Tresselesquemartinss01 is Tresselesque
step 16. format C:/
step 17. install linux

great doc muck. most internet providers have free security software that they update daily or weekly. once you get things cleaned up, do yourself a favor and at the very least use those. if you do have an infection of sorts. be patient, its possible you may have to repeat these steps over and over to get rid of it.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble it!Reddit! Share on Facebook!Google bookmark it!Wong this Post!
Reply With Quote
  #4 (permalink)  
Old 05-27-2008, 07:56 PM
Muck's Avatar
The Lone Shenanigan
 

Join Date: Feb 2004
Posts: 4,378
Points: 539,132.17
Bank: 1.00
Total Points: 539,133.17
Muck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and Hayes
Muck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and HayesMuck is beyond Tressel and Hayes
Quote:
Originally Posted by martinss01 View Post
step 16. format C:/
step 17. install linux
You can keep your bloated, buggy, insecure OS to yourself; thank you very much.


Open-BSD pwns linux
__________________

This post brought to you by the letters:

O H

Last edited by Muck; 05-28-2008 at 12:05 AM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble it!Reddit! Share on Facebook!Google bookmark it!Wong this Post!
Reply With Quote
  #5 (permalink)  
Old 05-27-2008, 09:34 PM
Hodge's Avatar
Heisman
 

Join Date: Jul 2004
Location: Ohio
Posts: 502
Points: 16,013.25
Bank: 0.00
Total Points: 16,013.25
Hodge has a helmet full of Buckeyes!Hodge has a helmet full of Buckeyes!Hodge has a helmet full of Buckeyes!Hodge has a helmet full of Buckeyes!Hodge has a helmet full of Buckeyes!Hodge has a helmet full of Buckeyes!Hodge has a helmet full of Buckeyes!Hodge has a helmet full of Buckeyes!Hodge has a helmet full of Buckeyes!Hodge has a helmet full of Buckeyes!Hodge has a helmet full of Buckeyes!Hodge has a helmet full of Buckeyes!Hodge has a helmet full of Buckeyes!Hodge has a helmet full of Buckeyes!Hodge has a helmet full of Buckeyes!Hodge has a helmet full of Buckeyes!Hodge has a helmet full of Buckeyes!Hodge has a helmet full of Buckeyes!Hodge has a helmet full of Buckeyes!Hodge has a helmet full of Buckeyes!Hodge has a helmet full of Buckeyes!Hodge has a helmet full of Buckeyes!Hodge has a helmet full of Buckeyes!
Can't resist....


Now back to the topic on hand. Does anybody have a good solution for when no .exe's can run (even in safe mode)? On top of that, I 'fixed' one recently that had implemented the built in security policies to prevent explorer.exe from ever running (ran a boot-time scan, virus took some system files with it. Had to re-format their box).
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble it!Reddit! Share on Facebook!Google bookmark it!Wong this Post!
Reply With Quote
  #6 (permalink)  
Old 05-27-2008, 09:53 PM
leroyjenkins's Avatar
Trained pogonologist.........look it up!
 

Join Date: Dec 2007
Posts: 1,371
Points: 280,432.77
Bank: 0.00
Total Points: 280,432.77
leroyjenkins is a revered BP posterleroyjenkins is a revered BP posterleroyjenkins is a revered BP posterleroyjenkins is a revered BP posterleroyjenkins is a revered BP posterleroyjenkins is a revered BP posterleroyjenkins is a revered BP posterleroyjenkins is a revered BP posterleroyjenkins is a revered BP posterleroyjenkins is a revered BP poster
leroyjenkins is a revered BP posterleroyjenkins is a revered BP posterleroyjenkins is a revered BP posterleroyjenkins is a revered BP posterleroyjenkins is a revered BP posterleroyjenkins is a revered BP posterleroyjenkins is a revered BP posterleroyjenkins is a revered BP posterleroyjenkins is a revered BP posterleroyjenkins is a revered BP posterleroyjenkins is a revered BP posterleroyjenkins is a revered BP posterleroyjenkins is a revered BP posterleroyjenkins is a revered BP posterleroyjenkins is a revered BP posterleroyjenkins is a revered BP posterleroyjenkins is a revered BP posterleroyjenkins is a revered BP posterleroyjenkins is a revered BP posterleroyjenkins is a revered BP posterleroyjenkins is a revered BP poster
I assumed from the thread name, that I would only need some penicillin to get rid of that stuff.......
__________________
"There are two kinds of people in this world that go around beardless ? boys and women ? and I am neither one." -Greek saying

"A woman with a beard looks like a man. A man without a beard looks like a woman." - Afghan Saying

In the course of history, men with facial hair have been ascribed various attributes such as wisdom and knowledge, sexual virility, or high social status; and, conversely, filthiness, crudeness, or an eccentric disposition.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble it!Reddit! Share on Facebook!Google bookmark it!Wong this Post!
Reply With Quote
  #7 (permalink)  
Old 05-27-2008, 09:56 PM
sandgk's Avatar
Watson, Crick & A Twist
 
BP Donor
Cincinnati Bengals Ohio State England

Join Date: Oct 2004
Location: SW Ohio
Posts: 14,566
Points: 1,609,381.95
Bank: 0.29
Total Points: 1,609,382.24
sandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retired
sandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retiredsandgk has his jersey number retired
Quote:
Originally Posted by leroyjenkins View Post
I assumed from the thread name, that I would only need some penicillin to get rid of that stuff.......
When it comes to your data accept no substitutes ...



Cipro ....
__________________
"They say a little knowledge is a dangerous thing, but it is not half so bad as a lot of ignorance." - Terry Pratchett
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble it!Reddit! Share on Facebook!Google bookmark it!Wong this Post!
Reply With Quote
  #