Go Back   AnandTech Forums > Hardware and Technology > Computer Help

Notices

Forums
· Hardware and Technology
· CPUs and Overclocking
· Motherboards
· Video Cards and Graphics
· Memory and Storage
· Power Supplies
· Cases & Cooling
· SFF, Notebooks, Pre-Built/Barebones PCs
· Networking
· Peripherals
· General Hardware
· Highly Technical
· Computer Help
· Consumer Electronics
· Digital and Video Cameras
· Gadgets Gear and Phones
· Audio/Video & Home Theater
· Software
· Software for Windows
· All Things Apple
· *nix Software
· Operating Systems
· Programming
· PC Gaming
· Console Gaming
· Distributed Computing
· Security
· Social
· Off Topic
· Politics and News
· The Garage
· Health and Fitness
· Merchandise and Shopping
· For Sale/Trade
· Hot Deals
· Free Stuff
· Contests and Sweepstakes
· Forum Issues
· Technical Forum Issues
· Personal Forum Issues
· Suggestion Box
   

Reply
 
Thread Tools
Old 04-06-2008, 03:03 PM   #1
DSF
 
Join Date: Oct 2007
Posts: 3,807
Default Help with computer virus - spools.exe

My girlfriend's sister is having some serious problems with her computer. Since it's not my computer the information I have is incomplete, but I'll do that best that I can.

The specs:
Windows XP SP 2
Dell (no idea about the processor and such because I can't access My Computer.)
I'm guessing it's roughly two years old.

The problem:
Upon startup, about a dozen command-line windows open on top of each other. They're titled "Cwindows\system32\drivers\spools.exe"
She's completely locked out of just about everything in her computer including anti-virus programs, she can't access the start menu, etc. The searching I've done on a clean computer has said that spools.exe is a pretty serious virus and can be difficult to remove. She says there isn't much irreplaceable data on her computer. She said it's mostly things like her resume that would be a pain to recreate, but she could manage.

Is it worthwhile to try to remove the virus, and if so, what should I do? Otherwise, should I just reformat and reinstall windows to be sure that the problem is history?
__________________
Thanks for the support everyone! For those of you who visited my thread in the FS/T forum, my students got all the calculators they needed!
DSF is offline   Reply With Quote
Old 04-06-2008, 03:23 PM   #2
CalvinHobbes
Diamond Member
 
Join Date: Feb 2004
Posts: 3,448
Default Help with computer virus - spools.exe

It would be a good idea to backup whatever is needed just to be sure. Just be careful that what is backed up is not infected. Then boot to safe mode, turn off recovery check point thing, and scan with a good AV program. See if that's enough to clean it off.
CalvinHobbes is offline   Reply With Quote
Old 04-06-2008, 03:26 PM   #3
DSF
 
Join Date: Oct 2007
Posts: 3,807
Default Help with computer virus - spools.exe

Quote:
Originally posted by: CalvinHobbes
It would be a good idea to backup whatever is needed just to be sure. Just be careful that what is backed up is not infected. Then boot to safe mode, turn off recovery check point thing, and scan with a good AV program. See if that's enough to clean it off.
Thing is, when I boot into safe mode I'm still unable to open the start menu or run her antivirus software. I suppose I should've mentioned that above.
__________________
Thanks for the support everyone! For those of you who visited my thread in the FS/T forum, my students got all the calculators they needed!
DSF is offline   Reply With Quote
Old 04-06-2008, 04:09 PM   #4
chame1eon
 
Join Date: Mar 2008
Posts: 5
Default Help with computer virus - spools.exe

Googling reveals Sophos has a removal instructions.

Or you could just try to kill the process then see if the antivirus works.

If you can't do that you can find out how it's starting and remove the entries. Hijack This can help with that.
chame1eon is offline   Reply With Quote
Old 04-06-2008, 04:48 PM   #5
mechBgon
Super Moderator
Elite Member
 
mechBgon's Avatar
 
Join Date: Oct 1999
Posts: 29,805
Default Help with computer virus - spools.exe

Quote:
Originally posted by: DSF
Quote:
Originally posted by: CalvinHobbes
It would be a good idea to backup whatever is needed just to be sure. Just be careful that what is backed up is not infected. Then boot to safe mode, turn off recovery check point thing, and scan with a good AV program. See if that's enough to clean it off.
Thing is, when I boot into safe mode I'm still unable to open the start menu or run her antivirus software. I suppose I should've mentioned that above.
Her antivirus software appears not to be up to the task anyway. Try Safe Mode With Networking and use some online antivirus scanners such as F-Secure's (use Internet Explorer). The suggestion of HijackThis is also good if you have someone tell you what to remove, or can deduce it yourself.

Personally, I would rescue whatever data is important, nuke it to the ground with a DBAN CD, then set Windows up securely for her.

mechBgon is offline   Reply With Quote
Old 04-06-2008, 05:15 PM   #6
redbeard1
Diamond Member
 
Join Date: Dec 2001
Posts: 3,006
Default Help with computer virus - spools.exe

That style virus is a pain in the behind to clean. If you have the time, you could start by pulling her hard drive out and scanning it from another system that has a good working AV and anti spyware programs

This link describes how to export/import a registry setting that re-enables the ability to run programs.

Tek-Tips

If the errors for running programs is from security rights restrictions, with XP Pro you can use gpedit.msc to enable them back.

If it is XP Home you will need to use this program to get them to run again.

Dial a fix

If you do not have the time for cleaning this, it may be easier to backup her data and reload the system.
__________________
Migrating user data? Remember your alphabet. BCDE as in: Bookmarks, Contacts, Documents & Email

Heatware is redbeard
redbeard1 is offline   Reply With Quote
Old 04-06-2008, 05:44 PM   #7
DSF
 
Join Date: Oct 2007
Posts: 3,807
Default Help with computer virus - spools.exe

Ok, I'm at her house now posting from their secondary computer.

I booted into safe mode and deleted spools.exe from the Cwindows\system32\drivers\ directory. Since I can't access the start menu, I had to do that by running C through Task Manager. I then tried to run regedit through Task Manager, and it asked me what program to use to run regedit.exe. (Like when you try to open a .pdf without having Acrobat Reader on your system.) Same thing with msconfig.

I would use something like HijackThis or an online scanner, but her internet access is completely borked on that computer. The machine is literally crippled except for the few things I can dance around, like skirting My Computer by running C directly.

If they have any blank CDs around, backing up the vitals and then nuking the poor machine is looking like the most attractive option. Then I will absolutely set them up securely mechbgon. Even with anti-virus programs, this family seems to have their computer go down at least once a month.
__________________
Thanks for the support everyone! For those of you who visited my thread in the FS/T forum, my students got all the calculators they needed!
DSF is offline   Reply With Quote
Old 04-12-2008, 12:52 PM   #8
DSF
 
Join Date: Oct 2007
Posts: 3,807
Default Help with computer virus - spools.exe

Bump since I just thought of something new.

I was in a hurry last week, so we didn't actually wipe the computer out that day. Would it be possible for me to burn some kind of Linux distro onto a CD, boot from that, and burn/email files that way without going into windows?

Any idea if this would work at all, and if so, what variety of Linux I should be looking for?

Thanks in advance.
__________________
Thanks for the support everyone! For those of you who visited my thread in the FS/T forum, my students got all the calculators they needed!
DSF is offline   Reply With Quote
Old 04-12-2008, 05:42 PM   #9
redbeard1
Diamond Member
 
Join Date: Dec 2001
Posts: 3,006
Default Help with computer virus - spools.exe

With this you can pull any hard drive, hook it up to something with USB and get the data off.

IDE/SATA to USB adapter
__________________
Migrating user data? Remember your alphabet. BCDE as in: Bookmarks, Contacts, Documents & Email

Heatware is redbeard
redbeard1 is offline   Reply With Quote
Old 04-13-2008, 03:47 AM   #10
tattoowolf
 
Join Date: Apr 2008
Posts: 1
Default Help with computer virus - spools.exe

here is something that might help. I use linux as my only op/sys and have used distros like dsl and puppy as a quick and dirty live cd. this link takes you to the INSERT project (Inside Security Rescue Toolkit) and is a bootable 60 Meg cd... I will be downloading a copy of this to see how well it works on my roommates computer (windoze based)


http://www.inside-security.de/insert_en.html

tattoowolf is offline   Reply With Quote
Old 04-13-2008, 09:36 AM   #11
Old Hippie
Diamond Member
 
Join Date: Oct 2005
Posts: 4,679
Default Help with computer virus - spools.exe

Everybody should have a copy of Hiren's boot CD.

A lotta times it cures what ails ya!
__________________
Rick
You Get What You Pay For!
Old Hippie is offline   Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 04:02 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.