My friend has some pretty bad malware...

imported_goku

Diamond Member
Mar 28, 2004
7,613
3
0
I've been working hard on trying to remove the viruses from his system and malware etc.. but he's still got issues...

I've run hjack this
Adaware
Kaspersky

most has been removed but...

His ping and speeds are irratic, which is actually better than before considering that his 6mb connection was downloading at 20Kb/s 9Kb/s upload, 1000-2000 ping.. Now it's like a rollercoaster where sometimes it'll download fast and fast ping and then it will bogg down but then speed up again...


One problem hes got is that random windows sounds are being made in the background. The sounds are coming from IE6 for Sp2 where it notifys you of a blocked popup despite popup block in IE6 being disabled, also it plays one of the other sounds associated with that program (isn't included with SP1, SP2 specific 'feature' LOL).

And to finally add a touch of hell, COMMERCIALS are actually being played through his speakers, you can actually hear sound, like a dove commercial and then you hear something like a tv station or something of the sort...

WTF how?
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
goku, can you get precise virus names from Kaspersky's logs, to help home in on what the malwares are? Just open up the panel and click the text in the Summary box. That opens up another panel, and post up some screenshots (go up & down the list and get a few if necessary).

Also, which version of Kaspersky does he have on there? Is it full-blown version 6, or is it the AOL free version? Both are good, but tell me which he's got. Either way, he can do what I show in this screencapture video to really fully arm it. I'd recommend saving the whole movie to disk so it plays back smoothly.

Additionally, have him

1) update Kaspersky's virus definitions (right-click the tray icon and choose "Update")

2) restart the system in Safe Mode, and run a full Kaspersky "Scan My Computer" in Safe Mode, then stay in Safe Mode and also run scans with Spybot Search & Destroy and Ad-Aware.


And after that, I'd follow John's excellent spyware-destruction guide on this page to make extra-sure. Actually if it were me, that Windows box would get burned to the ground with DBAN :evil: but I'm just that ruthless.
 

Mr Fox

Senior member
Sep 24, 2006
876
0
76
Originally posted by: goku
I've been working hard on trying to remove the viruses from his system and malware etc.. but he's still got issues...

I've run hjack this
Adaware
Kaspersky

most has been removed but...

His ping and speeds are irratic, which is actually better than before considering that his 6mb connection was downloading at 20Kb/s 9Kb/s upload, 1000-2000 ping.. Now it's like a rollercoaster where sometimes it'll download fast and fast ping and then it will bogg down but then speed up again...


One problem hes got is that random windows sounds are being made in the background. The sounds are coming from IE6 for Sp2 where it notifys you of a blocked popup despite popup block in IE6 being disabled, also it plays one of the other sounds associated with that program (isn't included with SP1, SP2 specific 'feature' LOL).

And to finally add a touch of hell, COMMERCIALS are actually being played through his speakers, you can actually hear sound, like a dove commercial and then you hear something like a tv station or something of the sort...

WTF how?





Sounds Like Major Issues.. Probably a Rootkit, and further Infections.... You are best off to Yank his Data, and Format.... And then make sure he has Valid Firewalls and AV in Place... Burn the Data off... after scanning the crap out of it..
And when you Format... Use a DoD Quality Wipe on the Drive to assure it is all wiped...