Wiped XP due to malware

imported_Graphite

Junior Member
Dec 28, 2008
17
0
0
G'Day all,
A friend of mine recently asked for help with their PC, and when I finally got to have a look at it, I found that, well, it was in a really bad way, hardware and software, but hardware is another story. In order to do anything at all I needed to start Explorer manually at startup even... And that crashed eventually. No AV or prior backup of course...

I told the friend to back as much of their important stuff up as they thought needed on to DVD's and my laptop, and I'd try to save it. I couldn't repair the friend's installation due to having an XP Pro disk on hand as opposed to their XP Home, which sucked...

So I started by trying to get to the control panel... And no go. This threw me immediately. A .dll was 'missing' according to Windows, and nothing I tried (run from Task Manager or Start, my *limited* command prompt knowledge, finding the .exe's in the Windows folder) would let me even open Add/Remove Programs... A quick scan of a couple of 'downloaded' folders over wireless with McAfee from my laptop pulled up a few nasties, but nothing brought back control I desired...

...I cracked, and after backing up as much as I could cram to my 30GB of free space (took all night over wireless :Q), I wiped it. The parent of the house halted any attempts to recover any files with Recuva while I was gone, and I properly formatted it the next visit after asking if the friend would prefer I attempt a recovery program (I had to offer to recover their installation - I only just got a good boot-recovery program that day).

So... My question is, should I have tried to install an Anti-Virus via Safe Mode or something like that before I gave in? Wait for the HDD to be fully open and try my McAfee over network again? I feel more than a little bad about it all since I cracked it first... Was wiping the drive still the best option..?

Thank you, and hope there's a few options I could know in future/post-job...

Graphite

P.S. I just noticed Schadenfroh's script, would that have saved me?
 

BKLounger

Golden Member
Mar 29, 2006
1,098
0
0
typically with severely infected machines the first thing i try is installing avg and running it from safe mode. If that doesn't work I will boot up my newest HawkPE live disc and run virus scan's and adware scans from that so that way nothing on the hard drive is running. So far that has solved all virus and spyware infected machines that have come my way yet.
 

Chiefcrowe

Diamond Member
Sep 15, 2008
5,055
198
116
Agreed, scanning from safe mode and from boot cd will work in some cases but if it is really bad, then wiping is the way to go.
As it is, wiping is always the safest option to definitely remove all traces of malware, etc.
 

Lemon law

Lifer
Nov 6, 2005
20,984
3
0
Been there done that when I bought a used computer on ebay that came with 4000+ pieces of malware thrown in for no extra charge.

I managed to clean it totally, but it proved to be a black hole in time. When I could have wiped everything and been up and running in a few hours rather than weeks. As is, I am glad I opted to try to save it, because I learned a lot in the process. But now that I have profited by that experience, next time I get in a similar bind with someone's computer, I would opt to wipe if it looks really bad.

But the other thing I learned in the process is how to set up a multilayered protection system that is almost bullet proof, so knock on wood, it will never happen to me again.

The other thing to learn is, anytime you buy a used computer, assume its infected, have an arsenal of anti malware programs ready to go before you ever expose it to the internet or your network.