Computing.Net > Forums > Security and Virus > Recalcitrant scumware

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

Recalcitrant scumware

Reply to Message Icon

Original Message
Name: Rimfire
Date: May 14, 2005 at 03:03:00 Pacific
Subject: Recalcitrant scumware
OS: Win XP
CPU/Ram: PIV 1800
Comment:

The things you are asked while at the pub. "You know a bit about computers, can you have a look at mine?"

As I was experiencing a brief moment of nonagriness and my apathy levels were low, I agreed to have a look.

When I arrived the next day, I found a computer running without any form of protection, not even antivirus and (shudder) it was operated by some teenagers who love chat and filesharing programs.

If you are still reading, thanks for not running away yet. I've installed their copy of Norton AV 2004 and updated and scanned. I also introduced them to Spybot S&D and Ad-Aware. Using these I've scanned, killed processes to allow updates. Run in safe mode. Deleted references in 'run' in the registry, yet still I have SB-S&D find 'Elitum.EliteBar' and 'ISearchTech.SideFind' and not be able to get rid of them. Not even after a scan on reboot.

I left this computer running an A squared scan this afternoon (Australian Eastern Standard Time). It had found one entry with a long way to go. No doubt, it will find many more.

I almost have control but those two files continue (unless A-squared gets them) to defy me. I also plan to introduce the main operator of the computer to this thread.

I'm running low on ideas, anybody faced and defeated these challanges?


Report Offensive Message For Removal


Response Number 1
Name: Mechanix2Go
Date: May 14, 2005 at 04:24:29 Pacific
Reply: (edit)

Hi Rimfire,

"no protection"

Not even a condom over the joystick?

When I get involved in a mess like that, I just tell the owner that s/he can pay me to spend all day and maybe get into the clear; or spend 2 hours to wpe it slick and do a fresh install.

Helps keep things in perspective.

Lemme guess. They want you to do this for nothing.

M2


If at first you don't succeed, you're about average.


Report Offensive Follow Up For Removal

Response Number 2
Name: Dog
Date: May 14, 2005 at 04:37:23 Pacific
Reply: (edit)

It's almost enough to keep you out of the pub. Spent a nice arvo in the pub this arvo (Aust. Eastern Standard Time) and fixed three computers while I had a few Carlton Draughts. The net, the pub, the club..aaaaarrrrgggghhhhh....I'll have to stay at home and talk and drink with the missus.

D4Dog


Report Offensive Follow Up For Removal

Response Number 3
Name: jabuck
Date: May 14, 2005 at 08:19:41 Pacific
Reply: (edit)

Try this for elite bar http://www.simplytech.it/ETRemover/

Then run this http://www.mwti.net/antivirus/mwav.asp to find remaining offending files and registriy entries. Remove the files in safe mode.

You don't have to buy it, after the scan is completed view the log and search for the offending files and reg entries.



Report Offensive Follow Up For Removal

Response Number 4
Name: johnr
Date: May 14, 2005 at 09:24:39 Pacific
Reply: (edit)

I'd agree with Mechanix - even if you manage to clean this malware out chances are that no other maintenance has ever been carried out on the system. If they have the original disks & you have access to a broadband connection do a reinstall & full update & then put on the safeguards you think they need - at least you'll be safe in the knowledge that you've given them a good restart.

"I know that I'm mad - I've always been mad..."


Report Offensive Follow Up For Removal

Response Number 5
Name: bofra
Date: May 14, 2005 at 10:55:22 Pacific
Reply: (edit)

XP...also try toolbarcop to remove BHO plugins,
in safe mode , empty temp folders and temporary internet folder,

analyze drive with disk defragmenter,
check for errors using scandisk,

repair/retore iexplorer if required,
try using regedt32 to search and remove any links to spyware,



Report Offensive Follow Up For Removal


Response Number 6
Name: Rimfire
Date: May 14, 2005 at 13:18:33 Pacific
Reply: (edit)

Wow five responses already! This is the S&V forum? I didn't realise that the subject title was that catchy.

You're right of course M2, it would have been much quicker and easier to simply reformat. Actually, I declined payment on this one. I've been looking at this for a few weeks now and collectively I've spent a couple of days on this. If I was to charge full rates, it might be cheaper just to replace the computer. A lot of click and wait involved.

However, I look upon this as a challenge and a learning experience. Also, it teaches the user to keep their computer clean. That way, I won't be reformatting every few weeks.

Dog, what can I say? Exellent taste! It was the barman who was serving me a schooner of Carlton that asked. I'm located on the Princes Highway, not far north of the Victorian border.

Thanks for those great links guys. I'll be brnging Carly into this thread and she can download and run them.


Report Offensive Follow Up For Removal

Response Number 7
Name: Wombat
Date: May 14, 2005 at 14:09:01 Pacific
Reply: (edit)

Recalcitrant scumware... didn't Paul Keating call a Malaysian dignitary this?

Wipe it clean clean Mate, then charge them for a couple of cartons of your favourite beer...

Learn How To GOOGLE! Here


Report Offensive Follow Up For Removal

Response Number 8
Name: Rimfire
Date: May 14, 2005 at 16:12:31 Pacific
Reply: (edit)

Our former esteemed Prime Minister may have been a little tactless and the Malay PM's advisors didn't translate very well, but even Mr Keating wouldn't have used the word scum in that context! Even if it was apropriate;-)

Yet another one using that four letter word... quit! I've just about got this beaten and I've taught a couple of teenagers a few tricks in the process. They should now be able to keep it clean.


Report Offensive Follow Up For Removal

Response Number 9
Name: Mechanix2Go
Date: May 14, 2005 at 22:44:05 Pacific
Reply: (edit)

Rimfire,

S&V isn't all that catchy, but how many subject lines dp you see which contain a four syllable word?

How many with words of two or more syllables used correctly?

[doooh]

M2


If at first you don't succeed, you're about average.


Report Offensive Follow Up For Removal

Response Number 10
Name: Rimfire
Date: May 15, 2005 at 01:00:17 Pacific
Reply: (edit)

Hmmm, I see what you mean. It does stand out a little. Even beyond the fact that my name is next to it. I suppose that if I had tried to dress it up, such as capitalising scumware and finishing with an emoticon, it would just look silly!

Time for a bit of an update, I had planned to hand over the reins to the teenagers you abused this computer to the point it wanted to pack up it's CDs and run back to the factory. However, it seems that they weren't home today. My first job tommorrow is two and a half hours drive away, I won't be able to bring them in for nearly a day.


Report Offensive Follow Up For Removal

Response Number 11
Name: Mechanix2Go
Date: May 15, 2005 at 01:36:59 Pacific
Reply: (edit)

hmmm

Two & a half hours. In Oz I guess that's about 200 miles.

In Thailand, about 25.

;(

M2


If at first you don't succeed, you're about average.


Report Offensive Follow Up For Removal

Response Number 12
Name: Rimfire
Date: May 15, 2005 at 02:33:19 Pacific
Reply: (edit)

I work on an average speed of 80Km/h. My licence is probably more important a tool than my favourite screwdriver. If a judge took away my screwdriver, I could buy another. They tend to jack up about drivers licences. Your figures suggest an average speed of 80 mp/h or 130 km/h.

That call is at a ski resort (Perisher Valley). There aint no freeways way up in the mountains! My work car is an old toyota diesel van. two and a half hours is about 200ks (125 miles).


Report Offensive Follow Up For Removal

Response Number 13
Name: Mechanix2Go
Date: May 15, 2005 at 02:43:45 Pacific
Reply: (edit)

Rimfire,

Understamd about the license.

More important than a fav screwdriver?

hmm

I have a pair of 8" channelocks that I've had since 1961. I would not care to be without them. Got 'em trained.

;)


M2


If at first you don't succeed, you're about average.


Report Offensive Follow Up For Removal






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home








Do you own an iPhone?

Yes
No, but soon
No


View Results

Poll Finishes In 7 Days.
Discuss in The Lounge
Poll History




Data Recovery Software