Forum start - Register
Name Password Forgot your password?

Forum start > miscellaneous > misc support > A quandry to stumble any computer nerd
Author
Thread
JDOG
Member


 

Location: 
Registered: 8/7/2006    Warnings: 0
A quandry to stumble any computer nerd
So, I am currently trying to fix a computer and I am so totally baffled and have no idea what to do. What happened you ask? Well, let me tell you...

It was a cold dark night when I logged onto my g/f's computer and I got onto the internet. All the sudden pop ups came out of no where and they wouldn't stop. I looked down at the bottom right hand corner and I seen that norton was disabled and was out of date. I had told her dad about two months ago to resubscribe but nope he didn't. So for two months the internet hackers and idiots out there were having a go at their computer. So, here's what I did to try and fix it. I got rid of norton (which everyone should do), I installed AVG, Spybot, and ZoneAlarm. AVG and SpyBot picked up thousands of corrupted files and I had them "fix" them (notice the quotes). After all the files were "fixed" I started up the computer and up comes two error messages saying that two dll files are missing, not a surprise there. But I keep going and everything seems to be ok except that the tea timer kept going off, it annoyed me so bad I just uninstalled SpyBot, but AVG has spyware removal stuff to so it's all ok. So, now when I get on the internet it works fine for going to different sites, but if I for example type something into the google search it gives me a nasty pop up and a pop up from AVG comes up and it won't let google get me the information. So, I told them to back it all up. They got an external hard drive and I started backing stuff up. After two hours of copying files I was finally done. I did an AVG scan just to be safe, but I was sure there wouldn't be any files corrupted. Oh was I wrong, about 70,000 files wrong. One of the folders had no files in it that I could see even when I selected to see hidden files. The folder wouldn't delete and every time AVG tried to remove it it would crash. So their are like 3 GB of data that don't appear without AVG and they don't erase and can't be cleaned out by AVG. HELP!!!! What do I do? Sniper says format everything. Please Please Please tell me I don't have to. I've already spent about 5 hours on this and I really don't feel like another five. Any idea's on whats going on? Oh by the way all the phantom files that won't delete are all .avi files. HELP!!!!
__________________
JDW
jdog44@gmail.com
5/18/2008 22:56 Link - Ip: Logged - Quote:
byerspc
Admin
avataren

 

Location: South Bend, IN
Registered: 4/14/2006      Warnings: 0
You need to format. once you get infected you pretty much have to start over. It really doesn't matter what you use to do the cleanup you may not be able to remove it all until you reformat. This is because the virus/worm/spyware stuff can embed themselves so much into your system you won't be able to clean. Antivirus/spyare software can prevent pretty well but they stink at cleanup. A good virus will rename itself in such away that it will appear to a scanner that it is part of the OS and then when the coast is clear...it will come out again.
If they are .avi...that could just be an extension they put on..doesn't really mean they are avi..they could be .exe but renamed etc.

The danger is if you backed up "everything" you may have backed up the virus to so I would be very careful with plugging that external into any other machine.

You can always plug it into a linux box or mac box to view the files...chances are they will be immune to any of the attacks.
__________________
byerspc
byerspc@gmail.com
5/19/2008 10:41 Link - Ip: Logged - Quote:
JDOG
Member


 

Location: 
Registered: 8/7/2006      Warnings: 0
So I should format the back up drive, reback up the good files that aren't infected. Leave the infected ones alone and format the hard drive?
__________________
JDW
jdog44@gmail.com
5/19/2008 13:01 Link - Ip: Logged - Quote:
byerspc
Admin
avataren

 

Location: South Bend, IN
Registered: 4/14/2006      Warnings: 0
that is probably the route I would go. You just want to be very careful when copying the data off etc and don't attach that drive to any machine that doesn't have a good up to data antivirus installed and you should be ok.
That way you know when you reformat the main drive you have gotten rid of everything etc. Then make sure they use firefox and have good antivirus :-)

This is the route most places like Best Buy ...staples etc. will take when you have viruses/spyware just because it is so hard to know for sure that you have removed everything once it is embedded...many times when you do the removal you remove "system" files as well anyway.
__________________
byerspc
byerspc@gmail.com
5/19/2008 13:08 Link - Ip: Logged - Quote:
JDOG
Member


 

Location: 
Registered: 8/7/2006      Warnings: 0
K thanks. Any help in trying to explain basic computer skills to them? j/k lol
__________________
JDW
jdog44@gmail.com
5/20/2008 06:53 Link - Ip: Logged - Quote:
tr
Admin
avataren

 

Location: 
Registered: 4/11/2006      Warnings: 0
that is still an untamed animal. we each have to approach that one differently. we wish you good fortune in your endeavors.
__________________
peace and java
5/20/2008 07:58 Link - Ip: Logged - Quote:
JDOG
Member


 

Location: 
Registered: 8/7/2006      Warnings: 0
Lol k thanks, that is one reality you learn anew every time you do this.
__________________
JDW
jdog44@gmail.com
5/21/2008 08:25 Link - Ip: Logged - Quote:
byerspc
Admin
avataren

 

Location: South Bend, IN
Registered: 4/14/2006      Warnings: 0
you could always install ubuntu and walk away..just make sure you are the only one that knows the root password..chances are no body would really be able to mess that up :-)
__________________
byerspc
byerspc@gmail.com
5/21/2008 09:01 Link - Ip: Logged - Quote:
tr
Admin
avataren

 

Location: 
Registered: 4/11/2006      Warnings: 0
i just got the latest cd yesterday. . .let me know if you need to borrow it.
__________________
peace and java
5/21/2008 09:49 Link - Ip: Logged - Quote:
JDOG
Member


 

Location: 
Registered: 8/7/2006      Warnings: 0
So, I fixed the computer and for some reason a notepad document pops up everytime someone logs onto their account and it says this:

[.ShellClassInfo]
LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21787

Any ideas what it is and how to stop it from popping up?
__________________
JDW
jdog44@gmail.com
6/8/2008 18:48 Link - Ip: Logged - Quote:
byerspc
Admin
avataren

 

Location: South Bend, IN
Registered: 4/14/2006      Warnings: 0
did you do a goole search?

Looks like an expected binary is not installed on the machine or a wrong version or something. If you install spybot you may be able to figure out what is being loaded at login that is causing it and just turn that part off. msconfig will let you do that too probably.
__________________
byerspc
byerspc@gmail.com
6/8/2008 21:41 Link - Ip: Logged - Quote:
JDOG
Member


 

Location: 
Registered: 8/7/2006      Warnings: 0
K I'll have to google it. I already looked into the start up but maybe I just missed it.

And my little bro got a new computer and he of course wanted a state of the arts graphics card. He got a dell computer and the graphics card needs power to run it's fan, this card is huge (512 DDR3 etc...). But dell of course doesn't allow for expansion and doesn't have any regular power supply cords but just enough for the board, processor and three for SATA devices only. This video card came with a cord that of course needs an older power supply attachement. I see a ton of the white power supply heads (don't know what they are called) to the new SATA power supply heads but none the other way around. Has anyone ever seen anything like that? I don't really want to install a new power supply but I might have to.
__________________
JDW
jdog44@gmail.com
6/10/2008 09:12 Link - Ip: Logged - Quote:
Forum start > miscellaneous > misc support > A quandry to stumble any computer nerd

Quick reply
You need to login before you can post.


Powered by ASPBB v0.5.2
© 2004-2006 ASPBB Developers team