G
Guest
Running WinXP Pro SP2, all critical updates. User has managed to get it
infected with something that AV and 3 anti-spyware packages can't seem to
clean, at least not yet. Have cleaned up in safe mode, checked/cleaned some
registry locations, deleted files, looked in msconfig/startup for clues, etc,
etc. One AS reports CWS, but CWShredder doesn't find it. When start IE,
triggers the little bugger and AV starts reporting various .exe files
infected with W32/Startpage.ATH and W32/Agent.AIU. However, AV scan says box
is clean. There's also a red shield with an X in systray, tells me AV is bad
and system is infected with spyware. Looks like MS program but I don't trust
anything at this point. Have started working with AV vendor but their initial
suggestions didn't fix it. Other interesting note: system restore refuses to
restore to selected points, have tried multiple points both few weeks ago
(different problem) and this issue. Before I spend more time on phone with AV
support, wanted to see whether others thought I should just format/reload
given the situation (no disk image). All opinions welcome, humble or not.
infected with something that AV and 3 anti-spyware packages can't seem to
clean, at least not yet. Have cleaned up in safe mode, checked/cleaned some
registry locations, deleted files, looked in msconfig/startup for clues, etc,
etc. One AS reports CWS, but CWShredder doesn't find it. When start IE,
triggers the little bugger and AV starts reporting various .exe files
infected with W32/Startpage.ATH and W32/Agent.AIU. However, AV scan says box
is clean. There's also a red shield with an X in systray, tells me AV is bad
and system is infected with spyware. Looks like MS program but I don't trust
anything at this point. Have started working with AV vendor but their initial
suggestions didn't fix it. Other interesting note: system restore refuses to
restore to selected points, have tried multiple points both few weeks ago
(different problem) and this issue. Before I spend more time on phone with AV
support, wanted to see whether others thought I should just format/reload
given the situation (no disk image). All opinions welcome, humble or not.