Problems in restoring the laptop after installing sp2

G

Guest

Hi, I have got a Fujitsu-Siemens laptop. The laptop comes with XP SP-1 CD.
Everything was fine after updating to sp2, until one day the laptop was
attacked by spyware as well as virus. I thought the simplest thing is to
reformat hard drive and reinstall windows xp. Yet, several strange things
still exist:
1. Even after re-format hard drive and re-install XP, the install program
never asked me to enter the CD key. (whereas before, it does ask for it.)

2. Even the CD only comes with XP SP-1, after completing the new
installation, there are always two-three folders created with folder names
with a combination of alfa-numeric name, such as 6fc7459b3f9cbee4, and with
sp2 as subfolder and the file update.exe as the only file under the folder.
The date for the file is always the same as the new installation date, and
the size is 267kb. If I do try to run the file, the error message is "Setup
could not find the update.ini file needed to update your system".

3. Continue with item 2. If I try to delete those folders with
Sp2/update.exe, the file is set as read only and always comes back with error
deleting file "Cannot delete update.exe: access is denied. Make sure the
disk is not full or write-protected and the file is not currently in use."
The only way I can remove it is to use safe mode as administrator, after
changing the administrator's access right to full control. However, after
doing that, I can't restart XP and it asks me to use recovery console.

4. Even though I have use Norton anti-virus to check virus including the
boot sector, I suspect the spyware somehow still exists. At times, even if I
just type the web address of www.hotmail.com, it will refer me to some
autosearch web site.

Can anyone please offer your help? I have spent two-three weeks and tried
various ways to solve the problems without success.
 
D

DL

A browser hi jack is usually the result of malaware, AV apps v.often do not
detect this type of infection

Below from an earlier post;

If you are using any version of Sun Java that is prior to JRE Version 5.0,
then you are strongly urged to remove any/all versions that are prior to
JRE/JSE
Version 5.0. There are vulnerabilities in them and they are actively being
exploited.
It is possible that is how you got infected with malware.

Therefore, it is highly suggested that if there are any prior versions of
Sun Java
to Version 5 on the PC that they be removed and Sun Java JRE/JSE Version 5.0
Update 7
be installed ASAP.

Simple check, look under...
C:\Program Files\Java

The only folder under that folder should be the latest version...

C:\Program Files\Java\jre1.5.0_07


http://www.java.com/en/download/manual.jsp



For non-viral malware...

Please download, install and update the following software...

* Ad-aware SE v1.06
http://www.lavasoft.de/
http://www.lavasoftusa.com/
http://www.lavasoft.de/ms/index.htm

* SpyBot Search and Destroy v1.4
http://security.kolla.de/
http://www.safer-networking.org/microsoft.en.html

* SuperAntiSpyware
http://www.superantispyware.com/superantispywarefreevspro.html

After the software is updated, I suggest scanning the system in Safe Mode.

I also suggest downloading, installing and updating BHODemon for any Browser
Helper Objects
that may be on the PC.

* BHODemon

http://www.majorgeeks.com/downloadget.php?id=3550&file=11&evp=245a87539eea8ed6904332b4b8b8442d

For viral malware...

* Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go
through your
FireWall to allow it to download the needed AV vendor related files.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in
Normal Mode.
This way all the components can be downloaded from each AV vendor's web
site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot
the PC.

You can choose to go to each menu item and just download the needed files or
you can
download the files and perform a scan in Normal Mode. Once you have
downloaded the files
needed for each scanner you want to use, you should reboot the PC into Safe
Mode [F8 key
during boot] and re-run the menu again and choose which scanner you want to
run in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal
Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more
comprehensive PDF help
file. http://www.ik-cs.com/multi-av.htm

Additional Instructions:
http://pcdid.com/Multi_AV.htm


* * * Please report back your results * * *
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top