PDA

View Full Version : Compromised system!


NFrancis
September 13th, 2006, 02:54 PM
Here we go.

My boss brought his home pc in this morning. It's so currently infected with something that it can no longer connect to the internet (from what he tell me), or at least, he can't recognize that it is. Browsers won't load any pages, can't connect his email server, etc.

I'm trying to install Norton 2006 on his box, but some other guy stuck him with eTrust AV. Norton will not install with it (or the MS Anti Spyware that's also there), and the virus is causing his box to auto-shutdown if I try to use add/remove programs to uninstall either.

I've followed some other instructions on removing registry keys and manually removing files related to eTrust, but I can't do anything with MS Anti Spyware. Even attempting to open the folder gets it immediately closed by the present virus(es). Attempting to add/remove through windows also causes the system to reboot.

Finally, even attempting to run Norton 2006, I have about one second to click the "install" option before the virus(es) kills the process.

I'm no PC technician or anything; he just uses the machine for surfing and email (and probably more nefarious things, considering how infected his box is). Does any of this sound familiar enough to anyone to provide any answers, or would it be easier to just tlak him into dropping $450 on a new box and calling it a day?

-Nate

Edit: I have successfully cleared eTrust. Still can't figure out how to clear out MS Anti Spyware.

leroys1000
September 13th, 2006, 03:16 PM
You should be able to set the BIOS to boot to CD and
boot to the norton antivirus CD.
If worse comes to worse,you don't have to dump the box.
Just reinstall windows on it.
Ask him if he has restore CD's,and if there is anything
on the computer he needs to save.

NFrancis
September 13th, 2006, 03:29 PM
Woo, I didn't know you could boot into Norton. I'll give that a try. However, won't I run into the same problem of Norton not running because MSAS is installed?

leroys1000
September 13th, 2006, 05:12 PM
You shouldn't,as the operating system is not loaded,
and the other software won't be running.