I have run tools such as Adaware and Spybot, which cleaned several problems. Then I ran an online scan from Trend Micro, which found nothing, and I've run Trend Micro's damage template. My problem is that I still can't get antivirus software to install locally. Where do I go from here?
QUESTION POSED ON: 26 AUG 2004
QUESTION ANSWERED BY: Kevin Beaver
Without knowing more details of your problem, I don't think I'm going to be able to help. What errors are you getting? What's the OS? What AV software are you trying to install?
Member's response:
The person's system was reloaded to clear up all of the problems. The OS was XP Home Edition. The person had been using instant messenger, Blubster, Kazza and downloading so much bad stuff. The computer had not been protected while visiting sites that were questionable security risks. One thing that happened initially was that My Computer either would not work or would be just missing altogether.
I first ran Adaware, which detected about 500 problems, and then Spybot, which detected a number of others. Both updated, of course. The person had McAfee installed, but it was effectively out of commission. You would try to start the program and only part of the program would display. If you tried to connect to the Internet (broadband), a Winsock error occurred. I deleted a couple of the Winsock keys in the registry, removed and restored the network card and Internet functionality was restored. I had tried to install Nav and to reinstall McAfee, but the programs would not finish installing, they would just hang up.
Since I could now get on the Internet, I went to Trend Micro and did an online scan that found 12 instances of Backdoor Sandbox.A in the restore points on the PC, so I deleted these. No other virus activity was found to be present. I even ran the damage template assessment from Trend Micro and found nothing.
The PC had been restored to a point of usability now, since I could navigate through My Computer and get on the Internet, and the system did not freeze up now. But I was still not able to install Nav or McAfee.
Since this was a one-year-old Dell PC, I was going to try to install XP Home over of the current XP Home, but the person could not find their restore CD. Since this was a neighbor of my boss, and I no longer had possession of the PC, she did a format and complete reload from the restore CD. The owner's brother got a hold of the PC and in two days managed to render it useless again. The OS was reloaded (again), and all was well.
So, after all of that, my question remains. When you use spyware tools to remove spyware and run antivirus scans to check for virus activity (.dat files up to date, of course) and you still cannot install Nav or McAfee, where do you turn to figure out where your system has been compromised? And what course of action needs to be taken to fully return the system back to a healthy state short of a full reload?
Kevin's reply:
Short of calling the anti-virus vendors, I'd suggest backing up the system (use something like TrueImage by Acronis to another drive for best results) and just reload Windows and re-install the apps. Otherwise, I think you'll be spinning your wheels to oblivion.
|
 |
|