Recommended Posts

I offered to fix one of my teacher's daughter's laptops and she has this virus (don't worry link is safe): http://blog.yoocare.com/computer-locked-by-fbi-moneypak-virus-asking-to-pay-200-fine-to-unlock/

Along with a ton of other viruses/malware/crapware/etc. She is running Windows 7 and has a ton of personal data on it (so she says). I'm doing the job tomorrow. I'm here to tell my plan of attack and take suggestions.

1. I'm going to boot into safe mode with networking and remove those registry entries as shown in the tutorial in the link above.

--I'll take 2 Advil before doing this... :argh:

2. I'm going to remove the crapware

--So I can get some f***ing work done. It's slowing down her machine and clogging up the computer. I will use:

* Revo Uninstaller

* CCleaner

3. Go ham on the malware

- Get all the other crap off. I will use:

* Malwarebytes

* Spybot

* Install MSE when all is said and done. (It's my antivirus of choice)

4. General System maintenance

* Update Drivers

* Update Programs

* Do Windows Updates

What Do ya think?

your post title makes no sense. you havent seen any viruses yet except the fbi scam one, that doesnt mean there are lots of them. I was expecting a screenshot with a massive number of alerts.

ugh.... find a decent spare system.... scan the files all of them..make sure the client's files (music,movies,pics,docs) are clean.. then if the files are clean backup the important ones only... then.... nuke the install and start fresh.

Kaspersky Emergency Boot Disk is your friend, will rid you of boot viruses, and most likely many more (had to tackle one recently).

http://support.kaspe...uses/rescuedisk

You could always backup all the important files and put on a fresh copy of Win 7. Extract the key beforehand obviously.

Might be quicker and less of a headache that way.

This isn't a corporate machine with a nice image of everything, it's a home PC. That's a last resort.

As I've said before in other places...do the job right, don't just wipe and install. That's a waste of your time, and their time.

Shane you're wrong... it may take 10 or more hours to clean it, when a fresh install is just under 1 hour on even a very very slow system. I'd rather do that.

To remove this crap use OTL, post logs on their forum or Bleeping Computer forum, they will make script for OTL and remove this crap. On so heavy infected machine it is extreme difficult to get rid malware completely using only scanners on demand . OTL is best solution ;)

Kaspersky Emergency Boot Disk is your friend, will rid you of boot viruses, and most likely many more (had to tackle one recently).

http://support.kaspe...uses/rescuedisk

+1. Had to fix someones computer with a similar virus the other day (without wiping it), nothing would work in standard boot and attempting to boot safe mode of any kind just caused a reboot loop. Kaspersky Emergency Boot Disk cleaned the worst of it off.

If time is of the essence; a backup of user data and a wipe is the way to go.

I can re-install Windows and most of the apps they use in less time to clean it. Difference is that with a re-install I know that the machine is 100% clean.

I also create an image of their C:\ drive with gimagex just in case they find something missing once I return the PC to the user.

To remove this crap use OTL, post logs on their forum or Bleeping Computer forum, they will make script for OTL and remove this crap. On so heavy infected machine it is extreme difficult to get rid malware completely using only scanners on demand . OTL is best solution ;)

what is OTL, I google it and I get a bunch of different crap

I've been hearing people mention it a few times lately yet i have no idea what it is

If a system is heavily infected i would always recommend backing up important files then doing a full reinstall. Salvaging the current installation may sound like a good plan but truthfully, it'll only result in more grief long term.

your post title makes no sense. you havent seen any viruses yet except the fbi scam one, that doesnt mean there are lots of them. I was expecting a screenshot with a massive number of alerts.

I have never seen a more infected computer in my life---it means I have never seen a computer this dirty. :p It's an attention grabber.

Shane you're wrong... it may take 10 or more hours to clean it, when a fresh install is just under 1 hour on even a very very slow system. I'd rather do that.

I was thinking about grabbing all her stuff with a Kubuntu live CD and pushing f11 or whatever it is to restore from the recovery partition. I just invited him to my house so I'll have more time to play with it. He was just going to bring it on campus.

Teach her a lesson -- wipe it clean and Install Windows 8 !

LOL! I was just thinking that.

I'd boot from a Linux Live CD/USB and delete the "App Data/ Temp" and "App Data/Microsoft/Windows/ Temporary Internet" files as well. While in the live disc you can also delete some of those pesky copy.exe and Bron.tok.xxx files that may be distributed in the documents, pictures and music folders. Also booting in safe mode and running combofix may be helpful but be careful using that one.

Shane you're wrong... it may take 10 or more hours to clean it, when a fresh install is just under 1 hour on even a very very slow system. I'd rather do that.

10 hours? What in the world are you doing with these systems?

I recently had a system that I worked on for a client. It had 6 drives with a total of around 4TB worth of storage that was mostly used. Someone had been doing some naughty things on that system.

It had a rootkit, and several other infections. I had the system clean and back in the clients hands within 3 hours...

What would you be doing that takes 10 hours? I've never had a single system clean take me more than about 4 hours...the one above was one of the longest clean jobs I've ever had.

what is OTL, I google it and I get a bunch of different crap

I've been hearing people mention it a few times lately yet i have no idea what it is

It is small app which list all files, registry entries, apps etc. in Your system, skilled guy will find malware entries, prepare script, User need to Ctr. C Ctrl. V this script into OTL window and confirm, OTL will do rest, after this You will get new log, You need to show this again on forum, if something stays in system You will get new script. It is 100% safe, OTL is used instead Combofix, CBfix is danger and suppose be used only if there is no other way to clean system.

Scripts for OTL and Combofix suppose be created by User with experience in system security, otherwise system can be damaged. :)

She's a 13 year old girl. 'nuff said.

Ah. I hadn't realized she was 13. I'm not saying that being a girl makes a difference (it doesn't), but at 13 oftentimes you haven't had the time to figure out how to work on these things as effectively.

That's just a matter of practice. :)

  • Like 2
This topic is now closed to further replies.
  • Posts

    • Stop asking people that. It's a "No True Scotsman" argument in that you are attempting to discredit the opinions of a person by Attacking the Messenger. The reason that these are logical fallacies is the TRUTH is based on facts as supported by evidence. Nothing else. So, always debate the facts with evidence to reach the truth. Once you learn to do this, you'll be able to recognize when people are fearmongering and lying to you for their own selfish ends.
    • It doesn't matter if you didn't directly hear it from person X or Y. Every one of your statements comes straight from the racist, skinhead, anti-immigrant, be afraid of everything, "they are all taking our jobs", etc. etc. mouthpieces. That's where Farag and Putin heard it from too...and used it against the UK. So, while you keep disavowing the people who publicly peddled that position, you keep proving over and over again that those lies influenced you into being tricked when the Brexit vote came around too. In fact, your final sentence makes it crystal clear that it was the racist/anti-immigrant lies you fell and voted for, since you stated that you didn't have an issue with the economic trade issues with the EU. Ahem. To be clear, all of these LIES are EONS old, mate. They are the same fearmongering lies peddled to the same ignorant, gullible cowards by the same charlatans, snake-oil salesmen, and would be demagogues who've been doing this since caveman Ugh lied about his slightly different neighbor in order to steal his land. And, finally, you answered your own previous question. The reason that the EU isn't clamoring to bring the UK back is that they have had enough of people who would rather shoot themselves in the foot than get over their "insecurity issues". It's the same reason the entire world is moving away from the USA as fast as it can...
    • Onkyo Dolby Atmos AV receivers are really solid deals by Sayan Sen Recently we covered great deals on several soundbar models from the likes of Sony, JBL, Samsung and others for really good prices (the lowest in several months). Aside from that we also reported on the Edifier S3000MKII, a hi-fi two-way bookshelf monitor that's available for only $800. Today we bring a list of AV receivers from Onkyo that are available at great prices including the Onkyo NR7100, RZ30, and 8470 (purchase links under the specs table down below). The Onkyo TX-NR7100 and Onkyo TX-RZ30 are both 9.2-channel AV receivers designed for immersive home theater setups but they occupy slightly different tiers within Onkyo’s lineup with the RZ30 positioned as the more advanced model. The TX-NR7100 is a THX Certified 9.2-channel receiver offering up to 100 W per channel (8 ohms, 2 channels driven). It supports Dolby Atmos, DTS:X, and IMAX Enhanced formats, with flexible configurations such as 5.1.4 or 7.1.2 speaker layouts. A key highlight is its built-in Dirac Live Room Correction which should help optimize sound based on your room and its acoustics. In comparison, both models share several core capabilities though the RZ30 is geared toward enthusiasts seeking more precise calibration and system flexibility, while the NR7100 is positioned as a slightly more accessible, value-focused option with strong all-round performance. The technical specs of the RZ30 and NR7100 9.2 AVRs are given in the table below: Specification Onkyo TX-RZ30 Onkyo TX-NR7100 Power Output (FTC, 2ch driven) ~100 W/ch (8Ω, 20Hz–20kHz, 0.08% THD) 100 W/ch (8Ω, 20Hz–20kHz, 0.08% THD) Dynamic / Peak Power 9 × 170 W (6Ω, 1kHz, 1% THD, 1ch driven) 220 W/ch (6Ω, 1kHz, 10% THD, 1ch driven) Frequency Response 5 Hz – 100 kHz (+1/-3 dB) 10 Hz – 100 kHz (+1/-3 dB) THD 0.08% 0.08% Room Correction Dirac Live (full bandwidth) Dirac Live (with AccuReflex support) Immersive Audio Dolby Atmos, DTS:X, IMAX Enhanced Dolby Atmos, DTS:X, IMAX Enhanced Speaker Layout Support Up to 7.2.2 / 5.2.4 / 9.2 processing Up to 7.2.4 / 5.2.4 / 9.2 processing HDMI Inputs / Outputs 6 inputs / 2 outputs (eARC) 6 inputs / 2 outputs (Main + Sub/Zone 2) HDMI 2.1 Support 8K/60, 4K/120, VRR, ALLM, QFT, DSC, eARC 8K/60, 4K/120, VRR, ALLM, QFT, DSC, eARC Video Formats HDR10+, Dolby Vision, HDCP 2.3 HDR10+, Dolby Vision, HDCP 2.3 Streaming / Network Wi-Fi, AirPlay 2, Chromecast, Bluetooth, DTS Play-Fi Wi-Fi, AirPlay 2, Chromecast, Bluetooth, DTS Play-Fi Get them at the links below: Onkyo TX-RZ30 9.2-Channel AV Receiver: $797.00 (Sold and shipped by Electronic Expo) Onkyo TX-NR7100 9.2-Channel AV Receiver: $699.00 (Sold and shipped by Adorma) Onkyo TX-8470 2 Ch Stereo Receiver: $449.00 (Sold and Shipped by Adorma) Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links or authorized dealer links (at the time of article publishing); ensure that you purchase from such links only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
  • Recent Achievements

    • Week One Done
      flexorcist earned a badge
      Week One Done
    • One Month Later
      Woland13 earned a badge
      One Month Later
    • Week One Done
      Woland13 earned a badge
      Week One Done
    • One Year In
      bernmeister earned a badge
      One Year In
    • Week One Done
      Scoobystu earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      498
    2. 2
      +Edouard
      224
    3. 3
      PsYcHoKiLLa
      148
    4. 4
      Steven P.
      74
    5. 5
      FloatingFatMan
      69
  • Tell a friend

    Love Neowin? Tell a friend!