Re: My Pharmacist Friend Called Me Yesterday



Bitey wrote:
He said he had a lot of pop-ups coming into his third computer on the
network.  He has been on vacation in Alaska for about ten days and while
he was gone he had temp help (several pharmacists taking turns) from a
nearby hospital filling in for him. These pop-ups didn't start until after
he was gone. Uh huh.. Who's been looking at p0rn?  <hehehe>

Anyway, I didn't know all that so I figured he just needed to go to
Windows Update and download some patches and told him so.  He insisted I
come over to the store and take a look.  Knowing he is just about
computer illiterate I agreed to do that.

Hoo boy.. I could not get IE to even start up, the virus definitions were
a mere 352 days out-of-date and the spyware program he uses told me he was
LOADED with all kinds of goodies but froze when asked to remove them.  The
computer C R A W L E D, his 1GB of memory notwithstanding.  I could do
NOTHING with it! He asked me what I would do and I told him it would take
mucho sweat and tears to clean up that system so I would opt to scrub the
drive and start from scratch. I've never seen anything like that before. I
mean, nothing that was more fouled up and packed with not only spyware,
malware and at least one trojan - but probably several. The task manager
showed me most of what it had going on but wouldn't allow me to stop any
of the "services". I guess I could have gone into Safe Mode and tried a
few things there but DAAYAMMM, I would hate to have to do it on MY machine
much less one with pharmaceutical pricing data that needed to be saved,
and on a machine and OS (Windows 2000) that I was not familiar with.

He had the guy who originally set up the system go over there today and
the guy told him the same thing, scrub the drive.  It was THAT bad. I got
the shivers just thinking about it and right away decided I needed to run
a spyware and virus scan on my machine just as soon as I got home.
Everything turned up ~clean~, thank the gods. I WILL be paying more
attention to keeping the updates going after seeing what all can happen
without doing it.


For most of the nasty nasty ass hat viruses you have to go into safe mode and remove it that way. There is one ad ware i can think of that seizes the free ware program spybot seek and destroy. If you set it to ignore it ignores the damn C2 ad wares.


I am a firm believer in anything that can be done can be undone. I would have a talk with the idiot that infected my PC with ass hat viruses though and i would set that system up so it can only run databases software and thats it. there is some sort of shield program out there that hides the run prompt and hides the c drive as well. No other services will run if you do not set it to run. I have found no weaknesses in the program. I just wish i could remember the name of the program.

I also believe this guy needs to learn to back up his data frequently. prior to infection! perhaps this is now a lesson in computers he is willing to learn that you can teach him?

TSS
.



Relevant Pages

  • Re: Home Page
    ... I believe if I were in your shoes, I would run spy-bot and check mark all ... the errors ad ware and spyware that it finds and remove ALL of them. ...
    (microsoft.public.windowsxp.help_and_support)
  • FW: Spyware & AD Ware
    ... You can stop spy/adware on your firewall at the protocol level with snort ... Yesadvertising Banking Spyware INFORMATION SUBMIT"; ... Spyware and AD Ware are ms/windows problems. ... To unsubscribe, ...
    (freebsd-isp)
  • RE: Spyware & AD Ware
    ... Spyware and AD Ware are ms/windows problems. ... www.download.com has the most popular free downloads for removing ... To unsubscribe, ...
    (freebsd-isp)
  • [IBC] DO NOT (was: Re: [IBC] Great Informaton From Bonsai Experts)
    ... this link -- and my virus, spyware, ad ware, other-ware programs are all up to date. ...
    (rec.arts.bonsai)
  • Re: IE6 been hijacked
    ... tried using many tools to remove the spyware or whatever *ware it is but ... still I cant use IE to browse the Net. ... Windows XP Pro SP2 ...
    (microsoft.public.windows.inetexplorer.ie6.setup)