[HOME]

Trojans everywhere - IE working in Background

Just recently I was called to clean out someone's computer. It seemed to be very slow. I checked in the background using the Task Manager, found by right-clicking on the Taskbar and simply choosing Task Manager in the resulting menu.

One thing I noticed was that Internet Explorer was running in the background, closing it only resulted in another instance opening, a sure sign of an infection.

They already had AVG Antivirus running and updated, but still the system was hijacked. Makes you wonder....why bother, sometimes.

I decided to restart the computer in Safe Mode and run three small scanners that I have had success with before.

  • SDFix.exe - www.bleepingcomputer.com/files/sdfix.php

    Full instructions are here: www.bleepingcomputer.com/forums/topic131299.html

  • SmitFraudFix - http://siri.geekstogo.com/SmitfraudFix.php

    Site includes instructions for use.

  • vundofix - www.softpedia.com/get/Antivirus/VundoFix.shtml

    Instructions on download site.

    SafeMode - http://bertk.mvps.org/html/safemode.html

    Just to be sure I decided, again in Safe Mode, I decided to run a full Anti-Virus scan using Trend Micro scanner - see my previous post -
    www.geocities.com/terryhollett2003/2928.htm

    It seemed to clear things up since when the computer started up normally it seemed more responsive and faster. But he also was concerned about Hard Drive space. He thought this was the problem at first, so I also decided to help him clean some stuff of his drive,

    Cleaning Hardrive

  • cleanmgr - Windows has a built in cleaner that can be accessed by Clicking on Start then Run - type in cleanmgr then hit enter

    In the Files to delete: box, it's recommended to select all options and then OK. You'll notice another tab listed as More Options. Here you can uninstall Windows components, uninstall unused programs and delete all old System Restore points.

    (note: You can get to the cleanmgr by going to My Computer, find your hard drive, usually (C:), Right-Click on it, chose Properties and on the first tab named General click on the Disk Cleanup button.

    Otherwise, some people would rather use other programs to do the job.

  • ccleaner - www.ccleaner.com
  • cleaup - www.stevengould.org/software/cleanup
  • delindex.bat - : www.burzurq.com/forum/delindex.html

    delindex.bat - For Windows ME and earlier(NOT WINXP). Just copy it to your hardrive, if you have WIN98 just restart in MSDOS mode or you may have to use a boot or starup disk for WinME. Run thr program then by simply typing delindex. It cleans out old temp files,cookies, etc. For Win95, Win98, Win98SE, WinME - NOT for WinXP. This was my main cleaner when I had WinME until I upgraded to WinXP.

    (note: The other two programs mentioned both still will work on earlier versions of Windows)

    Missing Extensions

    After cleaning out they had one more problem, they sent some attachments with their resume but the company receiving their resume couldn't open the attachment. They suggested a different template....Had no idea what they meant by that...

    I found the folder with the attachments in and noticed they had no extensions on them. To scan documents that you can open up in a word processor you need OCR - Optical character recognition software. Otherwise your just stuck with a picture.

    In this case, they where pictures .JPG format. I wouldn't want to do to much business with a company whos' computers couldn't open a simple JPG format picture. But I think it was the lack of extensions on the end of the image name that was the problem. So I clicked on a file, pushed F2 on the keyboard and put .jpg at the end of the file. Repeated for each other file there. (note: If your computer is set up Not to show extensions then usually you don't have to worry about renaming them).

    ask-leo.com/how_do_i_know_which_program_is_used_to_open_a_particular_type_of_file.html

    Cyclic Redundancy Check

    My Uncle recently made a DVD movie (a sing-a-long actually) and recorded it on camera. Then he got someone to transfer to a DVD for him. I don't have the setup to do such work. But I do have a DVD to make copies after. 25 to be exact.

    When I tried to copy it I keep getting errors. Basically, it wasn't going to happen. (It wouldn't work in my DVD player either) So I tried to copy it to my computer's hard drive and make copies from there. Still couldn't do it. kept getting the following error:

    Cannot Copy VTS_01_1: Data error (cyclic redundancy check)

  • An internet search gave a few possibilities:

  • Burned to fast
  • Poorly burnt CDs/DVDs - severe buffer underuns
  • Hardware problems

    Solution:

    I found a program called CDCheck -
    www.softwarepatch.com/software/cdrecovery-security.html

    Download, Install, Open, click on the D: drive (or whatever your CD/DVD drive is) and click on the Recover button at the top. Chose where you want to save the recovered file(s) when requested.

    It took 40 minutes on my system (P2-400MHz, 192MB RAM). But in the end I had a new set of files that I burned of onto a new DVD.