Sunday, March 6, 2011

Virus issue

I don't often get involved in fixing PC problems, but recent jobs involved the same type of issue.  The PC starts to report serious errors, and show problems with boot sector and other critical areas of the disk.  It all looks rather real, and very worrying.  However, in both cases it was caused by a similar, but different Fake Anti Virus program.  I think if you continue there was an offer of the program to fix the issue - in exchange for some $$$s.

The approach I tooks was to remove the drive from the laptop and create an image for security purposes.  I then ran Norton which tracked down several viruses, and removed them.  This is where the two viruses behaved differently.

Virus one did not want to be removed by Norton and started each time the machine booted.  The problem was that a startup function  (go to msconfig) was launching the virus at startup each time.  By removing this start up line - and seeing the program it was starting (it had a randomly generated name) the PC was then OK.  The free AVG virus checker was added to the PC to try and prevent this happening again.  A report a few weeks after this event indicated that eveything has been OK.

Virus two was removed by Norton, but left the PC in a state where no program would actually launch from explorer.  Various 'Googled' ideas pointed to the registry, but this did not help.  Launching the command prompt was also very difficult and the start program launcher did not work.  A solution to this was rather unusual, but worked, and hence I am including it here.  Do Ctrl-Alt_Del and b ring up the task manager.  Under the top menu item 'File' thre is a run command.  This worked and a command window was opened.  It did not seem possible to change file attributes to make sure that a .exe was launched so evenually the PC was restored to a restore point from afew weeks earlier.  Everything then nearly worked.

On examining the PC there were issue with McAfee antivirus which was not running, and also 18 months of Vista updates had not been loaded - 90 patches althogether.  The 90 patches were installed, McAfee updated and this worked.  PC now all OK, but all automatic updating was set to 4am when the PC is normally turned off.  This was changed to a time when the PC was likely to be on and hopefully the problem will not arise again.

In both cases, no data was actually lost

No comments:

Post a Comment