J
Jon Beckett
Hi all,
My father in law's new computer (XP Pro) has a virus on it, and it
appears to have had a real go at the operating system - meaning they
cannot boot up (it gets as far as the user profile selection screen,
then reboots when you choose a profile).
I haven't been able to visit them yet, but I have talked the most tech
savvy member of the house through trying to manually remove any worm
type virus - unsuccessfully so far. For informational purposes, they
had AVG Antivirus and ZoneAlarm installed, with a Speedtouch ADSL
modem.
Before the reboot issue started happening, they did manage to run AVG
and it reported the existence of a variant of the "AGOBOT" virus.
I talked them through getting into safe mode, but unfortunately AVG
Antivirus will not run (either it's been attacked or will not run in
safe mode). I then got them to take me through the contents of the
"windows/currentversion/run" branch in the registry - and removed
anything that sounded suspicious.
The machine is still not getting any further than the profile
selection screen - so I'm guessing the virus has hijacked one of the
other programs on the machine.
The catch 22 they face at the moment is that they cannot download a
fix until they can get back into "normal" Windows.
I'm wondering if the easiest way to solve this one is to burn a copy
of F-PROT to disk and take it round with me... and
remove/clean/re-install AVG - then find out what they might have done
that opened the doors to the AGOBOT virus...
Anybody else got any further ideas?
Jonathan
Jonathan Beckett ([email protected])
working on : http://www.pluggedout.com/penpals
My father in law's new computer (XP Pro) has a virus on it, and it
appears to have had a real go at the operating system - meaning they
cannot boot up (it gets as far as the user profile selection screen,
then reboots when you choose a profile).
I haven't been able to visit them yet, but I have talked the most tech
savvy member of the house through trying to manually remove any worm
type virus - unsuccessfully so far. For informational purposes, they
had AVG Antivirus and ZoneAlarm installed, with a Speedtouch ADSL
modem.
Before the reboot issue started happening, they did manage to run AVG
and it reported the existence of a variant of the "AGOBOT" virus.
I talked them through getting into safe mode, but unfortunately AVG
Antivirus will not run (either it's been attacked or will not run in
safe mode). I then got them to take me through the contents of the
"windows/currentversion/run" branch in the registry - and removed
anything that sounded suspicious.
The machine is still not getting any further than the profile
selection screen - so I'm guessing the virus has hijacked one of the
other programs on the machine.
The catch 22 they face at the moment is that they cannot download a
fix until they can get back into "normal" Windows.
I'm wondering if the easiest way to solve this one is to burn a copy
of F-PROT to disk and take it round with me... and
remove/clean/re-install AVG - then find out what they might have done
that opened the doors to the AGOBOT virus...
Anybody else got any further ideas?
Jonathan
Jonathan Beckett ([email protected])
working on : http://www.pluggedout.com/penpals