<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re:  Cleaning mom&#x27;s machine remotely in Security</title>
<link>http://www.dslreports.com/forum/r20206552</link>
<description></description>
<language>en</language>
<pubDate>Fri, 25 Jul 2008 14:10:51 EDT</pubDate>
<lastBuildDate>Fri, 25 Jul 2008 14:10:51 EDT</lastBuildDate>

<item>
<title>Re:  Cleaning mom&#x27;s machine remotely</title>
<link>http://www.dslreports.com/forum/remark,20227927</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : If you did not get it all cleaned off..best to look at this thread..my guess is that she still has more crap that came with that download.<br><br>Please Help! Msn Virus! <br><br>------------------------------------------------------------<br><br>The other day when I was on MSN messenger I got a virus from a contact. It's blocking certain sites and slowing down the computer. I did a McAfee search and nothing has come up. It disabled task manager and registry edit for me also. Here's the HTJ log:<br>&raquo;<A HREF="http://www.techsupportforum.com/security-center/hijackthis-log-help/134635-please-help-msn-virus.html" >www.techsupportforum.com/securit&middot;&middot;&middot;rus.html</A><br><br>F3 - REG:win.ini: load=C:\WINDOWS\system32\jwsgmvkbz\winlogon.exe<br>F3 - REG:win.ini: run=C:\WINDOWS\system32\jwsgmvkbz\winlogon.exe<br>F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,igxxgpb.exe<br><small>--<br>Gladiator Security Forum  &raquo;<A HREF="http://www.gladiator-antivirus.com/" >www.gladiator-antivirus.com/</A> Missing Kids &raquo;<A HREF="http://www.missingkids.com/" >www.missingkids.com/</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20227927</guid>
<pubDate>Wed, 26 Mar 2008 11:10:14 EDT</pubDate>
</item>

<item>
<title>Re:  Cleaning mom&#x27;s machine remotely</title>
<link>http://www.dslreports.com/forum/remark,20227820</link>
<description><![CDATA[<A HREF="/useremail/u/272914"><b>ccarlin</b></A> : Just went with the BartPE CD method.  I created one sent it to her and had her boot up with it then just walked her thru (painfully slow) editing the registry entry.  I have no idea what virus it was other than it came via MSN and attached to winlogon via the registry.  It opens a port thru the MS firewall as well.  ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20227820</guid>
<pubDate>Wed, 26 Mar 2008 10:48:24 EDT</pubDate>
</item>

<item>
<title>Re:  Cleaning mom&#x27;s machine remotely</title>
<link>http://www.dslreports.com/forum/remark,20216860</link>
<description><![CDATA[<A HREF="/useremail/u/1215698"><b>mikenolan7</b></A> : If you really don't want to have her wipe the machine, there might be an easier path than talking her through BartPE.  There is an O'Reilly book called "Knoppix Hacks" that comes with a Knoppix boot CD inside the back cover.  Inside are step by step instructions on how to set up an SSH server in Knoppix (which only requires a few mouse clicks).  There are also instructions on how to download and install chntpw once you are running Knoppix.<br><br>She could boot the disk, make a few mouseclicks, and set up the server.  You could connect remotely, download and install chntpw and edit the registry with that.  I have seen the book at Fry's, or you could order it from any technical bookshop with next day delivery.  The price is $35.  There are two editions out, I have purchased both, and they have been well worth the investment.  The first edition included a boot CD, the second edition includes a boot DVD, so make sure she has a DVD reader before she gets a second edition.  Of course, if you are familiar with Knoppix, you could do the same without spending $35.<br><br>Chntpw is very powerful software, if you go that way, do be careful.   :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20216860</guid>
<pubDate>Mon, 24 Mar 2008 12:34:47 EDT</pubDate>
</item>

<item>
<title>Re:  Cleaning mom&#x27;s machine remotely</title>
<link>http://www.dslreports.com/forum/remark,20216474</link>
<description><![CDATA[<A HREF="/useremail/u/668609"><b>EGeezer</b></A> : Just out of curiosity, what virus(es) did she pick up? I had a friend with a recent infection that his SAV didn't pick up, it turned out to be a dropper and a bot/rootkit. I recommended a scratch and reload.  <br><small>--<br>Mayors of New York come from nowhere and go nowhere.<br>Wallace Sayre (apparently, so do governors... )</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20216474</guid>
<pubDate>Mon, 24 Mar 2008 11:21:17 EDT</pubDate>
</item>

<item>
<title>Re:  Cleaning mom&#x27;s machine remotely</title>
<link>http://www.dslreports.com/forum/remark,20216413</link>
<description><![CDATA[<A HREF="/useremail/u/272914"><b>ccarlin</b></A> : AVG Free Edition]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20216413</guid>
<pubDate>Mon, 24 Mar 2008 11:09:04 EDT</pubDate>
</item>

<item>
<title>Re:  Cleaning mom&#x27;s machine remotely</title>
<link>http://www.dslreports.com/forum/remark,20216382</link>
<description><![CDATA[<A HREF="/useremail/u/1303852"><b>zteardrop</b></A> : <div class="bquote"><small>said by  ccarlin <A HREF="/useremail/u/272914"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Well her antivirus picked it up eventually took a few days for the sig to get it.  But the cure was worse then the disease it removed the file but left the entry in the registry in the userinit key.  So now when she starts the machine it just logs on then logs back off again. </div>Which antivirus is she using ?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20216382</guid>
<pubDate>Mon, 24 Mar 2008 11:03:10 EDT</pubDate>
</item>

<item>
<title>Re:  Cleaning mom&#x27;s machine remotely</title>
<link>http://www.dslreports.com/forum/remark,20215917</link>
<description><![CDATA[<A HREF="/useremail/u/272914"><b>ccarlin</b></A> : Well her antivirus picked it up eventually took a few days for the sig to get it.  But the cure was worse then the disease it removed the file but left the entry in the registry in the userinit key.  So now when she starts the machine it just logs on then logs back off again.  So the only way to fix this is to edit the registry off-line.  I tried a Hiren's Boot CD but just couldn't get the registry editor to load.  So may next attempt will be getting her a BartPE cd with a registry editor on it.  <br><br>My sister got the same virus (from my mom) and I was able to walk her thru booting to a linux boot cd and renaming the file and copying the userinit.exe to the virus file name and rebooted and cleaned up successfully.  <br><br>I don't know much about the BartPE stuff but I am hoping if I build the CD from my machine (using my windows image) and send it to her she can use it on her machine.  Can anyone confirm this?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20215917</guid>
<pubDate>Mon, 24 Mar 2008 09:11:12 EDT</pubDate>
</item>

<item>
<title>Re:  Cleaning mom&#x27;s machine remotely</title>
<link>http://www.dslreports.com/forum/remark,20206552</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : since she got it via MSN then most likely these are the things you are looking for on those types of exploits..and the links will show you how other found then and cleared the problem.<br><br>&raquo;<A HREF="http://blogs.msdn.com/matt_pietrek/archive/2006/01/03/508862.aspx" >blogs.msdn.com/matt_pietrek/arch&middot;&middot;&middot;862.aspx</A><br><br>&raquo;<A HREF="http://forums.spybot.info/archive/index.php/t-6621.html" >forums.spybot.info/archive/index&middot;&middot;&middot;621.html</A><br><br>&raquo;<A HREF="http://www.castlecops.com/t144656-wmf_exploit_caused_winlogon_memory_leak.html" >www.castlecops.com/t144656-wmf_e&middot;&middot;&middot;eak.html</A><br><small>--<br>Gladiator Security Forum  &raquo;<A HREF="http://www.gladiator-antivirus.com/" >www.gladiator-antivirus.com/</A> <br>Missing Kids<br> &raquo;<A HREF="http://www.missingkids.com/" >www.missingkids.com/</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20206552</guid>
<pubDate>Sat, 22 Mar 2008 09:20:01 EDT</pubDate>
</item>

<item>
<title>Re:  Cleaning mom&#x27;s machine remotely</title>
<link>http://www.dslreports.com/forum/remark,20206527</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : Does she know the name of the exploit ? That would help. You need safe mode and some tools that will find it and kill it on the next reboot.<br><small>--<br>Gladiator Security Forum  &raquo;<A HREF="http://www.gladiator-antivirus.com/" >www.gladiator-antivirus.com/</A> Missing Kids &raquo;<A HREF="http://www.missingkids.com/" >www.missingkids.com/</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20206527</guid>
<pubDate>Sat, 22 Mar 2008 09:11:49 EDT</pubDate>
</item>

<item>
<title>Re:  Cleaning mom&#x27;s machine remotely</title>
<link>http://www.dslreports.com/forum/remark,20206441</link>
<description><![CDATA[<A HREF="/useremail/u/1181920"><b>trickyrick</b></A> : Try getting her to boot into safe mode with networking and see if LMI Rescue can get you in...]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20206441</guid>
<pubDate>Sat, 22 Mar 2008 08:23:45 EDT</pubDate>
</item>

<item>
<title>Re:  Cleaning mom&#x27;s machine remotely</title>
<link>http://www.dslreports.com/forum/remark,20205853</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : In the past, I have just located the file and renamed it (like add xxx to end of name, progxxx.exe)<br>Then reboot, the program will not be found and will be unable to start. Windows usually just bypasses anything it doesn't find at startup. Then delete it. Works most of the time for me. <br>You can probably walk mom through this on the phone. Just explore to the file, right click and rename it. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20205853</guid>
<pubDate>Sat, 22 Mar 2008 00:41:51 EDT</pubDate>
</item>

<item>
<title> Cleaning mom&#x27;s machine remotely</title>
<link>http://www.dslreports.com/forum/remark,20205624</link>
<description><![CDATA[<A HREF="/useremail/u/272914"><b>ccarlin</b></A> : So no anti-virus software will detect or remove the annoying virus she picked up thru MSN.  One of those stupid click here and she ran some com file.  <br><br>Basically the Winlogon/Userinit key has a file added to it.  How can I remotely kill the process (it is attached to winlogon) and then remove the key/file.  The file is locked by winlogon (tried several unlock programs didn't work).  And of course removing the key just gets it rewritten by the program over and over again.  If the machine was here I am sure I could just boot to safe mode, or to a live linux cd or hell even DOS and just nuke the file, but I am going thru logmeinrescue to try and clean this.<br><br>Any suggestions (she lives several hundreds of miles away and is not very computer competent).]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20205624</guid>
<pubDate>Fri, 21 Mar 2008 23:43:24 EDT</pubDate>
</item>

</channel>
</rss>
