View Single Post
  #22  
Old November 25th 09, 10:53 PM posted to microsoft.public.security.virus,microsoft.public.windowsxp.help_and_support,alt.privacy.spyware
Robin Bignall
external usenet poster
 
Posts: 595
Default Infection messages?

On Tue, 24 Nov 2009 17:25:31 -0600, "NT Canuck"
wrote:


"David H. Lipman" wrote in message
...


Thus we need to understand what security related software
already existed on this platform PRIOR to the posting of this problem.


To check if antimalware/tool running pre-desktop look into
control panel taskmanager and enable view hidden
tasks, then also download autoruns and check the 'run'
section.

A-squared contains "Hijackfree" that has an autoruns section plus a
lot of other stuff. I can't see anything running that shouldn't be
there.

Programs recently installed may still have their residue/setup
in documents and settings (logon profile) so look for /temp
folder (may be more than one location).

Nothing recently installed or uninstalled, except updates to Windows
and running software.

Also look at restore points (usually a new restore point
setup prior to installing a program).

Don't use restore, never have.

In control panel system uncheck the auto restart option
that will leave any shutdown message sit on the screen
instead of just blinking over it and rebooting.

This is already unchecked. Windows does not see these messages as
something to stop/reboot on.

Download and install PUI (program uninstall utility) that
will show programs installed in Windows..even the
kb and 'uninstallable' type entries from registry.
http://www.softpedia.com/progDownload/PUI-Download-24439.html

Just some tips, FYI.


Thanks. I should say two other things:
I ran MRT.EXE /f:y this afternoon. Zero problems reported.
On reboot, sometimes all of these 'infection' messages are simply not
there. Then, on another reboot, they're back again, sometimes a few,
sometimes screens full. Normally I hibernate overnight and only
reboot when something, like critical updates, forces me to.

(alt.privacy.spyware added because this is being discussed there,
too.)
--
Robin
(BrE)
Herts, England
Ads