devi: (Default)
[personal profile] devi
So here I am, on a Monday morning, having been roped in to cure the Headmaster's computer, which seems very ill indeed. Alarmingly, I'm the most technical person in the whole GCSE department. And not having worked in IT for four years now (and even then it was often Linux boxes I worked on rather than PCs) I feel quite clueless.

Is anyone bored out there? Do you fancy casting your eyes over the list of symptoms and seeing what you think? There'll be pints in it for helpful people. (Or any professional proofing/editing you should need. Or a piece of calligraphy. Or whatever)


It's a Dell Dimension 2350 running Windows XP. It has 128 megs of RAM.

Firstly, it has slowed down from merely lazy to glacial in the course of the last week. It takes three or four minutes for icons to appear on the desktop.

Symantec LiveUpdate is blocked from downloading new updates, and suggests a virus may be causing any strange behaviour in application programs. It says to reinstall Norton, which is the first thing I'm going to try.

MSN (*spit*) won't let me refuse to sign in or close the sign-in window, or even minimise it.

IE: Many sites (eg Gmail) are refusing to accept sign-ins. My webmail page won't appear at all. Livejournal is OK, but it's in a minority. The address bar is acting oddly, refusing to accept any input till IE's been running for a few minutes.

No Works Word Processor files can be opened at all - "necessary files have been renamed, deleted or moved. Reinstall Works and restart." Headmaster claims he hasn't deleted or renamed anything (though he could be wrong).

I've scanned for spyware using Spybot, found four pieces of spyware and deleted them, which hasn't helped.

And oddest of all, the main Windows directory is full of folders, highlighted in blue, about 40 of the things, all called something like "$NtUninstallKB810217$" and containing a variety of bits and pieces, but most of them contain another folder called "spuninst". Again, he claims he hasn't uninstalled anything.

Do you know of a virus that behaves like this? Or could something else have gone wrong?

I'm tempted to just do a complete reinstall (because it's always been flaky), and put a firewall on it first thing I do. Headmaster would allow this in theory, though he says he wants to save some files first, but worries that if he mails them to another computer he'll infect that one too.

Any suggestions appreciated.


Edit: With the freaky shit. It's running Service Pack 1, I've increased the virtual memory and there was lots of free space on the disk. I've also persuaded the Head to buy some more memory, goddamnit. But I've just discovered, in the course of trying to burn a CD to save some of the files -

THIS MACHINE DOES NOT CUT AND PASTE.
IT DOES NOT DRAG AND DROP.

Nothing. Not text in Word, not files in My Computer. I've never seen anything like it.
Oh, and it says Windows Installer is not present, so I can't uninstall or reinstall anything at the moment. I presume there's a nice heavy-duty way of doing format c:// without going through Windows Installer? Oh please let there be.

Date: 2004-11-29 03:08 am (UTC)
From: [identity profile] thecesspit.livejournal.com
I am not an expert, but I think virii is the most likely. Let him take his files off, quaratine them and then scan the disc. If their bog standard office docs, you'll be able to pick up any infection. If the copy itself writes the virus out, you can pick that up too.

The Unisntall files look right to me after Windows Updates and the like. If you do reinstall, make sure you service pack it... WinXp and IE without the service packs is as buggy and insecure as a very insecure thing.

You might want to convince him to use firefox, as thats got far less holes than IE (and as it's less used, people try to exploit it less, so perhaps I shouldn't be trying to get people to use it...)

If you can get it, try AdAware and 'Hijack This!', and just trying a virus scan with Symantec as is?

Date: 2004-11-29 04:38 am (UTC)
From: [identity profile] bluedevi.livejournal.com
I'm going to reinstall Symantec this afternoon and see what happens. Thanks for the tips.

Expand Cut Tags

No cut tags

Profile

devi: (Default)
devi

Most Popular Tags

Style Credit

Page generated Dec. 26th, 2025 08:12 am
Powered by Dreamwidth Studios
June 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 2017