Windows Server - PC out of control, please help.
Asked By Sirius
12-Jul-07 08:16 PM
My friends PC keeps sending spam emails. We removed viruses, adware and
spyware with Norton, Spybot search and destroy, Xsoftspy. Firewall is on,
all up- to date. The spam does not goes out because Norton stops them, but
it just keeps trying to send them and the PC slows down to a halt. How do we
gain control back over it?
Thank you.
Windows Server
(1)
Windows Update
(1)
Windows Vista
(1)
Firewall
(1)
Premimum
(1)
Autoruns
(1)
Adaware
(1)
Spybot
(1)
John John replied...
You haven't removed all the pests on the computer. Use the Task Manager
or go to Microsoft.com and download Process Explorer and see if you can
identify the running processes that might be responsible.
John
Sirius replied...
I use Task Manager, but I do not know which process is the bad one.... How
can you tell.
John John replied...
You have to research the process names on the internet. Autoruns, which
can also be downloaded on the Microsoft site is another good utility
to help root out unwanted pests that are started when Windows is booted.
You may have to broaden your asrsenal of tools to find all the pests.
There is a resident virus/malware expert who regularly reads and posts
here, he should be by shortly to offer further help or advice. Try his
page and see if you can get a bit further along with your efforts:
http://www.claymania.com/removal-trojan-adware.html Also, these pests
are generally easier or may be easier to get rid of if you boot to
Safe-Mode.
John
Maximus the Mad replied...
Sirius aka anyone@some.net on 7/12/2007 at 8:16:22 PM in
microsoft.public.win2000.general<qvzli.18125$qu5.893@trndny02> after
much thought,came up with this jewel:
go through removal instructions below
max
--
Virus Removal http://www.freespaces.com/maxwachtel/removal.html
Keep Clean http://www.freespaces.com/maxwachtel/keepingclean.html
Tools http://www.freespaces.com/maxwachtel/tools.html
Change nomail.afraid.org to gmail.com to reply by e-mail.
Sirius replied...
Are you saying Norton is not very good? For the price they charger for
it....shame on them.
Maximus the Mad replied...
Sirius on 7/12/2007 at 10:53:22 PM in
microsoft.public.win2000.general<COBli.10316$lY4.3304@trndny07> after
much thought,came up with this jewel:
No,what I am saying is not all AVs find everything,sooooo,
go through removal instructions below
post back with results.
max
--
Virus Removal http://www.freespaces.com/maxwachtel/removal.html
Keep Clean http://www.freespaces.com/maxwachtel/keepingclean.html
Tools http://www.freespaces.com/maxwachtel/tools.html
Change nomail.afraid.org to gmail.com to reply by e-mail.
paulc replied...
If all else fails, it may be time to reformat. A real PITA but I've seen
some insidious malware be really good at cloaking itself and, what's more,
being buried in the registry so that it recreates itself upon startup even
if you do the service/executable.
Sirius replied...
I was thinking about it....
Sirius replied...
Thank you, much better.... However some corrupted files
happened I am not sure what to do about. If I do "repair installation", I
will lose the updates.
Maximus the Mad replied...
Sirius aka anyone@some.net on 7/13/2007 at 11:13:07 PM in
microsoft.public.win2000.general<7bXli.1163$fP4.318@trndny07> after
much thought,came up with this jewel:
What files are corrupted now?
What is the exact error message?
What problem are you experiencing now?
--
Virus Removal http://www.freespaces.com/maxwachtel/removal.html
Keep Clean http://www.freespaces.com/maxwachtel/keepingclean.html
Tools http://www.freespaces.com/maxwachtel/tools.html
Change nomail.afraid.org to gmail.com to reply by e-mail.
Sirius replied...
Problems with win update. .net framework update will either hang or say
"install failed" I assume windows update must be corrupted.....
Maximus the Mad replied...
Sirius aka anyone@some.net on 7/14/2007 at 10:55:53 AM in
microsoft.public.win2000.general<Zt5mi.2547$yx4.2476@trndny08> after
much thought,came up with this jewel:
What was the exact error message? What is the MSKB number of the update?
--
Virus Removal http://www.freespaces.com/maxwachtel/removal.html
Keep Clean http://www.freespaces.com/maxwachtel/keepingclean.html
Tools http://www.freespaces.com/maxwachtel/tools.html
Change nomail.afraid.org to gmail.com to reply by e-mail.
Sirius replied...
Kb886903. In installation history a red X.
Maximus the Mad replied...
Sirius on 7/14/2007 at 11:55:05 PM in
microsoft.public.win2000.general<tUgmi.2665$Wh4.2564@trndny06> after
much thought,came up with this jewel:
Try downloading the update from Microsoft Download Center instead of
using Windows Update.
--
Virus Removal http://www.freespaces.com/maxwachtel/removal.html
Keep Clean http://www.freespaces.com/maxwachtel/keepingclean.html
Tools http://www.freespaces.com/maxwachtel/tools.html
Change nomail.afraid.org to gmail.com to reply by e-mail.
Joan3741 replied...

This is a new one for me and may not address your issue but, being a "Newbie"
of sorts, I just received an error message while reading your post and its
driving me crazy because I've been getting spam, unwanted emails, and
everyday when I wake up to get on my system "Windows Vista Premimum ed." I
find my Firewall has been disabled. I'm not totaly ignorant regarding
computers but when I spoke to my ISP Tech the response regarding my firewall
was "I don't know why your firewall is turning itself off" I believe I'm
being "hacked"; Also, my ISP decided set up a pop 3 account" so my email
could be forwarded to that account. Only when I threatend to close my
account, was I abel to get through a technician. Previously no one ever got
back to me to let me know if my issues had been resolved so this a.m. I took
it upon myself to try and change the temp. password and user name for my
email account and was on the phone for abut an hour trying to get a new
password and user name and give the ISP back the temp passcode given the day
before. Needless to say I'm still having problems and am going banannas
trying to protect my system.
I apologize for this imposition in the middle of your problem but, I'm
desperate.
JR
DL replied...
So what anti virus are you using?
Have you run Adaware, SpyBot and Windows Defender - all of these?
Your ISP is not someone who would usually give advice on a windows problem,
or PC infection, though the more helpfull ones would usually have
information on their web sites about 'internet security'
Lastly you have posted to a win2k group, but you are using Vista?
Windows Update Windows XP (KB967715) Re-installs Every Time I Shu Windows Server Windows Update Windows XP (KB967715) re-installs on my Windows XP Pro SP3 plus latest updates machine every
Error connecting to the Windows Server Update Services database Windows Server I keep getting the error: Error connecting to the Windows Server Update Services database There was an error connecting to the Windows Server Update Services database. Either
New Product Windows Server I notice there is a new product listed under Windows (sub)category: Windows Server Manager - Windows Server Update Services (WSUS) Dynamic Installer Description: Windows Server Manager uses this category to find and download
Disconnecting Drive Maps over WAN Windows Server We currently have a remote office connected to our network via a T1 WAN. They have their own file server which they map to and they also map to a file server on our side via the WAN. When a user at the remote office launch Windows Explorer or My Computer the window will freeze for a couple of minutes and then display the drives. From testing, it seems that the drive mappings to our local server seem to be the issue. The drive mappings are timing out (disconnecting) after 15 minutes to reconnect. This issue seems to have started after recently running critical updates on our Windows 2003 server. I’m aware of the article on how to increase the auto disconnect time out
Dfs replication between Windows server 2003 R2 and Windows server Windows Server Every time I try to replicate a folder between a windows server 2003 SP1 and windows server 2003 R2 I have the fallowing error: \ servername (server which