[There's a reason that Yoda is the unofficial mascot of SBS.  Size indeed matters not.] I flattened a box tonight - THE OFFICIAL BLOG OF THE SBS DIVA
Tue, Apr 26 2005 22:56 bradley

I flattened a box tonight

It wasn't my workstation...but rather than of my hairdressers.  I was cleaning it up for her.  And even with Norton Antivirus and Microsoft's Antispyware I only  had about 3 minutes after bootup before 57 Internet Explorer Windows popped up ...mind you this was with the machine “not” on the Internet.  Oh and it had about.blank on there as well.  So what did I do with it?

I booted it long enough to get the necessary documents off [which fortunately didn' take that long] and then I booted it from a Windows XP cdrom, removed the partition, repartioned it and had it totally wipe the harddrive and reformat.  Now I'm putting programs back on.

Oh, and I'm doing something else too... I'm making the daughter and son's account into limited user mode and not giving them administrator rights.  You see that's how this computer got into this mess.  Even with Norton up to date... even though Microsoft antispyware was on the machine [which in fairness this was added later in a last ditch effort to clean the box, unfortunately it was unsuccessful], and even while I was getting the data off, the spyware cleaner was attempting to block stuff but it just couldn't do it. 

Now this system has XP sp2 on it with the firewall enabled and the auto updates turned on.  Antivirus is on, Anti Spyware is on.... and now I'm sending it back off to hopefully stay safe and secure.

Filed under:

# re: I flattened a box tonight

Wednesday, April 27, 2005 2:10 AM by bradley

Get ready for the calls from that distraut mother. Her kids have the power and she will suffer! And you will be the one getting the tech support phone call in the middle of ER one night.

# re: I flattened a box tonight

Wednesday, April 27, 2005 8:51 AM by bradley

Why will this be a problem if she only gives the kids limited access? I think that you read Susan's comment wrong. She is only giving the mother Administrative rights, not the kids.

Scott

# re: I flattened a box tonight

Wednesday, April 27, 2005 9:35 AM by bradley

Went through the same thing this weekend. Four PM til 1 AM straight trying to save it. Finally came down to deleting "Nail.exe" and finding the "Abetterinternet" culprit. Windows safe Mode and alotta luck. Almost as bad as Herpies from what I hear......

# re: I flattened a box tonight

Thursday, April 28, 2005 5:36 AM by bradley

The wonderful thing about Microsoft Anti-Spyware is that it will tell you the files names that you need to remove for About:Blank. Once you have those the removal process isn't too bad. We've been successfully removing it without having to flatten the boxes. Too bad that nothing seems to catch it before the infection occurs. :(

# re: I flattened a box tonight

Thursday, April 28, 2005 6:04 AM by bradley

That's the whole point Scott. Without admin rights, the kids can't do the things they WANT to do. Good luck with that one!

# Running as Non-Admin (LUA)

Thursday, May 05, 2005 7:24 AM by TrackBack

http://msmvps.com/bradley/archive/2005/04/26/44743.aspx
Susan says that her kids are running as LUA...

# Lots of LUA links

Friday, May 06, 2005 12:18 AM by TrackBack

I’ve added a bunch of new links to the non-admin wiki, taken from various blog posts over the past month....

# Lots of LUA links

Thursday, May 19, 2005 9:33 AM by TrackBack

[I originally posted this two weeks ago, but it got lost when they had to roll back the servers, and...