Hi Riva,

[pop-ups, aargh] Did I do the right thing?

If you're really paranoid, any compromised machine should have its data backed up and its OS reinstalled.

If you just want to clean it up, though:

1. Remove suspect program via "add/remove programs" list. Check in Explorer to make sure it hasn't left anything behind.

2. Go through the rest of the list and kill off anything else that looks suspicious. Google anything you're not sure about. If Kazaa is there, get rid of it and explain about BitTorrent.

3. If it's a 2000 or XP machine, have a look at the processes list in Task Manager and search for the names of any that aren't familiar. Follow removal instructions for anything you find.

4. If it's 98 or XP, run msconfig and check the startup list: if you don't know what an item is, disable it (you can always turn it back on later). If you're feeling geeky or you're running 2000, regedit HKEY_LOCAL_MACHINE > SOFTWARE > Microsoft > Windows > CurrentVersion > Run and check through there instead.

5. Update AV signatures and scan system. Check for spyware as well. Run disinfection tools from places like Sophos or Symantec if you find anything really nasty.

6. Run a registry cleanup. Norton Utilities does this, there are standalone tools as well but I don't have any recommendations.

7. Set up a pop-up blocker for next time - Proxomitron is good - or, even better, install Firefox and make it the default browser.

8. If your friend uses Outlook or Outlook Express, check that it has images disabled, shows all mail in plain text, doesn't send read receipts, and is operating in the IE secure zone (you could even install a freebie spam filter like K9 if you're feeling generous).

9. Restart the PC and let it boot up fully. Check the lights on the front of the box - is the hard drive constantly churning? Open Task Manager - is the CPU usage graph stuck at the 30% mark? Do you have 50+ processes running? Things like that are a bad sign. If you can't explain them, go back to step 2 :-)

10. Obtain free beer and promises never to do this agan from friend.

in a bit of a panic because I have a job interview in 30 minutes!!

Hope you stopped panicking and everything went OK...

Cheers
Jon

--
This message has been scanned for viruses and
dangerous content by Swift Internet, and is
believed to be clean.


____ • The WDVL Discussion List from WDVL.COM • ____
To Join wdvltalk, Send An Email To: mailto:[EMAIL PROTECTED] or
use the web interface http://e-newsletters.internet.com/discussionlists.html/
      Send Your Posts To: [email protected]
To change subscription settings, add a password or view the web interface:
http://intm-dl.sparklist.com/read/?forum=wdvltalk

________________  http://www.wdvl.com  _______________________

You are currently subscribed to wdvltalk as: [email protected]
To unsubscribe send a blank email to [EMAIL PROTECTED]
To unsubscribe via postal mail, please contact us at:
Jupitermedia Corp.
Attn: Discussion List Management
475 Park Avenue South
New York, NY 10016

Please include the email address which you have been contacted with.

Reply via email to