• Welcome to Overclockers Forums! Join us to reply in threads, receive reduced ads, and to customize your site experience!

Deleting Malware + Windows file protection

Overclockers is supported by our readers. When you click a link to make a purchase, we may earn a commission. Learn More.

redwraith94

Member
Joined
Feb 17, 2005
I am looking to remove some malware from a clients computer, I ran TDS-3 and cleaned up most of it. There is this one pesky @SS piece that will not allow me to remove it, I have been able to kill it's process, but windows will not let me delete the file, it tells me that it is protected (not in use though) I was going to use recovery console to get rid of it, but they do not know the admin password. I do not know how to reset an admin password, I have heard of progs to do it, but I'm not sure. so I'm looking for all of the following:

How to reset an admin password on Winxp.
How to delete a 'protected operating system file' (even after it's process is killed), but from the desktop, not the recovery console.
Is their is a more powerful tool than taskman for killing processes, I have process viewer for win2k, and it works great, but it won't work on xp, I have tried.

This install is really messed up, I am going to try restoring it, w/o a clean install, to save time, we just ordered the op sys disk for them (it is an hp) and it's sp1, which will be upgraded. Computer management won't open, sysinfo won't open, user accounts won't open. I should mention that tds-3 found an enormous amount of trojans, and malware ~80+ in that area, and their comp did not work well before I deleted them. I also put Norton 2005 on this machine 1 1/2 months ago, when I came back it had been disabled and could not run live update, could not un-install, could not re-install. So their computer is pretty screwed, but I want to avoid a complete reinstall if at all possible, so any input is appreciated.
 
Well, you could slave the drive and pop it into another computer. Then boot up with a master disk 2k or xp...

Then delete the nasty files from the slave drive. Pull the drive and put it back in the original computer. This would atleast allow you access to the file system.

also, doing crapware cleanups seem to work better in safe mode.

Have fun :)
 
Back