Aaaarrrggghhhh…. nightmare
Tuesday, February 21st, 2006My flatmate’s laptop has been playing up recently so I decided to finally have a look at it this weekend to fix it for him. I really wish I hadn´t! Having a quick look at it showed that it had Panda antivirus but it was a few years old and the subscription had expired, it had Ad-Aware on it but wasn’t used and SP2 had never been installed.
The home page was set to a random IP address that was no longer used, there were random popups to "search engines" plus other definate Spyware and Virus activity. After a few hours of installing Norton, updates and removing dubious programs it was looking a bit better so I went for the SP2 install. Unfortunately, after the reboot all I got was a Blue Screen of Death.
A quick Google showed that it was due to a bit of spyware causing the update to fail and that I had to remove SP2 and the spyware then try again. The best way to get rid of SP2 was through the Recovery Console so I booted into it, selected the windows installation and then asked my flatmate for the Administrator password, to which I got the response I was expecting: “er…don’t know…”.
We then spent the next hour rebooting and trying all his usual passwords plus anything that I could think of that he might of used. Just as we were about to give up I came across a boot-cd on t´interweb that boots a Linux distro and reads the registry to find the password for any user account. We booted off the CD and hey presto! The password for the Admin account is… BLANK PASSWORD!!! I nearly screamed….
After removing SP2 the next problem was that NAV wouldn´t run now, just kept asking for a reboot which didn´t work. I found a tool on the Symantec site to remove all registry entries to the program and then let you manually delete the program folders. I then spent the next eight hours running various online virus scans, installing and running the latest NAV then MS Defender, Ad-Aware and Spybot S&D until it only came up with clean scans from everything! Woo hoo!
And the moral of the story is… go for a clean install every time… it’s quicker!