what to do if your computer suddenly tells you to reinstall windows

Status
Not open for further replies.

rosey_krh

Solid State Member
Messages
10
I don't know how common this problem is out there right now, but I work in IT at a college campus and we have had a rash of Sidefind.
It's a very nasty little bugger and is usually accompanied by 180search, webrebates, and IST slotch bar.

We get calls to remove spyware constantly, but a few weeks ago things started going wrong. A worker went out to remove spyware and came back in carrying a crapped out machine. He said the spybot S&D removed a bunch of stuff, but was unable to remove one called sidefind. He accessed add/remove programs and clicked on sidefind to remove it. As soon as he clicked on the remove button the machine restarted itself. When it came back up Windows 98 appeared not to load. Instead the screen gave the message that windows needed the product key code to begin installation.

He thought he somehow screwed up, brought the machine in and we reimaged it. The next machine to go down didn't even make it through spybot S&D's entire scan before it hit sidefind, restarted itself and asked for the product key. We reimaged it. We ended up reimaging about 6 machines which sucks because we weren't able to save any personal data off of them since we could not access windows.

Now I am hear to tell you, we have finally found a fix to prevent reinstalling windows and losing everything. It didn't sit right that a virus could uninstall you operating system. We knew that the screen asking for the product key was probably a false screen that the virus was placing there in order to gather key codes. We blitzed out a few machines before we were able to solve the problem. If this happens to you, don't reinstall windows.

Restart your pc and as it is coming back up hit the F8 key like you would to boot into safe mode. Instead of safe mode, choose command prompt only. At the command prompt type in scanreg and restore a backup copy of your registry. I recommend choosing the oldest copy.

Then restart pc like normal and it should come up just like it was before it freaked out. Then you can work on getting rid of the spyware in your normal fashion.
 
rosey_krh, thank you for posting this...I'm sticking it here and going to copy it to the HiJack Forum as well. Liz
 
I've had problem with Sidefind and 180search etc... on several machines a few months back. I didn't research it too much but after much frustration of finding the source. I've found that the trojan plants itself into the Windows folder and from they're continually uploads itself to any local network. Any Windows based computer without the proper security updates or firewalls can recieve the uploaded copy of the trojan and is then infected. Any attempts to remove the programs associated with sidefind is futile (even going so far as to remove the regkeys manually) because they will just be downloaded via the trojan. Even removing the trojan is useless in that they're must be a back-up somewhere that I wasn't able to find. All in all this is a major pain. If your trying to install a fresh copy of windows on a pc hooked up to a network then make sure you unplug your connection until you get a firewall or a hard copy of the security updates.
 
Rosey: Thanks so much for post this. I am also having problems with sidefind!. I am going to put my log in order to find help, because i have not been able to restore a backup copy of my registry. Thanks any way!
 
Had the same problem. Thanks for your notes. One thing, I think the 'virus' is nuisance/malicious type rather than trying to harvest Win98 product keys. Why would anyone bother doing that? They're easily available on the net.

In my case, even entering the right key wouldn't let me complete startup. So, if it can't start then it can't connect to the net to send back to whoever is trying to collect the keys.

Also, they could have easily written a program to get the key and send it without the user knowing, and without this whole "please enter your product id" fiasco. That's why I think it's more likely to be malicious.
 
Status
Not open for further replies.
Back
Top Bottom