Pelican Parts
Parts Catalog Accessories Catalog How To Articles Tech Forums
Call Pelican Parts at 888-280-7799
Shopping Cart Cart | Project List | Order Status | Help



Go Back   Pelican Parts Forums > Miscellaneous and Off Topic Forums > Off Topic Discussions


Reply
 
LinkBack Thread Tools Rating: Thread Rating: 3 votes, 2.33 average.
Author
Thread Post New Thread    Reply
Registered
 
pwd72s's Avatar
 
Join Date: Apr 2001
Location: Linn County, Oregon
Posts: 48,517
Virus warning from our 'puter guy...

As many here know, I'm a computer illiterate. I use a local guy for computer service, etc. Here's a cut & paste from his latest newsletter about a tricky virus that needs a heads up:

"Virus Alert
Right before Christmas we have several customers who have been hit with some pretty bad viruses.

One really bad one is called the Win7 Virus. It tries to look like Windows security, but it is not. These viruses are so bad we have had to reload several systems. It makes repairing it with our normal tools and processes almost impossible.

Remember, do not touch any weird windows or pop ups with your mouse. If you try to close the window by clicking on the X, that virus will own your computer.

Hit Control/Alt/Delete all together, then go to task manager, and select the window, and choose end task."

__________________
"Now, to put a water-cooled engine in the rear and to have a radiator in the front, that's not very intelligent."
-Ferry Porsche (PANO, Oct. '73) (I, Paul D. have loved this quote since 1973. It will remain as long as I post here.)
Old 01-05-2012, 09:08 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #1 (permalink)
Registered
 
slodave's Avatar
 
Join Date: Sep 2005
Location: Encino Man
Posts: 22,394
Garage
Send a message via Skype™ to slodave
The Win 7 antivirus 2012 malware is horrible. I had a client get the xp version recently and it deleted files related to networking and registry entries. My laptop, running 7, was hit with it earlier this week and it's pretty much hosed. I've done everything but an in place install and worse case, full reinstall.

MSE is useless against it as are most other programs.
Old 01-05-2012, 09:15 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #2 (permalink)
Registered
 
Join Date: Mar 1999
Location: Vancouver,Wa.
Posts: 4,457
Yeah.....got the pop-ups but never opened them. Just getting rid of the pop-ups was bad enough for a semi-puter literate soul.
__________________
JPIII
Early Boxster
Old 01-05-2012, 09:16 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #3 (permalink)
Registered
 
pwd72s's Avatar
 
Join Date: Apr 2001
Location: Linn County, Oregon
Posts: 48,517
Normally I don't post the usual email "virus alerts" I get....but this one seemed worth posting the warning.

It seems that Ctrl-Alt-Delete is your only friend in this case.
__________________
"Now, to put a water-cooled engine in the rear and to have a radiator in the front, that's not very intelligent."
-Ferry Porsche (PANO, Oct. '73) (I, Paul D. have loved this quote since 1973. It will remain as long as I post here.)
Old 01-05-2012, 09:21 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #4 (permalink)
The Unsettler
 
stomachmonkey's Avatar
 
Join Date: Dec 2002
Location: Lantanna TX
Posts: 23,885
Send a message via AIM to stomachmonkey
Yeah, my daughter managed to get it on one of my dev PC's last weekend.

It can be removed but doing so totally hoses the registry and you lose all app associations.

It basically associates .exe with itself so no matter what app you try to run it opens the malware.

Easiest fix I found to avoid reinstalling the system is to remove it, create a new user account then migrate the user data from the infected one to the new one.
__________________
"I want my two dollars"
"Goodbye and thanks for the fish"
"Proud Member and Supporter of the YWL"
"Brandon Won"
Old 01-05-2012, 09:24 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #5 (permalink)
Registered
 
slodave's Avatar
 
Join Date: Sep 2005
Location: Encino Man
Posts: 22,394
Garage
Send a message via Skype™ to slodave
Not quite. It'll come back when you restart. There is a way to clean this one, but the steps have to be followed. Time for me to adapt. My old tricks for removing the previous versions no longer work.

One hint, but I did not get to try it, is to set your computer clock ahead by 7 days. It's reported that it will uninstall itself when this is done.
Old 01-05-2012, 09:28 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #6 (permalink)
 
Registered
 
slodave's Avatar
 
Join Date: Sep 2005
Location: Encino Man
Posts: 22,394
Garage
Send a message via Skype™ to slodave
It's easy to fix the exe association. A lot of files needed for networking have their permissions removed. I had to go into the system32/drivers folder and put them back. On XP, it deletes AFD.sys and it's registry entries.
Old 01-05-2012, 09:30 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #7 (permalink)
The Unsettler
 
stomachmonkey's Avatar
 
Join Date: Dec 2002
Location: Lantanna TX
Posts: 23,885
Send a message via AIM to stomachmonkey
Restarting did not help in my situation.
__________________
"I want my two dollars"
"Goodbye and thanks for the fish"
"Proud Member and Supporter of the YWL"
"Brandon Won"
Old 01-05-2012, 09:43 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #8 (permalink)
Registered
 
Join Date: Apr 2005
Location: outta here
Posts: 53,129
Look into running a sandbox. I do this and have had no virus issues since I started. Part of your disc is quarantined and that's where you run a web browswer. Get a virus? Delete the contents of the sandbox and you're done.

Sandboxie - Sandbox software for application isolation and secure Web browsing

JR
Old 01-05-2012, 09:47 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #9 (permalink)
Registered
 
slodave's Avatar
 
Join Date: Sep 2005
Location: Encino Man
Posts: 22,394
Garage
Send a message via Skype™ to slodave
Nice for home users. Not so much for the business clients.
Old 01-05-2012, 10:01 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #10 (permalink)
Registered
 
Join Date: May 2002
Location: St Louis
Posts: 4,211
Malwarebytes worked for me

Windows Vista Antispyware 2012
__________________
Rick
88 Cab
Old 01-05-2012, 10:02 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #11 (permalink)
Friend of Warren
 
Join Date: Oct 2000
Location: Lincoln, NE
Posts: 16,486
1. Get a good anti-virus program. I use the free version of avast.
2. Never use Internet Explorer for your web browser.
__________________
Kurt V
No more Porsches, but a revolving number of motorcycles.
Old 01-05-2012, 10:08 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #12 (permalink)
Registered
 
slodave's Avatar
 
Join Date: Sep 2005
Location: Encino Man
Posts: 22,394
Garage
Send a message via Skype™ to slodave
The Win antivirus gets by everything. It also doesn't care which browser you use.
Old 01-05-2012, 10:18 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #13 (permalink)
Student of the obvious
 
LeeH's Avatar
 
Join Date: May 2000
Location: Phoenix
Posts: 7,714
Just curious if any of you have any idea where/how your computers were infected.
__________________
Lee
Old 01-05-2012, 10:23 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #14 (permalink)
Registered
 
slodave's Avatar
 
Join Date: Sep 2005
Location: Encino Man
Posts: 22,394
Garage
Send a message via Skype™ to slodave
For me, I think based on some of the file creation dates I found, it was when I was cleaning a clients pc.

It's network aware and scans for computers on the same network.

Time for me to isolate a network at home for this.

I'm gone for now. Taxiing to take off from Las Vegas and heading to Death Valley.
Old 01-05-2012, 10:28 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #15 (permalink)
Registered
 
Zeke's Avatar
 
Join Date: Jan 2002
Location: Long Beach CA, the sewer by the sea.
Posts: 37,694
If and when it gets to me, I will pick this unit up and toss it as far as it will fly. I got it out of the trash, held on to it in case. Well, the in case happened last year and my computer with all my stuff sits on the floor behind me.

I know I can last the rest of my life on older castaways. In fact, really all I need is older castaway HD's. Or out of date crap from overstock.

Afet having been enamored with computers for 15 years, I now find they are really, really boring time sucking machines.

Thanks for the warning Paul, but if I suddenly disappear, you'll know what happened.
Old 01-05-2012, 10:36 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #16 (permalink)
canna change law physics
 
red-beard's Avatar
 
Join Date: Jul 2000
Location: Houston, Tejas
Posts: 43,366
Garage
I had one earlier this year on our neighbors laptop. It had some autoclose sequence on the task manager. It also would move the cursor if you got near certain things. Really tough. I had to use Combofix and then Malwarebytes.
__________________
James
The pessimist complains about the wind; the optimist expects it to change; the engineer adjusts the sails.- William Arthur Ward (1921-1994)
Red-beard for President, 2020
Old 01-05-2012, 11:14 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #17 (permalink)
Registered
 
slodave's Avatar
 
Join Date: Sep 2005
Location: Encino Man
Posts: 22,394
Garage
Send a message via Skype™ to slodave
Hello from Death Valley.

The 2011 and prior versions were easy to get rid of with combo fix and MB. 2012, not so much.
Old 01-05-2012, 11:28 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #18 (permalink)
canna change law physics
 
red-beard's Avatar
 
Join Date: Jul 2000
Location: Houston, Tejas
Posts: 43,366
Garage
Glad you made it!
__________________
James
The pessimist complains about the wind; the optimist expects it to change; the engineer adjusts the sails.- William Arthur Ward (1921-1994)
Red-beard for President, 2020
Old 01-05-2012, 11:29 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #19 (permalink)
Registered
 
Jandrews's Avatar
 
Join Date: Apr 2000
Location: Kansas City
Posts: 1,675
I got this and lost all my file associations. I was able to get rid of the "virus" itself with Malwarebytes, but the damage is done. It completely cleared my desktop. In order to run any applications, I have to go to "My Computer", and find the application file in the appropriate folder, right click on it, and choose "run as administrator".

Can anyone help me get the file associations back? Heck, I even tried to install a copy of XP over the top of this Vista just to start over and I even got an error when booting from the Windows CD!

Thanks,

JA

__________________
John
- '70/73 RS Spec Coupe (Sold)
- '04 GT3
Old 01-05-2012, 06:13 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #20 (permalink)
Reply


 


All times are GMT -8. The time now is 09:34 AM.


 
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0
Copyright 2025 Pelican Parts, LLC - Posts may be archived for display on the Pelican Parts Website -    DMCA Registered Agent Contact Page
 

DTO Garage Plus vBulletin Plugins by Drive Thru Online, Inc.