PDA

View Full Version : New Virus out there...



Wittpilot
May 29th, 2011, 21:03
Just a heads up... I got hit with a new virus I haven't seen before tonight... It pops up with all these errors saying your hard drive is corrupted and starts bringing up a fake Windows 7 Recovery Console... Working on getting it off right now... I never renewed my kapersky because I didn't like the slowed browsing it gave me... So I can't really blame anyone but myself... However, as much as is a painful experience, it almost is kind of a sick way of feeling nerdy for a little bit... That is, spending grueling hours trying to save everything and get the damn thing off!!!!

anyways, be on the look out for this one... for the first couple of seconds, I really thought I had a problem w/ the hard drive!

-witt

SpitXIV
May 30th, 2011, 19:24
Just a heads up... I got hit with a new virus I haven't seen before tonight... It pops up with all these errors saying your hard drive is corrupted and starts bringing up a fake Windows 7 Recovery Console... Working on getting it off right now... I never renewed my kapersky because I didn't like the slowed browsing it gave me... So I can't really blame anyone but myself... However, as much as is a painful experience, it almost is kind of a sick way of feeling nerdy for a little bit... That is, spending grueling hours trying to save everything and get the damn thing off!!!!

anyways, be on the look out for this one... for the first couple of seconds, I really thought I had a problem w/ the hard drive!

-witt

Just be careful what you download, and don't open spam mail. You might want to download Malware
Bytes It's an anti virus program. Also Spybot is good too. What's the virus called?

EasyEd
May 30th, 2011, 19:35
Hey All,

Yeah that's a bad one. I fought it twice as there is more than one variant. Malware bytes (mbam) is your friend. Get the latest Rkill as well and I don't recall where it is but there is a set of instructions for fixing your windows update which the virus shuts off. Also if it does wierd stuff to your directory structure you can fix it - it isn't gone. Good Luck!

-Ed-

CG_1976
May 30th, 2011, 23:28
This virus I have been fighting since last friday. Good thing I have back up computers till I repair the main.

Dangerousdave26
May 31st, 2011, 04:01
Just be careful what you download, and don't open spam mail.

This type of Viruses is not new. It just has been refined for the last few years.

They are commonly embedded in adds that are placed in normal everyday sites. I got one a number of months ago when using Fire Fox so the typical use FF or Opera instead of IE does not come into play. Any browser will leave you exposed you only need to visit the page at the same time the infected add gets displayed. A few years ago I was exposed to two of them one from the local news paper and one from MySpace. No I did not have a MySpace account. I let one of my coworkers wife use my laptop to check her MySpace account and that is how it got attacked.

They are pretty easy attacks to recover from provided you responded correctly when they attacked you. The number one first thing to do is disconnect from the internet by pulling the network cable. This simple action stops them from downloading any additional software and installing it on your system.

The next thing to do is do not click anything to shut it off. Clicking OK and Cancel have the same affect of confirming the installation of the software to your system. To kill the process open the task manager and look for strangely named process and kill them. Of course this should mean you understand what is running on your PC normally. You should look from time to time.

Next delete all temp files, cookies and your java cache

Now run Malware bytes and it should clean it out.

The last one I got changed the settings in IE to access the internet by a proxy. The proxy was part of the program its self. You may need to go to the settings in IE and change it back to the normal settings. On the connections tab look at the LAN Settings. it will be set to 127.0.0.1 and some strange port number. Remove the check box from Proxy server and check the box Automatically detect settings. Remember that FF at default uses the system proxy settings which are set in IE Options so FF will not fuction until you fix the IE Settings.

You should be able to safely connect to the internet to get updates to your anti virus and start running scans.

You can also use

http://www.f-secure.com/en_EMEA-Labs/security-threats/tools/online-scanner

to scan your PC to make sure you are clean. (Thanks Ickie for that one)

You may want to run malware bytes in safe mode but if you followed this format you did not get a very bad infection or you may not have been infected at all.

Ickie
May 31st, 2011, 04:13
all my emails go through the server and a boxtrapper, its plain and simple, an area in my linux server where incoming mail goes, and the sender has 24 hours to return my email from the server to prove they are human, all they have to do it click return the servers email to be white listed and the email is finally sent to me after going through spamhass.
tham avg pro goes to work to filter the rest.

I also do an online scan daily, about 5 minutes.

frankwi
May 31st, 2011, 12:39
When I get that sort of garbage, I just RESTORE my system to the day before I got it ...