Computer Talk Discussions here pertain to mods, troubleshooting, and PC/console gaming

I got a really nasty computer virus for Christmas

Thread Tools
 
Search this Thread
 
Old 01-20-2010, 01:12 PM
  #21  
Registered User
 
SWLABR's Avatar
 
Join Date: Oct 2008
Location: Long Island
Posts: 27
Likes: 0
Received 0 Likes on 0 Posts
If your PC is back to a working state, copy 'My Documents' / 'Documents and Settings' to a USB drive (your IE favorites, pix, music, etc. are in there). Use your restore disks to give yourself a fresh OS and invest in Norton Internet Security 2010. It's the best against viruses, malware, spyware and pretty much any threat. It'll catch and quarantine viruses like you have/had before it takes over your machine. The 'free' antivirus and spyware protection out there - Spybot, AVG, etc. - are limited. Going forward, you'll have no issues if you run Norton IS 2010...

Hope this helps...
Old 01-20-2010, 01:26 PM
  #22  
Registered User
 
m1ashooter's Avatar
 
Join Date: Jul 2008
Location: North Texas
Posts: 52
Likes: 0
Received 0 Likes on 0 Posts
This is why I quit using windows but unfortunately running it is sometimes a necessary evil. That being said anytime you're surfing the Internet and a window pops up similar to what 92 Toy posted above it's some kind of malwire, virus, etc. They pop up a window making you think you have every virus in existence and you naturally click on it cuz you don't want a virus. When you click "Remove" or whatever they say you actually "execute" the malware, virus, whatever. After that you're screwed. They are next to impossible to get rid of without drastic measures such as reinstalling, formatting, so forth.

A free open source virus scanner is http://www.clamwin.com.
In the past I always used and had success with AdAware. (http://www.lavasoft.com/products/ad_aware_free.php)
There was something else similar to Ad-Aware but I can't remember what it's called now. It's been a couple of years since I used windows at home. I would almost say it should be mandatory to download and only use Firefox (http://www.mozilla.com/en-US/) but now I'm showing my anti-microsoft bias.
Final thoughts: If you have McAfee, Norton, or ClamAV installed and anything else pops up saying you have a virus don't click on it.

Last edited by m1ashooter; 01-20-2010 at 01:28 PM. Reason: Update
Old 01-20-2010, 01:28 PM
  #23  
Registered User
 
m1ashooter's Avatar
 
Join Date: Jul 2008
Location: North Texas
Posts: 52
Likes: 0
Received 0 Likes on 0 Posts
Spybot is the one I couldn't remember. I see SWLABR posted it while I was typing my two cents worth.
Old 01-20-2010, 01:50 PM
  #24  
Contributing Member
Thread Starter
 
mt_goat's Avatar
 
Join Date: Nov 2002
Location: Oklahoma State
Posts: 10,666
Likes: 0
Received 5 Likes on 5 Posts
Originally Posted by 92 TOY
Hey guys......I've been following this thread, a little, sounds like Mt Goat has a clue what he's doing, whereas I have zero clue. I'm the kind of ignoramous that just wants the computer to wrk when I want it to and that's about it.

Anyhoo..I found the link to the demon that infected my desktop PC and figured I'd paste the picture of what mine looked like (not mine, but it's a screenshot from a website talking about it).

Sounds like similar crap to mine....

Yes that looks very much like one screen I was getting, except the name was "Internet security 2010".

This thing kept on countering every move to get rid of it, almost like it was learning from my efforts to stop it. At first I found the way around its task manager disable. By going to Hkey_current_user\software\microsoft\windows\curre ntversion\policies\system and looking for a file called "Disable Task Mgr" then right click> delete. That would (at first) give me back use of the Task manager. But after a reboot it would disable it again. Then after a few times of disabling it and it coming back it wouldn't let me do it.

All the pros are talking about how hard this (TDL3 rootkit) is to get rid of, one guy called it the "stealthiest rootkit in the wild".

Last edited by mt_goat; 01-20-2010 at 02:03 PM.
Old 01-20-2010, 01:57 PM
  #25  
YotaTech Milestone-Two Millionth Post
 
92 TOY's Avatar
 
Join Date: Jan 2009
Location: Northeast Pennsylvania
Posts: 12,009
Received 122 Likes on 57 Posts
Yeah, I had talked to an I.T. geek I know from some YOTATECH site and he said that was a bad one.

Basically my computer powers up and shuts off and just keeps doing that over and over.

Thank goodness we still have a laptop, but with everybody wnting to be on the computer at the same time and my dang YOTATECH addiction, it makes it interesting.

I'm hoping that the "geek" can take care of my mess because I am a complete idiot when it comes to this stuff...and getting the oil pan off my truck....I suck.
Old 01-20-2010, 02:07 PM
  #26  
Contributing Member
Thread Starter
 
mt_goat's Avatar
 
Join Date: Nov 2002
Location: Oklahoma State
Posts: 10,666
Likes: 0
Received 5 Likes on 5 Posts
Originally Posted by Lumpy

...You are going to need to know if you have a SATA drive or a IDE drive...
How can I tell which I need? Thanks very much.
Old 01-20-2010, 02:18 PM
  #27  
Contributing Member
Thread Starter
 
mt_goat's Avatar
 
Join Date: Nov 2002
Location: Oklahoma State
Posts: 10,666
Likes: 0
Received 5 Likes on 5 Posts
Another interesting quote from this link: http://www.prevx.com/blog/139/Tdss-r...s-the-net.html

This infection is bringing all together the best of MBR rootkit, the best of Rustock.C and the experience of old Tdss variants. Result is an infection that is quickly spreading on the net and it is undetected by almost every security software and 3rd party anti rootkit software.
Old 01-20-2010, 02:21 PM
  #28  
Registered User
 
SWLABR's Avatar
 
Join Date: Oct 2008
Location: Long Island
Posts: 27
Likes: 0
Received 0 Likes on 0 Posts
An IDE has two rows of pins and is about 2+ inches wide. A SATA is much smaller and looks somewhat like a USB type connector. It is one or the other. You'd have to pull the hard drive to find out, or reboot, hit F2 and go into the BIOS. That should tell you what type of drive you have...
Old 01-20-2010, 02:41 PM
  #29  
Contributing Member
Thread Starter
 
mt_goat's Avatar
 
Join Date: Nov 2002
Location: Oklahoma State
Posts: 10,666
Likes: 0
Received 5 Likes on 5 Posts
Originally Posted by SWLABR
An IDE has two rows of pins and is about 2+ inches wide. A SATA is much smaller and looks somewhat like a USB type connector. It is one or the other. You'd have to pull the hard drive to find out, or reboot, hit F2 and go into the BIOS. That should tell you what type of drive you have...
Ok thanks, it looks like from this its SATA.

Old 01-20-2010, 02:45 PM
  #30  
Registered User
 
mick cassidy's Avatar
 
Join Date: Jul 2009
Location: los angeles
Posts: 117
Likes: 0
Received 0 Likes on 0 Posts
get norton 360 best on the market
Old 01-20-2010, 03:12 PM
  #31  
Registered User
 
Lumpy's Avatar
 
Join Date: Jan 2009
Location: Just North of Pittsburgh
Posts: 6,086
Received 17 Likes on 10 Posts
Yessirre that would be correct. I agree with the other folks here as well about Symantec (Norton) I use it we use it at work it just uses more resources than most.

But now that we know you have a SATA drive. Grab another one, open the case on yours swap drives, toss in the Windows CD and your off and a runnin.

After you get everything reinstalled and (this part is im-po-tint ) and have an Anti-virus installed you then can plug in the old drive via usb and copy all your documents over.

.
Old 01-20-2010, 03:16 PM
  #32  
Registered User
 
Lumpy's Avatar
 
Join Date: Jan 2009
Location: Just North of Pittsburgh
Posts: 6,086
Received 17 Likes on 10 Posts
it's a bad but and a bear that's why I typically reload them when I get a client that has this. Less headache for me smaller bill for them.
Old 01-21-2010, 06:58 AM
  #33  
Contributing Member
Thread Starter
 
mt_goat's Avatar
 
Join Date: Nov 2002
Location: Oklahoma State
Posts: 10,666
Likes: 0
Received 5 Likes on 5 Posts
Well another day goes by and no sign of trouble, dare I say this thing is gone? The PC is running great, as fast as ever! I really think that Hitman Pro worked (knock on wood).
Old 01-21-2010, 07:01 AM
  #34  
Registered User
 
Lumpy's Avatar
 
Join Date: Jan 2009
Location: Just North of Pittsburgh
Posts: 6,086
Received 17 Likes on 10 Posts
Good to hear!!! I hope you keep on keeping on without issue.

.
Old 01-21-2010, 09:39 AM
  #35  
Co-Founder/Administrator
Staff
iTrader: (1)
 
Corey's Avatar
 
Join Date: May 2002
Location: Auburn, Washington
Posts: 32,242
Received 19 Likes on 15 Posts
Glad it is fixed.
You may have read a thread here from me about the DOS attacks we have been having here.

It was narrowed down to infected computers that were instructed to specifically attack this site.
It brought the server to a stand still a month back.
Many do not even know their PCs have been turned into zombies to do the malware masters bidding.
Old 01-21-2010, 09:56 AM
  #36  
Registered User
 
Lumpy's Avatar
 
Join Date: Jan 2009
Location: Just North of Pittsburgh
Posts: 6,086
Received 17 Likes on 10 Posts
These lil schmucks need to be drawn and quartered!!!
Old 01-21-2010, 09:58 AM
  #37  
Contributing Member
Thread Starter
 
mt_goat's Avatar
 
Join Date: Nov 2002
Location: Oklahoma State
Posts: 10,666
Likes: 0
Received 5 Likes on 5 Posts
Originally Posted by Corey
Glad it is fixed.
You may have read a thread here from me about the DOS attacks we have been having here.

It was narrowed down to infected computers that were instructed to specifically attack this site.
It brought the server to a stand still a month back.
Many do not even know their PCs have been turned into zombies to do the malware masters bidding.
Yes, I remember that. Hope it wasn't my fault.
Old 01-22-2010, 06:33 AM
  #38  
Contributing Member
Thread Starter
 
mt_goat's Avatar
 
Join Date: Nov 2002
Location: Oklahoma State
Posts: 10,666
Likes: 0
Received 5 Likes on 5 Posts
Another day goes by and all is good! Some things I'm doing different now:

I surf the web logged on as a user with limited use (no administrative privledge)

I keep all the security settings on high, yes there are some sacrafices in that, but I'm getting used to it. The worst thing is I have to manually put in [Quote]s and smilies and stuff and click to redirect back to pages.

I use passwords to log on or switch users.

I use spybot everyday and immunized everything.

Microsoft has released a new patch for IE (yesterday) and I got that installed.

I'm very careful about giving permissions for access to programs and what links I click on.

Making sure auto updates is running for McAfee, my subcription is paid for on this or I'd try Norton. Plus I'm not conviced Norton would have stopped this attact either. As of 1/20/10 it was not listed as one of the programs that could fix or even detect this TDL3 rootkit.

Last edited by mt_goat; 01-22-2010 at 07:01 AM.
Old 01-22-2010, 08:18 AM
  #39  
Registered User
 
Lumpy's Avatar
 
Join Date: Jan 2009
Location: Just North of Pittsburgh
Posts: 6,086
Received 17 Likes on 10 Posts
One other thing to consider...Start using FireFox, I don't use IE for anything. It may take a bit getting used to but I do like it.
Old 01-22-2010, 08:46 AM
  #40  
Contributing Member
Thread Starter
 
mt_goat's Avatar
 
Join Date: Nov 2002
Location: Oklahoma State
Posts: 10,666
Likes: 0
Received 5 Likes on 5 Posts
Originally Posted by Lumpy
One other thing to consider...Start using FireFox, I don't use IE for anything. It may take a bit getting used to but I do like it.
I have used it some, the problem is I have a large catalog of saved favorites (from many hours of research) and when transfered to Firefox or Google Chrome the whole thing got reordered to alphabetical. Yes, I know it could all be reordered with "organize favorites" command but it would take a long long time. I do like Firefox though.


Quick Reply: I got a really nasty computer virus for Christmas



All times are GMT -8. The time now is 10:56 PM.