It is currently 05/24/24 5:57 pm

All times are UTC - 6 hours




  Page 1 of 1   [ 12 posts ]
Author Message
 Offline
PostPosted: 05/17/11 4:45 am • # 1 
User avatar
Editorialist

Joined: 01/16/09
Posts: 14234
several of us, including me- TWICE- have contracted this really shitty piece of malware.

here is what it does:

when you are on some website (could be almost any, ime- but i got mine once at youtube, or some site linked from youtube), you will suddenly get a popup for antispyware.  it will inform you that you have an invasion, and that you need to download their software to fix it.  if you try to close the program, it won't let you.  it will remain resident on the screen, or it will pop up any time you try to run a program.

what this malware does is rewrite your .exe associations in your registry, and block all access to the internet.  so if you try to download software, or find a fix for it, you can't.  it only takes a few seconds to screw up your registry, so there is really no time to fix it before it gets you.

here is the procedure for fixing it:

1) do a hard shutdown on your computer by "powering down"
2) start back up in "safe mode"
3) create a NEW USER (this is something you can do in safe mode) with admin functionality
3) "log off" and when you come back up, access the new user.

now you will have a registry that does NOT have the bad .exe association.
you can access the internet and download the trial version (free) of MalwareBytes.
run a full scan and delete the malware.
now, go on the internet to HERE:

http://www.sevenforums.co...ssociations-restore.html

and download the registry patch (the one labeled EXE).  here is where it gets tricky.  since you have to run the patch from the defective user area, and you can't do it because it limits access to the net, you have to open the NEW user first, get the patch, and right click and download it to the C: directory (which is accessed through My Computer).  once on the root directory, you can use the "My Computer" method to find the patch and run it from the defective user.  you don't need to reboot, it fixes the .exe association immediately.

for more information on this really fucked up piece of malware shit, look HERE:

http://www.bleepingcomputer.com/virus-removal/remove-win-7-antispyware-2011

note to jab: these websites contained everything other than the user stuff mentioned above, and how to navigate around this.  i found that information in a windows 7 users forum, and, of course, in your pm to me.


Last edited by macroscopic on 05/17/11 5:05 am, edited 1 time in total.

Top
  
 Offline
PostPosted: 05/17/11 4:46 am • # 2 
User avatar
Editorialist

Joined: 01/16/09
Posts: 14234
oh, the final fix is to either not allow popups, or to download the paid version of MalwarBytes for $25, and run it when you are operating. it will ask permission for popups, and you can deny it for the crappy antispyware stuff.


Top
  
 Offline
PostPosted: 05/17/11 4:54 am • # 3 
User avatar
Administrator

Joined: 04/05/09
Posts: 8047
Location: Tampa, Florida
Quick question
Do you run firefox or IE?


Top
  
 Offline
PostPosted: 05/17/11 5:00 am • # 4 
User avatar
Editorialist

Joined: 01/16/09
Posts: 14234
jabra2 wrote:
Quick question
Do you run firefox or IE?

Firefox.  the wife runs IE and she got it, too.  good question tho- it goes after the browsers FIRST, apparently.


Top
  
 Offline
PostPosted: 05/17/11 5:04 am • # 5 
User avatar
Administrator

Joined: 04/05/09
Posts: 8047
Location: Tampa, Florida
If you run Firefox, please tell me that you have the free Ad Block Plus add-on installed.


Top
  
 Offline
PostPosted: 05/17/11 5:07 am • # 6 
User avatar
Editorialist

Joined: 01/16/09
Posts: 14234
jabra2 wrote:
If you run Firefox, please tell me that you have the free Ad Block Plus add-on installed.

i have the Ad Block Plus add-on installed.

jabra- i have Nod 32 AV, i have Windows Defender Security Suite, i have at least one other program to defend against this- and it blows by all of them.


Top
  
 Offline
PostPosted: 05/17/11 5:19 am • # 7 
User avatar
Administrator

Joined: 04/05/09
Posts: 8047
Location: Tampa, Florida
I never got any of those specific malwares, but then, I haven't used a symantec/McAfee/Norton programs in decades.


Top
  
 Offline
PostPosted: 05/17/11 5:23 am • # 8 
User avatar
Editorialist

Joined: 01/16/09
Posts: 14234
jabra2 wrote:
I never got any of those specific malwares, but then, I haven't used a symantec/McAfee/Norton programs in decades.

me neither.  i used the Defender suite because it came with the computer (which is only six months old).  don't care for those programs, but it blows by all of them, as well.


Top
  
 Offline
PostPosted: 05/17/11 5:24 am • # 9 
User avatar
Editorialist

Joined: 01/16/09
Posts: 14234
note to all: it took me five hours to figure out how to do this. but most of you should be able to fix it in under an hour, if you can follow the procedure in post 1.


Top
  
 Offline
PostPosted: 05/17/11 5:29 am • # 10 
User avatar
Administrator

Joined: 11/07/08
Posts: 42112
Jab, I'm thinking this is the same PAV you cleaned off my machine ~ that was when I was still using PCTools ~ I've had no problems since I switched to Avast ~ but Gramps just had this same PAV and it blew by Avast, so he switched back to [I think] Norton ~

Sooz


Top
  
 Offline
PostPosted: 05/17/11 5:46 am • # 11 
User avatar
Administrator

Joined: 04/05/09
Posts: 8047
Location: Tampa, Florida
Well, then all I can guess you folks visit hardcore porn sites too much. I never got infected with that or similar malware. Image


Top
  
 Offline
PostPosted: 05/17/11 6:17 am • # 12 
User avatar
Editorialist

Joined: 01/16/09
Posts: 14234
jabra2 wrote:
Well, then all I can guess you folks visit hardcore porn sites too much. I never got infected with that or similar malware. Image

see, your second point disproves your first.Image


Top
  
Display posts from previous:  Sort by  

  Page 1 of 1   [ 12 posts ] New Topic Add Reply

All times are UTC - 6 hours



Who is online

Users browsing this forum: No registered users and 11 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
© Voices or Choices.
All rights reserved.