Bloody infection!

for all net-related stuff
Post Reply
User avatar
faceless
Posts: 26492
Joined: Tue Apr 25, 2006 6:16 pm

Bloody infection!

Post by faceless »

I'm typing this on my spare computer as my main one has become infected with some bastard virus that's blocking me from doing just about anything.

I can't install anything, or go into safe mode, so I'm going to have to plug the hard drive from it into this computer and try to clean it that way.

What a bastard though! It's the first time in maybe 3years that I've been affected, but it's still bloody annoying.
modern
admin
Posts: 522
Joined: Sun Jan 04, 2009 2:00 am

Post by modern »

Is it something going about or are the gremlins just after you???

Pain in the arse though, right?!
User avatar
faceless
Posts: 26492
Joined: Tue Apr 25, 2006 6:16 pm

Post by faceless »

it's a multi-faceted spyware/virus thing which I think I got after using a keygen from a non-safe site last night.

It's basically affected the windows security advsor and is blocking me from running anything (such as regedit) and also won't let me get into safe mode.

There's not much you can do when it's like that, but I've got the drive plugged into this computer now and am scanning it - hopefully I'll be able to get rid of at least part of it this way and then be able to sort the rest later.

If not, I'll have to delete windows and reinstall - harrumph!
User avatar
Ash
admin
Posts: 539
Joined: Tue May 22, 2007 12:01 pm
Location: Al-Ard
Contact:

Post by Ash »

Sorry to hear about that, face. :( ... (in case you don't know,) Hiren's bootCD probably* has something to address this sort of problem.

[*] My problem was entirely different - screwed up hd partition whilst trying things in Acronis. Now I use cobian for my backup - free and very easy to use. :)
User avatar
faceless
Posts: 26492
Joined: Tue Apr 25, 2006 6:16 pm

Post by faceless »

well that's me back online with this computer now - I had to reinstall windows completely as the virus ended up deleting the contents of the windows/system folder and that stopped it from even booting.

Just a malicious bastard thing with no real intent. It had posted links to sites like youporn on the desktop while forcing explorer to open at a page called av-force.net.

this page gives some info on what that site is.. CLICK

But that was only one part of it - in those intstructions it says to edit the registry, but some other part of the virus pack had blocked any access to msconfig, regedit etc. On starting in safe-mode it gave a 'this product is not activated' screen, so it was impossible to get past that too.

Quite a substantial computer-fecker all-in-all. Just as well I keep everything of value on other computers...
User avatar
SquareEyes
admin
Posts: 387
Joined: Sun May 10, 2009 4:32 pm
Location: Vienna, Austria

Post by SquareEyes »

I'd recommend always running keygens etc. from within a sandbox (download Sandboxie - it's free & safe).
User avatar
faceless
Posts: 26492
Joined: Tue Apr 25, 2006 6:16 pm

Post by faceless »

I've not heard of that, but I'll give it a go - my first thought yesterday was that the only way to be sure of safety was to do it within a virtual machine...

just gave it a shot and it doesn't work on XP64. Bah.
User avatar
major.tom
Macho Business Donkey Wrestler
Posts: 1970
Joined: Sun Jan 21, 2007 7:07 pm
Location: BC, Canada

Post by major.tom »

Sorry to hear about your bad luck, faceless.

While less frequent, it still seems that occasional re-format-and-install's are still necessary. For this reason, I decided years ago to make it a little easier for myself to accomplish this with minimal loss of data. I use a small (20-30 GB) partition for my C: drive and map my "Documents" folder to another partition. For the most part, this means that a re-format only requires re-installing programs.

There are a couple other small things (Firefox profile) but that's not difficult to work around. (Firefox -P allows you to create your profile -- bookmarks, etc -- somewhere outside of the c: partition.)
User avatar
SquareEyes
admin
Posts: 387
Joined: Sun May 10, 2009 4:32 pm
Location: Vienna, Austria

Post by SquareEyes »

faceless wrote:I've not heard of that, but I'll give it a go - my first thought yesterday was that the only way to be sure of safety was to do it within a virtual machine...

just gave it a shot and it doesn't work on XP64. Bah.

I'll PM you another solution...
Post Reply