Cigar Asylum Cigar Forum  

Go Back   Cigar Asylum Cigar Forum > Non Cigar Specialty Forums > Misc > General Discussion

Reply
 
Thread Tools Display Modes
Old 04-14-2009, 10:30 PM   #1
icehog3
Admiral Douchebag
 
icehog3's Avatar
15
 
Join Date: Oct 2008
First Name: Tom
Location: Clermont, Kentucky
Posts: 71,441
Trading: (60)
HUpmann
icehog3 has disabled reputation
Default Computer Virus

Had a strange bug on my computer when I tried to log onto the internet tonight.

Every site I tried to reach, I got a message, with an Internet Explorer logo at the top, from a Spyware company saying the site I was trying to reach was unsafe, and that I could buy their software for $49.99 to solve the problem.

When I found the icon for the Spyware company on my lower icons and right-clicked it, it began a "software" scan. Each time I hit it to stop, it would restart where it left off each time I tried to click on something else. Told me I had 74 "severe risk" viruses on my computer, and that their Spyware would fix it for $49.99.

Rebooted...nothing. Tried to log onto Yahoo, ESPN, CA, etc, and just get getting the message. Shut down, rebooted again, nothing.

Finally solved it with a system restore, restoring my computer to yesterday's settings.

Just a heads-up in case this is going around, got through all my virus protection and firewalls.
__________________


Thanks Dave, Julian, James, Kelly, Peter, Gerry, Dave, Mo, Frank, Tır and Mr. Mark!
icehog3 is offline   Reply With Quote
Old 04-14-2009, 10:33 PM   #2
Whee
formerly illinoishoosier
 
Whee's Avatar
 
Join Date: Oct 2008
First Name: Sean
Location: Bishopville, SC
Posts: 3,591
Trading: (17)
Partagas
Whee is a splendid one to beholdWhee is a splendid one to beholdWhee is a splendid one to beholdWhee is a splendid one to beholdWhee is a splendid one to beholdWhee is a splendid one to behold
Default Re: Comptter Virus

Quote:
Originally Posted by icehog3 View Post
Had a strange bug on my computer when I tried to log onto the internet tonight.

Every site I tried to reach, I got a message, with an Internet Explorer logo at the top, from a Spyware company saying the site I was trying to reach was unsafe, and that I could buy their software for $49.99 to solve the problem.

When I found the icon for the Spyware company on my lower icons and right-clicked it, it began a "software" scan. Each time I hit it to stop, it would restart where it left off each time I tried to click on something else. Told me I had 74 "severe risk" viruses on my computer, and that their Spyware would fix it for $49.99.

Rebooted...nothing. Tried to log onto Yahoo, ESPN, CA, etc, and just get getting the message. Shut down, rebooted again, nothing.

Finally solved it with a system restore, restoring my computer to yesterday's settings.

Just a heads-up in case this is going around, got through all my virus protection and firewalls.
Apparently affected your spell-check in your title too..

My daughter had the same problem, but no clean restore point. Will have to reformat to completely remove it. Sounds like Conficker...

http://www.pcworld.com/article/16210...ml?tk=rss_news

This virus has become active recently after freakin everyone out on 4/1.
__________________
"Maybe I'm wrong, when they tell me they're right…..naaaaahhhhhh, I'm an asshooooooleeee"--Denis Leary
Whee is offline   Reply With Quote
Old 04-14-2009, 10:49 PM   #3
icehog3
Admiral Douchebag
 
icehog3's Avatar
15
 
Join Date: Oct 2008
First Name: Tom
Location: Clermont, Kentucky
Posts: 71,441
Trading: (60)
HUpmann
icehog3 has disabled reputation
Default Re: Comptter Virus

Quote:
Originally Posted by illinoishoosier View Post
Apparently affected your spell-check in your title too..

My daughter had the same problem, but no clean restore point. Will have to reformat to completely remove it. Sounds like Conficker...

http://www.pcworld.com/article/16210...ml?tk=rss_news

This virus has become active recently after freakin everyone out on 4/1.
Based on the article, should I restore my computer to a much earlier date? Makes it sound like the bug might have been there for a coupel weeks and just gone off today...
__________________


Thanks Dave, Julian, James, Kelly, Peter, Gerry, Dave, Mo, Frank, Tır and Mr. Mark!
icehog3 is offline   Reply With Quote
Old 04-14-2009, 10:54 PM   #4
Whee
formerly illinoishoosier
 
Whee's Avatar
 
Join Date: Oct 2008
First Name: Sean
Location: Bishopville, SC
Posts: 3,591
Trading: (17)
Partagas
Whee is a splendid one to beholdWhee is a splendid one to beholdWhee is a splendid one to beholdWhee is a splendid one to beholdWhee is a splendid one to beholdWhee is a splendid one to behold
Default Re: Comptter Virus

Quote:
Originally Posted by icehog3 View Post
Based on the article, should I restore my computer to a much earlier date? Makes it sound like the bug might have been there for a coupel weeks and just gone off today...
I'd run a scan. I used the McAfee and the F-protect mentioned in the article. If you can, you could turn off your restore temporarily, just to make sure you don;t recreate it and see what happens.

My daughters PC got sick a week before the first, so I think she just picked up a stubborn virus.

You are right, though, it may have lain dormant until recently.

Where are the real nerds at when you need them? Is there a Star Trek marathon on SciFi tonight...
__________________
"Maybe I'm wrong, when they tell me they're right…..naaaaahhhhhh, I'm an asshooooooleeee"--Denis Leary
Whee is offline   Reply With Quote
Old 04-14-2009, 11:00 PM   #5
icehog3
Admiral Douchebag
 
icehog3's Avatar
15
 
Join Date: Oct 2008
First Name: Tom
Location: Clermont, Kentucky
Posts: 71,441
Trading: (60)
HUpmann
icehog3 has disabled reputation
Default Re: Comptter Virus

Quote:
Originally Posted by illinoishoosier View Post
I'd run a scan. I used the McAfee and the F-protect mentioned in the article. If you can, you could turn off your restore temporarily, just to make sure you don;t recreate it and see what happens.

My daughters PC got sick a week before the first, so I think she just picked up a stubborn virus.

You are right, though, it may have lain dormant until recently.

Where are the real nerds at when you need them? Is there a Star Trek marathon on SciFi tonight...
I am so computer un-savvy.
__________________


Thanks Dave, Julian, James, Kelly, Peter, Gerry, Dave, Mo, Frank, Tır and Mr. Mark!
icehog3 is offline   Reply With Quote
Old 04-14-2009, 11:05 PM   #6
Whee
formerly illinoishoosier
 
Whee's Avatar
 
Join Date: Oct 2008
First Name: Sean
Location: Bishopville, SC
Posts: 3,591
Trading: (17)
Partagas
Whee is a splendid one to beholdWhee is a splendid one to beholdWhee is a splendid one to beholdWhee is a splendid one to beholdWhee is a splendid one to beholdWhee is a splendid one to behold
Default Re: Comptter Virus

Quote:
Originally Posted by icehog3 View Post
I am so computer un-savvy.
Stop clicking on the "free cigar ****" links and you'll be ok.

My daughter picked it up through a games site. Had to be embedded in one of her games she downloaded.
__________________
"Maybe I'm wrong, when they tell me they're right…..naaaaahhhhhh, I'm an asshooooooleeee"--Denis Leary
Whee is offline   Reply With Quote
Old 04-14-2009, 10:34 PM   #7
darb85
Guest
 
Posts: n/a
Default Re: Comptter Virus

Quote:
Originally Posted by icehog3 View Post
Had a strange bug on my computer when I tried to log onto the internet tonight.

Every site I tried to reach, I got a message, with an Internet Explorer logo at the top, from a Spyware company saying the site I was trying to reach was unsafe, and that I could buy their software for $49.99 to solve the problem.

When I found the icon for the Spyware company on my lower icons and right-clicked it, it began a "software" scan. Each time I hit it to stop, it would restart where it left off each time I tried to click on something else. Told me I had 74 "severe risk" viruses on my computer, and that their Spyware would fix it for $49.99.

Rebooted...nothing. Tried to log onto Yahoo, ESPN, CA, etc, and just get getting the message. Shut down, rebooted again, nothing.

Finally solved it with a system restore, restoring my computer to yesterday's settings.

Just a heads-up in case this is going around, got through all my virus protection and firewalls.
Grandpa had the same thing. I ended up having to dig it out through a reg search. it sucked. freaking programs. I wonder how many people just buy the program
  Reply With Quote
Old 04-14-2009, 10:40 PM   #8
MedicCook
Mila smoked my cigar
 
MedicCook's Avatar
 
Join Date: Jan 2009
First Name: Ryan
Location: Schaghticoke, NY
Posts: 10,946
Trading: (7)
LGC
MedicCook has much to be proud ofMedicCook has much to be proud ofMedicCook has much to be proud ofMedicCook has much to be proud ofMedicCook has much to be proud ofMedicCook has much to be proud ofMedicCook has much to be proud ofMedicCook has much to be proud of
Default Re: Comptter Virus

I am convinced that these viruses are made by Norton & Co. just to sell more of their product.
MedicCook is offline   Reply With Quote
Old 04-14-2009, 11:31 PM   #9
TheRiddick
Non-believer
 
TheRiddick's Avatar
 
Join Date: Jan 2009
First Name: Greg
Location: Las Vegas
Posts: 943
Trading: (7)
TheRiddick will become famous soon enoughTheRiddick will become famous soon enough
Default Re: Comptter Virus

Quote:
Originally Posted by MedicCook View Post
I am convinced that these viruses are made by Norton & Co. just to sell more of their product.
A bunch of us, old IT guys, think this may be true. Don't forget, Norton was not much back in the day, all of a sudden a "virus" thing made it huge. As is, Norton is as much a virus as anything out there, it makes any PC crawl and it is next to impossible to root it out. I once spent a full day hacking through the registry and still didn't wipe it out completely. Same for McAfee, BTW.
TheRiddick is offline   Reply With Quote
Old 04-14-2009, 11:18 PM   #10
Genetic Defect
difetosso
 
Genetic Defect's Avatar
 
Join Date: Oct 2008
First Name: Perry
Location: An elevator
Posts: 5,202
Trading: (5)
VR
Genetic Defect has disabled reputation
Default Re: Computer Virus

__________________
I'm an outcast riding into town alone
I got wanderlust branded deeper than the bone
Genetic Defect is offline   Reply With Quote
Old 04-14-2009, 11:26 PM   #11
Whee
formerly illinoishoosier
 
Whee's Avatar
 
Join Date: Oct 2008
First Name: Sean
Location: Bishopville, SC
Posts: 3,591
Trading: (17)
Partagas
Whee is a splendid one to beholdWhee is a splendid one to beholdWhee is a splendid one to beholdWhee is a splendid one to beholdWhee is a splendid one to beholdWhee is a splendid one to behold
Default Re: Computer Virus

Well you're a "Fist Fightin' Son of a Gun" aren't you? All I got left is Little Miss Dangerous.
__________________
"Maybe I'm wrong, when they tell me they're right…..naaaaahhhhhh, I'm an asshooooooleeee"--Denis Leary
Whee is offline   Reply With Quote
Old 04-15-2009, 02:58 AM   #12
butterB
Guest
 
Posts: n/a
Default Re: Computer Virus

buy a Mac... all your virus problems will be gone
  Reply With Quote
Old 04-15-2009, 03:59 AM   #13
Savor the Stick
~Loves the Lord~
 
Savor the Stick's Avatar
 
Join Date: Oct 2008
First Name: Kevin, or just K
Location: Wichita Falls, Texas
Posts: 1,945
Trading: (67)
Partagas Navy (Served With Honor)
Savor the Stick has disabled reputation
Default Re: Computer Virus

Quote:
Originally Posted by icehog3 View Post

Every site I tried to reach, I got a message, with an Internet Explorer logo at the top, from a Spyware company saying the site I was trying to reach was unsafe, and that I could buy their software for $49.99 to solve the problem.

When I found the icon for the Spyware company on my lower icons and right-clicked it, it began a "software" scan. Each time I hit it to stop, it would restart where it left off each time I tried to click on something else. Told me I had 74 "severe risk" viruses on my computer, and that their Spyware would fix it for $49.99.

Rebooted...nothing. Tried to log onto Yahoo, ESPN, CA, etc, and just get getting the message. Shut down, rebooted again, nothing.

Finally solved it with a system restore
I had the same thing happen to mine. I hate these v's
__________________
Pastor K Please Support the Troops
Savor the Stick is offline   Reply With Quote
Old 04-15-2009, 05:19 AM   #14
SeanGAR
Crotchety Geezer
 
SeanGAR's Avatar
 
Join Date: Oct 2008
Location: Radford VA
Posts: 911
Trading: (3)
SeanGAR has disabled reputation
Default Re: Computer Virus

Ran a scan on a student's computer yesterday. She had around a dozen viri/trojans and around 60 spyware program instances (bunch of different ones) including this fake antivirus thing. Had to do some manual registry edits as well as dos boot antivirus scans and spybot. Quite a royal mess. Now I need to convince her to install Linux.
__________________
How can you have any pudding if you don't eat your meat?
SeanGAR is offline   Reply With Quote
Old 04-15-2009, 07:30 AM   #15
RGD.
God Like Status
 
RGD.'s Avatar
 
Join Date: Oct 2008
First Name: Ron
Location: Alexandria, Virginia
Posts: 971
Trading: (1)
VR Army (Served With Honor)
RGD. has a spectacular aura aboutRGD. has a spectacular aura aboutRGD. has a spectacular aura about
Default Re: Computer Virus

It's not the Conficker virus. It's either Antivirus 2009 or some variation of it. Restore very rarely works on these things.

Go here - and get the latest greatest and run the free version it.

Malwarebytes

A month or so ago I had it real bad and took two weeks working with the guy that developed that and with the Eset team. In the past I have just done a format - don't have the time now so I was determined to clean it. There is a previous post I made on it somewhere.

Here is one of my logs from when I had it - it will give you some of the file names to look for and delete:

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 10
Registry Values Infected: 4
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 12

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
c:\WINDOWS\system32\sekuseva.dll (Trojan.Vundo.H) -> Delete on reboot.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects\{ecb252fd-1b0f-4695-abbd-8a4930662488} (Trojan.BHO.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{ecb252fd-1b0f-4695-abbd-8a4930662488} (Trojan.BHO.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Ext\Stats\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Ext\Stats\{500bca15-57a7-4eaf-8143-8c619470b13d} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\yayyappf (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\MSFox (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\cpm87154a51 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\ShellServiceObjectDelayLoad\ssodl (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\javomanene (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\sekuseva.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\sekuseva.dll -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
c:\WINDOWS\system32\sekuseva.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\SysWOW64\wilelazi.dll (Trojan.BHO.H) -> Delete on reboot.
c:\WINDOWS\SysWOW64\sekuseva.dll (Trojan.BHO) -> Delete on reboot.
C:\WINDOWS\system32\awtsqoNg.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\jkkLedcD.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\opnKbcBS.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\opnnoopN.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\pmnlJcAr.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\xxyxXPfe.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\yayyApPF.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\~.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\lamahazi.dll (Trojan.Vundo) -> Quarantined and deleted successfully.


Also on edit: When a window pops up - don't click to stop it. Go to your processes and stop the iexplore32 process.




Ron
RGD. is offline   Reply With Quote
Old 04-15-2009, 07:36 AM   #16
rack04
Lebowski Urban Achiever
 
Join Date: Oct 2008
First Name: Justin
Location: Dallas, TX
Posts: 1,023
Trading: (20)
HUpmann
rack04 will become famous soon enoughrack04 will become famous soon enough
Default Re: Computer Virus

A couple years ago I came to the realization that Antivirus software is not something that I needed. As long as you don't open email attachments from people you don't know and don't download programs from unknown sources I think you should be OK. I've been clean and sober for 2 years.
__________________
"Why don't you put them in your secret compartment" - 12stones (Ricky)
rack04 is offline   Reply With Quote
Old 04-15-2009, 07:42 AM   #17
poker
1:11
 
poker's Avatar
2
 
Join Date: Oct 2008
First Name: Kelly
Location: SoCal
Posts: 5,280
Trading: (7)
Cohiba
poker has disabled reputation
Default Re: Computer Virus

Malwarebytes and AVG AV is what I use.
__________________

Cigar Asylum: A cigar board birthed without agendas, without profiting, and without advertisements. Amor puro


Character is what you do when no one is watching
poker is offline   Reply With Quote
Old 04-15-2009, 08:57 AM   #18
icehog3
Admiral Douchebag
 
icehog3's Avatar
15
 
Join Date: Oct 2008
First Name: Tom
Location: Clermont, Kentucky
Posts: 71,441
Trading: (60)
HUpmann
icehog3 has disabled reputation
Default Re: Computer Virus

Quote:
Originally Posted by butterB View Post
buy a Mac... all your virus problems will be gone
Next computer.

Quote:
Originally Posted by RGD. View Post
It's not the Conficker virus. It's either Antivirus 2009 or some variation of it. Restore very rarely works on these things.

Go here - and get the latest greatest and run the free version it.

Malwarebytes

Ron
Thanks Ron.
__________________


Thanks Dave, Julian, James, Kelly, Peter, Gerry, Dave, Mo, Frank, Tır and Mr. Mark!
icehog3 is offline   Reply With Quote
Old 04-15-2009, 09:00 AM   #19
icehog3
Admiral Douchebag
 
icehog3's Avatar
15
 
Join Date: Oct 2008
First Name: Tom
Location: Clermont, Kentucky
Posts: 71,441
Trading: (60)
HUpmann
icehog3 has disabled reputation
Default Re: Computer Virus

Ron, I looked at the website but was not sure which download was the right one, can you guide me?
__________________


Thanks Dave, Julian, James, Kelly, Peter, Gerry, Dave, Mo, Frank, Tır and Mr. Mark!
icehog3 is offline   Reply With Quote
Old 04-15-2009, 07:45 AM   #20
adampc22
Guest
 
Posts: n/a
Default Re: Computer Virus

i use f-secure its very good it scans file on your pc on its own just i case u forget to scan it
  Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -6. The time now is 02:20 AM.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
All content is copyrighted jointly by Cigar Asylum and the content provider.