Free Republic
Browse · Search
Bloggers & Personal
Topics · Post Article

To: little jeremiah

I got the virus yesterday too when I visited that site. A nasty one. It was one of the Fraud type viruses. It deactivates the windows Active Desktop, then uses attrib.exe to set the HIDDEN attributes on most of the Start Menu folders to seemingly wipe out your whole system. After it wipes out your desktop it puts up an Advertisement where you can pay someone money to get it out of your system. It ripped my notebook here a new one. I immediately opened the running process window and started dumping processes that shouldnt be running. normally I have 12 but this added 3 more. by going into Safe mode and running Spybot Search and Destroy it got rid of the virus infection, but nothing was left but a blank desktop, so it took a few hours to go into that subsystem and unHIDE stuff and reconstitute a few things by taking files off of another good running system. AND then after all of that, I ran tdsskiller to look for a ROOT KIT and sure enough it had put in a root kit too, but luckily tdsskiller got rid of it... I got the impression it was some kind of DU trick. It may have come in through the banner advertisements on that page like most viruses seem to (come in through banner adverts). what a day


1,463 posted on 05/25/2011 7:23:19 AM PDT by WashStateGirl
[ Post Reply | Private Reply | To 1458 | View Replies ]


To: WashStateGirl; Fred Nerks

Fred, check out WashStateGirl’s comments about what happened to her computer.


1,464 posted on 05/25/2011 7:32:06 AM PDT by little jeremiah (Courage is not simply one of the virtues, but the form of every virtue at the testing point. CSLewis)
[ Post Reply | Private Reply | To 1463 | View Replies ]

Free Republic
Browse · Search
Bloggers & Personal
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson