Free Republic
Browse · Search
News/Activism
Topics · Post Article

I got caught by this last night. I am only minimally proficient in computer usage (enough to read sites)but if you run across this virus, this website will help. I actually spoke with someone who felt the only 100% certain way to remove this is to reinstall the OS. If this does not beong on Free Republi, I apologize.
1 posted on 08/17/2008 1:24:35 PM PDT by AZFolks
[ Post Reply | Private Reply | View Replies ]


To: AZFolks

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Download, follow the directions, good to go.


2 posted on 08/17/2008 1:26:11 PM PDT by Riley (The Fourth Estate is the Fifth Column.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: AZFolks

I had to remove it from a couple of machines at work.


3 posted on 08/17/2008 1:26:33 PM PDT by Army Air Corps (Four fried chickens and a coke)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: AZFolks

I apologize for the misspelling of belong and Republic.


4 posted on 08/17/2008 1:27:30 PM PDT by AZFolks
[ Post Reply | Private Reply | To 1 | View Replies ]

To: AZFolks

It also goes by VISTA 2008. I googled it a found I website I trusted for removable instructions. It required editing the registry.


5 posted on 08/17/2008 1:29:16 PM PDT by ThomasThomas (Orationem pulchram non habens, scribo ista linea in lingua Latina.***)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: AZFolks
The easiest thing to do that might help regarding viruses would be.

You do NOT turn off the computer once you see something is crazy, though you should pull out the Internet connection.

Do a search for new created files that day or so.
Look for especially .exe and .dll files newly created.

Hit Ctrl + ALt + Del and review running processes in task manager.

See particularly if any of the newly found files are running as processes.

Go to the internet and look the files up and see what they say.

Lastly close down, go to safe mode F8 key at startup and potentially delete the new files.

That would be an easily removable thing if caught like some viruses or ad ware.

It can get bad, once my niece asked me to check her computer. There were viruses going for many months, they corrupted the computer and I had to reinstall the operating system.
She had only 465 viruses found.

6 posted on 08/17/2008 1:32:13 PM PDT by A CA Guy ( God Bless America, God bless and keep safe our fighting men and women.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: AZFolks

Got caught last month by a form set up to emulate Vista.It found its way into my system and would not allow access to uninstall. I’d get popups telling me I had 73 viruses and trojans. My virus pgm dtected nothing. I wound up isolating and shredding it with windows defender. No trouble since.


7 posted on 08/17/2008 1:33:37 PM PDT by xkaydet65 (Freedom is purchased not with gold, but with steel.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: AZFolks
I recently disinfected a machine that had this and an older variant — Antivirus2008. And a rootkit that hid certain system files, so that the guy's machine wouldn't update. (He was running Service Pack 1...)

I believe in the death penalty for ——s who foist this crap on users who don't know any better.

8 posted on 08/17/2008 1:36:21 PM PDT by DJ Frisat (SPAM: best in the can and in sammiches -- not for use on computers.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: AZFolks

Put down the “beong” and step away from the Free Republi... :) Seriously, though, thanks for posting this.


12 posted on 08/17/2008 1:42:39 PM PDT by Andonius_99 (There are two sides to every issue. One is right, the other is wrong; but the middle is always evil.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: AZFolks

I’ve seen two computers eaten by this. It claims to be an antivirus program and convinces users to let it doa scan. and yes, if it gets far enough along it does require a Windows reinstall.

It doesn’t require reformatting, however, just a clean reinstall. That does mean you have to reinstall all your programs.


14 posted on 08/17/2008 1:46:39 PM PDT by js1138
[ Post Reply | Private Reply | To 1 | View Replies ]

To: AZFolks

On the rare occasions when something like this has happened, I’ve just used the system restore feature and it worked like a charm.


16 posted on 08/17/2008 1:51:30 PM PDT by kms61
[ Post Reply | Private Reply | To 1 | View Replies ]

To: AZFolks; All

How can I find out if this is on my system? This morning I turned it on and got busy elsewhere. I heard the system restart (a first without my being at the keyboard) and it came up the way it usually does.

I’ve got the Vista OS on my computer.

Thanks. I’m not a computer geek at all and the older I get the more I hate to deal with technical things.


20 posted on 08/17/2008 2:13:08 PM PDT by proudofthesouth (Homosexuality IS a choice! There isn't any biological reason for it. They CHOOSE to be that way!)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: AZFolks; rdb3; Calvinist_Dark_Lord; GodGunsandGuts; CyberCowboy777; Salo; Bobsat; JosephW; ...

21 posted on 08/17/2008 2:22:15 PM PDT by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: AZFolks

Did you download and install the thing, or did you just get redirected to the website. I got the redirect, but I didn’t install the thing.


23 posted on 08/17/2008 2:27:21 PM PDT by Gondring (I'll give up my right to die when hell freezes over my dead body!)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: AZFolks

Hah, sounds like you got hit by a rootkit trojan. I got infected by one a few weeks ago. I downloaded and ran SDFix to remove it.


31 posted on 08/17/2008 3:10:14 PM PDT by Justa (The media lied while Americans died.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: AZFolks
There are a number of different "strains" of this nasty piece of work. In and of itself, it's what can be described as "Extortion-ware." However quite a few "bad guys" have grabbed it and piggybacked all sorts of nasty trojans and keystroke loggers along with it. A buddy of mine got hit by it, and it was impossible to safely remove. In fact, it even infected the HP system restore files on the hidden partition. Among other things, it locked out the Administrator's account, disabled regedit and other system utilities using policies.

The only thing I could do was boot the infected system to BARTS, and then copy the files they wanted to save to another system with functional AV... Then wipe the disk and do a fresh install off of DVDs they had to order from HP. It was UGLY.

Mark

67 posted on 08/17/2008 6:44:44 PM PDT by MarkL (Al Gore: The Greenhouse Gasbag! (heard on Bob Brinker's Money Talk))
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Nightshift

gnip...


68 posted on 08/17/2008 6:49:38 PM PDT by tutstar (Baptist Ping list - freepmail me to get on or off.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: AZFolks

I just got finished fixing a PC after this nasty infected it. In the end, to fix the corrupted files I had to wipe her clean and reinstall Winders. What a pain.


78 posted on 08/18/2008 8:31:59 AM PDT by Bloody Sam Roberts (There are many kinds of love. As for me, nothing swells the heart quite like love of country.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: AZFolks

Having read all the comments in this thread, I know most of the technical comments would be incomprehensible to the average computer user - the kinds of people that turn to me for help. Many of you are highly technical, but most users aren’t. They either don’t realize how bad the security problem is, or else they try to ignore the problem and keep computing until the PC won’t run. After my son’s Windows PC got clobbered a few times, I decided to make a radical change. Now he boots his PC from a Ubuntu Linux CD. There is nothing for a virus or worm to corrupt, because a CD cannot be overwritten. In the unlikely event that the Linux session was ever compromised, you turn off the PC and poof! the virus is gone. I’m running the FireFox browser on a Linux PC right now and it looks just the same as if running on a Windows PC.


79 posted on 08/18/2008 1:17:06 PM PDT by TexasRepublic (When hopelessness replaces hope, it opens the door to evil.)
[ Post Reply | Private Reply | To 1 | View Replies ]

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson