Southern Maryland Online - Serving Calvert, Charles, & St. Mary's Counties.  Click here to go to the Front Page of somd.com.
 
| Write Us | Help | Sponsors | Classifieds | Employment | Forums | MarketPlace | Calendar | Headlines | Announcements | Weather | More... |


Go Back   Southern Maryland Community Forums > General Interest > Computers, Technology, & the Internet
Register Blogs FAQ Members List Calendar Chat Search Today's Posts Mark Forums Read Wireless

Computers, Technology, & the Internet Talk about computers, the net and the latest technology, e.g. music, video, wireless, you name it. Who do you love more? Your wife or your Tivo?

Reply
 
LinkBack Thread Tools Display Modes
Old 12-17-2008, 02:08 PM   #1 (permalink)
Flame Tamer
 
G1G4's Avatar
 
Member Since: Jul 2008
Location: SMC
Posts: 1,583
A Nasty Little Virus

I'm not sure how, but yesterday I got a virus. It would give me repeated BSOD's on normal boot attempts. The only way I could access anything is to boot into Safe Mode with Networking. Anyway, after about 9 hours, I came to the conclusion that it's imbedded itself into Winlogon. Even in safe mode, explorer would repeatedly crash, so that left me to leaving explorer alone when the message came up, and surf through notepad to delete files that I needed.
It locked the registry, turned off system restore, and hijacked my DNS to the point that I couldn't go to any antivirus sites or the Windows/Microsoft website. I finally gave up and replaced my hard drive with an old HD I had lying around. Anybody else had any experience with a virus like this? It's almost like Virtumondo, but worse.
G1G4 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Add post to Facebook
[ Reply w/Quote ]
Old 12-17-2008, 02:30 PM   #2 (permalink)
.
 
GWguy's Avatar
 
Member Since: Sep 2007
Location: I got nuttin.
Posts: 13,317
Quote:
Originally Posted by G1G4 View Post
I'm not sure how, but yesterday I got a virus. It would give me repeated BSOD's on normal boot attempts. The only way I could access anything is to boot into Safe Mode with Networking. Anyway, after about 9 hours, I came to the conclusion that it's imbedded itself into Winlogon. Even in safe mode, explorer would repeatedly crash, so that left me to leaving explorer alone when the message came up, and surf through notepad to delete files that I needed.
It locked the registry, turned off system restore, and hijacked my DNS to the point that I couldn't go to any antivirus sites or the Windows/Microsoft website. I finally gave up and replaced my hard drive with an old HD I had lying around. Anybody else had any experience with a virus like this? It's almost like Virtumondo, but worse.
There's a few that have those symptoms. Once you get them, it's just easier to wipe and reinstall.

Just goes to show, even us techies get bit once in a while, no matter how good your defenses are.
__________________
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
Sunday

There is no "Someday".
GWguy is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Add post to Facebook
[ Reply w/Quote ]
Old 12-17-2008, 02:34 PM   #3 (permalink)
Shaving the bits
 
Geek's Avatar
 
Member Since: Nov 2005
Location: Fantasyland
Posts: 11,295
Blog Entries: 1
I heard not to open anything named "postcard"
__________________
.·:*¨¨*:·. .·:*¨¨*:·.If you are not having a good time, it's your own damn fault .·:*¨¨*:·. .·:*¨¨*:

Quote:
Originally Posted by Mojo View Post
I told you, Geek paved the way a long time ago
Geek is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Add post to Facebook
[ Reply w/Quote ]
Old 12-17-2008, 02:46 PM   #4 (permalink)
.
 
GWguy's Avatar
 
Member Since: Sep 2007
Location: I got nuttin.
Posts: 13,317
Quote:
Originally Posted by Geek View Post
I heard not to open anything named "postcard"
Half true. That's been floating around for a few years. Look it up on snopes for the details. I'd post it, but don't have access to snopes from here.
__________________
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
Sunday

There is no "Someday".
GWguy is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Add post to Facebook
[ Reply w/Quote ]
Old 12-17-2008, 03:34 PM   #5 (permalink)
Flame Tamer
 
G1G4's Avatar
 
Member Since: Jul 2008
Location: SMC
Posts: 1,583
Yep, completely unaware how I got it. I was going to try a system recovery, but it wouldn't even let me boot from a cd lol. I was on the verge of deleting everything and just starting over, until I remembered I had that old computer lying around. I put that in and the damn thing didn't want to recognize the mouse and keyboard.
G1G4 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Add post to Facebook
[ Reply w/Quote ]
Old 12-17-2008, 05:45 PM   #6 (permalink)
Registered User
 
bobbyb's Avatar
 
Member Since: Mar 2007
Posts: 228
Did you run Stinger.exe????
bobbyb is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Add post to Facebook
[ Reply w/Quote ]
Old 12-17-2008, 06:02 PM   #7 (permalink)
Just play
 
PsyOps's Avatar
 
Member Since: Sep 2006
Posts: 10,299
Quote:
Originally Posted by G1G4 View Post
Yep, completely unaware how I got it. I was going to try a system recovery, but it wouldn't even let me boot from a cd lol. I was on the verge of deleting everything and just starting over, until I remembered I had that old computer lying around. I put that in and the damn thing didn't want to recognize the mouse and keyboard.
I just spent this past Saturday working on my dad's PC that sounds like the same thing. He is doing geneology research on our family, and we have some relatives in the Ukraine and Russia. Well, he went to (what appeared to be) a Russian website, then all h3ll broke loose. I tried Symantec, AVG, Vipre, and PC-cilin to try to clean it up and all of them seemed to be blocked to gather definition updates. When I ran IE the PC would lock up.

All the symptoms you describes were the same except we were able to boot from CD and reload windows which solved the problem. He lost a lot of photos and other files, so now I've bought him an external HD for Christmas for his file storage. What a mess. I have a fingernail extraction tool that is ready when they catch these creeps that create these viruses.
__________________
My relationship to music is a very personal one.
PsyOps is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Add post to Facebook
[ Reply w/Quote ]
Old 12-17-2008, 06:43 PM   #8 (permalink)
Flame Tamer
 
G1G4's Avatar
 
Member Since: Jul 2008
Location: SMC
Posts: 1,583
Quote:
Originally Posted by bobbyb View Post
Did you run Stinger.exe????
Negative.

Quote:
Originally Posted by Psyops View Post
I just spent this past Saturday working on my dad's PC that sounds like the same thing. He is doing geneology research on our family, and we have some relatives in the Ukraine and Russia. Well, he went to (what appeared to be) a Russian website, then all h3ll broke loose. I tried Symantec, AVG, Vipre, and PC-cilin to try to clean it up and all of them seemed to be blocked to gather definition updates. When I ran IE the PC would lock up.

All the symptoms you describes were the same except we were able to boot from CD and reload windows which solved the problem. He lost a lot of photos and other files, so now I've bought him an external HD for Christmas for his file storage. What a mess. I have a fingernail extraction tool that is ready when they catch these creeps that create these viruses.
It probably was. Sad thing is, I don't think it's a new virus. I think it's an old virus/trojan that has taken a new variation. It was NASTY.
G1G4 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Add post to Facebook
[ Reply w/Quote ]
Old 12-17-2008, 06:56 PM   #9 (permalink)
.
 
GWguy's Avatar
 
Member Since: Sep 2007
Location: I got nuttin.
Posts: 13,317
Quote:
Originally Posted by PsyOps View Post
He lost a lot of photos and other files, so now I've bought him an external HD for Christmas for his file storage.
That didn't have to be the case. The drive could have been accessed without going thru the corrupted operating system, and everything could have been saved, scanned for viruses and restored.

I take the drive out, connect it to a USB adapter and hook it to a computer that I don't care about.
__________________
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
Sunday

There is no "Someday".
GWguy is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Add post to Facebook
[ Reply w/Quote ]
Old 12-17-2008, 07:59 PM   #10 (permalink)
Flame Tamer
 
G1G4's Avatar
 
Member Since: Jul 2008
Location: SMC
Posts: 1,583
Quote:
Originally Posted by GWguy View Post
That didn't have to be the case. The drive could have been accessed without going thru the corrupted operating system, and everything could have been saved, scanned for viruses and restored.

I take the drive out, connect it to a USB adapter and hook it to a computer that I don't care about.
That's part of the reason why I didn't format. I can still access and move everything to my slave drive, THEN put it back onto my main drive. Thank god for know-how and technology.
G1G4 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Add post to Facebook
[ Reply w/Quote ]
Reply




Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -4. The time now is 01:48 AM.



| Home | Help | Contact Us | About somd.com | Privacy | Advertising | Sponsors | Newsletter |

| What's New | What's Cool | Top Rated | Add A Link | Mod a Link | Link to Us |

| Announcements | Bookstore | Chat | Calendar | Classifieds | Community |
| Contests & Surveys | Culture | Dating | Dining | Education | Employment | Entertainment |
| Forums | Free E-Mail | Games | Gear! | Government | Guestbook | Health | Marketplace | Mortgage | News |
| Organizations | Photos | Postcard | Real Estate | Relocation | Sports | Survey | Travel | Wiki | Weather | Worship |

Brought to you by Virtually Everything, Inc.   ©1996-2009, All rights reserved.


SEO by vBSEO 3.1.0 ©2007, Crawlability, Inc.