|
||||
|
OH..... EM..... EFF... GEE
I have never, ever experienced a rogue trojan as bad as this one. I'm STILL trying to recover from it and I've been working on it for 6 hours. I went to brush my teeth last night before bed and came back to find about a million popups saying the system couldn't write or something to C:\System32\00026a23. I got other popups telling my harddrive was failing, the RAM was at critical levels. All my desktop items were gone, my background was gone, all the start menus were gone. It LOOKED LEGIT! It immediately popped up this "System Checker" that looked like a Windows program. Did it's "scan" and "found" problems with my harddrive being corrupted, etc. etc. It only "removed" SOME of them but wanted me to buy the full version ($85). It even has VeriSign and McAfee "badges" (none link to anything) to fool you. If you actually pay the money, you end up downloading the REAL virus. Anyway, I panicked for a bit, thinking it was legit, then hopped on my Android to Google (b/c I couldn't access the Internet from the computer or else the damn popups would come back). Found it was a virus. I couldn't start in Safe Mode. I couldn't do a restore (still can't). I kept trying, and trying, and trying to start in Safe mode. FINALLY it let me. I found this website: Remove System Check (Uninstall Guide) And followed it. When I went to install Malwarebytes (which I already had on the computer but couldn't access), the trojan tells me it was a "corrupt" file and "Access Denied." I tried several times before I just decided to IGNORE it and re-click on the installer for Malwarebytes. That worked. It tricked the trojan into allowing it to run. I let the full scan run while I slept and came back with 7 reported problems. I fixed them all according to the tutorial. I followed the rest of the tutorial but I'm still under attack. My icons still aren't back on my desktop. I still can't change my background (it's black at the moment). I can't access my Task Manager. I can't do a system restore. I'm running another Malware scan. I have to go to work soon, so I'll have to try and finish this when I get home. But holy jeez this is the worst I've ever had. I've never had it where you couldn't get into Safe mode and do a restore. There's no trojans left, apparently (UnhackMe told me so lol) but I bet there are still viruses. Unfortunately, the company I was working for pulled my Kaspersky off and put on Avast! which failed to catch the viruses (if they're viruses). If I can't fix it, I'm going to have to take it in and have someone with more expertise do it since my computer guy isn't answering his damn texts! I'd rather do it myself, since I'm about to go to the vet with the dog and fork out another $150 for a urine culture and antibiotics. Did I mention I have $11 in my bank account? This week cannot get any worse.
__________________
Nikon D40x | Nikkor 18-55mm f/3.5-5.6 | Nikkor 55-200mm f/4-5.6G | Nikon 50mm f/1.8D | Adobe Photoshop CS3 | Adobe Photoshop CS5 --Flickr |
|
||||
|
Can't. It won't let me do anything like that.
And I'm not ready to give up so easily. I have a lot of pictures on this computer and no external drive to throw them on to save them. Reinstalling Windows would make me lose them all. Not doing that.
__________________
Nikon D40x | Nikkor 18-55mm f/3.5-5.6 | Nikkor 55-200mm f/4-5.6G | Nikon 50mm f/1.8D | Adobe Photoshop CS3 | Adobe Photoshop CS5 --Flickr |
|
||||
|
Quote:
__________________
Nikon D40x | Nikkor 18-55mm f/3.5-5.6 | Nikkor 55-200mm f/4-5.6G | Nikon 50mm f/1.8D | Adobe Photoshop CS3 | Adobe Photoshop CS5 --Flickr |
|
||||
|
Quote:
__________________
Nikon D40x | Nikkor 18-55mm f/3.5-5.6 | Nikkor 55-200mm f/4-5.6G | Nikon 50mm f/1.8D | Adobe Photoshop CS3 | Adobe Photoshop CS5 --Flickr |
|
||||
|
Do you have the factory disk? Or the backup disk that came with it or made yourself? If you can get in to my computer - drive folders and copy everything over to a external. I know you said you didn't have one, but they are reasonably inexpensive if you can get one and copy everything over then use your recovery disk to restore your computer to factory settings ( just like new) out of the box.
__________________
I shoot for me - I shoot for fun. |
|
||||
|
This sort of thing is why you should always run Windows under a Limited account, aka not the Administrator account. An admin account can do anything. Edit the registry. Screw with the critical system folder files. Reroute your IP traffic to a proxy. Run malicious programs at start up on every account. Block access to system critical functions. You name it. If you're running as an admin and malicious code manages to find its way onto your system, that code has a free pass to screw up your PC in whatever awful ways it pleases.
When running as a Limited account however, you pretty much only have permission to change the settings within that account. You can't install malicious software, nor mess with \Windows\system32, nor \Program Files, nor the registry, nor any setting that affects the OS on a system-wide basis. If your account gets a virus/trojan, the infection is effectively quarantined to that single account. You can make a new account, delete the old one, and never worry about the infection again. Learn to love the limited account, it will save your ass.
__________________
My flickriver |
|
||||
|
Quote:
__________________
My flickriver |
![]() |
| Bookmarks |
| Thread Tools | |
| Display Modes | |
|
|
Each day we send out a quick email to thousands of DPS readers to notify them of updates. This email is just short excerpt of the first few lines of our latest post with a link if you want to read it all. You can unsubscribe from this this service at any time.
This service is provided by a third party (Feedburner) and you can subscribe to it by leaving your email address in the following field and confirming your subscription when you get an email asking you to do so.
Enter your email address for
Daily Updates:
For those wanting a weekly summary of what happens on this site this free email newsletter is probably your best option. It includes a summary of the tips posted to the site each week. This newsletter is subscribed to by over 25000 readers (many who also subscribe to the other options above) - come join the community!
To subscribe to this weekly newsletter simply add your email address to the following field and then follow the confirmation prompts. You will be able to unsubscribe at any time.
Enter your email address for
Free Weekly Newsletter: