Home
 Downloads
 Forums
 Apply Here
D. Knight - Closed
Druid - Closed
Hunter - Closed
Mage - Closed
Paladin - Closed
Priest - Closed
Rogue - Closed
Shaman - Closed
Warlock - Closed
Warrior - Closed


You must be logged in to post comments on this site - please either log in or if you are not registered click here to signup


iconoclast on 07 Sep : 13:52
Sept. 9th, be on!!
EtherBoo on 06 Sep : 21:11
VV is gay..
Shill on 23 Aug : 14:34
^^ was here..
EtherBoo on 21 Aug : 16:51
Holy shit, Bal on the forums? WTF?
Grishuruk on 19 Aug : 06:07
Dear god! not bal back in the game again.
Ånima on 18 Aug : 23:57
do it, u kno u want to
Morphz on 18 Aug : 14:26
Don't do it!!!
ballthazar on 17 Aug : 08:12
hmm to wow or not to wow
EtherBoo on 06 Aug : 07:46
Was that a question or a statement Craig?
iconoclast on 05 Aug : 17:34
I will be at a company function tomorrow. Not sure how late i'll be,
iconoclast on 02 Aug : 08:03
Aren't you a stand up guy.
Grishuruk on 01 Aug : 20:26
I have my own vent so... not it! lol.
iconoclast on 26 Jul : 08:45
Ventrilo is due once again... I put in half.
Emry on 25 Jul : 14:15
I didn't get hacked until 3 months after I deactivated my account. Then again about 18hrs after I reactivated my account.
Featherstep on 23 Jul : 23:50
Keep clicking on those pr0n links and you're bound to be hacked.

Attrition :: Forums :: Visitor Center :: General Chat
 
<< Previous thread | Next thread >>
BEWARE of INTERNET SECURITY 2010!!!
Moderators: iconoclast, TheDarkside, Manube, Morwraith, Agrilles
Author Post
Tànk
Wed Feb 10 2010, 11:46PM
Registered Member #960
Joined: Sun Jan 31 2010, 08:35PM
Posts: 39
You do not want this! Not sure how it found me, but I received a popup from this at lunch today, and my computer has gone downhill since then. This is a nasty virus, that will cause you lots of grief. Not sure how much damage was done already even by the time you see the popup, but as soon as you get a popup, touch nothing, shut your computer off, and find an alternate computer to plan your attack on preserving your system. I did not install this (intentially anyways), but I did click cancel, and that might have been enough, as cancel buttons can be set to function exactly like the 'Ok' button. It looks official enough when it first popped up, and it will run a fake scan that tells you to install it now to fix these, so unless you are aware of it ahead of time, you might make the mistake of clicking something.

This virus attacks your registry. It will change values to limit your ability to perform functions, and this is the beginning of the end. It changes your login info, disables your task manager, and who knows what else. I was able to go into my registry, and enable the task manager (which you need to do to kill the virus processes currently running), and I reset my login info. However, once I was in the task manager, the process names were multiples of each other (some being Microsoft), so I was unable to determine which threads to kill. It will also block you from installing, and running things set to kill it, such as Malwarebytes, so this was another punch your fist through the wall set back.

After a couple hours of trying to oust this beast, and an hour more of planning how I was going to find the fucker that codes these, and apply some pain, I gave up, wiped all my drives, and have begun the reinstall process. I have windows back up and running with all patches and drivers current. Got all of my HDDs reformatted, and defragged, etc, so at least functional. Currently going through the eight hour reinstall of wow.

A note on security apps, as I suggest everyone make sure theirs is current, and of good quality. If not, get it current, and find one that is. I was using the free version of AVG, and it still got through. To hell with AVG. I brought home a paid version of Kaspersky from work, and that is my new protection. We'll see how it works.
Back to top
iconoclast
Thu Feb 11 2010, 08:15AM


Registered Member #1
Joined: Fri Mar 30 2007, 08:06AM
Posts: 1778
GL man



Back to top
EtherBoo
Thu Feb 11 2010, 08:51AM
Registered Member #67
Joined: Wed May 23 2007, 08:51PM
Posts: 1045
Best thing to do when you see that is ALT+F4.

Any interaction with the pop-up (assuming you're talking about a pop-up on a web page) will usually mean "Yes."

Formatting was a good idea.

If you got this from the web (most likely), here are my recommendations to help prevent this kind of thing from happening.
1) Use Firefox. No other browser is as customizable and secure as Firefox.
2) Use the "NoScript" Addon. This takes the out of the box Firefox, and makes makes it super secure by disabling JavaScript. It doesn't allow scripts to run unless you allow it.

The bad thing about this is that it breaks some web pages. You pick and choose which scripts are allowed. For example, if I didn't want to wait for the vent add-in to load on this site, I would just click the NoScript button and click "Forbid ugt-servers.com" This speeds up the load time by not processing any information sent from that site. The bad news is I can't see who's on vent (not a huge deal anyway).

Most sites are untrusted to begin with, so I had to allow scripts to be run to show that.

3) Use Ad-Block Plus. It blocks ads, or more specifically, traffic from known advertising sites. You can ad filters as you go. For example, I have a filter "*double-click.com*" The *'s mean a wild card, so my browser just ignores traffic from anything that has "double-click.com" in it's name.

------------------

I rarely get SpyWare / AdWare and viruses.

I'd also recommend a good Firewall. Zone Alarm Plus is pretty good I hear.
Back to top
Evalin
Thu Feb 11 2010, 10:28AM
Registered Member #955
Joined: Fri Jan 29 2010, 03:34AM
Posts: 39
Damn bro that sucks. GL I know how fun that install can be :0

Back to top
bigoil
Thu Feb 11 2010, 03:36PM
Registered Member #381
Joined: Mon Mar 17 2008, 06:26PM
Posts: 32
Ive had luck with ComboFix taking care of that types of virus.
Back to top
Iocane
Thu Feb 11 2010, 04:01PM

Registered Member #558
Joined: Fri Aug 22 2008, 04:32PM
Posts: 140
same, ad-block plus and noscript for my firefox, and combofix in case anything does get through

Back to top
 

Jump:     Back to top

Syndicate this thread: rss 0.92 Syndicate this thread: rss 2.0 Syndicate this thread: RDF
Powered by e107 Forum System
Username:

Password:


Remember me

[ ]
[ ]
[ ]
Guests: 3, Members: 0 ...

most ever online: 33
(Members: 0, Guests: 33) on 07 Jun : 00:51

Members: 821
Newest member: Breasandis
This site is powered by e107, which is released under the terms of the GNU GPL License.
Distributed by %THEMESBASE_TAG%, %THEMESBASE_TAG%