 | |
08-06-2011, 10:22 AM
|
#101 | | Couldnt take it anymore Join Date: Sep 2010 Location: Mod impersonation carries a stiff penalty YKWYA
Posts: 10,761
| I used eset online scanner to remove it before...
__________________ |
| |
08-06-2011, 10:40 AM
|
#102 | | Vapezilla Join Date: Oct 2010 Location: Escaping Hades
Posts: 9,724
| Quote:
Originally Posted by CountryCarolyn I haven't tried that one but this thing needs to be detected before it fully executes. It's that bad. It blocks internet, I tried removing the dll out of it and it regenerates. Reminds me of a worm infection. | I believe they have pills for that now |
| |
08-06-2011, 10:41 AM
|
#103 | | Vapezilla Join Date: Oct 2010 Location: Escaping Hades
Posts: 9,724
| Quote:
Originally Posted by berger I used eset online scanner to remove it before... | That scanner is awesome! Takes a long time to scan everything but works very well. I use it at least once a week now that you told me about it. |
| |
08-06-2011, 11:06 AM
|
#104 | | Banned Join Date: Jul 2011 Location: tennessee
Posts: 1,095
| Before it executes I shut my computer down. I have my settings to remove cookies and history upon exit of firefox. Reboot and I am good!! I have my dad set the same way, he never reboots and rarely closes his browser, so it does him little good.
Last edited by CountryCarolyn; 08-06-2011 at 11:24 AM..
|
| |
08-06-2011, 11:24 AM
|
#105 | | Vapezilla Join Date: Oct 2010 Location: Escaping Hades
Posts: 9,724
| Quote:
Originally Posted by CountryCarolyn Before it executes I shut my computer down. I have my settings to remove cookies and history upon exit of firefox. Reboot and I am good!! I have my dad set the same way, he never reboots and rarely closes his browser. | I had it happen once when I was looking for desk pad calendars. What a PITA! Hope I never stumble across another either. |
| |
08-06-2011, 11:36 AM
|
#106 | | Banned Join Date: Jul 2011 Location: tennessee
Posts: 1,095
| I was on facebook looking at a friends pictures when I encountered it. I understand how people execute it cause it looks like it is coming from windows. If I hadn't already formatted my fathers and experienced it like that, I would of probably executed it. |
| |
08-06-2011, 11:46 AM
|
#107 | | Senior Member Join Date: May 2011 Location: Iz in ur megabites, stealin ur avatars
Posts: 1,338
| I'm not sure if an AV detects Security Center as a virus/malware.
It seems to get treated just like any other program you choose to install.
The only success I've had removing it involves using RKill to kill the process and then Malwarebytes to get rid of it while it's temporarily disabled.
I've never been able to try an online scanner because by the time I get the infected PC it's already blocking the browser from accessing certain sites or downloading any programs.
Bleeping Computer has an easy to follow guide for removing it here: http://www.bleepingcomputer.com/viru...ecurity-center
It may take a few attempts, but eventually you'll succeed. |
| |
08-06-2011, 12:34 PM
|
#108 | | Threadkiller/foot gourmet Join Date: Jun 2011 Location: PA
Posts: 298
| Little trick I've found handy for when I'm in that horrid situation, (internet blocked, all hell has ensued) if you have already identified the virus file name or process, rename your browser executable and antivirus executable to the name of the operating virus file. Most apply permissions giving themselves full access and control of everything, but don't check file size, parity, checksum data or anything else, so the virus lets it out, it thinks it's itself. I've only ever had to boot from a dos disk and use file utilities once to rename stuff, that was a particularly nasty one though. I've gotten much better at backing up lately, downloading multiple mmos and patching them at the last minute really kills my weekend, so I image frequently now, and have an old HP machine that stays off the network and does nothing but hold images. I use macrim reflect btw berger, it takes longer to image, but I find the images to be a bit more stable than other free programs.
__________________ No trees were harmed in sending this message, but a large number of electrons were terribly inconvenienced. |
| |
08-06-2011, 07:00 PM
|
#109 | | Couldnt take it anymore Join Date: Sep 2010 Location: Mod impersonation carries a stiff penalty YKWYA
Posts: 10,761
| I used to use acronis on disk and have had to use it a few times...one due to norton live update that caused spontaneous reboots....but all of them need to be tested prior to actual need..or else..  ...on fresh installs I will restore after to make sure it actually works..rather find out then I have an issue..
__________________ |
| |
08-06-2011, 07:25 PM
|
#110 | | Vapezilla Join Date: Oct 2010 Location: Escaping Hades
Posts: 9,724
| Looks like I will be learning all about imaging stuff before too long. |
| |
08-06-2011, 07:37 PM
|
#111 | | Threadkiller/foot gourmet Join Date: Jun 2011 Location: PA
Posts: 298
| always restore after image, if not to the source box, to a copy, and have an OS install disk on hand, just in case...
I bought two for just that reason, to play
__________________ No trees were harmed in sending this message, but a large number of electrons were terribly inconvenienced. |
| |
08-06-2011, 08:24 PM
|
#112 | | Darth Vaper Join Date: Sep 2010 Location: Leftern Mass
Posts: 10,348
| Quote:
Originally Posted by CountryCarolyn Before it executes I shut my computer down. I have my settings to remove cookies and history upon exit of firefox. Reboot and I am good!! I have my dad set the same way, he never reboots and rarely closes his browser, so it does him little good. | That thing is a PITA. I haven't found anything to remove it, but you can easily edit the registry and cut it out and then remove the executable.
__________________ Do you mind if I STEAM?! "well, you see Steam, we never had a rule about it because we didn't think anybody would ever DO it!" I'm one lab accident away from being a supervillan. I knew that a hole wasn't from jersey...
Now will you all please leave while Dr Berger and I make out the Death Certificates! |
| |
08-06-2011, 08:25 PM
|
#113 | | Darth Vaper Join Date: Sep 2010 Location: Leftern Mass
Posts: 10,348
| Quote:
Originally Posted by rglassmyer always restore after image, if not to the source box, to a copy, and have an OS install disk on hand, just in case...
I bought two for just that reason, to play  | http://www.mypclinuxos.com/
__________________ Do you mind if I STEAM?! "well, you see Steam, we never had a rule about it because we didn't think anybody would ever DO it!" I'm one lab accident away from being a supervillan. I knew that a hole wasn't from jersey...
Now will you all please leave while Dr Berger and I make out the Death Certificates! |
| |
08-06-2011, 10:30 PM
|
#114 | | Vapezilla Join Date: Oct 2010 Location: Escaping Hades
Posts: 9,724
| Quote:
Originally Posted by rglassmyer always restore after image, if not to the source box, to a copy, and have an OS install disk on hand, just in case...
I bought two for just that reason, to play  | Berger is going to show me how when I get my stuff situated. Guess it is about time I learned. |
| |
10-30-2011, 12:16 AM
|
#115 | | Junior Member Join Date: Oct 2011 Location: Texas
Posts: 23
| Wow talk about off topic.....nice flash back to the past though!
I have used ecigexpress for flavors and they have great prices fast shipping considering the distance traveled (Wa to Tx in 3 days) the range of selection is vast and varied. The Faerie Queen aka my wife loves the Lorann Bubble Gum and we must always have at least 30ml of juice at the ready to keep her carts full. |
| |
10-30-2011, 12:28 AM
|
#116 | | Vapezilla Join Date: Oct 2010 Location: Escaping Hades
Posts: 9,724
| Quote:
Originally Posted by DykeWymn Wow talk about off topic.....nice flash back to the past though!
I have used ecigexpress for flavors and they have great prices fast shipping considering the distance traveled (Wa to Tx in 3 days) the range of selection is vast and varied. The Faerie Queen aka my wife loves the Lorann Bubble Gum and we must always have at least 30ml of juice at the ready to keep her carts full. | Yeah, we get off topic at times.  Sounds like me with some of my RY4 flavors. |
| |  | | | |