Obscure Mania

Computers, Gadgets, Grilling, Politics and Anything Else I can think of

It’s what I was trying to point out in my last post, My PC Has Virus. You can have a bullet proof system with a great antiv-virus program, but if you download something you could be toast.

Trend Micro CEO: hackers hitting AV infrastructure
By Robert McMillan
October 23, 2009 06:28 PM ET

IDG News Service – It’s become an all-too-common scam: A legitimate Web site pops up a window that looks just like a real security warning. It says there’s something wrong with the computer, and click here to fix it. A few clicks later, the victim is paying out US$40 for some bogus software, called rogue antivirus.

The rest of the article is worth a quick read. What happened to my virus? I did it on virtual machine so it didn’t really affect anything real. Between school and work, I’m still playing with it.

The Real Fix

For an ordinary person is to backup your data and reinstall Windows. If you don’t already have a backup, it’s usually safe to backup only your Document folder, just none of your program folders. Reinstall with a quick format should do it. If not you don’t have a backup or your backup is infected, then you’re getting into the paid part of the program and finding someone that can boot into Linux or a specialized program on CD or bootable USB and cleaning it that way.

I went and got my PC infected on purpose. It was not hard at all, I clicked on a link in my spam mailbox and it went downhill from there, these things can be nasty!

How Did I Get Infected?

When I clicked a link it sent me to a website to watch a video and I was told I had to download something to view it, that’s the first clue. If you change your mind, it won’t let you cancel. It’s getting serious now and you should turn off the machine immediately because that’s the only way you’re getting away from that website.

So, I downloaded what it wanted and nothing happened, I still couldn’t watch the video. It was supposed to be good too! So I downloaded it again and again and still nothing. What did happen, a strange program popped up in my task manager as “a.exe”, I killed it, but I still had problems. Even if you kill every single process you think is a virus, it’s not enough and they’re only going to come back alive anyway.

If I did a search, either a different search engine would pop up or when I clicked a link, I went to a completely different website than what I clicked.

These programs are really helpful when they tell you you’re infected and they send you to a site that will scan your PC for free, then the scan tells you your PC is infected with 54 viruses that sound really nasty. Of course you want to get rid of them, but you have to pay $49.99 to download the anti-virus. And not just any anti-virus, their anti-virus, because it won’t let you go to any other site and download any other anti-virus.

Now What?

I tried to download a real anti-virus and I was able to download it, but every time I installed it, it would disappear. I couldn’t open a Command Line to run Microsoft’s MSRT program. Every time I would open a CMD window, it would open for a second, then disappear.

viruspicI tried going to legitimate sites that had virus scans and sometimes I could go there and start the scan, but it usually hung the system or got worse. Now I can’t start Internet Explorer or even another browser I downloaded earlier, it keeps bugging me about buying their protection and it won’t let me do anything else.

I also had something called “Spyware Doctor” that kept popping up too.

Every time I try and start a program a balloon pops up and tells me a program is a keylogger and it trying to steal my identity and sometimes it would throw in credit card information or equally scary stuff.

The program that kept bugging me to buy to fix everything was called “Security Tool” for $49 or for a lifetime of grief I could pay $79. Any time I would try and do something it would pop up and tell me something bad.

Going into control panel and clicking Add/Remove programs was when it would tell me it “detected harmful software” and they strongly recommend buying their crap to fix it. I couldn’t open the Properties of My Computer to go back to a Restore Point, this PC is really hosed.

I really feel bad for people that don’t know what to do, because even though I know what to do, it won’t let me.

What Did I Do?

To be continued…