If you have any stories you would like to add, feel free to contact our tech staff.
As always we can help with any computer repair needs you may have.
For No-obligation Computer Help call (775) 200-6171 or email your questions to us.
|
One of the first signs of infection is that it will hijack your browser launching pages upon pages of porn sites slowing your system to a crawl making your pc virtually unuseable. Upon loading these sites, more malware may be transfered to the computer. Another sign of infection is the following alert:
"Windows Security alert. Windows reports that your computer is infected. Antivirus software helps to protect your computer against viruses and other security threats. Click here for the scan you computer. Your system might be at risk now."
This particular bug however is not as difficult as others to repair. I do recommend that before attemting to repair this, that you have at least a basic understanding of the registry as removing the wrong keys can damage the operating system preventing the computer from booting up.
1) The first thing to do is to boot to a LiveCD and launch a registry editor. Look for files that are told to run at startup, specifically anything that uses "SYSGUARD", "SYSTEM TOOL" or "Antivirus System PRO" as part of the file name as well as other files that were out of place or do not belong in the "Run" sections of the registry. This prevents the malware from starting back up on restart.
2) After restart you may find that your browser if you use Internet Explorer will not load any pages. This infection changes your Internet Explorer settings to use a proxy server that prevents you from browsing any pages on the Internet. Therefore, if you only have Internet Explorer installed, we will first need need to fix this problem so that we can download the utilities we need to remove this infection.
3) Start Internet Explorer, then when the program is open, click on the "Tools" menu and then select "Internet Options". Click on the "Connections" tab and then on the "Lan Settings" button. Under the "Proxy Server" section, uncheck the checkbox labeled "Use a proxy server for your LAN". Then press the "OK" button to close this screen. Press the "Apply" button and then the "OK" button to close the Internet Options screen. Now that the the proxy server is disabled, you will be able to browse the web again with Internet Explorer.
4) Then search for and remove the following files:5) We then recommend using spyware and antivirus programs, Malwarebytes Anti-Malware 1.41, Ad-Aware Free Anti-Malware 8.1.0, Spybot - Search & Destroy 1.6.2, and Avast anti-virus to scan the drive and registry for any more signs of malware. Several may be found and removed. Finally, scan and optimized the registry.
Just verified this with Snopes and it is REAL.. ALSO WENT TO TRUTH OR FICTION, IT'S on their site also.
PLEASE INFORM EVERYONE you know! Emails with pictures of Osama Bin-Laden hanged are being sent and the moment that you open these emails your computer will crash and you will not be able to fix it!
1.) If you get an e-mail along the lines of 'Osama Bin Laden Captured' or 'Osama Hanged', don't open the Attachment!!!! This e-mail is being distributed through countries around the globe, but mainly in the US and Israel Be considerate & send this warning to whomever you know. PLEASE FORWARD THIS WARNING AMONG FRIENDS, FAMILY AND CONTACTS:
We'll start with this first part. NEVER EVER open any email attachment from people you don't know. Before you open an attachment, scan it with a good anti-virus scanner. If the files in the attachment don't match what they are suppose to be, don't open them. Delete them. For example, if the files are suppose to be images but the extension is an executable file such as .com, .dll, .exe, etc. These are not images and likely contain a virus. Also, the email says to inform everyone you know. It even gives a good argument for doing that. If you are going to notify several people, to not put their email addresses in the TO: field. Instead, use the BCC: (blind carbon copy) field. By doing this, you protect their email addresses from everyone else in your list and from being picked up from the net by spammers using programs called bots to harvest the addresses from the emails.
More information on this can be found on Snopes at www.snopes.com/computer/virus/osama.asp
Now for the second part of the email.
2.) You should be alert during the next few days: Do not open any message with an attached file called 'Invitation' regardless of who sent it. It is a virus that opens an Olympic Torch which 'burns' the whole hard disc C of your computer!!!! This virus will be received from someone who has your e-mail address in his/her contact list, which is why you should send this E-mail to all your contacts. It is better to receive this message 25 times than to receive the virus and open it. If you receive e-mail called 'invitation', even though sent by a friend. Do not open it!!! Shut down your computer immediately!!!! This is the worst virus announced by CNN; it has been classified by Microsoft as the most destructive virus ever. This virus was discovered by McAfee yesterday, and there is no repair yet for this kind. This virus simply destroys the zero sector of the hard disc, where other vital information is kept.
This part of the email is a HOAX! No such (incurable) virus exists! Please see www.snopes.com/computer/virus/invitation.asp at Snopes.
Please visit other sections of this site for information on remaining safe online and some of the dangers that are lurking in our area.
|
SecurityTool is a self-proclaimed anti-spyware program, promoted through pop-ups, Trojans and malware web sites. The rogue anti-spyware programs are distributed through web sites that simulate virus scans, and then the user is told to download the software to clean his PC.
Once installed, the SecurityTool will start automatically each time you turn on your PC and log in to Windows. Then it will start scanning your computer and show you a list of fake infections. When you try to clean the infected files, you are prompted to buy the software. This is a scam. Do not purchase the software. If you have already given your credit card information out, we recommend you contact the credit card company immediately and have the credit card replaced with a new number.
Be careful, don’t believe anything this rogue software prompts to you and DO NOT delete the infected files found by it, because those are just legitimate files.
The latest version we've seen disables the task manager and prevents you from booting into safe mode to greatly hinder its removal. It even shut down process explorer when we tried to run it. This program installs several different types of malware slowing your pc to a crawl. The method we found to remove it was by using a LiveCD to boot the machine and then manually remove the program and all of its components. This included removing entries that were made in the registry.
We then used Process Explorer to check the running processes and find other files that were not part of the windows operating system but attempted to mask themselves as such. Once those processes were killed, we were able to remove those files as well as their registry entries and perform a complete scan of the system.
Our advice is to keep your computer up to date, install a good anti-virus program, (we use Avast) as well as a good firewall (we use Comodo). Both Avast and Comodo have free versions as well as pro versions. If you use Avast antivirus, you will not want to install the Comodo Antivirus that comes with the firewall. Often having more than one anti-virus program installed causes conflicts and slows the system down. Another good idea is before downloading any software from a vendor you are not familiar with; always check the software through a search engine like Google. Make sure it is a legitimate program.
For more information on scams and other rogue applications like this one, please visit Symantec’s Security Blog, Rogue Apps – Catch Me if You Can.