Saturday, June 20, 2009

Still working at cleaning up $hiba!!!

18 comments:

  1. Just thought you'd all like to know... I think I got the virus taken care of... but I may be doing a complete system wipe & restart... We'll see. Anyway, just wanted to give you an update!!

    *HUGS to all*

    ReplyDelete
  2. You know what's strange Dio... I never did find out the exact name... I THINK... I have to admit... my cleaning up of it has been a bit ... uh... shall I say... like a Chicken McNugget? (Pieces parts) LOL

    **NOTE** If ANYONE has a virus... do NOT do what I did to combat it!! I do believe I went about it the hard way!! & I'm still waiting to see if I got it all!!!

    Anyway... I know EXACTLY what I did... & I will blog about how you all should NOT use Crack Codes or KeyGens (if Kitty hasn't beat me to it!)... I knew soon as I opened the file that it was going to be trouble... So, I started running AVG to try to find it... It didn't find anything... that way... HOWEVER... while I was doing it... one of the problems with the virus was an annoying audio ad... & so I opened task manager, I found the process in question & did the "end process"

    After a couple times of that happening... I wrote it down... & found it on the harddrive... scanned it & the on that was right next to (off by a couple numbers) & the one that was popping up did not have a virus... but the counter part had a "Trojan Fake Alert...." .... I don't know the rest, because I hurried up & put it in the virus vault & emptied my vault....

    This is why I am not sure what I had.

    Anyway... the annoying audio ad was gone... HOWEVER... when I was Googling.. my searches were being misdirected... So, I figured I still had something. (Because I was trying to Google for the Trojan removal.)

    WELL.... With all that... I have done a lot more... & I think I have got it... but like I said, I still waiting to hear back from the ones at MajorGeeks.

    Uh... I will stop here for everyone to see... & Dio... I just remembered... You might know something... Going to send you a PM!!! :)

    Again, all... DO NOT USE CRACK CODE / KEYGENS!! Not only are the illegal... but they likely have a virus!! As the forum says... even if you've had success in the past... you may just run into one that you won't.

    Figure... my 1st time... I'd get hit!! BUT HEY... LESSON LEARNED!!!

    Oh... one good thing has come out of this... I had to uninstall my AVG & reinstall it... & when I did... I got a component that I was missing!! WOO HOO... (Long story won't bore ya all with the details more than I already have!!) :)

    ReplyDelete
  3. Whew! I'm glad you found the virus and got rid of it. I've actually never even heard of crack codes/keygens before. At least, that doesn't sound familiar to me.

    ReplyDelete
  4. That was a Trojan, which is why AVG didn't catch it. Sounds like the kind the fake spyware and anti-virus companies put out. (see http://www.2-spyware.com/remove-antivirus-2009.html) for how to remove one of them. One of the things it does is to disable your browser so that you can only go to sites it approves of. Getting rid of these usually entails having a second uninfected computer to go to the places you need to get rid of the damned things. Anti-virus programs, any of them, are only so-so at catching Trojan programs.

    ReplyDelete
  5. Nah, I'll let you. Consider it part of your reform ;)

    ReplyDelete
  6. Crack codes are illegal codes posted in order to 'crack' software that is supposed to be purchased with a licence. They're called 'crack' because they give you a keycode to use to 'activate' the product.

    Keygens are programs that work on an algorithm to 'discover' the product key in order to activate the product which should be purchased with a license. Same thing, just different ways of going about it.

    The people who post these codes do so after purchasing legal copies (usually), the cost of which they recover by dropping hidden programs (usually a trojan or keystroke logger) to help them gain access to your personal information, along with a bag of other 'goodies' just for 'fun'.

    Other sites support themselves through association with porn sites, etc, in order to fund the cost of buying the legal software and hosting the site.

    Not only are these ripe with viruses, they're also illegal, and most companies will prosecute you to the full extent of the law if you are caught.

    We learned all about this in my course; the lecturer actually took us to several crack sites and taught us what to look for. I tell you, some of the stuff they have on there is awful! (ad-wise)

    Most people are pretty lenient on first offenders, and will help them rid their computer of the virus. If you do it more than once, though (and preferably not even that often), the people you turn to for help will most likely report you.

    This is why I was not too hard on Lady this time around; she didn't realise what she was getting into, and has learned her lesson well (haven't you hon LOL). I don't want to hear of ANY of you using these sites, however; having read this, you can't plead ignorance.

    ReplyDelete
  7. Yeah... I was lucky in the fact that I didn't get anything nasty... HOWEVER... the misdirecting of my links may have... if I had let it go... but I was prompted if I wanted to let it be redirected... Thankfully... I was a little more aware of what was happening!!

    I just hope that my hubby will learn from my lesson... He's the reason I even looked... & I had a sneaky feeling that I was opening a can of worms (oh, bad pun!! LOL) when I did this... but thankfully... I figured it out almost immediately after opening the file!! & Yep... I'm paying for it!!

    Oh... yeah... I never did get anything to "crack" the registration key for the game... So, no worries about the company coming after me for that!!! I just have the virus to deal with!!!

    I think I'll be doing a major clean of $hiba (meaning wiping clean & starting from out of the box type).... SO... if you all don't see me for a little while... you'll know what's going on! :)

    But it may take a little bit before I get to that point... for I still am backing up files & etc. ... Oh & I do have hubby's computer I can always sign onto!!

    (Yes... I'm on $hiba right now... I just am doing limited stuff. Still have not opened my email. Boy, that's going to be a headache when I finally can!!!)

    Well, I'm off to work some more on this! Toodles!! :)

    *tosses out some chocolate kisses & hugs to all*

    ReplyDelete
  8. Thanks for the explanation, Kitty!

    LH, I hope you have a current back-up of all of your files (or are able to do one before you wipe your drive). That would stink to lose your pictures and such.

    ReplyDelete
  9. Oh yeah... I have backed up stuff already!!

    Just wondering when it's going to be ok to do it? (Wipe the hd.)

    May I presume, Maegan, that you're keeping a watch on "The Last Word"??? Thanks ahead of time! :)

    ReplyDelete
  10. Yep.. I've been keeping an eye on The Last Word game. I'm glad you already have your files backed up. I know that's something I do every couple of months or so to keep a fairly current backup of our files.

    ReplyDelete
  11. Oh this has been a big learning lesson, that's for sure!!! Long story & I'm sure I'll blog about it... when I am up to it.

    Because I have a feeling after I get a clean bill of health from the help I'm getting... I think I may take a break from the computer for a day or so. (Getting to that burned out feeling again.)

    BY THE WAY... Dio, if you're still watching this... I found the exact name of what happened. (again, another long story) anyway, it was the Trojan.Vundo ... uh... is it a virus, malware ... Well, I don't know. But I think I finally got the bugger... but I have to wait to see!

    (Caught it with MalwareBytes Anti-Malware program.)

    So, that's where I am at the moment... Still thinking of wiping the hard drive & starting fresh... Thinking...

    ReplyDelete
  12. Yeah... I know Dio... it's been a pain! & the thing is I did NOT get it from an email!!

    & yet I have been lucky to have not had hardly any of what that link says it could do... YET... I hope that I caught it in time! & I hope that MajorGeeks can reassure me of that!! (They've been a great help. Yes, I'll be blogging about them once I get the all clear!) :)

    Let's recap... all that I've had problems with is... (mainly for my sanity than anything! LOL)
    1. an audio pop up ad (fixed?)
    2. Google searches redirected (fixed?)
    3. AVG found Trojan Fake Ad Alert (thought removed.)
    4. Malwarebytes found different Trojan (Vundo). (removed, I HOPE!)

    Now I still think I have stuff lurking about... but I am going to have to wait (on MG's reply!) & see...

    I SO NOT GOOD AT THIS WAITING GAME!!!!!!

    ReplyDelete
  13. Crikey! I was reading that Wiki article that Dio linked to, sounds like what Chrissy had! (In 2005, I had to take Chrissy back to her builder to be fixed, because of symptoms such as degraded performance, browser redirecting, explicit gay pornography flashing up (and being redirected to on the browser), and so on, and I was unable to find the source.

    My computer guy found that I'd picked it up from a social networking site that I used to frequent, called Sparkle Road.

    I mentioned this at work, and a co-worker (who I was connected to via email) said that he'd been getting the gay porn flashing up, and thought that his brother had done it as a joke, and had gotten mad at him. We worked out the timing, particularly the fact that it had started after I had sent him that email ...
    "What email?" I asked. I hadn't sent him an email for about two months prior. He said it had come the week before ...

    I switched to Firefox after that (linux-based, less prone), and started carefully guarding which sites I go to. Haven't had one since. I no longer go to Sparkle Road.

    ReplyDelete
  14. YIKES! ... See, I wonder if anyone is getting any emails from me during this time. We'll see!! :)

    ReplyDelete