Virused.
Moderator: clw54
- adamlaneus
- CCW likes me more than Rollo
- Posts: 37805
- Joined: Sun Jan 03, 2010 1:30 pm
- Location: Close to SanFran
Virused.
Through the fuddernutter swiss cheese that is the damn microsoft operating system.
Virus software never saw anything.
I'm burning the computer right now; typing from my alternate.
Yay, Friday. Time for some whine!
Virus software never saw anything.
I'm burning the computer right now; typing from my alternate.
Yay, Friday. Time for some whine!
- adamlaneus
- CCW likes me more than Rollo
- Posts: 37805
- Joined: Sun Jan 03, 2010 1:30 pm
- Location: Close to SanFran
I detected it when I launched Internet Explorer and my computer became slow. The task manager indicated that something was chewing up about one minute of CPU time needlessly. Not only was it impacting my work, but it's just not supposed to work like that. No CPU time should be used for showing a damn blank page.
So, I run Internet Explorer. Then I run the debugger; attach it to iexplore.exe. Stop it cold. Bring up the list of modules. One of the modules is running from my temp directory. "mstmp" That is never a good sign. I delete the file and then search my registry. Yep; it's installed itself as a "Microsoft Improved HTML MIME Filter". Looks like an Office component. But it's malware.
The only solution is to format the drive and pave it over. There is no such thing as 100% reliably removing a virus from an operating system. I might have gotten one tendril, but these things tend to come in packages and there's no good way to undo damage. There are too many hidey-holes in the operating system. I've learned about some of them just by studying my own infected (or my dad's infected) computers.
I feel sorry for computer owners on some days. Not everyone knows how to use a debugger. Elmo.
Anger anger anger.
So, I run Internet Explorer. Then I run the debugger; attach it to iexplore.exe. Stop it cold. Bring up the list of modules. One of the modules is running from my temp directory. "mstmp" That is never a good sign. I delete the file and then search my registry. Yep; it's installed itself as a "Microsoft Improved HTML MIME Filter". Looks like an Office component. But it's malware.
The only solution is to format the drive and pave it over. There is no such thing as 100% reliably removing a virus from an operating system. I might have gotten one tendril, but these things tend to come in packages and there's no good way to undo damage. There are too many hidey-holes in the operating system. I've learned about some of them just by studying my own infected (or my dad's infected) computers.
I feel sorry for computer owners on some days. Not everyone knows how to use a debugger. Elmo.
Anger anger anger.
- adamlaneus
- CCW likes me more than Rollo
- Posts: 37805
- Joined: Sun Jan 03, 2010 1:30 pm
- Location: Close to SanFran
The virus protection software was McAfee. The virus itself was first seen 'in the wild' on September 24th which is not long ago. So it is unlikely that any virus scanner would have seen it.
Our IT department is checking the logs; I was able to give them quite a bit of information.
they will see exactly how much I post to the OFR from work. go ahead and fire me you lousy fuddernutter. see who fixes your broken Elmo then.
I use Windows, Mac and the Linuces when I have to. It is not practical to 'switch' when I must use them all.
Our IT department is checking the logs; I was able to give them quite a bit of information.
they will see exactly how much I post to the OFR from work. go ahead and fire me you lousy fuddernutter. see who fixes your broken Elmo then.
I use Windows, Mac and the Linuces when I have to. It is not practical to 'switch' when I must use them all.
I am not sure if my computer blew up from a known heat issue (and took out all three attached harddrives) or it was a virus, but it wiped me out a good about a month ago. Took 3 weeks to get it all back.
I actually had to replace the motherboard (BIOS Change may have worked, but I just went with the whole MB), and wiped all the hard drives. Luckily, I was able to use EASEUS Data Recovery ( I think it was 80 bucks), and I got back almost 100% of my info, including all of my emails.
Working on a backup laptop, especially before I got my info back, was a PITA.
OK, whining does feel good sometimes.
I actually had to replace the motherboard (BIOS Change may have worked, but I just went with the whole MB), and wiped all the hard drives. Luckily, I was able to use EASEUS Data Recovery ( I think it was 80 bucks), and I got back almost 100% of my info, including all of my emails.
Working on a backup laptop, especially before I got my info back, was a PITA.
OK, whining does feel good sometimes.
- adamlaneus
- CCW likes me more than Rollo
- Posts: 37805
- Joined: Sun Jan 03, 2010 1:30 pm
- Location: Close to SanFran
Because of this virus, they have pulled my internet access records.
Anyone who looks through those records will be led to this website, as I do post things here from work, usually on a break when my computer is otherwise tied up.
Anyone who looks through what I have been posting on this website will see various images...
Hm. This is where we see if the IT department has a sense of humor or not.
Anyone who looks through those records will be led to this website, as I do post things here from work, usually on a break when my computer is otherwise tied up.
Anyone who looks through what I have been posting on this website will see various images...
Hm. This is where we see if the IT department has a sense of humor or not.
- Petescorner
- Mr. Nice Guy
- Posts: 37525
- Joined: Thu Jan 11, 2007 7:53 pm
- adamlaneus
- CCW likes me more than Rollo
- Posts: 37805
- Joined: Sun Jan 03, 2010 1:30 pm
- Location: Close to SanFran
- Coincopwife
- Site Admin
- Posts: 26007
- Joined: Thu Jan 11, 2007 7:57 pm
- adamlaneus
- CCW likes me more than Rollo
- Posts: 37805
- Joined: Sun Jan 03, 2010 1:30 pm
- Location: Close to SanFran
So, which administrator can erase all trace of my existance on this forum?Coincopwife wrote:No moderator can do that.adamlaneus wrote:So, which moderator can erase all trace of my existence on this forum.
And, how much will it cost me?
I have cash, silver, gold. Cats, lint and marbles. Popcorn purchases. Direct donations. Whatever you want.
I see you didn't have enough of any of those.adamlaneus wrote:So, which administrator can erase all trace of my existance on this forum?Coincopwife wrote:No moderator can do that.adamlaneus wrote:So, which moderator can erase all trace of my existence on this forum.
And, how much will it cost me?
I have cash, silver, gold. Cats, lint and marbles. Popcorn purchases. Direct donations. Whatever you want.
- adamlaneus
- CCW likes me more than Rollo
- Posts: 37805
- Joined: Sun Jan 03, 2010 1:30 pm
- Location: Close to SanFran