Author Topic: I want to clear what steve said on the blog about this virus scam  (Read 1223 times)

Offline spiderman

  • ****
  • Sr. Member
  • Posts: 441
  • Spiderman
    • View Profile
I just want to clear some stuff up....

enjoy.

...In some cases you won't even be able to boot to safe mode.

That is true, depending on the situation this malware may indeed still run immediately upon booting even in safe mode, so you may need to boot from an unaffected disc, drive or system in order to remove it.


Quote:

I have even seen one computer that will not boot to the CD/DVD to do a re-image of the system.

There is no way this malware can prevent you from booting from a known-good CD/DVD, USB flash, HDD or any other drive for that matter, and it also can't prevent you from re-loading the system once you do. If you were unable to boot from a CD/DVD then other issues such as a defective disc, drive, or improperly configured system (e.g. BIOS Setup not configured to boot from optical before HDD) were involved.


Quote:

...It's pretty tricky to kill.

Actually once you can boot without it immediately running (try Last Known Good Configuration or Safe Mode with Command Prompt) this ransomware is fairly easy to find and remove, even with tools as simple as Autoruns or Malwarebytes Free. It's much less tricky to find and remove than a rootkit for example.

In any case, it is certainly far easier to prevent this from getting on your system in the first place than it is to remove later, so I do recommend disabling Java in your browsers to prevent something like this from getting on your system in the first place. Here are the official instructions for disabling Java in all browsers, it's easy to do (merely uncheck one box) and highly recommended: How do I disable Java in my web browser?  this is the official link and instructions for disabling java http://www.java.com/en/download/help/disable_browser.xml

Note that if you don't see the "Enable Java content in the browser" box to uncheck, then you should uninstall your existing Java version, then reinstall the latest version. With the latest version installed, you can then uncheck the box.   
« Last Edit: January 16, 2013, 12:20:02 pm by cyberghost »
SPIDERMAN THE KING OF THE WEB

Offline jscott2

  • *****
  • Hero Member
  • Posts: 521
    • View Profile
Re: I want to clear what steve said on the blog about this virus scam
« Reply #1 on: January 16, 2013, 09:15:46 am »
A few days ago I put some more detailed instructions on removing Java here http://stevedgood.com/community/index.php?topic=12509.0

I certainly agree with Steve on backing up your data.  I have two physical drives on my PC, one for programs and a separate drive that has only data - pictures, patterns, letters, music, emails, etc., etc. so backup to an external drive is pretty easy.  I don't even use a backup program, just copy/paste.

Jim
Using a Delta 40-690 in the Montreal, Quebec (Canada) area

Offline spiderman

  • ****
  • Sr. Member
  • Posts: 441
  • Spiderman
    • View Profile
Re: I want to clear what steve said on the blog about this virus scam
« Reply #2 on: January 16, 2013, 12:21:50 pm »
A few days ago I put some more detailed instructions on removing Java here http://stevedgood.com/community/index.php?topic=12509.0

I certainly agree with Steve on backing up your data.  I have two physical drives on my PC, one for programs and a separate drive that has only data - pictures, patterns, letters, music, emails, etc., etc. so backup to an external drive is pretty easy.  I don't even use a backup program, just copy/paste.

Jim

Thanks but I have posted the official link  in my first post again thanks.
SPIDERMAN THE KING OF THE WEB

 

SMF

Teknoromi