[identity profile] laptop-mechanic.livejournal.com posting in [community profile] techrecovery
I hope the idiot responsible for this annoyance gets fed feet first into a wood chipper. I also hope that some day, people stop believing the "ZOMG, YOUR MACHINE IS INFECTED CLICK HERE TO CLEAN" messages they get. Or that somebody makes Windows actually something loosely resembling secure. Yeah, it's a pipe dream. But there you are.

Thankfully, there's tools available to get rid of it.

Date: 2009-01-06 05:00 pm (UTC)
From: [identity profile] alcoholiday.livejournal.com
My PC at work got Vundo. I just sent it down to the tech shop to have it wiped after trying and trying to remove it myself :/

Date: 2009-01-06 11:30 pm (UTC)
From: [identity profile] ravan.livejournal.com
One of our users got it. The answer was "reimage the box". Not much additional software, and they need reimaging every few months anyway.

Why not use Deepfreeze?

Date: 2009-01-09 12:18 am (UTC)
From: [identity profile] bothunter.livejournal.com
If you have to reimage the box on a regular basis, why not load Deepfreeze on it?

http://www.faronics.com/html/deepfreeze.asp

(deleted comment)

Date: 2009-01-06 05:14 pm (UTC)
jecook: (Default)
From: [personal profile] jecook
Incidently, how portable is that program? will it run on a BartPE disc?
(deleted comment)

Date: 2009-01-07 02:12 pm (UTC)
From: [identity profile] major-error.livejournal.com
Yeah, I used to think the same thing...
Recently, DriveImage XML (http://www.runtime.org/driveimage-xml.htm) was made to work on it. It beats the snot out of trying to get a floppy to work in an older system that won't boot USB.

Date: 2009-01-06 05:45 pm (UTC)
ext_130371: (ho hum)
From: [identity profile] ravenofdreams.livejournal.com
I have gotten malwarebytes into BartPE, but having fiddled with it since, it's not really necessary. MB runs and installs in safe mode, and when I can't get the infected machine to run initially in safe mode, a quick scan in MB with the infected drive hooked to another computer tends to clean it off enough that I can do so.

Date: 2009-01-06 05:53 pm (UTC)
jecook: (Default)
From: [personal profile] jecook
Cool- I'll have to play around with it a bit.

Date: 2009-01-06 05:30 pm (UTC)
From: [identity profile] sdaemon.livejournal.com
I'll second the malwarebytes recommendation. Between that, the official MSRT tool from microsoft, adaware, spybot s&d, and whatever flavor of antivirus you prefer...you can have a decent chance of cleaning up a machine in slightly less time than it would take to just rebuild the machine...

*sigh*

Date: 2009-01-06 05:50 pm (UTC)
ext_130371: (Default)
From: [identity profile] ravenofdreams.livejournal.com
What usually works for me is a MB quick scan in safe mode, then SuperAntiSpyware and MB full scans in normal mode afterwards.

Date: 2009-01-07 03:34 am (UTC)
ext_74: Baron Samadai in cat form (Default)
From: [identity profile] siliconshaman.livejournal.com
Thanks for that recommendation, I was looking for something to use as 'the big guns' in the event that my current set up of AVG and SpyBotS&D proved inadequate to stop an infection.

Date: 2009-01-06 05:18 pm (UTC)
From: [identity profile] bitterfun.livejournal.com
This post is infected, PLEASE CLICK HERE TO CLEAN THIS POST. (http://www.beyondprivacy.com/uselessantivirus/index.htm)

Date: 2009-01-06 05:43 pm (UTC)
jecook: (Default)
From: [personal profile] jecook
... Please tell me this is a joke and I don't have to dig out the ban hammer.

Date: 2009-01-06 05:44 pm (UTC)
From: [identity profile] bitterfun.livejournal.com
Yes, it is a joke. Apparently not as funny as I would have liked. :(
Edited Date: 2009-01-06 05:47 pm (UTC)

Date: 2009-01-06 05:52 pm (UTC)
jecook: (Default)
From: [personal profile] jecook
One hopes so- the phone # and address don't match (AZ area code /= portland, OR), and the first three reasons tripped just about every "tinfoil hat alert!" meter I have. Paranoia does not begin to describe it. The authors sounds like someone who only knows half the story, and never bothered to find out the rest of it, preferring to live in their own special flavor of reality. Kind of scary, when one ponders it.

Date: 2009-01-06 05:58 pm (UTC)
From: [identity profile] bitterfun.livejournal.com
WHAT?!??!? You don't believe the Man is engineering viruses and spy ware to infiltrate American citizens' computers to Big Brother some more control on the sheeples?

Date: 2009-01-06 05:21 pm (UTC)
From: [identity profile] grayhawkfh.livejournal.com
Thankfully, there's tools available to get rid of it.

Tools available to get rid of Windows?

Oh yeah, that would be pronounced "LIN ux"

LOL!

Date: 2009-01-06 06:06 pm (UTC)
From: [identity profile] superbus.livejournal.com
Yeah, sure. Put an end user on a freshly installed Linux machine - even Ubuntu - and watch the fireworks.

Date: 2009-01-06 06:56 pm (UTC)
From: [identity profile] wxgeek.livejournal.com
People under thirty and over sixty cope remarkably well. The under-thirties pick up on it quickly, and the over-sixties had to be pointed to the correct icons anyhow.

It's not like they know how -Windows- works anyway.

Date: 2009-01-06 05:41 pm (UTC)
ext_130371: (don't fuck with the vyvyan)
From: [identity profile] ravenofdreams.livejournal.com
I second feet first into a wood chipper. Frikkin' Vundo.

Date: 2009-01-06 11:27 pm (UTC)
From: [identity profile] ravan.livejournal.com
Stuff an infected windows box up his ass sideways first. Then it will slow down when it hits that and hurt just that much longer.

Date: 2009-01-06 11:25 pm (UTC)
From: [identity profile] ravan.livejournal.com
My roomie got it. I spent 9 hours on a Sunday trying to kill it. I finally told her to fucking reinstall.

Date: 2009-01-07 03:44 am (UTC)
ext_74: Baron Samadai in cat form (Gimme the coffee)
From: [identity profile] siliconshaman.livejournal.com
Oy vey, I know that one... ended up recommending the user get a new hard drive it was so bjorked. Couldn't even reinstall as something the user had done earlier had disabled the optical drive and USB ports as well...[and no way was I going to connect that typhoid mary to a network!]

Coincidently, anyone ever hear of a Threatfire AVG? A review of it I read on Cnet said it was the bee-knees, but the couple of times I tried running it, it completely bollocked up my system and it took me ages to uninstall the POS and restore everything.

Is it just bad, or another malware laden decoy?

[and it's things like this that makes me grateful we never developed direct neural interfaces...]

Date: 2009-01-07 01:32 pm (UTC)
From: [identity profile] coyoteden.livejournal.com
Threatfire works (even on Windows 7) and it takes up a whole 8 MB of RAM.

The only thing that sucks: no x64 version, so my desktop is still running AVG Free.

And the judges in my area are wising up to this kind of crap: http://www.baltimoresun.com/technology/bal-md.regionbriefs200dec20,0,4426795.story
Edited Date: 2009-01-07 01:34 pm (UTC)

Date: 2009-01-07 01:48 pm (UTC)
ext_74: Baron Samadai in cat form (Default)
From: [identity profile] siliconshaman.livejournal.com
It's about time the justice system got tough with such scams... it's just another form of fraud and obtaining money by deception.

Hmm...re threatfire, must be a incompatibility problem with something else, or a bad download. Certainly doesn't sound like my experience with it...freakin' nightmare that was!

Date: 2009-01-08 03:23 pm (UTC)
From: [identity profile] amynnah.livejournal.com
My work PC got it while I was looking up, of all things, maps of the US on Christmas Eve, for a coworker. While our Support Group was out on vacation, and the poor Desktop Engineers were swamped with doing Support's job.

It took the DIG guy over a week to get my PC cleared, and it even ended up being a reimage. I hate Vunda. My home PC is relatively safe because it's only used to play WoW. >.>;;; And I check my processes once a week, and after new downloads, for keyloggers.

Profile

techrecovery: (Default)
Elitist Computer Nerd Posse

April 2017

S M T W T F S
      1
2345678
91011121314 15
16171819202122
23242526272829
30      

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Mar. 20th, 2026 12:46 pm
Powered by Dreamwidth Studios