Jump to content


Augh!


  • Please log in to reply
9 replies to this topic

#1 OFFLINE   raymac46

raymac46

    Multithreader

  • Members
  • PipPipPipPipPipPipPipPip
  • 1,119 posts

Posted 15 June 2012 - 06:12 PM

My Win 7 notebook picked up some nasty malware today. Not sure how but both McAfee and Windows Defender were hopeless to stop it. It shut both spyware apps down. It's called "Smart Data Recovery" virus.
I got about 50 read/write errors and hard disk failure notices all at once. Yeah right. How could I boot at all if my hard drive were that bad?
Googling on another machine gave me a fake key so I could "register" the malware and stop  it. Then I rebooted in safe mode and had McAfee do a virus scan and get rid of it. Then I could delete the stupid launch icon and program. Took me about 3 hours to get my Windows 7 install back to normal.
I'm fairly computer literate. Imagine if this crap got on the PCs of my senior citizen "clients" in the neighborhood. Give me Linux. Please.
http://www.2-viruses...t-data-recovery


Registered Linux User 445659

#2 ONLINE   V.T. Eric Layton

V.T. Eric Layton

    Nocturnal Slacker

  • Forum Admins
  • 14,854 posts

Posted 15 June 2012 - 06:54 PM

That sounds like a variant of THIS, Ray.

By the way, moving this to All Things Windows. :)

Posted Image


#3 OFFLINE   raymac46

raymac46

    Multithreader

  • Members
  • PipPipPipPipPipPipPipPip
  • 1,119 posts

Posted 16 June 2012 - 06:46 AM

Well maybe checking the weather in Donetz Ukraine or reading some Euro 2012 coverage did it. That is about as naughty as I get at my age.
What bugs me though is that two anti-malware apps didn't catch it. This sort of scareware is just an annoyance for me but it could make the Web innocent come unhinged enough to pay for a spurious software "licence" that doesn't do anything.


Registered Linux User 445659

#4 OFFLINE   zlim

zlim

    It's me, plodr

  • Forum MVP
  • 6,063 posts

Posted 16 June 2012 - 10:05 AM

Malwarebytes, the paid version, stops me from even getting to sites that are deemed problematic. You can over ride but I rarely do.
Liz
Registered Linux User # 401459
Posted Image

#5 OFFLINE   LilBambi

LilBambi

    Australisches Googler

  • Forum Admins
  • 16,494 posts

Posted 16 June 2012 - 12:09 PM

I would start here Ray: S.M.A.R.T Data Recovery over at Bleeping Computer. Or wait for Corrine to help.
Posted Image
BambisMusings Blog :: Fran's Computer Services Blog :: MyPassionIsBooks Blog :: 5BuckReview :: CNIRadio
"The Net interprets censorship as damage and routes around it." ~John Gilmore (Time Magazine, Dec 6, 1993)

#6 OFFLINE   raymac46

raymac46

    Multithreader

  • Members
  • PipPipPipPipPipPipPipPip
  • 1,119 posts

Posted 16 June 2012 - 06:38 PM

OK now thanks Fran. After I got into Safe Mode, McAfee was able to take care of it.


Registered Linux User 445659

#7 OFFLINE   Corrine

Corrine

    The Mystical Rose

  • Forum Admins
  • 2,912 posts

Posted 16 June 2012 - 07:08 PM

raymac46, the 2-viruses website you linked to isn't the best source.  The Bleeping Computer link that Fran provided is the most effective for that rogue (and 99.999% of all the rogues).
,

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

#8 OFFLINE   raymac46

raymac46

    Multithreader

  • Members
  • PipPipPipPipPipPipPipPip
  • 1,119 posts

Posted 16 June 2012 - 09:27 PM

Maybe but the 2 viruses site gives pics of what the malware looks like. I was able to take care of it so no worries.
Here's the Bleeping Computer Page for reference. It also shows the screens I got,
http://www.bleepingc...e-data-recovery

The unhide.exe program at Bleeping Computer is excellent to restore all your start menu items after you get rid of the virus. Thanks!

Edited by raymac46, 16 June 2012 - 09:50 PM.



Registered Linux User 445659

#9 OFFLINE   Temmu

Temmu

    The Assimilator

  • Forum MVP
  • 9,798 posts

Posted 19 June 2012 - 04:42 PM

as zlim said above, not going to the site in the first place is the best defense - but i use something else - the mvp hosts file http://winhelp2002.mvps.org/hosts.htm
and as lilbambi said, bleeping computer is a great site, after the unfortunate fact.
but corrine hits the nail on the head every time if you need help!
Posted Image

#10 OFFLINE   LilBambi

LilBambi

    Australisches Googler

  • Forum Admins
  • 16,494 posts

Posted 20 June 2012 - 08:13 AM

Yes, so true Temmu! Corrine is an excellent malware fighter! Which is why I mentioned BleepingComputer or wait for Corrine. :D
Posted Image
BambisMusings Blog :: Fran's Computer Services Blog :: MyPassionIsBooks Blog :: 5BuckReview :: CNIRadio
"The Net interprets censorship as damage and routes around it." ~John Gilmore (Time Magazine, Dec 6, 1993)




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users