The desktop is in the shop again.
Last Thursday I was surfing the net and got a Malicious Software warning from my Avast anti-virus. Avast Pro has successfully blocked threats to our PC safety forever. We have to search the net constantly, looking up odd things for books, and typically our PC’s are covered with armor and bristle with spikes. Bad stuff usually bounces off without a scratch. We haven’t had a virus infection in the last four years and we frequently scrub stuff out with Malwarebytes and Spybot. So I did what I always do: shut down the browser before the nasty bugger could do any damage.
And then my computer blew up. The desktop went twitchy, the shortcuts vanished, and two dozen false alerts popped up, telling me that the guts of my Alienware were collapsing.
I disconnected the Ethernet cable to keep it from spreading and got on my laptop. A quick search identified the culprit: the System Check Virus, a nasty critter engineered by a couple of guys in Europe. It holds your PC hostage until you pay them to activate their fake virus removal software. The procedure for removal was long and complicated and there were several versions of it.
I tried the standard operating procedure. Ran Avast. It found nothing. Ran Malwarebytes. Four infected files. I quarantined them and shut down as prompted.
The PC rebooted to a completely black desktop.
Tried Regedit to manually edit registry keys.
Denied.
Tried to run Malware again.
No infections found.
The false warnings continued to cascade at me in regular bursts. Clearly I needed someone who knew more about it than I did. We took the PC to the shop.
Gordon has been rather gracious about the whole thing, even though he had to carry the big super-heavy desktop back and forth.
Friday night I get my PC back. It is clean and beautiful. I fire it up and of course log into Star Wars. I have weird crap on auction and I want to know if my colored light saber crystals had sold. The connection is painfully slow. Something isn’t right. I back out and fire up the Firefox. I try a sample search and I am immediately redirected to four different windows. Google Redirect virus. Damn it all to hell.
I disable all of the Firefox extensions, install the script blocker add-on, and run Malware again. Malware comes clean. The problem is spreading: the virus keeps trying to open IE to send me to new windows and Avast keeps stomping on those attempts, sending frequent warning flares, screaming about malicious sites, and asking for air support.
Checked registry for Firefox trouble extensions such as Xulrunner. Nothing. Everything comes back roses.
Argh.
So yesterday we took it back to the shop. I don’t blame the repair guys – they clearly purged the System Check from the PC but it apparently came bundled with Google Redirect.
Here is hoping I will get my computer back today.









So in my spare time I fix both my work computers and laptops. My work usually focuses on viruses we do not have the luxury of reformatting and must get the computer back up and working. Acronis is great software but not really user friendly and all virus software at a certain level is alike with daily updates. The problem is that although good virus protection will protect from some viruses these are usually the stupid ones not the latest and greatest. The bad viruses will get through and will take down your computer, happens all the time. If you surf around then you are a prime target for them all and it will happen. Same thing goes for changing account from admin I understand where this is coming from but again if you have virus software it is going to take care of the dumb viruses which are the only ones that are going to get stopped by this. But there some solutions that can mitigate the issue.
1: Use different distro Mac already been talked about or Linux “Ubuntu,Kubuntu” this could involve dual booting so that you would still be able to play your games and just do the surfing on the other distro. This is the safest issue with linux you can surf as you want with no problems as there are only about 15 viruses that can hurt it and most are lab made. But this does require a degree of tech savyness.
2: If you have to use Windows as your only distro “scary I know” then you need to make frequent backups I prefer an external harddrive you can make one from an old computer or buy one for less than 100. If you want contact me and I can see what I can do to make you one. Then if need be you would still have to reformat and then reload everything personally I don’t think that this solves any problems it is like having a car with a bad radiator that has duck tape on it to make it run. Windows is the worst distro for viruses and they do work hard on it but still it sucks. All the computers I work on have Windows with a virus good for me and money but bad for everyone else.
If it is still bad when it comes back let me know and I would be willing to look at it if you ship it for free. You can just ship me the hard drive if you want just have the tech take it out. Hope it works out for you hate to see someone good get hit with something bad. Also if you need any advice I am more than willing.
I had the same thing not 2 months ago except i didnt know it was a virus and i thought it was something to actually help until my dad told me it was a virus. it took us 4 days to fix it (my dads a computer nerd ;P ) but it had to go back to my factory settings and i had to save everything on an external harddrive or else i would have lost everything, SO I KNOW HOW YOU FEEL!
I had that same damn virus. I ::think:: I’ve cleared it, but it already came back once.
It’s an evil one.
Wow, ok, i thought you guys were awesome because I love the Kate books, now I find out you play SWTOR also?!!! Which server do you play on if you don’t mind me asking?
I’m on Shien
I have had this before myself. It was a while ago but I believe I nuked it with a combination of spybot, ad-aware, and advanced system care malware software. I do suggest firefox and microsoft security essentials as well. Super Antispyware is another good one that my company uses at work.