Free Republic
Browse · Search
News/Activism
Topics · Post Article

To: thecodont

I was reading about this the other day. There are actually 3 versions. One directed at porn sites, one at music download sites, and the other at sites for drivers/OS upgrades.

If you are ever locked out of taskmanager in a normal boot by a virus, you can kill these by doing a safeboot and then running msconfig.exe and killing the processes that are listed from unknown providers. Then rename and delete the executables that have weird names and time stamps when the virus began. These will be in the startup applications list, but you should do a search of the entire boot drive.


5 posted on 11/11/2012 11:19:38 AM PST by Kirkwood (Zombie Hunter)
[ Post Reply | Private Reply | To 1 | View Replies ]


To: Kirkwood

While in msconfig, you should also delete any files in your internet temp directory with time stamps around the time of infection.


6 posted on 11/11/2012 11:23:48 AM PST by Kirkwood (Zombie Hunter)
[ Post Reply | Private Reply | To 5 | View Replies ]

To: Kirkwood

Start - Run regedit (type it in the box)

HKEY_CURRENT_USER - Software - Microsoft - Windows - CurrentVersion - RunOnce and Run are also favorite hiding spots for this sort of nonsense


12 posted on 11/11/2012 12:01:06 PM PST by Technocrat (Romney-Ryan 2012)
[ Post Reply | Private Reply | To 5 | View Replies ]

To: Kirkwood

Bump for reference.


14 posted on 11/11/2012 1:36:38 PM PST by MeneMeneTekelUpharsin (Freedom is the freedom to discipline yourself so others don't have to do it for you.)
[ Post Reply | Private Reply | To 5 | View Replies ]

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson