Confidence Can Make You do Dumb Things

Log in

SmokingPipes.com Updates

Watch for Updates Twice a Week

PipesMagazine Approved Sponsor

PipesMagazine Approved Sponsor

PipesMagazine Approved Sponsor

PipesMagazine Approved Sponsor

PipesMagazine Approved Sponsor

Status
Not open for further replies.

admin

Smoking a Pipe Right Now
Staff member
Nov 16, 2008
8,774
5,006
St. Petersburg, FL
pipesmagazine.com
Confidence is a good thing.
However, being confident that everything will be ok if you click the "Run" button on an alert that says, this page requires an older version of Java, is not a good thing.
This Trojan slapped McAfee in the face, then spit at it, and kicked it in the balls.
This happened while remotely connected to my home machine this morning. My main desktop working machine is currently dead in the water. I had to shut it down in the hopes that all my banking info hadn't already been transmitted.
And almost as bad as that, there are several articles, and some on-location photos, and pipe babe photo shoots that are not backed up on any other machines.
Pray that we can save the pipe babes and all my other much more important stuff.
I am traveling today and have a tech scheduled between 9 - 11 tomorrow morning. This is the first time I've ever had to call in outside professional help. Sparing a lot of details, this Trojan took over everything, and just laughed at McAfee, Malwarebytes, and Windows Defender. It is also trying to extort money to fix the problem.
Fucking jerks.

 

jcsnaps

Lifer
Oct 18, 2010
1,031
10
Please Lord save the pipe babes. Oh and the other stuff too. Hope that helps.

 

nemrod

Can't Leave
Apr 28, 2011
337
1
Sweden
The solution is pretty simple, boot with a Linux live CD, copy the important files to an external drive and you're done. Now you can proceed to make sure the drive is completely clean and reinstall an OS of your choice.

 

nbpiper

Starting to Get Obsessed
Aug 31, 2011
172
1
+1 for the linux live CD idea. That has come in handy a couple of times for me. Hope you are able to get the important stuff back.

 

spartan

Lifer
Aug 14, 2011
2,963
7
+1 on the warning
I hope everything ends up being fine and it doesn't cost too much to fix.

 

bhpdrew

Can't Leave
Oct 8, 2010
367
0
Washington State
images-2.jpg


 
Jul 15, 2011
2,363
31
This Trojan slapped McAfee in the face, then spit at it, and kicked it in the balls.
Thats when you let the tech that you called take the Trojan, kick its ass, bang its girlfriend, and steal its lunch money.
All kidding aside, I do hope that everything works out for you. And I do pray that we can save the pipe babes.

 

yohanan

Lifer
Oct 1, 2011
2,121
4,017
Old Belt/U.S.A.
Fucking jerks.

That's putting it mildly, Some idiot for whatever reason it may be, has to be messing with someone else's stuff.

Then they want to eff with it and screw it up some more and make someone's life more complicated. Hopefully You will be able to recover all your information and won't have any problems. I hope everything works out for You.

 

yoru

Part of the Furniture Now
Jan 5, 2011
585
1
That sounds like the same fucker that killed my PC over the summer!
Bit of advice. . Do NOT delete the damn thing, at least not without oven mitts, rubber gloves, a Kevlar-and-steel vest and a condom -- it has a kill code that takes explorer with it -- and the rest of my post got truncated, what the heck?
Anyway! Yeah I got a trojan over the summer that did that when I deleted it and then after 4 hours of screwing with the thing -- somehow, I dunno how -- it cut the CPU fan and well. . . did you know computers really CAN catch on fire?

 

markw4mms

Lifer
Jun 16, 2011
2,176
2
Bremen,GA
That really blows,Kevin! I hope you get it all straightened out, and none of your sensitive information has been compromised.

 

juni

Lifer
Mar 9, 2010
1,184
11
Now there's your first problem. It is strange that so many people are unaware of Microsoft Security Essentials, which beats many commercial ones.

 

wallbright

Part of the Furniture Now
Aug 22, 2010
845
2
If it is the same one that infected my computer (it represented itself as a anti-spyware software that found many many trojans etc. when it was in fact itself a trojan/virus) I booted in safe mode and then did a system restore. It worked on both my computer and my girlfriends. This might be a totally different virus/trojan/whatever but I am just saying it worked for me. It was a pain in the ass and blocked EVERYTHING I was trying to do to fix the issue but it couldn't do anything in safe mode if I recall. You could also just boot from a CD and then do a system restore. I am no professional though so maybe this helps and maybe it doesn't I just know it worked for me in the past. Anyways, it sounds like you have a pro coming out so this could all be moot anyways.

 

admin

Smoking a Pipe Right Now
Staff member
Nov 16, 2008
8,774
5,006
St. Petersburg, FL
pipesmagazine.com
We have been at it for 2.5 hours so far. We made some progress, but still have a long way to go.
We tried Knoppix (Linux) and it worked a little bit, but then the virus was still in control.
So, easier said than done.
Doing a fresh install is no trivial thing, and is the last resort.
This thing seems pretty new as the only good instructions are on a Korean website that we translated.
If you want the info, Google (in quotes) "system-restore.com trojan".
Then look for the Korean result, about 4 - 5 down and click "Translate this page".
I paid for the tech for 4-hours up front, and it is looking like will will use all the time.

 

admin

Smoking a Pipe Right Now
Staff member
Nov 16, 2008
8,774
5,006
St. Petersburg, FL
pipesmagazine.com
It took us 4-hours, with me helping the tech - so 8-man-hours, plus one more hour to do a tune up.
The good news is that everything is fixed, all data is saved and backed-up, and my PC is tuned up.
This was kind of blessing in disguise as it forced me to do some maintenance and housekeeping that I have been putting off for a long time. Regular incremental back-ups are on an auto schedule and a new pipe babe shoot is going up.

 
Status
Not open for further replies.