Go Back  FlyerTalk Forums > Travel&Dining > Travel Technology
Reload this Page >

*(#%&*( Malware! - The Saga Continues

Community
Wiki Posts
Search

*(#%&*( Malware! - The Saga Continues

Thread Tools
 
Search this Thread
 
Old May 21, 2013 | 3:57 pm
  #16  
20 Countries Visited
500k
All eyes on you!
15 Years on Site
 
Join Date: Apr 2010
Location: ORD
Programs: AA, UA, GE
Posts: 5,388
Originally Posted by DeafFlyer
Why not (after you reinstall) just setup a user account for Mrs. PTravel with limited privileges. That's much simpler than getting another computer.
And for yourself too. There is really no need to cruise online with a security profile that allows the installation of devices., programs, modification of operating system parameters, etc.
cheltzel is offline  
Old May 21, 2013 | 5:45 pm
  #17  
Original Poster
FlyerTalk Evangelist
 
Join Date: Mar 2004
Location: Newport Beach, California, USA
Posts: 36,062
Originally Posted by DeafFlyer
Why not (after you reinstall) just setup a user account for Mrs. PTravel with limited privileges. That's much simpler than getting another computer.
I leave the computer on all the time -- there are other machines that access it for various reasons, and I'll frequently remote into it via VNC to do something. I don't want to lose that access, plus it's a pain to log in and out -- it takes almost as much time as warm reboot.
PTravel is offline  
Old May 21, 2013 | 5:46 pm
  #18  
Original Poster
FlyerTalk Evangelist
 
Join Date: Mar 2004
Location: Newport Beach, California, USA
Posts: 36,062
Originally Posted by cheltzel
And for yourself too. There is really no need to cruise online with a security profile that allows the installation of devices., programs, modification of operating system parameters, etc.
If all I did was cruise online, I'd agree with you. However, there's an awful lot that I do that requires administrator-level access.
PTravel is offline  
Old May 21, 2013 | 5:54 pm
  #19  
30 Countries Visited
All eyes on you!
15 Years on Site
 
Join Date: Dec 2009
Location: RDU
Programs: DL DM+(segs)/MM, UA Ag, Hilton DM, Marriott Ti (life Pt), TSA Opt-out Platinum
Posts: 3,366
Before you reload your OS. I would give combofix a try. I have seen it fix some really nasty trojans, worms, etc that nothing else could fix. It's a low level utility that's aimed at ridding PC's of nasty malware, which it sounds like you have encountered.

http://www.bleepingcomputer.com/download/combofix/
HDQDD is offline  
Old May 22, 2013 | 5:05 am
  #20  
20 Countries Visited
500k
All eyes on you!
15 Years on Site
 
Join Date: Apr 2010
Location: ORD
Programs: AA, UA, GE
Posts: 5,388
Originally Posted by PTravel
If all I did was cruise online, I'd agree with you. However, there's an awful lot that I do that requires administrator-level access.
On a daily basis? Not trying to start an argument ... just a serious question.

My malware attack that caused me a similar issue was caused by typing in a misspelled URL and once I hit enter, it was too late.
cheltzel is offline  
Old May 22, 2013 | 7:47 am
  #21  
All eyes on you!
15 Years on Site
 
Join Date: May 2010
Programs: Delta Silver, HH Gold, Accor Gold, IHG Platinum
Posts: 5,395
Originally Posted by HDQDD
Before you reload your OS. I would give combofix a try. I have seen it fix some really nasty trojans, worms, etc that nothing else could fix. It's a low level utility that's aimed at ridding PC's of nasty malware, which it sounds like you have encountered.

http://www.bleepingcomputer.com/download/combofix/
In addition to Malware Bytes, HitmanPro and Emsisoft Emergency Kit. Those scanners should get almost all infections.
KLflyerRalph is offline  
Old May 22, 2013 | 8:20 am
  #22  
10 Countries Visited20 Countries Visited30 Countries Visited10 Years on Site
 
Join Date: Oct 2012
Posts: 639
I don't know what the best solution is in your case, but if you're going to wipe the entire drive, you might consider just buying a new drive. That way you're sure there's no bad stuff on it.

Also, if logging in takes as long as rebooting, then it sounds as if you might be due for a new computer?
flyingnosh is offline  
Old May 22, 2013 | 8:26 am
  #23  
Original Poster
FlyerTalk Evangelist
 
Join Date: Mar 2004
Location: Newport Beach, California, USA
Posts: 36,062
Originally Posted by KLflyerRalph
In addition to Malware Bytes, HitmanPro and Emsisoft Emergency Kit. Those scanners should get almost all infections.
Thanks! I'm running scans with them now in safe mode.
PTravel is offline  
Old May 22, 2013 | 9:12 am
  #24  
10 Countries Visited
2M
60 Nights
20 Years on Site
 
Join Date: Dec 2002
Location: Oregon
Programs: AA EXP, UA 1MM, HH Diamond, National EE, Hertz PC
Posts: 4,055
Originally Posted by robroy90
Scorched Earth Troubleshooting is in order here. Even if it isn't malware, the cruft you will remove will make it worth it. Windows is notorious for "bit-rot" and before I joined the enlightened, I would wipe and type once a year or so. It was always worth it to me.
Wow. I haven't had to do that on my own computer since before I moved to NT 4. Of course, I'm super anal about what I will let be installed on my computer - resorting to VM's and snapshots any time I have to use something like a "mandatory comcast installer disc".
elCheapoDeluxe is offline  
Old May 22, 2013 | 10:41 am
  #25  
10 Countries Visited
20 Countries Visited
30 Countries Visited
10 Years on Site
 
Join Date: Dec 2012
Location: ORD
Programs: AS, IHG Platinum, Marriott Gold, Hilton Gold, former AA EXP, UA Gold, Hyatt Diamond
Posts: 458
Another thought for after you fix your system is to partition your hard disk into 2 logical drives:
C: OS
D: Data

I make an image backup of C: twice a year, and can always restore to that point. My data isn't impacted because I have all the data on a separate logical drive (D.

If you want to get more flexibility, and have the time to configure it, you can further partition your disk into a third partition. We'll call it C2:. When you boot, it can ask if you want to boot to C: or C2: which gives you two OSs on the same PC. I do this, and only use C: for banking, purchases, but I use C2: for work VPN, internet, etc. All data is accessible via either OS. I have image backups of C2: also.

Good luck
ChicagoDave is offline  
Old May 22, 2013 | 12:54 pm
  #26  
10 Countries Visited
2M
60 Nights
20 Years on Site
 
Join Date: Dec 2002
Location: Oregon
Programs: AA EXP, UA 1MM, HH Diamond, National EE, Hertz PC
Posts: 4,055
Originally Posted by PTravel
...I think the best approach is a virtual machine set-up under Win7 on my primary machine. That would just require a single icon for Mrs. PTravel to click and I could even put FireFox (her browser of choice) in the start up folder. I'd give it internet access and access to a printer, only, and no file access (though maybe I'll stick a USB drive on the computer or the LAN for her to use).
I think this is a great solution for her (and any time you do something risky) because you can take a snapshot of the machine when it is working, and if it goes kaput then restore to the working snapshot in a few minutes.
elCheapoDeluxe is offline  
Old May 22, 2013 | 3:55 pm
  #27  
10 Countries Visited
All eyes on you!
20 Years on Site
 
Join Date: Mar 2003
Location: IAD
Programs: United MP
Posts: 7,857
Originally Posted by PTravel
I leave the computer on all the time -- there are other machines that access it for various reasons, and I'll frequently remote into it via VNC to do something. I don't want to lose that access, plus it's a pain to log in and out -- it takes almost as much time as warm reboot.
I thought that it can still be accessed. I don't remote into my computers, though, so I could be wrong.
DeafFlyer is offline  
Old May 22, 2013 | 4:24 pm
  #28  
Original Poster
FlyerTalk Evangelist
 
Join Date: Mar 2004
Location: Newport Beach, California, USA
Posts: 36,062
I think my inclination at this point is to re-partition the SSD and copy the system drive over from the hard drive on which it originally resided when I installed the SSD last year. I'll lose a lot, but it's better than having to install everything again from scratch. I will still have to "deactivate" a lot of my purchased software, and will undoubtedly have to deal with some vendors that don't provide for deactivation and will tell me I've already activated my software. What a pain!

BTW, does anyone know if (1) it is possible to do a low-level format on an SSD, and (2) whether there's any free software around that will do it?
PTravel is offline  
Old May 22, 2013 | 4:25 pm
  #29  
FlyerTalk Evangelist
40 Countries Visited3M100 Nights20 Years on Site
 
Join Date: Sep 2000
Programs: BA, AA, DL, KLM, UA
Posts: 37,489
Originally Posted by PTravel
I think my inclination at this point is to re-partition the SSD and copy the system drive over from the hard drive on which it originally resided when I installed the SSD last year. I'll lose a lot, but it's better than having to install everything again from scratch. I will still have to "deactivate" a lot of my purchased software, and will undoubtedly have to deal with some vendors that don't provide for deactivation and will tell me I've already activated my software. What a pain!

BTW, does anyone know if (1) it is possible to do a low-level format on an SSD, and (2) whether there's any free software around that will do it?
http://www.intel.com/support/ssdc/hp.../cs-032319.htm
ScottC is offline  
Old May 22, 2013 | 4:36 pm
  #30  
FlyerTalk Evangelist
20 Countries Visited
30 Countries Visited
2M
15 Years on Site
 
Join Date: Apr 2009
Location: Democratic People's Republic of the UK
Programs: Lifetime Gold, Global Entry, Hertz PC, and my wallet
Posts: 21,896
I think the best solution is to hit Mrs PTravel over the knuckles with the laptop ! Mind you it does sound like she is being treated as guilty until proved innocent !
Silver Fox is offline  


Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.