View Single Post
Old 03-30-2009, 09:15 PM
who moi's Avatar
who moi who moi is offline
'Thanks' Button Team Community Member T.K.S.
 
Join Date: Jan 2007
Location: with the Brady Bunch, honey bunch,and now the crazy bunch
Posts: 2,751
15 yr Member
who moi who moi is offline
'Thanks' Button Team Community Member T.K.S.
who moi's Avatar
 
Join Date: Jan 2007
Location: with the Brady Bunch, honey bunch,and now the crazy bunch
Posts: 2,751
15 yr Member
Default

you're welcome, ladies.

~~~~~~~~~~~~~~~~~

I am a bit worked up about this particular worm because it has wreaked
havoc with some of the folks' puters that I've been trouble shooting.

and when it hit my high tech friend, I knew I had better take an even deeper look at it...

the main purpose of this worm IS to make money. It wants your puter to WORK and be on line. So it really doesn't disable you. What it wants to do, is to steal all your personal information and all your passwords. That's the scary part.

maybe this would also be a good time to discuss on what IF our puters are infected by this worm.

~~~~~~~~~~

if we all made sure that everything is up to date and we still get this bug.

The very first thing to do is to DISCONNECT your puter from the internet. Unplug it from the modem or turn off your wi-fi

provided that your anti-virus/spywares are up to date. Run the anti-virus scanner first, then the anti-spyware.

restart. Run them again.

Some of the anti-spyware might have to be run in the safe mode if you are not able to get it all in one shot.

the other thing to remember is that this worm can embed itself and grow.

Catching it the first time or even the second time might not mean that it's gone. (and we also have to remember there are many variants of
this worm. A, B, B++ and the eventual "C" (or variant 3)

I would run it at least three times with at least once in safe mode.

~~~~~~~~~~

this website provided by MS has the latest variant removal. It is free.

I would download it to the desktop and keep it there. (and NOT wait until you're infected for you might not be able to download it)

And if one was to get the infection. Run all your anti-virus and spyware first. Then run this tool.

Go to the site and click on download.

Don't click on "Run" but click on "SAVE"

save it to a location where you can find it. (I prefer to save it to my desktop)

*one thing to remember, this does NOT catch all the variants of the worm. But it'll help catch those that your anti-virus/spy doesn't catch but still might NOT catch all of it. And it is ONLY a supplement.


~~~~~~~~~~

After you're sure your puter is cleaned up. Change ALL your passwords.

This worm is a mirror and a keystroke tracker.

meaning that if you go to your bank site. The hacker can see exactly what you're seeing.

And whatever you type in, the hacker can track your keystroke. Even back space.

So, the best bet is to change the passwords. (After you're sure that you are NOT infected)

Now, you may ask, even if I just got it a minute ago?

The problem is, at the time of detection, it might have been in your puter for a period of time. And let's say
you were trying to log in to your bank account around that time. It could've gotten those keystrokes by then.

Although unlikely, always better safe than sorry.

the other thing to be aware of is if you are on a network in your home. Check to see if other computers are infected as well.

~~~~~~~~~~~

if all else fails or if you think you did catch all of it but your puter is still infected. It might be that you
have to reformat.

Unfortunately, just from what I've trouble shooted and from what my friend told me. The % is high for reformatting....

so backing the files would be my hortatory opinion/advice.

~~~~~~~~~

if anyone gets really bored and want to read up on the tech aspects of the previous versions and what they suspect in the new version.

click here....

but be forewarned, it's tech talk and you might fall asleep reading it. LOL

stay safe, everyone.
__________________
.
.
.
.
.
.
.
.


"you're entering, the



.


zone..."

Last edited by who moi; 03-30-2009 at 09:41 PM.
who moi is offline   Reply With QuoteReply With Quote
"Thanks for this!" says:
Curious (03-30-2009), ewizabeth (03-31-2009), Jomar (03-31-2009), mrsD (03-31-2009), SallyC (03-30-2009)