Where does that virus come from?

Discussion in 'Tech Talk' started by Drjones, Jun 29, 2011.

  1. I've been helping a LOT of people with that virus/malware that pops up, says "oh noez! Your computer is infected! Pay us money with your credit card & we will remove the problems for you!"

    Where does that thing come from? All my clients ask me where & I just shrug...:dunno:
    Well, there's like 50 variations of that virus.. so at least that many "where did it come from" answers.

    I'm thinking you could just sum it up with.. "*****holes"

    I have also noticed an increase in this virus. Seems to really like XP systems with no passwords on the user / Admin accounts.

    Haven't been able to recover one fully yet. Each variation has it's twist.

    Would really be nice if people would BACK THEIR DATA UP! I need to find a form they can sign that holds me harmless for their data...


    Two kinds of people in this world:
    Those who backup religiously,
    Those who SOON WILL! :supergrin:

    Why make backups? The government has copies.... [/foilhat]

    I would like to get my hands on the turds who writing these viruses, it is like a living organism; everytime you figure out how to beat it, it changes. It's a sick game.
  5. It comes from people who click everything that moves without thinking.
    Yeah but have you ever tried to get access to it ... all the red tape and hoops, it can be a *****! :rofl:

    I'm have mixed feelings on this subject; whenever I'm struggling to clean a clients computer I would like to beat the crap out of creator of the virus ... but then again it I'm getting paid to clean the computer.

    It's not really a virus, they are selling protection, just like paying the Mafia to 'protect' your business.....from the Mafia.

    It's done with JavaScript using a open window function, that's why ad and popup blockers usually don't block it. So if you have JavaScript turned off you'll never get the initial pop-up to OK installation. But it steals focus by requiring an input to continue and once the window pops up you can't close the browser, change tabs or anything else. Clicking on anything in the window authorizes installation, it doesn't matter if you click 'Close, Cancel, X, or OK' it's all the same. So eventually most will click somewhere in the window (usually 'X") to get rid of it so they can use their browser again, and it installs.

    I've encountered it a number of times usually while searching for computer stuff, like PERL scripts. I don't know if it works with other browsers but with Firefox I open Taskmanager and kill the browser process. Wait a few minutes to make sure Firefox has ended then start it up again. You'll get the "Well, this is embarrassing" message that it can't restore the session, that's good. Remove the check from the webpage/tab where you encountered the popup and Firefox will start back up and you have escaped harm. Don't go back to that site again...... although I have since I wanted to study their scripts to see what they were doing.

    Almost everyone I know has gotten it at some point, but all of them now know to kill the browser when the popup first shows up. Don't click on anything in the window and you'll be OK.

    Unlike MoviePass and some of the other really evil ones I've always been able to remove it. Use something like Process Explorer running on a thumb drive to kill the malware processes, then just scan with Malwarebytes in normal mode. Usually takes me about 15 minutes to remove it depending on how long it takes Malwarebytes to do the scan and remove the malware files.