# ARRGGHHH you fucking hijacking virus making SOBS

**URL:** <https://boards.straightdope.com/t/arrgghhh-you-fucking-hijacking-virus-making-sobs/550802>\
**Category:** The BBQ Pit\
**Created:** [August 19, 2010, 11:14pm UTC](https://boards.straightdope.com/t/arrgghhh-you-fucking-hijacking-virus-making-sobs/550802 "2010-08-19T23:14:38Z")\
**Posts on this page:** 13\
**Page:** 3

<div class="post-metadata">

**Author:** ![cosmosdan](https://avatars.discourse-cdn.com/v4/letter/c/a6a055/32.png) [@cosmosdan](https://boards.straightdope.com/u/cosmosdan)\
**Post date:** [August 22, 2010, 9:20pm UTC](https://boards.straightdope.com/t/arrgghhh-you-fucking-hijacking-virus-making-sobs/550802/41 "2010-08-22T21:20:20Z")

</div>

> [@Bijou\_Drains](#):
>
> Maybe this is well known , but you can avoid a lot of this stuff by making sure you don’t run as a root user (administrator) on your PC. By default Windows sets up 1 account for a new PC and that account is an admin account which means you can change the system. If you only run that you can have a lot of problems. You need to setup a normal Windows user account and only use that account because a normal account cannot change the Windows system.

Ahhhhhh that’s something I didn’t know and will give it a shot after I clean of the the slightly different variety of the anti virus scumming sucking scam that I just fucking got AGAIN!!!

---

<div class="post-metadata">

**Author:** ![Bijou\_Drains](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bijou_drains/32/2814_2.png) [@Bijou\_Drains](https://boards.straightdope.com/u/Bijou_Drains)\
**Post date:** [August 22, 2010, 9:45pm UTC](https://boards.straightdope.com/t/arrgghhh-you-fucking-hijacking-virus-making-sobs/550802/42 "2010-08-22T21:45:49Z")

</div>

Also you should run Firefox with adblock which means you never are exposed to ads that might contain a virus.

BTW, I got hit with this nasty virus a few times on an old PC that my kids use. Since I could not trust my kids to keep that PC clean that machine now only runs Linux.

---

<div class="post-metadata">

**Author:** ![Bearflag70](https://avatars.discourse-cdn.com/v4/letter/b/8e7dd6/32.png) [@Bearflag70](https://boards.straightdope.com/u/Bearflag70)\
**Post date:** [August 22, 2010, 9:47pm UTC](https://boards.straightdope.com/t/arrgghhh-you-fucking-hijacking-virus-making-sobs/550802/43 "2010-08-22T21:47:58Z")

</div>

Don’t browse SDMB unless you use Firefox browser with the ADBLOCK PLUS plug-in or similarly safe system.

---

<div class="post-metadata">

**Author:** ![BrotherCadfael](https://avatars.discourse-cdn.com/v4/letter/b/977dab/32.png) [@BrotherCadfael](https://boards.straightdope.com/u/BrotherCadfael)\
**Post date:** [August 22, 2010, 10:01pm UTC](https://boards.straightdope.com/t/arrgghhh-you-fucking-hijacking-virus-making-sobs/550802/44 "2010-08-22T22:01:35Z")

</div>

> [@Bijou\_Drains](#):
>
> Maybe this is well known , but you can avoid a lot of this stuff by making sure you don’t run as a root user (administrator) on your PC. By default Windows sets up 1 account for a new PC and that account is an admin account which means you can change the system. If you only run that you can have a lot of problems. You need to setup a normal Windows user account and only use that account because a normal account cannot change the Windows system.

I have seen these things infect a machine where the user does not have admin (or even power user) rights. This took me a while to figure out.

Ultimately, I determined that the _machine_ wasn’t infected, his user profile was. You could log in to the machine as a different user, and never see a thing. The infection was in a section of the Local Machine section of the user profile - delete that, and everything was good. (The Local Machine is for machine-specific details, and is not copied to the user’s roaming profile. If it is deleted, it is recreated from scratch the next time the user logs on. No big deal.)

We had a rash of three or four users infected (out of 285) about four months ago, and I haven’t seen anything since - I presume our anti-virus got smarter.

---

<div class="post-metadata">

**Author:** ![Bijou\_Drains](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bijou_drains/32/2814_2.png) [@Bijou\_Drains](https://boards.straightdope.com/u/Bijou_Drains)\
**Post date:** [August 22, 2010, 10:25pm UTC](https://boards.straightdope.com/t/arrgghhh-you-fucking-hijacking-virus-making-sobs/550802/45 "2010-08-22T22:25:00Z")

</div>

Another thing I do since I had problems is I always keep Malwarebytes running. That way the virus cannot prevent it from starting up. If I think I have a virus I immediately run a scan with Malwarebytes.

---

<div class="post-metadata">

**Author:** ![Caridwen](https://avatars.discourse-cdn.com/v4/letter/c/c89c15/32.png) [@Caridwen](https://boards.straightdope.com/u/Caridwen)\
**Post date:** [August 24, 2010, 12:23am UTC](https://boards.straightdope.com/t/arrgghhh-you-fucking-hijacking-virus-making-sobs/550802/46 "2010-08-24T00:23:32Z")

</div>

> [@cosmosdan](#):
>
> > [@Bijou\_Drains](#):
> >
> > Maybe this is well known , but you can avoid a lot of this stuff by making sure you don’t run as a root user (administrator) on your PC. By default Windows sets up 1 account for a new PC and that account is an admin account which means you can change the system. If you only run that you can have a lot of problems. You need to setup a normal Windows user account and only use that account because a normal account cannot change the Windows system.
> 
> Ahhhhhh that’s something I didn’t know and will give it a shot after I clean of the the slightly different variety of the anti virus scumming sucking scam that I just fucking got AGAIN!!!

That happened to me. Possibly you didn’t get rid of it the first time.

I got help at the Geeks to Go Board. You run a series of programs and post the logs and they check the logs for you.

> **[Geeks to Go - Free help from tech experts](https://www.geekstogo.com/forum/)**
>
> Geeks To Go is a helpful hub, where thousands of volunteers serve up answers and support. Check out the forums and get free advice from the tech experts.

---

<div class="post-metadata">

**Author:** ![muldoonthief](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/muldoonthief/32/3188_2.png) [@muldoonthief](https://boards.straightdope.com/u/muldoonthief)\
**Post date:** [August 24, 2010, 12:35am UTC](https://boards.straightdope.com/t/arrgghhh-you-fucking-hijacking-virus-making-sobs/550802/47 "2010-08-24T00:35:13Z")

</div>

> [@silenus](#):
>
> Fuck prosecute. I hope somebody tracks them down, buys a plane ticket, knocks on their door and carves their eyes out with a spoon. On Youtube.

From Greg Bear’s “Slant”, a near-future scifi book written in 1997:

"Also in the late twentieth, with the advent of popular computers, dataflow evolvons were unleashed by pasty, sweating young intellectuals as a kind of game, and were called viruses. They were quickly and efficiently countered, though several such outbreaks caused severe economic disruption.

One prominent computer HACKER or CRACKER was kidnapped from Los Angeles in 2006 and removed to Singapore, where the death penalty was imposed and carried out, after extensive torture…"

---

<div class="post-metadata">

**Author:** ![cosmosdan](https://avatars.discourse-cdn.com/v4/letter/c/a6a055/32.png) [@cosmosdan](https://boards.straightdope.com/u/cosmosdan)\
**Post date:** [August 24, 2010, 3:20am UTC](https://boards.straightdope.com/t/arrgghhh-you-fucking-hijacking-virus-making-sobs/550802/48 "2010-08-24T03:20:01Z")

</div>

> [@Caridwen](#):
>
> That happened to me. Possibly you didn’t get rid of it the first time.
> 
> I got help at the Geeks to Go Board. You run a series of programs and post the logs and they check the logs for you.
> 
> [Geeks to Go - Free help from tech experts](http://www.geekstogo.com/forum/)

Thanks. I think it was a different one. Different name, graphics and behaviour, but maybe not. This last one was harder to get rid of but eventually Malware Bytes on safe mode got it.

---

<div class="post-metadata">

**Author:** ![cards](https://avatars.discourse-cdn.com/v4/letter/c/ecd19e/32.png) [@cards](https://boards.straightdope.com/u/cards)\
**Post date:** [August 24, 2010, 1:17pm UTC](https://boards.straightdope.com/t/arrgghhh-you-fucking-hijacking-virus-making-sobs/550802/49 "2010-08-24T13:17:54Z")

</div>

> [@statij](#):
>
> I recently had ANTIVIR as well. I’m an IT consultant, and so do virus cleanups on a more and more frequent basis, they’re becoming so common. So I _thought_ I knew what I was doing. Until this one. Yes, MalwareBytes is the tool of choice but ANTIVIR left a nasty rootkit infection which required a special tool by Kaspersky to clean. You’ll know if you have this rootkit if you do a google search, click a search result link, and you get redirected to a strange site. I can provide a link to this tool if you have this problem.

Can you post the link, please?

---

<div class="post-metadata">

**Author:** ![cosmosdan](https://avatars.discourse-cdn.com/v4/letter/c/a6a055/32.png) [@cosmosdan](https://boards.straightdope.com/u/cosmosdan)\
**Post date:** [August 24, 2010, 4:42pm UTC](https://boards.straightdope.com/t/arrgghhh-you-fucking-hijacking-virus-making-sobs/550802/50 "2010-08-24T16:42:54Z")

</div>

I’d also like to know how to run MAlware bytes or antivirus from one network computer on another on the network.

---

<div class="post-metadata">

**Author:** ![Bijou\_Drains](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bijou_drains/32/2814_2.png) [@Bijou\_Drains](https://boards.straightdope.com/u/Bijou_Drains)\
**Post date:** [August 24, 2010, 7:16pm UTC](https://boards.straightdope.com/t/arrgghhh-you-fucking-hijacking-virus-making-sobs/550802/51 "2010-08-24T19:16:48Z")

</div>

> [@cosmosdan](#):
>
> I’d also like to know how to run MAlware bytes or antivirus from one network computer on another on the network.

Do you mean load the software on 1 machine but run it on another? You can do that if you have 1 machine act as a server on your network, then all the other machines can connect to the server and run software on the server. However in most cases you still need to install at least part of the software on the machine it runs on so that may not really work for antivirus software.

---

<div class="post-metadata">

**Author:** ![Slow\_Moving\_Vehicle](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/slow_moving_vehicle/32/291_2.png) [@Slow\_Moving\_Vehicle](https://boards.straightdope.com/u/Slow_Moving_Vehicle)\
**Post date:** [August 24, 2010, 11:55pm UTC](https://boards.straightdope.com/t/arrgghhh-you-fucking-hijacking-virus-making-sobs/550802/52 "2010-08-24T23:55:20Z")

</div>

> [@congodwarf](#):
>
> My boyfriend, who uses his for pretty much the same stuff except that he doesn’t read SDMB or take any classes and he usually has internet porn open in the background, has never had an infection on his computer.

Clearly, you need to spend less time on SDMB and online classes, and more on internet porn. Pictures of nekkid people is what the web is _for_, dammit!

---

<div class="post-metadata">

**Author:** ![statij](https://avatars.discourse-cdn.com/v4/letter/s/c2a13f/32.png) [@statij](https://boards.straightdope.com/u/statij)\
**Post date:** [August 25, 2010, 3:09pm UTC](https://boards.straightdope.com/t/arrgghhh-you-fucking-hijacking-virus-making-sobs/550802/53 "2010-08-25T15:09:23Z")

</div>

> [@cards](#):
>
> > [@statij](#):
> >
> > I recently had ANTIVIR as well. I’m an IT consultant, and so do virus cleanups on a more and more frequent basis, they’re becoming so common. So I _thought_ I knew what I was doing. Until this one. Yes, MalwareBytes is the tool of choice but ANTIVIR left a nasty rootkit infection which required a special tool by Kaspersky to clean. You’ll know if you have this rootkit if you do a google search, click a search result link, and you get redirected to a strange site. I can provide a link to this tool if you have this problem.
> 
> Can you post the link, please?

Here you go:

[http://www.removespywareguides.com/how-to-remove-the-tdss-tdl3-or-alureon-rootkit.html](http://www.removespywareguides.com/how-to-remove-the-tdss-tdl3-or-alureon-rootkit.html)

[Previous page](https://boards.straightdope.com/t/arrgghhh-you-fucking-hijacking-virus-making-sobs/550802.md?page=2)
