...and swear

May 07, 2011 12:13

I seem to be in a bit of a pickle laptop wise ( Read more... )

Leave a comment

Comments 15

(The comment has been removed)

whotheheckami May 7 2011, 11:32:34 UTC
Got it. Thanks. I'd worked it out at about the same time you posted. Most difficult thing was finding where Firefox 4 had hidden the Tooks button ;@)

Now to tackle the file association glitch

Reply

emmavescence May 7 2011, 11:35:06 UTC
This sounds like something I had to deal with this week. While the file association thing is something you can fix (quite easily with a registry edit, I can dig it out for you if it still gives you trouble after running MWB scans, just amounts to a bit of copy and paste and double clicking), it's usually a sign of an "exe hijack" component of some malware, so make sure the nasties are gone first.

Reply


emmavescence May 7 2011, 11:33:23 UTC
Download a copy of Malware Bytes (http://www.malwarebytes.org/). Then boot into safe mode, run MWB and do a full scan. Wander off for a bit and come back when it's done, let it remove what it wants to remove, and boot back into normal mode. That should help a lot; MWB is very good with malware, better than I've found AVG to be. Csrss.exe is a system process but what these things often do is copy the names of system files and save them in other places, which makes it really hard to figure out what's naughty and what's an important part of your system. You've probably managed to delete the naughty bit rather than the system file, but you've undoubtedly got remnants of the malware lingering around which will just put things back when you reboot your machine. MWB should sort you out.

Reply

perfectlyvague May 7 2011, 19:59:16 UTC
The last trojan I picked up manages to run a dummy version of this. You have to download it onto a different pc, rename it move it to the other pc via USB rather than disc and then use it.

Reply


(The comment has been removed)

alexmc May 7 2011, 11:59:57 UTC
This was roughly what I was going to suggest.

Reply

whotheheckami May 7 2011, 12:02:43 UTC
You chaps are wonderful. Malwarebytes is chewing away as we speak and I'll look at the File Association thing after it's done its stuff

Reply

emmavescence May 7 2011, 12:04:47 UTC
Safe mode! It works much better if you boot into safe mode first because then a lot more of the background processes aren't running and it's easier for it to remove anything.

Reply


dougs May 7 2011, 12:03:18 UTC
As others have said, wipe-and-reinstall is the only approach you can trust.

Reply

alexmc May 7 2011, 12:08:46 UTC
You may also find it is the *quickest* and easiest method too.

Reply

sarah_mum May 7 2011, 15:53:25 UTC
you mean "nuke it from orbit..."?

Reply

dougs May 7 2011, 16:52:04 UTC
Take off [your files] and nuke it from orbit.

Reply


specialunclet May 7 2011, 14:03:58 UTC
hitmanpro

download it onto a usb key on another machine, run it in safe mode with networking. when it wants a reboot go back into normal mode

reinstall is the safest option but an arse if you havent got a back up or even the disks for all your hooky software

Reply


Leave a comment

Up