Friday, May 20, 2011

On Comments And Worms

I'm working on updating this blog into having more military look, and as I was going through doing a little updating here and there, I noticed a few comments I had never read. Sometimes as I read the comments, I click on the names to see what that person has as a blog. More often than not it is a dead blog or link. Well, what I didn't realize is that the comments aren't set up in such a way to weed out malicious websites, as in, worms, viruses, trojans, the general crap that someone with nothing better to do with their time than create something that attempts to destroy your computer. So, as I clicked on one name... suddenly a strange website popped up, and the all familiar computer-lockup, and that tell-tale 4 color fake Microsoft shield in the lower right hand corner... CRAP!!!

Immediately shut down the computer and restarted but it was too late, the damage had been done. As the programs loaded I got an actual warning message that the Windows firewall was disabled, there was no way to turn it on, and MOST of my anti-virus software (I run 4 active at all times) had shut down.

When I went to click on CC-Cleaner, one of my programs for fixing problems... I received this:

This file does not have a program associated with it for performing this act

This was at about 8 a.m. this morning. I worked it for about a half hour, couldn't get much done because I had an appointment coming up at 0900, then I noticed that, oddly enough, Ad-Aware remained running, and that basically saved me. I ran Ad-Aware on a complete sweep while I went to my appointment, when I came back, it had found the W32.Sircam.Worm virus and quarantined it.

The problem? It had deleted out the portion of the Windows registry associated with running most .exe files. So I shut down the internet, borrowed belly's mini-laptop (keep forgetting what they call these, palmtops?) and used that to look up issues while I attempted to up a fix, as I opened my own laptop in safe mode, then in safe mode with prompt, then regular mode after I found (by some miracle) an actual windows registry fix after both belly and I worked on this for probably 3 more hours.

Anyways, I have deleted to offensive comment, and as part of my updating I plan on putting in some better defenses against that sort of shit. My apologies if anyone else got hit by this.

1 comment:

Anonymous said...

younix!