From: retsuhcs@xinap.moc (Mike S.) Newsgroups: comp.sys.laptops Subject: Re: Oh, God-- What To Do Now? Date: Sun, 17 Apr 2011 01:30:19 +0000 (UTC) Organization: What? ME organized? Lines: 41 Message-ID: References: <55a0fff7-e1b7-499f-865c-b6ee68cddc37@r4g2000prm.googlegroups.com> <97d3e5f9-95f5-4792-bf13-efd9708dd5bc@e26g2000vbz.googlegroups.com> NNTP-Posting-Host: panix5.panix.com X-Trace: reader1.panix.com 1303003819 313 166.84.1.5 (17 Apr 2011 01:30:19 GMT) X-Complaints-To: abuse@panix.com NNTP-Posting-Date: Sun, 17 Apr 2011 01:30:19 +0000 (UTC) X-Email-Address: If Backwards, Reverse The Letters X-Newsreader: trn 4.0-test76 (Apr 2, 2001) Path: csiph.com!x330-a1.tempe.blueboxinc.net!usenet.pasdenom.info!news.dougwise.org!feed.ac-versailles.fr!news.in2p3.fr!in2p3.fr!kanaga.switch.ch!switch.ch!newsfeed-00.mathworks.com!panix!not-for-mail Xref: x330-a1.tempe.blueboxinc.net comp.sys.laptops:143 In article <97d3e5f9-95f5-4792-bf13-efd9708dd5bc@e26g2000vbz.googlegroups.com>, Ron wrote: >On Apr 16, 4:22 pm, Pen wrote: >> On 4/16/2011 6:57 PM, Ron wrote:>  XP >> > Antivirus Program 2011 >> >> You have a virus nothing to do with xp; see >here.http://www.spywareremove.com/removeXPAntiVirus2011.html > >I've been a fan of Windows NT and to a lesser extent, Windows 2K; that >kind of crap couldn't happen on either of those two systems. They >happen on XP because the OS doesn't really give you the freedom of >choice to use whatever kind of firewall and Av programs you want to >use: it only recognizes certain programs or even just the one AV >program. Who designed such a totally deranged OS? > >If I could, I would go back to Win2k in a heartbeat. Unfortunately, my >copy requires a disk drive to load in parts of Win2k and this laptop >has only a DVD/CD to load programs. Win2k was never all that cheap to >begin with, and it's more costly now than it ever was before, so I sem >to be stuck with XP but I don't like it. I'm not sure I would have >gotten the laptop from Amazon if I had known that XP was its operating >system. > >But back to the matter at hand, that article doesn't say what to do >when your computer has been hijacked an you can run *any* other >program to even find the culprit at work or to get rid of it.We are >talking about total lock-down. This is a fake antivirus. Among other things, it intercepts the handler for .exe files and directs the requests to itself ... so any time you try to run any program it executes the malware instead. You need to terminate the process from Task Manager. You can then start CMD.EXE by choosing FILE --> NEW TASK and ctrl-clicking on RUN. From there, import the "exe file association fix" from the web site of your choice and run your REAL antivirus to remove the malware. It typically lives in the NETWORK SERVICE local settings folder.