Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.sys.laptops > #140 > unrolled thread

Oh, God-- What To Do Now?

Started byRon <ryon@dslnorthwest.net>
First post2011-04-16 15:57 -0700
Last post2011-04-21 18:35 -0700
Articles 10 on this page of 30 — 15 participants

Back to article view | Back to comp.sys.laptops


Contents

  Oh, God-- What To Do Now? Ron <ryon@dslnorthwest.net> - 2011-04-16 15:57 -0700
    Re: Oh, God-- What To Do Now? Pen <nospam@spam.none> - 2011-04-16 19:22 -0400
      Re: Oh, God-- What To Do Now? Ron <ryon@dslnorthwest.net> - 2011-04-16 17:51 -0700
        Re: Oh, God-- What To Do Now? retsuhcs@xinap.moc (Mike S.) - 2011-04-17 01:30 +0000
        Re: Oh, God-- What To Do Now? Bob Villa <pheeh.zero@gmail.com> - 2011-04-17 05:47 -0700
          Re: Oh, God-- What To Do Now? Ron <ryon@dslnorthwest.net> - 2011-04-17 17:30 -0700
    Re: Oh, God-- What To Do Now? BJ <backroadjunkie@sbcglobal.net> - 2011-04-17 04:26 -0500
      Re: Oh, God-- What To Do Now? Ron <ryon@dslnorthwest.net> - 2011-04-17 17:22 -0700
        Re: Oh, God-- What To Do Now? Pen <nospam@spam.none> - 2011-04-17 20:45 -0400
        Re: Oh, God-- What To Do Now? "~misfit~" <sore_n_happy@nospamyahoo.com.au> - 2011-04-18 21:05 +1200
          Re: Oh, God-- What To Do Now? Charlie Hoffpauir <invalid@invalid.com> - 2011-04-18 11:35 -0500
        Re: Oh, God-- What To Do Now? lmarco@panix.com (Lou Marco) - 2011-04-20 06:55 +0000
          Re: Oh, God-- What To Do Now? Ron <ryon@dslnorthwest.net> - 2011-04-21 17:20 -0700
            Re: Oh, God-- What To Do Now? lmarco@panix.com (Lou Marco) - 2011-04-25 22:49 +0000
    Re: Oh, God-- What To Do Now? "Ryan P." <rdeletepaque@wi.rr.comm> - 2011-04-17 10:14 -0500
      Re: Oh, God-- What To Do Now? Ron <ryon@dslnorthwest.net> - 2011-04-17 17:57 -0700
        Re: Oh, God-- What To Do Now? "Ryan P." <rdeletepaque@wi.rr.comm> - 2011-04-18 19:10 -0500
          Re: Oh, God-- What To Do Now? schotty456_at_gmail_dot_com@foo.com (schotty456) - 2011-04-19 15:29 +0000
            Re: Oh, God-- What To Do Now? Bob Villa <pheeh.zero@gmail.com> - 2011-04-19 09:31 -0700
            Re: Oh, God-- What To Do Now? lmarco@panix.com (Lou Marco) - 2011-04-20 07:02 +0000
        Re: Oh, God-- What To Do Now? "BillW50" <BillW50@aol.kom> - 2011-04-19 12:00 -0500
          Re: Oh, God-- What To Do Now? lmarco@panix.com (Lou Marco) - 2011-04-20 07:09 +0000
            Re: Oh, God-- What To Do Now? "Ryan P." <rdeletepaque@wi.rr.comm> - 2011-04-20 17:36 -0500
              Re: Oh, God-- What To Do Now? lmarco@panix.com (Lou Marco) - 2011-04-25 22:52 +0000
                Re: Oh, God-- What To Do Now? "Ryan P." <rdeletepaque@wi.rr.comm> - 2011-04-28 20:02 -0500
                  Re: Oh, God-- What To Do Now? "Joel Koltner" <zapwireDASHgroups@yahoo.com> - 2011-05-02 12:49 -0700
                  Proper security (Was Re: Oh, God) wrat@panix.com (the wharf rat) - 2011-05-03 20:25 +0000
                    Re: Proper security (Was Re: Oh, God) Robert Sneddon <fred@nospam.demon.co.uk> - 2011-05-05 13:14 +0100
        Re: Oh, God-- What To Do Now? lmarco@panix.com (Lou Marco) - 2011-04-20 06:58 +0000
    Re: Oh, God-- What To Do Now? dg <david.goodnow@gmail.com> - 2011-04-21 18:35 -0700

Page 2 of 2 — ← Prev page 1 [2]


#156

From"BillW50" <BillW50@aol.kom>
Date2011-04-19 12:00 -0500
Message-ID<iokf3r$28l$1@dont-email.me>
In reply to#150
In 
news:8ecfa058-99f8-4a43-9af7-4726c9868089@e26g2000vbz.googlegroups.com,
Ron wrote:
> On Apr 17, 8:14 am, "Ryan P." <rdeletepa...@wi.rr.comm> wrote:
>> On 4/16/2011 5:57 PM, Ron wrote:
>>
>>> Perhaps I've said it before: I really hate Windows XP. I only use
>>> because it came with my Dell D610 laptop which I bought cheap. What
>>> I really HATE about XP is it's antivirus feature which occasionally
>>> kicks in to make my life a living hell.
>>
>>> A week ago, something set it off and I kept getting a message about
>>> XP Antivirus Program 2011; that I *needed* this program to get rid
>>> of what it said was 12 infections. Maybe yes, maybe no-- but this
>>> message became malware in itself because I could not get rid of it
>>> and it literally held my laptop hostage until I paid nearly $60 and
>>> bought the damn program! Once a number was keyed in, the program
>>> "cleaned" my system and finally went a way, to lurk in the
>>> background like some Mafia thug waiting to extort me again. I'm not
>>> kidding here.
>>
>> Sorry to say, you got scammed. You picked up a trojan virus which
>> pretended it was an antivirus program, and you got tricked into
>> paying an unknown party $60.
>>
>> No offense, but I find it curious that you are computer savvy enough
>> to access USENET, but not savvy enough to recognize the fairly
>> obvious signs that you were being presented with a virus, not a
>> legitimate program. You should read up on basic security. Again, no
>> offense. Trying to help you out so this doesn't happen to you again.
>>
>> There are NO legitimate antivirus programs out there that will charge
>> you to scan and clean your system. Either they won't monitor your
>> system at all, or they will not update the virus definitions. Again,
>> any antivirus that scans your system but insists on a payment to
>> clean is NOT legitimate.
>
>
> Golly, gee; I kinda figured that out.
>
> However, I sat for over a week trying to find a way out of a bad
> situation, and for reasons unknown, I couldn't even post to Google
> Groups for a couple of days. My system was totally  locked up and my
> number of options could be counted on one finger--
>
> So since you are obviously much more informed than poor stupid me,
> what would *you* do when absolutely NOTHING else worked? I'd like to
> know.
>
>
>> And, since it sounds like you weren't actually running any antivirus
>> software in the first place, I suggest you download one of the free
>> programs out there... Avast, AVG, etc. Also, download some anti
>> malware software... Superantispyware for example.
>
> You don't get it, do you? I have anti-virus programs. I USE anti-virus
> programs. But NOTHING will run when the system is totally locked up.
>
> Note that I said NOTHING in big large letters.... My only regret is
> that they weren't flamng letters just to be totally clear about this.
>
> If you ever find yourself in such a situation you might be a little
> less smug.

Hi Ron! I don't know how you paid that 60 bucks by, but if it was by 
credit card, I would call the credit card company and tell them what 
happened if it isn't too late.

And once a computer is badly compromised, it is best to pull the hard 
drive out and scan it with a clean computer. My nephew brought over his 
laptop for me to work on. And that is how I removed 18 rootkits that was 
on his computer.

Some people say once a computer has been badly compromised, you would be 
much safer to wipe everything clean and reinstall all over again. And 
while it is more work, it would be the safest approach.

And just to let you know where I am coming from, I've been using Windows 
since '93. And so far I haven't got one single virus yet (knock on 
wood).

-- 
Bill
Gateway M465e ('06 era) - OE-QuoteFix v1.19.2
Centrino Core Duo 1.83G - 2GB - Windows XP SP3 

[toc] | [prev] | [next] | [standalone]


#160

Fromlmarco@panix.com (Lou Marco)
Date2011-04-20 07:09 +0000
Message-ID<iom0qj$6f0$4@reader1.panix.com>
In reply to#156
In article <iokf3r$28l$1@dont-email.me>, BillW50 <BillW50@aol.kom> wrote:
>
>And once a computer is badly compromised, it is best to pull the hard 
>drive out and scan it with a clean computer. My nephew brought over his 

	Sure, if you need more information for the incident report.  Otherwise
send the poor thing to the Great CPU in the Sky and break out the distribution
disks.

>laptop for me to work on. And that is how I removed 18 rootkits that was 
>on his computer.

	How do you know rootkit #19 isn't laughing at you while it gets ready
to ftp your Quickbooks files to a porn site operator in Asia?

>And so far I haven't got one single virus yet 

	I've never seen a black swan, either.  That's how I know they're
all white.

[toc] | [prev] | [next] | [standalone]


#161

From"Ryan P." <rdeletepaque@wi.rr.comm>
Date2011-04-20 17:36 -0500
Message-ID<ionn5v$v0i$1@dont-email.me>
In reply to#160
On 4/20/2011 2:09 AM, Lou Marco wrote:

>> And so far I haven't got one single virus yet
>
> 	I've never seen a black swan, either.  That's how I know they're
> all white.

  Given the proper level of security paranoia, its not really that 
unrealistic.

  The vast majority of viruses and other malware are caught by opening 
email attachments willy-nilly and visiting infected websites.

  An up-to-date malware monitor and antivirus program, not using 
Internet Explorer, and never running as an Administrator on your system 
for casual use is a great start.

[toc] | [prev] | [next] | [standalone]


#169

Fromlmarco@panix.com (Lou Marco)
Date2011-04-25 22:52 +0000
Message-ID<ip4tvm$lhj$3@reader1.panix.com>
In reply to#161
In article <ionn5v$v0i$1@dont-email.me>,
Ryan P. <rdeletepaque@wi.rr.comm> wrote:
>
>  The vast majority of viruses and other malware are caught by opening 
>email attachments willy-nilly and visiting infected websites.
>

	Think so?  Look up the latest Adobe and image processing exploits,
check into some of the sql injection attacks that hijack trusted servers,
or think about what you can do with a hidden frame and a bit of Javascript.

>  An up-to-date malware monitor and antivirus program, not using 
>Internet Explorer, and never running as an Administrator on your system 
>for casual use is a great start.

	How do you run 2K or XP and not be administrator?  Well, I suppose
you could simply never install anything.  Or change a setting.  Or backup a
file.

[toc] | [prev] | [next] | [standalone]


#175

From"Ryan P." <rdeletepaque@wi.rr.comm>
Date2011-04-28 20:02 -0500
Message-ID<ipd2n4$d0t$1@dont-email.me>
In reply to#169
On 4/25/2011 5:52 PM, Lou Marco wrote:

> 	Think so?  Look up the latest Adobe and image processing exploits,
> check into some of the sql injection attacks that hijack trusted servers,
> or think about what you can do with a hidden frame and a bit of Javascript.

  There are lots of ways to get bad things on your computer, I'm not 
disputing that one bit.

>
>>   An up-to-date malware monitor and antivirus program, not using
>> Internet Explorer, and never running as an Administrator on your system
>> for casual use is a great start.
>
> 	How do you run 2K or XP and not be administrator?  Well, I suppose
> you could simply never install anything.  Or change a setting.  Or backup a
> file.

  That's why most people don't do it.  Proper security policy would 
involve you logging out of your regular user account, and logging on as 
an administrator, doing what you need to do, and then logging off and 
back on to your user account.

  Yes, its annoying to have to switch accounts in order to change screen 
resolution or install (or uninstall) anything, but its far more secure.

[toc] | [prev] | [next] | [standalone]


#180

From"Joel Koltner" <zapwireDASHgroups@yahoo.com>
Date2011-05-02 12:49 -0700
Message-ID<cVDvp.79545$885.53422@en-nntp-14.dc1.easynews.com>
In reply to#175
"Ryan P." <rdeletepaque@wi.rr.comm> wrote in message 
news:ipd2n4$d0t$1@dont-email.me...
>  That's why most people don't do it.  Proper security policy would involve 
> you logging out of your regular user account, and logging on as an 
> administrator, doing what you need to do, and then logging off and back on 
> to your user account.

You can use "run as" to eliminate most -- if not all -- of this hassle.

>  Yes, its annoying to have to switch accounts in order to change screen 
> resolution or install (or uninstall) anything, but its far more secure.

One can also spend a lot of time messing around with group policy to tweak 
exactly what various classes of users can and can't do.  Indeed, I believe 
that by default even "Power Users" can change the screen resolution and --  
usually -- install and remove software.

---Joel

[toc] | [prev] | [next] | [standalone]


#182 — Proper security (Was Re: Oh, God)

Fromwrat@panix.com (the wharf rat)
Date2011-05-03 20:25 +0000
SubjectProper security (Was Re: Oh, God)
Message-ID<ippoc4$l49$1@reader1.panix.com>
In reply to#175
In article <ipd2n4$d0t$1@dont-email.me>,
Ryan P. <rdeletepaque@wi.rr.comm> wrote:
>>
>> 	How do you run 2K or XP and not be administrator?  Well, I suppose
>
>  That's why most people don't do it.  Proper security policy would 
>involve you logging out of your regular user account, and logging on as 
>an administrator, doing what you need to do, and then logging off and 
>back on to your user account.

	Proper security includes not causing so much pain that your
policies drive users to non-compliance.  If security prevents work from 
being done 50% of your users will not do any work, and the other 50% will
ignore policy.  100% of the security team will have monster.com as their
home page.

	Windows security is not proper security because to maintain good
posture requires that you dispense with getting anything useful done.
(I'm talking about consumer desktops here.  They're actually very good on
the server side.)  Any organization that deliberately chooses to annoy and
antagonize users to convince 3rd party developers to use a different file 
system layout needs to get their glass navels  polished.

>
>  Yes, its annoying to have to switch accounts in order to change screen 
>resolution or install (or uninstall) anything, but its far more secure.

	It's much LESS secure because people will not perform actions required 
for adequate security (such as software updates) and because people will work
around the roadblock by exploiting ways to elevate their priveleges or 
disregard permissions.

	Perfect security causes 0 pain to legitimate users and 100% pain
to intruders.  You're suggesting that a guard dog that bites everybody is
OK because you can always throw steaks at it until you can sneak by.

---

	I once worked for an agency that would not allow their computers to
connect to any network but one they'd vetted, would not allow you to change
settings on their computers, required staff members to travel extensively,
and required staff members to use electronic systems to work and communicate
while traveling.  See the problem?  Was this good security or not?

[toc] | [prev] | [next] | [standalone]


#183 — Re: Proper security (Was Re: Oh, God)

FromRobert Sneddon <fred@nospam.demon.co.uk>
Date2011-05-05 13:14 +0100
SubjectRe: Proper security (Was Re: Oh, God)
Message-ID<$hR9uULeSpwNFwbd@nospam.demon.co.uk>
In reply to#182
In message <ippoc4$l49$1@reader1.panix.com>, the wharf rat
<wrat@panix.com> writes
>
>       I once worked for an agency that would not allow their computers to
>connect to any network but one they'd vetted, would not allow you to change
>settings on their computers, required staff members to travel extensively,
>and required staff members to use electronic systems to work and communicate
>while traveling.  See the problem?  Was this good security or not?

 Depends how it was implemented. The company I contracted for as a
customer support engineer had the same restrictions, pretty much.
Storage on the laptops was whole-disk encrypted requiring two-part token
authentication and trusted user login to access any data. The OS on all
desktops and laptops was locked down to only accept authenticated
network connections with the company intranet; any attempt to connect a
laptop to the internet was barred whether via a modem (including 3G
cellular modems) or broadband. WiFi was disabled with prejudice (the
WiFi adaptors were removed by the engineers before the machines were
issued) and the USB ports disabled for mass storage devices such as
thumb drives and printers etc., leaving only support for HIDs such as
mice and keyboards and USB charging for phones etc.

 It's not too difficult to keep machines like that secure. You do have
to be firm with the sort of user who wants Facebook and Angry Birds on
company equipment, pointing out that there's nothing preventing them
doing what they like with their own laptop. It's just that they're not
going to get it on the machine supplied by their employer.
-- 
 To reply, my gmail address is nojay1              Robert Sneddon

[toc] | [prev] | [next] | [standalone]


#158

Fromlmarco@panix.com (Lou Marco)
Date2011-04-20 06:58 +0000
Message-ID<iom06b$6f0$2@reader1.panix.com>
In reply to#150
In article <8ecfa058-99f8-4a43-9af7-4726c9868089@e26g2000vbz.googlegroups.com>,
Ron  <ryon@dslnorthwest.net> wrote:
>
>what would *you* do when absolutely NOTHING else worked? I'd like to
>know.

	Formatted the drive and restored from yesterday's backup.

[toc] | [prev] | [next] | [standalone]


#163

Fromdg <david.goodnow@gmail.com>
Date2011-04-21 18:35 -0700
Message-ID<636e7a08-87a3-42c2-b7ab-6608abf45e44@j28g2000vbp.googlegroups.com>
In reply to#140
I keep an old Blue & White Power Mac I've added USB 2.0 to, and a USB
drive case, for just such occasions. Intel Macs are vulnerable to CPU
microcode exploits, same as any other i386-based system. It doesn't
have Java, or anything else, just the operating system. I copy off any
desired pictures, documents, etc., then delete all partitions, re-
partition, and format with a secure wipe (eight-way-rewrite, which
will generally kill a failing drive... saves trouble in the long run,
I think). Then put it back in the Windows machine it came from and re-
install.

If you're using a Windows machine and boot disks, 'cause you haven't
got a Power Mac (G3, G4, G5) sitting around nor access to one, don't
forget fdsk /mbr before reloading, and zero/secure erase that drive!

On Apr 16, 6:57 pm, Ron <r...@dslnorthwest.net> wrote:
> Perhaps I've said it before: I really hate Windows XP. I only use
> because it came with my Dell D610 laptop which I bought cheap. What I
> really HATE about XP is it's antivirus feature which occasionally
> kicks in to make my life a living hell.
>
> A week ago, something set it off and I kept getting a message about XP
> Antivirus Program 2011; that I *needed* this program to get rid of
> what it said was 12 infections. Maybe yes, maybe no-- but this message
> became malware in itself because I could not get rid of it and it
> literally held my laptop hostage until I paid nearly $60 and bought
> the damn program! Once a number was keyed in, the program "cleaned" my
> system and finally went a way, to lurk in the background like some
> Mafia thug waiting to extort me again. I'm not kidding here.
>
> When I tried to use my laptop, not one single program would work
> except for the two M$oft programs, IE8 and Outlook express; everything
> else I could click on until the cows came home and nothing would
> happen-- except that damn AV program might pop up again. Oh yeah,
> *that* worked too. But 95% of my programs didn't.
>
> I had a vaguely similar problem before and went into safe mode, to see
> what I could do. I couldn't do anything. Everything I tried resulted
> in an almost total lockout to my programs. I even tried making new
> accounts-- eight of them. Most of them would have the same problem:
> the non-Microsoft programs wouldn't work, and the AV program would pop
> up although it claimed there were no more infections.
>
> I have been working at this for nearly a week, and now after the 9th
> account, I finally got one that worked right. I came to within a hair
> of doing a root canal and totally getting rid of WP and installing
> something reliable like Windows 2K. But I had already spen $60 for the
> Av program and I can't afford to bleed money for this stupid laptop. I
> have no doubt that sooner or later, this kind of problem is going to
> re-occur as long as it seems to be no way to truly get rid of the  AV
> program and the part of XP that controls it. I can't keep going
> through accounts as this wates a lot of time and by accident, I
> already lost a lot of my precious files when I deleted a "corrupt"
> account. Does anyone know what to do about a problem like this. If so,
> help!
>
> Ron

[toc] | [prev] | [standalone]


Page 2 of 2 — ← Prev page 1 [2]

Back to top | Article view | comp.sys.laptops


csiph-web