Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

.gif virus


  • Please log in to reply
3 replies to this topic

#1 bikaone

bikaone

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:41 PM

Posted 26 April 2013 - 10:21 AM

I have downloaded a nasty .gif virus (again) first time like a year or so. Then NO antivirus program was able to detected beside Combofix. I worked on it 18 1/2 hours nonstop but i find the sucker finally. I have downloaded every known program out there and still all came up empty until i run in to this site . My second time around even Combofix didnt work but luckily through you guys i got RougeKiller what find the registry entries. The second i downloaded the picture i know i was in trouble. The mouse curser freezed and started moving funnily around i got nocontrol over it. So yes i fixed this issue again 1000 thanks to all of you guys whom giving helping hand to keep our computers going.

 

Now here is my question. How to stop windows auto executing the virus "instructions" so it can not change the registry keys in seconds. Generally it turns off the virusprotection, the updates, and the bad websites  blocking. Windows7 asking every time before you install a legelimate program if you want to install "this" unkonw program? Why is it not sensing it an other program is like a .gif virus modify's the registry? How could we block , there is any way to block this virus to do this? And i am positive there are the jpeg cousins are working in the similar matter. There is a thing like a jpeg or .gif quarantine? So download first.Goes strait to a quarantine.If it is virus frre then release it for use.It would be a wonderful program to have.

 

I tried Sandboxie but the 64bit version (still experimental) slows the browsing  to a snail paste. So if any of you would know the "hot fix" for this issue...Otherwise this will be a never ending battle. I got Viper antivirus.Funny thing is seems to be non of this programs are capable of detecting the virus as it comes in. And even if the program is still works cant find the virus.After all this time it just amazing this issue can not be come around. So if anyone knows a program or how to change the registry from "auto" execution of downloaded junk , the help would be greatly appriciated.

 

 



BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,329 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:10:41 PM

Posted 26 April 2013 - 10:28 AM

Having run ComboFix we ill need to see that log. Please repost per this guide.

Please follow this Preparation Guide and post in a new topic.

Let me know if all went well.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 bikaone

bikaone
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:41 PM

Posted 26 April 2013 - 06:51 PM

As i said i have removed the virus . The question would be if there is any program to block the script to execute first place. So windows not automatically just install the trojan....Funilly it ask you for the legelimite programs to install. Not the trojan. And this is not packed in to an archive.Comes with a page. Piggibacks...Thanks for anyone who would have some info on it...



#4 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,329 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:10:41 PM

Posted 27 April 2013 - 07:20 PM

If using Firefox you can use the "No Script" Add on,

 

 

 

 

 

 

 

 

 

 

 

 

'


How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users