Category Archives: computer virus

Seamonkey SSL problem Silver Spring MD

I took the ICC over to zip code 20904 to help out a long time customer.

After an update Seamonkey would not load secure ( https ) sites properly.  Per instructions from the Mozilla folks, deleted the cert.db file.  No love.  Restored system to an earlier time.

Removed the anti-virus (temporarily).

Ran windows update.

Re-installed norton.

Updated seamonkey, to the current release.

Now everything works as advertised!

During the re-update of seamonkey, a message popped up indicating the initial download of seamonkey had a problem.  So likely the initial update of SM was corrupt.

Once again, simplifying, and re-applying updates from the top down …. Saves the day!!!

🙂

File Cleaner Alert gog.exe Virus – Leisure World, MD – 20906

Jim K. on Interlachen Dr. — sorry that your curiousity got the better of you.  You just had to open that piece of spam.  You won’t do that again too soon.

Regardless I am glad I was able to help.

Jim’s problem was that when he would turn on the computer, and try to log in, his desktop would bring up only a splash screen, generated by the gog.exe virus.

Clean This Virus Splash Screen

Ugh a virus

Luckily, although annoying, I was able to get past it and banish it without too much trouble.  Jim – sorry your McAfee did not get it, before you were infected, but at least cleaning it up was not terribly difficult.  But as we discussed, your computer is close to being obsolete.  Next time there is a problem, lets really work on getting you a new computer, and moving your data from the old to the new.  A single core P4 with 512 MB of RAM, just does not cut it any longer.

ROOTKIT virus removal Gaithersburg, Maryland – 20878

B.K. of Gaithersburg, I am glad I was able to help you get rid of that nasty rookit virus.  It was a nasty one where even running our normal set of tools did not quite do it.  I had to re-write the master boot sector to finally get it clean.

Keep in mind, if this happens again, we can send you our Watza Emergency Repair and Recover disk.  Boot from our emergency disk, and we can then scan for even the most persistent viruses remotely, even fix the boot sector !!

Regardless, I am glad I was able to help, and you seemed to be off and running virus free, when I left.

Mouse Problem Gaithersburg – MD – 20878

Sometimes a mouse problem, is just a mouse problem ….

J.A. of Gaithersburg. I don’t know what to say, except sometimes a mouse problem is just a mouse problem.

Not quite sure of what you expected, I try to look at the most obvious first.  You had done many good and correct things before I got there.  Scanning with multiple AV’s, and anti-spyware tools, you picked good ones to try, but you did not try a new mouse.

Also, you seemed very concerned about how much this was all going to cost, but had not tried the most simple, and inexpensive solution yourself.

I am not sure why your business IT department was convinced it was something more malicious then a bad piece of hardware, but even so, why not try the most obvious thing first?

Keep in mind, the folks in your company’s IT org are smart, but they never even looked at the log files, or anything specific to their computer.  They had to go on only the information you gave them, and you did not have the solution.  That is not a criticisim, or you, or them.  Well, really if they had said, we have no idea unless we look at it, and that is not our job, then you would have been better off.  So, shoot me, but I criticize them just a tiny bit, for trying to help, when they really did not have enough information to be helpful.

I know you felt a little silly about the result, but be glad it did not seem to be a bad motherboard, or failing hard drive, or rootkit virus.  Pretty sure it was just the mouse ……….

Mt Airy MD HP Business Desktop pro 3130 Numlock login problem – 21771

HP — you are building some very nice computers right now, but there is one little detail that you have slipped up on.

It is easy to Work Around, but it is ANNOYING.

You are shipping your business desktop pro with a very cool keyboard that does not have a separate number keyboard.  It uses less desk space, and really very few computer users ( at least few of my customers), use the number kepad keys.  BUT there is no BIOS setting to allow the owner of the computer to manage turning the numlock on, or not on, on bootup.

The Numlock key wants to start up locked on nums.  The keypad is integrated into the normal keys on the keyboard …. so …..

If you set up win7 to not require a login/password then you can turn off numlock the first time you login, and it seems to stay off …

If you watch it while you reboot, it actually come on during the bootup process, and once your win7 desktop starts … it is off.  Easy Peazy.

BUT if you follow industry standard, or turn on the HP Protect options, then you must visit the login screen during bootup.

UGH — if you watch the numlock lamp, it is lit when you are sitting at the password screen.  So every time you log in, you need to click off the numlock before you type in your password ( unless you have a left-hand only password).

The keyboard IS COOL, but you must either change the BIOS to never turn on numlock, or at least change the BIOS to allow the user to manage the BIOS.  Given many users never need to look at the CMOS settings, it would be best to add the option, but default it to NOT turning on num-lock.

Ironically enough I am preparing a HP ProBook 4520s for delivery to a customer.  It is a well priced, 15″ screen notebook, that HAS a separate number keypad.  Go Figure — a Desktop Pro 3130 with a keyboard w/out number keys, and a laptop computer with separate number keys ……

My .02 — fix the BIOS on the 3130 leaving the number keys off is a good move, and take the number keys off of most of your laptops w/ 15″ screens.

PLEASE PLEASE PLEASE release a BIOS update for the 3130 to address this annoying problem.

Remote Support – Virus removal and Maintenance – Bethesda MD

K.S. Thanks for letting us help you get your computer going yesterday.  It is great when we are able to get this kind of work done remotely.  Only $60 for you, and we don’t have to fight traffic, or burn fuel.  Thanks KS of Bethesda!

Computer Remote Support – Silver Spring MD 20906

D.E. your spyware and virus problem was a little challenging, but I am glad we were able to resolve the problem remotely … and in only 1 hour.  A big win-win.  We did not have to drive out to you, and you had your whole problem resolved for only $60.

Ask Bob a Question

Do you have a technical question.  Click on “Leave a Comment” below to post it here, I will try to check for and answer questions at least once a day.

ZLOB Downloader SmitFraud problem Bethesda MD

THERE IS NO WARRANTY IMPLIED IN ANY WAY FOR ANY OF THE INFORMATION FOUND IN THIS BLOG. IF YOU CHOOSE TO DOWNLOAD, AND USE ANY TOOLS I REFERENCE, YOU ARE DOING SO AT YOUR OWN RISK. I HOPE YOU FIND THIS BLOG HELPFUL, BUT USE THE INFORMATION HERE AT YOUR OWN RISK.

Thanks for stopping by.

Hi Joanne, of Bethesda, MD.  I am glad I was able to help you out with your ZLOB Downloader / Smitfraud problem.

When I arrived on-site I saw that Joanne’s computer had been infected by ZLOB, and Smitfraud.  It had the tell-tale applications showing on the desktop, etc.

I had with me the latest versions of ATF-Cleaner, ComboFix, Hijack This, and SpyBot. So I could get right to work.

First I installed, and ran ATF-Cleaner.  ATF-Cleaner removes many different types of temporary files.  Many viruses, trojans, and other types of malware “hide” as temporary files, so getting rid of all of the temp files can be a big help in curing your computer.

Then I ran Combo-Fix.  There are risks (as combo-fix itself tells you).  ComboFix is a specialized tool.  It won’t find, and cure your computer of the thousands of viruses that Norton, or McAfee will, but it targets the Virtumundo, and SmitFraud strain of malware.  Combo-Fix ran just fine.

After ComboFix had finished doing what it does, I used Hijack This to clean out anything that appeared malicious.  In this case there were 4 different users defined for this computer, so I had to go user, to user, looking at the Hijack This log, and deciding which entries were likely malicious.

Finally I ran Spybot to see if there was anything else going on.  I tried it in normal mode, first, but that just did not cut it. It was unable to remove some  ZLOB related items in normal mode.  I re-ran it in Safe Model and it ran just fine.

With the four different user id’s defined for the computer, it took a little while to get the above done, but I was able to eradicate the trojan, and it’s accompanying bit of malware.

Thanks!

At WatzaNetwork? we offer you help with your PC, Mac, Blackberry, Palm, Router, DSL, or Cable modem.

We provide at your site services in Montgomery, and Frederick counties MD, including

Gaithersburg, Montgomery Village, Germantown, Rockville, Potomac, Darnestown, Bethesda, Chevy Chase, Silver Spring (including Liesure World), Clarksburg, Urbana, Ijamsville, and Frederick, MD.

Or see our computer products store. We sell PCs ( XP and Vista ), Macs, Routers, etc.

WinXP Win98se sharing problem Norton Internet Security Problem in Potomac, MD

THERE IS NO WARRANTY IMPLIED IN ANY WAY FOR ANY OF THE INFORMATION FOUND IN THIS BLOG. I HOPE YOU FIND THIS BLOG HELPFUL, BUT USE THE INFORMATION HERE AT YOUR OWN RISK.

Hey Craig, of Autumn Wood Way, in Potomac,

I am glad I was able to help you get your old Win98SE computer onto your Network.

Craig has an old Dell Dimension 4100, a much newer Dell Dimension 8400, and a new notebook with Windows Vista.

He wanted to be able to share a folder between his Win98SE Dell, and his WinXP Home machine. It should have been pretty simple. I turned on file and printer sharing on his older system, and also on his XP system. Shared a folder on the older system, and then tried to map to it from the new system.

Two problems

  1. The XP system was not seeing the older Dell on the network at all, and
  2. The Older Dell’s keyboard was not working very well. Some critical keys were not working.

The keyboard problem needed to be solved first. Of course WinXP has the “keyboard on screen” option, but not Win98. So I downloaded a virtual keyboard, and was then able to type again.

With the virtual keyboard I was able to change the workgroup, and also explicitly map \\new_dell_name to the newer dell.

Still no luck. So I started to look around to figure out what could be blocking. On the old Dell Craig had an old version of Norton Internet Security, that was disabled, and also no longer current. Norton, as well as just about all of the other software firewalls are complicated, and thus prone to failure. Don’t get me wrong, I like Norton Internet Security, but like McAfee, and Zone Alarm, and all the rest … software firewalls break the KISS (Keep It Simple Stupid) rule, and thus are prime suspects when you have problems.

Sure enough. I removed Norton Internet Security ( 2004 version, I think), and the file sharing then worked.

Thanks for stopping by.

At WatzaNetwork? we offer you help with your PC, Mac, Blackberry, Palm, Router, DSL, or Cable modem.

We provide at your site services in Montgomery, and Frederick counties MD, including

Gaithersburg, Montgomery Village, Germantown, Rockville, Potomac, Darnestown, Bethesda, Chevy Chase, Silver Spring (including Liesure World), Clarksburg, Urbana, Ijamsville, and Frederick, MD.

Or see our computer products store. We sell PCs ( XP and Vista ), Macs, Routers, etc.