Switcher Hangout The place for switchers to discuss their new machines, and how to work with OS X. General support can be had here for newbie stuff, like "How do I restart my new iMac?" :)

Mac, Win XP, Parallels & now a bloody virus


Post Reply New Thread Subscribe

 
Thread Tools
Dubliner

 
Member Since: Nov 21, 2007
Posts: 4
Dubliner is on a distinguished road

Dubliner is offline
New switcher here, & I was hardly a "Power user" to begin with, anyway prob is I installed Parallels to run some Win only SW I have to have. Of course I didnt install AV SW and I got eaten alive by Brave Sentry/SpySherrif. I had great fun getting Paralles to run in the first place, so I'm not looking forward to wiping WinXP & Parallels so I can start fresh. How would I go about getting this spyware off & how difficult or wise is it to erase Win & Plls. & re-install? WIll this get rid of the hidden files that Adaware, Spyhunter, Norton and a few others dont seem to be able to find & destroy ? TIA Dubliner
QUOTE Thanks
kirby14

 
kirby14's Avatar
 
Member Since: Nov 20, 2007
Posts: 93
kirby14 is on a distinguished road

kirby14 is offline
Once you have viruses and spyware, your best bet is to just reinstall.

First thing you should do after installing windows is run ALL updates including IE7 and NEVER randomly click yes on boxes that appear from the internet.

Mac Pro | 3GB | 250GB| Dell E207WFP
QUOTE Thanks
Dubliner

 
Member Since: Nov 21, 2007
Posts: 4
Dubliner is on a distinguished road

Dubliner is offline
"NEVER randomly click yes on boxes that appear from the internet."
I got you there, it posed as an Anti Spyware notice.

Last edited by Dubliner; 11-21-2007 at 01:16 PM. Reason: spelling
QUOTE Thanks
Neo

 
Neo's Avatar
 
Member Since: Aug 14, 2007
Posts: 557
Neo is a jewel in the roughNeo is a jewel in the rough
Mac Specs: white MB 2.16GHz 3GB 320GB 10.6.1

Neo is offline
Ask yourself, "What would I do if I had this infection on a windows PC?"
Would you format the HD then reinstall Windows and all applications? Granted, the process is a little easier with a virtual machine, but it can be dealt with. It is possible to clean up from this. When you are done, install Spybot, AdAware, and reputable antivirus software (if you haven't).
Don't even use the internet on the Windows VM! I mean, why would you do this?
Finally, NEVER, UNDER ANY CIRCUMSTANCES, CLICK ON POPUPS! NEVER!

Good luck
QUOTE Thanks
Brown Study

 
Brown Study's Avatar
 
Member Since: Mar 11, 2004
Location: Winnipeg
Posts: 1,964
Brown Study is a name known to allBrown Study is a name known to allBrown Study is a name known to allBrown Study is a name known to allBrown Study is a name known to allBrown Study is a name known to allBrown Study is a name known to all
Mac Specs: G4 — Tiger and OS 9

Brown Study is offline
After cleaning up the malware, it might be wise to use the Mac on the web to download all the Windows anti-malware programs you need, copy them over to the Windows side and install them before going on the web with Windows again.

That way, it will have protection from the outset.
QUOTE Thanks
opus_az

 
opus_az's Avatar
 
Member Since: Dec 06, 2006
Posts: 275
opus_az has a spectacular aura about

opus_az is offline
I don't see a need to reinstall Parallels, though you may want to delete the shared folder.

Disinfecting Windows can be very tricky and often times it's quicker just to reinstall Windows, but it depends on your time cost/benefit. Perhaps this forum http://forums.techguy.org/54-malware...jackthis-logs/ can help if you want to try to disinfect before you reinstall your Windows virtual machine.

iMac, MB, MB Air, nano
QUOTE Thanks
theonegod

 
theonegod's Avatar
 
Member Since: Nov 02, 2006
Posts: 476
theonegod has a spectacular aura about
Mac Specs: 24" 2.8ghz IMAC, MB Pro

theonegod is offline
This is what virtual machine snapshots are for. I would just blow out your virtual machine, reinstall XP in a new vitual machine and then fully patch it and install anti virus. Install IE 7. Then when all that is done make a snapshot. Now if you get any trouble you can always revert back to this saved point.
QUOTE Thanks
damainman

 
Member Since: Nov 14, 2007
Posts: 135
damainman is on a distinguished road

damainman is offline
Are you saying he needs to format his whole mac, just for the windows virus?

I've actually had a good success rate of removing any viruses I've ever got on my windows xp system. Not sure about vista, but on xp even though it might've took a week, i was able to remove all viruses and spyware from the systems i've worked on.
QUOTE Thanks
knightlie

 
knightlie's Avatar
 
Member Since: Mar 22, 2007
Location: UK
Posts: 1,463
knightlie is just really niceknightlie is just really niceknightlie is just really niceknightlie is just really nice
Mac Specs: Lenovo Z560 Hackintosh -:- '06 iMac -:- iPod Touch 2ndGen

knightlie is offline
Quote:
Originally Posted by Dubliner View Post
"NEVER randomly click yes on boxes that appear from the internet."
I got you there, it posed as an Anti Spyware notice.
It doesn't matter, don't answer Yes from ANY questions from the Internet.

[URL="http://beadia.net"]Beadia[/URL - Jewelry Business Management Software]
I judge you when you use poor grammar.
QUOTE Thanks
smartyMAC

 
smartyMAC's Avatar
 
Member Since: Jun 20, 2007
Location: Land of Rising Sun
Posts: 337
smartyMAC will become famous soon enough
Mac Specs: MB White 160GB, 2GB RAM,

smartyMAC is offline
One more word of advise would be to take a snapshot immediately after install ... if you face a similar problem you can always go back to the snapshot which is a point in time image of your xp installation.... No amount of AV & spywares can protect windows completely. This can save you lot of effort to restore back.

Ofcourse this feature is available in VMF not sure whether Parallels has it.
QUOTE Thanks
Alexis

 
Alexis's Avatar
 
Member Since: Apr 20, 2006
Posts: 2,255
Alexis is a jewel in the roughAlexis is a jewel in the roughAlexis is a jewel in the rough
Mac Specs: Al iMac 20" 2.4Ghz Intel Core 2 Duo

Alexis is offline
1.) Run Ad Aware
2.) Run Spybot
3.) Run HiJackThis and post your report log at a PC security forum such as www.security-forums.com
The sole purpose of these forums is to help people who post their HiJackThis logs.

Reinstalling should be a last resort. 95% of junk can be removed by people helping you on HiJackThis forums.
QUOTE Thanks
Neo

 
Neo's Avatar
 
Member Since: Aug 14, 2007
Posts: 557
Neo is a jewel in the roughNeo is a jewel in the rough
Mac Specs: white MB 2.16GHz 3GB 320GB 10.6.1

Neo is offline
Quote:
Originally Posted by knightlie View Post
It doesn't matter, don't answer Yes from ANY questions from the Internet.
No, it DOES matter! I've seen pop-ups that LOOK like a message box with a Yes and Cancel button and all, but the whole popup was the Yes button. Even if you clicked the Close button in the top right corner, it would proceed to install the bad thing. For instance, think about those annoying, floating Flash popups.) The best thing to do (in Windows) is to key Alt + F4 to close the popup when it has focus.
QUOTE Thanks
knightlie

 
knightlie's Avatar
 
Member Since: Mar 22, 2007
Location: UK
Posts: 1,463
knightlie is just really niceknightlie is just really niceknightlie is just really niceknightlie is just really nice
Mac Specs: Lenovo Z560 Hackintosh -:- '06 iMac -:- iPod Touch 2ndGen

knightlie is offline
Quote:
Originally Posted by Neo View Post
No, it DOES matter! I've seen pop-ups that LOOK like a message box with a Yes and Cancel button and all, but the whole popup was the Yes button.
It's very simple to spot this - if you get a hand-pointer when you hover over the Yes or No buttons then you can tell it's an ad. This is a basic form of security - DO NOT just blindly click on an unsolicited question box without taking a few seconds to work out what it is.

Quote:
Even if you clicked the Close button in the top right corner, it would proceed to install the bad thing.
Same thing - hover over the X close button - if you get a web-link hand pointer, then it's a popup/ad. Either way, you should not click on an unsolicited question box displayed when you visit a web page, no matter what they look like. Think about it - no Windows message box displays a Hand pointer on any of it's buttons, Yes, No, OK or Close.

Another simple method is to adjust your Windows fonts or colours slightly, so spoof message boxes from web pages don't look like your Windows setup and are easier to spot.

[URL="http://beadia.net"]Beadia[/URL - Jewelry Business Management Software]
I judge you when you use poor grammar.
QUOTE Thanks
Sgt Beavis

 
Sgt Beavis's Avatar
 
Member Since: Oct 18, 2006
Posts: 285
Sgt Beavis is a jewel in the roughSgt Beavis is a jewel in the rough

Sgt Beavis is offline
Word of advice for future reference....

This is what I do on all my VMs...

Set your virtual hard disk to Non Persistant. That way, if you catch a virus or malware, you just reboot and its gone because all changes are discarded...

All you need to do then is use the shared folder to store any important files and such...
QUOTE Thanks
Neo

 
Neo's Avatar
 
Member Since: Aug 14, 2007
Posts: 557
Neo is a jewel in the roughNeo is a jewel in the rough
Mac Specs: white MB 2.16GHz 3GB 320GB 10.6.1

Neo is offline
Quote:
Originally Posted by knightlie View Post
It's very simple to spot this - if you get a hand-pointer when you hover over the Yes or No buttons then you can tell it's an ad...
Same thing - hover over the X close button - if you get a web-link hand pointer, then it's a popup/ad. Either way, you should not click on an unsolicited question box displayed when you visit a web page, no matter what they look like. Think about it - no Windows message box displays a Hand pointer on any of it's buttons, Yes, No, OK or Close.

Another simple method is to adjust your Windows fonts or colours slightly, so spoof message boxes from web pages don't look like your Windows setup and are easier to spot.
So it DOES matter...
It's still not as simple as you make it out to be.
Yes, the hand pointer is often the GUI default for links, but if you are coding a spoof popup, you can assign different pointer types for different areas of the window (or, in this case, the same pointer type for the whole window).

I like the color-tweak idea! However, since it is well-known where Windows settings are stored, a sophisticated spoof could populate itself with those settings. It's not fool-proof. We need something like...keying Alt + F4.
QUOTE Thanks

Post Reply New Thread Subscribe


« New to Mac | Warranty »
Thread Tools

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off
Forum Jump

Similar Threads
Thread
Thread Starter
Forum
Replies
Last Post
Sharing libraries between Mac and Win iTunes? richarnd iPod Hardware and Accessories 0 07-28-2007 06:47 PM
Windows virus while running Bootcamp on my Mac ScottsFire Running Windows (or anything else) on your Mac 4 01-10-2007 12:19 AM
Is Mac OS X really safer from virus attacks? Murlyn Apple Rumors and Reports 39 12-19-2006 11:42 PM
Switcher Article in Today's Times studio34 Switcher Hangout 9 08-11-2006 03:10 PM
Mac Users Get More ISP Choices schweb Apple Rumors and Reports 1 03-06-2003 10:57 AM

All times are GMT -4. The time now is 05:18 AM.

Powered by vBulletin
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
X

Welcome to Mac-Forums.com

Create your username to jump into the discussion!

New members like you have made this community the ultimate source for your Mac since 2003!


(4 digit year)

Already a member?