Forum Home
Press F1
 
Thread ID: 118097 2011-05-19 11:20:00 ms tools?? LOCK DOWN notechyet (4479) Press F1
Post ID Timestamp Content User
1203299 2011-05-19 22:30:00 you could try renaming rkill to explorer.exe which is one of the tricks the websites use to get Malwarebytes to install and run.

Seems likely the mse update you clicked was a fake one in a browser page rather than an actual update.

This this is really doing the rounds, I've removed it for two of my friends so far and seen multiple threads here on it.
dugimodo (138)
1203300 2011-05-20 03:11:00 you could try renaming rkill to explorer.exe which is one of the tricks the websites use to get Malwarebytes to install and run.
....

First time I got caught out. I just clicked while talking, bummer.
Hmmm.. I tried to execute the rskill without success. Tried to start up in safe mode which, for whatever reason, switched over to standard login as soon as I typed in the passwords.
Tried with a Kaspersky Live CD without success as it stallled.
At some stage the whole OS played up and needed to be restored by the IT's of the school.
Long story short, a good lesson!
:mad::blush::blush:
notechyet (4479)
1203301 2011-05-20 08:25:00 Oh the wonders of schools and their attempts to lock down machines, and they still cannot prevent drive by infections..
Clicking on a link is not exactly a drive infection.
mikebartnz (21)
1 2