Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - Geek it 'till it MHz.

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews


Opera One
Everything
you need.
Already
there.
AI assistant
Aria, built right in
Free VPN
No account needed
Ad blocker
Faster, cleaner web
Tab Islands
Grouped browsing
Useful sidebars
Make it yours
No Clunky Extensions Needed.



MajorGeeks Approved.



Download free

spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. GS Auto Clicker
2. Smart Defrag
3. Macrium Reflect FREE Edition
4. K-Lite Mega Codec Pack
5. MusicBee
6. Microsoft Visual C++ 2015-2022 Redistributable Package
7. Sergei Strelec's WinPE
8. K-Lite Codec Pack Full
9. Visual C++ Redistributable Runtimes AIO Repack
10. McAfee Removal Tool (MCPR)
More >>

top reads

Star How Much Storage Space Are Your Installed Apps Using in Windows 11?

Star How To Reset and Fix the Settings App in Windows 11

Star How To Remove the Windows 11 Updated Start Menu

Star How To Download a Windows 11 ISO

Star How To Disable Drag Tray

Star How To Boot Into WinRE (Windows Recovery Environment)

Star How To Find the Installation Date of Apps

Star Recently Opened Files - How To Hide or Show Them In Jump Lists, File Explorer, and Start Menu

Star How To Change the Name of a Local or Microsoft Account

Star How To Remove OneDrive From the Navigation Pane in File Explorer


MajorGeeks.Com » News » August 2017 » Update to the PDF Virus

Update to the PDF Virus


Posted by: J. McMahon on 08/16/2017 01:13 PM [ comments Comments ]


On the 14th we wrote of a nasty little PDF virus running amok.

We know a little more now so here's an update.


As of yesterday, only 10 antivirus apps were tagging this virus. As of right now, it is up to 28 on virus total It also looks, like Sophos was first out of the blocks with a heuristic detection - so kudos to them.



However, we also know that if the payload were to be released on a system it recreates itself as common Windows program names that you would find in your Windows directories like; Ckconfig.exe or bootcfg.exe as an example. Those files will be placed outside of the normal directories and are not being detected - probably because the names are whitelisted. With this now being a known hash - this should change soon.

We also know that the virus is using debug.exe to keep itself alive, turning on User Account Control and using any admins shares to propagate. if you get it and want any chance of stopping it, you will need to turn off Machine debugging. In with 10 run services and look for Machine Debug Manager and stop that service. In previous Windows you have to dust off Internet Explorer got to Internet Options then click the Advanced tab and deselect the Disable script debugging check box(es). Frankly though, once this one has it's hooked in your PC you are probably looking a format.



Admin shares are hidden shares created by Windows when you have computers networked together that are accessible only by admins. They are used by admins to manage the local network - back things up, configure settings, etc. If you are not on a local network - then there is nothing to worry about. However, if you do not have one of the 28 antivirus products that currently detect this PDF Virus then you may want to turn off admin shares on things like your backup drive or NAS server and other local network shares as the virus could jump to the share and encrypt that content as well. To do so is rather easy but if you do start removing admin shares, please make sure you backup up your registry before hand.

Then, just run fsmgmt.msc, click on shares and then right click the share you wish to stop and choose stop sharing.



New virii come out every day and these PDF infections seem to be the new thing. The best defense is to:
  • Never open an attachment from someone you do not know.
  • Do not open a PDF if it has a weird name to it - even if it is from someone you know.
  • If you open a PDF and it pops up a window asking for something like to open a file or to click "yes" - close the PDF and start a virus scan.
  • Most importantly - Have good, up to date backups of any data that is important. You can get a 2 TB backup drive on Amazon for less than $70.00 which is a LOT cheaper than paying a ransom.


  • « The 20 Most Viewed USB Tools on MajorGeeks · Update to the PDF Virus · AMD RX VEGA – hit or miss? and more (19 Reviews) @ NT Compatible »




    Comments
    comments powered by Disqus

    MajorGeeks.Com » News » August 2017 » Update to the PDF Virus

    © 2000-2026 MajorGeeks.com
    Powered by Contentteller® Business Edition