I could keep this post much shorter, but since some of my experiences and findings might some day be useful to others in case they have a similar virus issue, i´ll go into more detail.
Ok, so on saturday my mom came to me and she was interested in looking for info on a recent movie on the web.
My mom is a very charming and intelligent person but not into computer things at all. Like so much not at all that she is still getting used to getting the mouse cursor moved to where she wants.
I guess its a thing of not getting used to it while being younger and then on top of it being worried she might do it wrong which is one of life´s big self fullfilling prophecies in my eyes, but to that in a bit.
So i sat her down in front of my old pc, reminded her how to open the browser, navigate to google when she is searching for something and then type in the key words she looks for and hit enter.
She did so and while i was working on my mac, she would go through the search result pages, so far so good.
I thought.. Cause when i looked over to her monitor i noticed that not knowingly she had pretty much instantly navigated to some piracy sites.
I should have thought of the side that entering keywords “<moviename> + movie” into google is likely to return some movie pirate sites among the other hits..
Well, i told her about this issue and that she should better visit one of the few bigger known movie info sites rather than clicking links where it has download movie, torrent, xvid, avi etc in the name, address or description.
I thought with that it was sorted out.
Well, after a while she got bored of not finding what she wanted so i decided we could look together.
Well, then i noticed something weird was happening with the google site: When searching for something it would list search results, but when actually clicking one of the search results it would suddenly forward me to some spyware/malware sites instead of the linked search result site. And yes, i checked that the site we were on was really google.
I noticed that suddenly happened in all of the browsers installed on that machine.
Obvsiously my mom, in less than 10 minutes of surfing the web had caught some nasty thing which was quick to change settings and files on the system.
So i thought the best thing to do would probably be to download and run the next best Protection app, so i downloaded Norton 360.
During install of that one of the installer parts already crashed, but the installer went on besides that.
At the end of the install process it said something in the vein of some files were corrupted and it started a repair process.
Once that was done the machine had to be rebooted.
Well, after the reboot what happened was that on the windows user login screen as soon as one would log in it would automatically log the user out again, so there was no way to get into windows anymore.
I tried various things to get into windows again, starting protected mode, debug mode, trying to restart the last working version etc, etc, all haven´t worked anymore.
So back on my mac i googled some for possible reasonings and found various threads on the topic. What seemed to be a common case was that some Antivirus apps would in case of some infections on the system modify/ delete userinit.exe, which is needed during user login.
Great, so i install an antivirus app and the first thing it leads to is i can´t log into windows anymore..
The pc in question had been my work pc a while ago before i got a new box and also a mac next to that. It didn´t have any most recent projects on it but basically my backlog archive of older things, newer than my last full archive backup on the external drive and older than anything i worked on in more recent history.
It wouldn´t have been a huge loss but still an annoying one to format the hard drive to clean install windows on it right away and not knowing what was lost.
So i wanted to get access to the hdd again to backup the most important things and afterwards wipe it and clean install windows.
Since i didn´t have a second pc close and even if i had i wouldn´t want to connect the messed up hard drive to it, it was a rather cumbersome and longwinded process to backup the important files without being able to get into windows.
It took me most of sunday, so i´ll keep it at the points that actually had some benefitial result:
-I downloaded knoppix on my mac and burnt that on cd. Knoppix is basically a full on linux version that can sit on a single cd or dvd (back in computer sciences eduction a few years ago we even used a smaller version that could sit on a floppy disc) and it can boot and run from that cd.
No install required at all.
So yeah, thanks to knoppix i could start the system, connect a second external drive and copy everything important from the main drive onto the second one.
On a sidenote knoppix starts up with a very linuxy look (blocky single color text reminding one more of shells and dos days than a modern OS gui) but under the main menu there´s an option graphical applications there and among some others a full on graphical user interface is available there.
Bottomline on that point is I recommend that anyone who has a pc should put his windows cd with serial and a knoppix cd next to that in a well known seperated safe place for easy access anytime when needed. It might save your day or many years of content on your pc =)
-I copied a working version of userinit.exe into Windows/System32 which then allowed me to boot up Windows again and actually log in.
(I had found the info on this in some forums: a version of userinit.exe is in C:WINDOWS\system32\dllcache or in case one installed service packs also in C:Windows/ServicePackFiles/i386 which one can copy to the system32 folder)
-I could then start up Windows and check for any other important files i hadn´t copied yet and copy those over to a backup drive
-At that point i finally got kinda sleepy, it was already late at night/early in the morning, so back up now after some sleep what i´m doing right now is wiping the hard drive and reinstalling windows freshly on it.
Ok,
so this experience mainly reminded me that its always a good idea to have a good backup solution =)
It also further decreased my trust in antivirus and anti malware apps.
They sure are very useful in many cases, but in this case they basically caused me much additional trouble. Looking through forums for possible help i also noticed that threads of incidents where userinit.exe was being corrupted or deleted by antivirus apps after an infection of the system were dated as far back as 2003.
So that sorta made me worry why in all these years the anti virus application creators haven´t addressed this problem to a degree where the app would either not delete mandatory system files or if it does so when it detects an infection, why then does it not replace them with a working copy?
Its also not the first problematic experience i had with anti virus tools:
A few years back i had another computer getting infected experience and back then one of the things the virus did was basically causing files from all my main anti malware/ virus programs getting corrupted/ deleted so none of those would start up anymore and therefore none of them helped a lot getting rid of the infection.
So it wasn´t the fault of the tools in that case but that experience had already reduced my trust in them a lot, what are they good for if in case of a serious infection it can happen that none of them work anymore or they delete mandatory system files while getting rid of the infection and that way render the system useless themselves?
Bottomline for me is now its probably no bad idea to have some installed and use them as they get rid of many problems but best to have a good backup solution and don´t trust on the anti malware tool for sure getting rid of bigger issues and still leaving the system in usable state after their cleanup.
Another thought all this brought to me was it reassured me that yes, there totally is a market for something like the iPad.
You know, a computer for all the people who don´t want to or can´t deal with such things. Who want to browse the internet but maybe aren´t that savey regarding hey, maybe you have to check the url of external links better before clicking them. Or hey, if you got infected in some way here´s how to copy rescue files using linux and then its best to reinstall windows.
There are many like that.
People like my mom.
Actually not just people like my mom, because me, surely working lot with macs and pcs actually creating content i will still always need some full on machines for work, but yeah, just for casualy surfing on the couch i´d actually like it, too if the thing just does what it should do and one surely never experiences anything like this =)