Announcement

Collapse
No announcement yet.

This guy should NOT be a tech….

Collapse
This topic is closed.
X
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • sld72382
    replied
    I do admit that sometimes you need to format for a virus, so long as you tell the client to back up their stuff first and to make sure all drivers/patches are installed. This may sound simple but like I said in my OP the so-called "tech" this woman dealt with didn't even do that.

    BTW, about 2 weeks ago an email was sent out to all techs at my dept about a new virus that is yet another variation of those fake alert pests. They said "If someone calls in with this virus advise them we don't know a fix for it and they need to run a format and reload of windows." Translation: There IS a fix (2 of them, in fact) but because of the allowed software list not listing them we can't use them, and thus we have to play dumb and tell the client right away that they need to format after spending their hard-earned cash to get it removed.

    Leave a comment:


  • volatile
    replied
    Quoth minchazo View Post
    Any tech, working as such, should have a second machine available for testing, specificially in case a second OS is needed. You can then slave the old drive out and scan it for virii or malware. (Actually, I've never attempted to remove a root kit myself, so I don't know if even *that* would work)

    The fact that he did not install the drivers on the machine really shows his incompetence. It means he didn't even *attempt* to use the machine after blowing away all the customer data. I would bet money he doesn't even know what a root kit is, let alone what it does to a machine.
    Like Pederson said, however, if the unit is infected with a root kit remote scanning will do no good. It may remove the known and obvious infections but the rootkit won't be removed. It is a good first step to scan remotely. After that, you'll have to hope that the OS is functional enough to attempt a removal of the rootkit.

    Leave a comment:


  • clowninasack
    replied
    He has a snazzy spider-man shirt too.

    Leave a comment:


  • Naaman
    replied
    Quoth clowninasack View Post
    He definitely isn't as good as Dr. PC.

    Hmmm, I kinda like him

    I don't install AOL Internet access!

    I don't install Norton Antivirus!

    Leave a comment:


  • clowninasack
    replied
    He definitely isn't as good as Dr. PC.

    Leave a comment:


  • Naaman
    replied
    Quoth Dreamstalker View Post
    Flashdrive = USB key (at least in my neck of the woods) IME it doesn't matter what's on the key if the system won't see USB as bootable.
    Regional jargon aside you still missed the "or CD" bit of the line

    Leave a comment:


  • Kilamon
    replied
    You can put the bart pe on to USB, too. It doesn't have to be CD. Also, any PC produced with a Vista sticker on it -must- be able to boot from USB. It's part of the requirements for certification to get that sticker, or it was when I last read the requirements during beta.

    Leave a comment:


  • Dreamstalker
    replied
    Flashdrive = USB key (at least in my neck of the woods) IME it doesn't matter what's on the key if the system won't see USB as bootable.

    Leave a comment:


  • Naaman
    replied
    Quoth Dreamstalker View Post
    Wouldn't a machine need to be able to boot from USB for the flashdrive option to work? Many older machines can't do this.
    If you look closely I said "USB key or CD" , Bart PE is a popular CD one

    Leave a comment:


  • earl colby pottinger
    replied
    Formatting

    1) I am of the reformat it school myself. I just like a cleaned up system - they tend to run faster.

    2) No drivers installed means this guy was no tech.

    3) After wiping the system and restoring the main data folders I like to review every single program that I am reinstalling. If I have not made use of it in the last year it does not get installed at all. If I used it a few times I may add an archive of the program to the computer, but I still don't install it as active code on my system.

    4) Backup, Backup, Backup. All the files I consider important are copied onto multiple drives.

    5) If he did not give a lecture on backups, that is just another point to prove he was not a real tech.

    Leave a comment:


  • Dreamstalker
    replied
    Wouldn't a machine need to be able to boot from USB for the flashdrive option to work? Many older machines can't do this.

    Leave a comment:


  • Naaman
    replied
    Quoth minchazo View Post
    Any tech, working as such, should have a second machine available for testing, specificially in case a second OS is needed. You can then slave the old drive out and scan it for virii or malware.
    A USB key or CD with a bootable, no-install linux version works wonders as well. Make sure you've got the latest updates for your AV and Anti spy\mal ware preference sorted and your set.

    Leave a comment:


  • minchazo
    replied
    Any tech, working as such, should have a second machine available for testing, specificially in case a second OS is needed. You can then slave the old drive out and scan it for virii or malware. (Actually, I've never attempted to remove a root kit myself, so I don't know if even *that* would work)

    The fact that he did not install the drivers on the machine really shows his incompetence. It means he didn't even *attempt* to use the machine after blowing away all the customer data. I would bet money he doesn't even know what a root kit is, let alone what it does to a machine.

    Leave a comment:


  • sld72382
    replied
    Well according to Sunbelt Software and the research team at 2-spyware.com, the most common malware that people get these days by far are those stupid "fake alert" trojans that constantly pop up with "you are infected!" and try to goad people into buying a bogus spyware scanner.

    I can back this up because 85% of our virus removal calls are for this malware. The reason why people get this virus is because they visit a site that claims to be hosting a video but in order to view it you need to download a plug-in, and the plug-in turns out to be the fake alert virus.

    Now if these malwares use rootkits I'd be surprised, because these viruses want you to see them (for the fake alerts), not hide in the background.

    As far as removing them the most effective tools are three specialized removers that take 3 minutes or less to run: Smitfraudfix, SDFix and Antipuper. All 3 tools are not on our call center's approved software list, so we can't use them. (Although the chat techs frequently use them because their PCs aren't being monitored so they can't get caught using an unapproved tool, that's how I know they work.)

    BTW, the reason why there are so many of those fake alerts (started with Spyaxe in '06) is because malware vendors figure out of 100 people who get infested 25 of them will fall for the scam and buy the bogus software. They must be correct due to the MANY variations of this pest. One malware news website said it best: "Malware vendors don't really write viruses like sasser anymore, now it's all about frauds."

    Side story here: I had a woman once that paid for the bogus software, and when I went to remove it she said, "Don't remove that I paid for it!" She was shocked when I pulled up a website showing her it's a scam. The funniest part? In the purchase confirmation email she was sent by them, it said "Please do not contact your credit card company to do a chargeback otherwise it will lower your credit score." I told her that was false, and to go ahead and do it because getting a refund will be a mission all in itself. Not to mention change your card # because once those crooks get ahold of it, there's no telling what they'll do.

    Leave a comment:


  • Shabo
    replied
    Not only is a reformat the only way to guarantee you get rid of the process, but also, how many infected machines have you seen that only had one thing on them? Most of them have multiple viruses/spyware/trojans/etc. and would be faster to reformat than try to track down and remove everything.

    Speaking of which, gotta go reformat the rent's compy.

    Leave a comment:

Working...
X