Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
bazaar apparatus
Dec 1, 2006

Whenever my body starts to feel sick, I just stop being sick and be awesome instead.
Nthing Antivirus 2009 and its variants. Sometimes that loving "tatemupuku" registry entry just won't go away without using something like ComboFix (awesome little utility, by the way).

Adbot
ADBOT LOVES YOU

bazaar apparatus
Dec 1, 2006

Whenever my body starts to feel sick, I just stop being sick and be awesome instead.

ShizCakes posted:

By the way, if you have things that are "hidden", and resurgent or whatever, you need this tool:

http://www.gmer.net/index.php

It's aimed at rootkits but really it picks up anything running on the system.

I've got something that I think is like this. It's just called RootkitRevealer, and I think I got it from the same site I got AutoRuns from. Anyone know which is the better of the two rootkit tools?

bazaar apparatus
Dec 1, 2006

Whenever my body starts to feel sick, I just stop being sick and be awesome instead.

abominable fricke posted:

What a poo poo day in virus land. We should start posting combofix, malwarebytes, superantispyware, spybotsd, and hijack this logs to use as a community resource. Anyone onboard?

On some of these nastier strains of av2009 etc. I've sent myself the log files for research purposes, and I'd be glad to see some other logs if it'd help track some of this stuff down faster.

bazaar apparatus
Dec 1, 2006

Whenever my body starts to feel sick, I just stop being sick and be awesome instead.

Varkas posted:

Has anyone gotten a virus that seems to block internet connections to specific known anti-virus/anti-spyware sites, and also seems to inhibit such installed programs from actually running?

I started noticing pop-ups this morning, so I ran AVG and picked up some stuff, rebooted. I wanted to follow up with Spybot, but now nothing happens when I try to start it up. If I go out and search for it on google, I seem to get redirected to bogus crap now. While I keep my important install executables on hand, reinstalling doesn't seem to help.

AVG still seems to be able to scan and pick up threats, but it's not able to connect for updates suddenly.

Edit - I'm going to try some of the other tools mentioned. Thankfully I've got my laptop and a thumb drive to get the apps over. Only concern though might be getting the updates.

Make sure to go to Start->Run->type in msconfig->Startup and google every item in there if you have to, but uncheck the bad ones or any blank spaces. And terminate those processes in Task Manager if you can. And I always go through the registry to get rid of any instances of those items, but you may or may not be comfortable with something like that.

Also try booting into Safe Mode w/ Networking and then try going to those sites (superantispyware.com, malwarebytes.org, etc.) and download what you can and rename the executables to something generic like setup.exe, to avoid the installer being blocked by anything. Superantispyware won't install in safe mode but Malwarebytes runs just fine. After I run Malwarebytes in safe mode I generally can reboot back into normal Windows and then run Superantispyware to pick up the rest of the crap.

If all else fails, I've never gone wrong with running ComboFix. I believe bleepingcomputer.com has a guide on how to use it.

bazaar apparatus fucked around with this message at 20:56 on Dec 20, 2008

bazaar apparatus
Dec 1, 2006

Whenever my body starts to feel sick, I just stop being sick and be awesome instead.

Midelne posted:

As a bonus, the first user to report the infection took one look at the fake security center popup and called for help without touching anything. How often does that happen? Loving it.

Why can't my users do this....

By the time I ever get to look at most of their systems, they've hosed it up so bad just clicking on things without thinking that a 15-minute call turns into a few hours just trying to get everything out of there.

bazaar apparatus
Dec 1, 2006

Whenever my body starts to feel sick, I just stop being sick and be awesome instead.

Midelne posted:

Trade you jobs.

Heh, I'm entry-level at this place, you probably make a lot more than I do

bazaar apparatus
Dec 1, 2006

Whenever my body starts to feel sick, I just stop being sick and be awesome instead.
Ok, this mousehook.dll/frmwrk32.exe thing that's been popping up today has been a bit ridiculous

bazaar apparatus
Dec 1, 2006

Whenever my body starts to feel sick, I just stop being sick and be awesome instead.

do it posted:

Doesn't even have to be that clever. I've had about six clients who paid $50 for Rapid Antivirus.

Heh my coworker had one of those yesterday. The thing installed like 12 different fake spyware/antivirus scanners and they wondered how they could possibly be getting so many popups when they have so many programs trying to block them

Not to mention they uninstalled the McAfee suite we install on all of our users' computers because "it told them to"

and yeah I know McAfee sucks

Adbot
ADBOT LOVES YOU

bazaar apparatus
Dec 1, 2006

Whenever my body starts to feel sick, I just stop being sick and be awesome instead.

heat vision posted:

I'm going to guess that ComboFix got something, but I don't know...

It should have saved a log file to C:\Combofix.txt or something. Check that and see what it says.

  • Locked thread