Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
redeyes
Sep 14, 2002

by Fluffdaddy

mixitwithblop posted:

Raluek, that sounds pretty messed up and if you aren't certain you'll be able to repair it 100%, I'd suggest format and reinstall. Especially if there isn't a whole lot of data you'd need to backup/apps to reinstall...

Repair install works sometimes, and it *might* be easier in this case(although it tends to screw up a lot of apps, in which case a complete wipe would be less time consuming in the end)... there's a lot of stuff you could fix via Dial-a-Fix and sfc, but as you say, it sounds like you'll have to manually fix quite a bit yourself. At a minimum prior to repair install, I'd suggest full scans with AntiMalware, SuperAntispyware and Trojan Remover as mentiond by me previously, if you can get them working on an seemingly fubar'd box.

Yeah that level of destruction means you need to reload. It will be faster to back up the data and reformat/reinstall.

Adbot
ADBOT LOVES YOU

redeyes
Sep 14, 2002

by Fluffdaddy

hobb posted:

Anyone know whats up with the very elaborate fake virus scanners that I'm assuming are coming from infected ads?

My mom told me the other night that she was on facebook, when this full page fake scanner came up, and attempts to close the window would trigger a prompt with accept/cancel and what not, trying to close that would just loop it.

She's relativly smart about not loving with stuff like that, and all scans I've done today seem clean with nothing obvious going on, so I'm fairly sure it wasn't installed, but just contained to the browser from an ad.

The base URL was don't click this > prime-defendere.com < with random gibberish at the end of the address that I'm assuming randomises it so that its harder to purposefully find.

Ive spent the last 3 weeks removing these goddamn things. Best thing to do is install Firefox with Adblock Plus.

redeyes
Sep 14, 2002

by Fluffdaddy

OSI bean dip posted:

Since Khablam has yet to answer my question about how to deal with rootkits, I'll ask mindphlux here:


Of which of these tools will it address a rootkit where the malware is loaded before the bootloader? Explain to me why you'd think that if you really do believe you understand how the tools work.

Roguekiller would check the boot stuff. You didn't list it. So the malware is loaded before the boot loader? How about imaging the hard drive and then zero'ing it out and restoring only the MBR and main partition?

Also before the bootloader might be the UEFI.. so I would try and re-flash the BIOS although I really don't know much about UEFI exploits, this is new territory for my skills.

I thought the secure boot process prevented stuff like this. Maybe I am mistaken.

redeyes fucked around with this message at 16:30 on Oct 27, 2015

redeyes
Sep 14, 2002

by Fluffdaddy
TDSS/Alureon is not that big of a deal really. Easily detectable. Roguekiller will remove that sucker.
The crypto locker poo poo is way way worse for most people.

redeyes
Sep 14, 2002

by Fluffdaddy

OSI bean dip posted:

It has been mostly thwarted in the past few years for a number of reasons, but it's a matter of time before another one comes up and evades your fancy suggestion.


Fancy? So how is this going to load unsigned drivers in a 64bit OS with secure boot?

redeyes
Sep 14, 2002

by Fluffdaddy

Wiggly Wayne DDS posted:

i'm glad code signing certs are hard to obtain

There are certainly problems with compromised certs recently but it seems like the industry revokes them pretty fast. I've yet to see a boot sector virus or anything like it on systems with secure boot enabled.

quote:

turbo-sperg
:laffo:

redeyes
Sep 14, 2002

by Fluffdaddy

OSI bean dip posted:

Yeah. Secure boot is never going to have issues.

http://www.kb.cert.org/vuls/id/976132
http://seclists.org/bugtraq/2015/Oct/70

Please stop while you're ahead.

That was a question not a statement pal. Windows 10 is not Windows 8 so maybe this is fixed.

quote:

No public attack against systems for which the owner does not want the
exploit is known.
So maybe not so important other than theoretically?

redeyes fucked around with this message at 20:54 on Oct 27, 2015

redeyes
Sep 14, 2002

by Fluffdaddy
So do you have a set of techniques to share? If not, what the gently caress is the point of letting other people know they are doing it wrong.

Adbot
ADBOT LOVES YOU

redeyes
Sep 14, 2002

by Fluffdaddy

OSI bean dip posted:

If people were not giving negligent advice such as what we have consistently seen by people I quote then this sort of arguing going on would cease. There are individuals who are quick to chime in on solutions akin to divining rods with no technical knowledge behind them to explain how they are effective.

If we want to go on about putting our dicks on the table, I have yet to do that and yet others who refute me have no problem.

There is no negligent advice in this thread but you are still killing the thread dead.

  • Locked thread