Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Kaboobi
Jan 5, 2005

SHAKE IT BABY!
SALT THAT LADY!

Namlemez posted:

Got this on a machine through some random Java applet. This was like the most nefarious one I've ever had by far:

http://en.wikipedia.org/wiki/Vundo

I've been dealing with this for the last 2 days, that fix thing doesn't work for me. Aaaarrrgghhh

Adbot
ADBOT LOVES YOU

Kaboobi
Jan 5, 2005

SHAKE IT BABY!
SALT THAT LADY!

gently caress you Rapid Antivirus 2.7. Looks like combofix took care of it pretty quick though.

Kaboobi fucked around with this message at 17:13 on Jan 2, 2009

Kaboobi
Jan 5, 2005

SHAKE IT BABY!
SALT THAT LADY!

Maniaman posted:

Had an Acer on Friday with something called Antivirus8. Malwarebytes couldn't catch/kill it, external MSE scan couldn't get rid of it, ComboFix wouldn't even run on it. I finally got fed up and formatted the thing.

and then spent ages trying to find WLAN drivers for the thing because Acer's website didn't have them.

Just ran into this today, it ate through Malwarebytes, but Combofix nuked it in safe mode. However, it left a "Debugger" registry key in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe that wouldn't let explorer start when you booted up the system. Removed that and it all seemed fine after that.

Kaboobi fucked around with this message at 23:41 on Nov 2, 2010

Kaboobi
Jan 5, 2005

SHAKE IT BABY!
SALT THAT LADY!

sfwarlock posted:

I'm crossing swords with ThinkPoint or whatever that poo poo is called for the first time.

Pray for me.

Boot into safe mode, kill the process, run combofix, make sure it didn't crap up anything in the registry.

That should take care of it, at least in the two times I ran across it.

Kaboobi
Jan 5, 2005

SHAKE IT BABY!
SALT THAT LADY!

One of my friends got hit by something that looks like the same thing today, I told her how to get into safe mode around it and run Combofix and Malwarebytes but haven't heard back from her yet.

http://www.bleepingcomputer.com/virus-removal/remove-hard-drive-diagnostic

edit:

Probably a PDF exploit?

(4:19:51 PM) Xxxxx: I feel bad for the people who get fooled by it
(4:20:49 PM) Xxxxx: I was browsing with firefox and a page abruptly told me to update java and I needed additional plug ins and poo poo
(4:20:55 PM) Xxxxx: On a page with no java on it
(4:21:10 PM) Me: Hm
(4:21:17 PM) Xxxxx: So I just closed everything and it opened some PDF file
(4:21:25 PM) Xxxxx: Which I closed before it loaded
(4:21:47 PM) Me: keep your adobe reader up to date!
(4:22:12 PM) Xxxxx: I minimized it and saw the hdd diagnostic icon on the desktop and it auto popped the dumb fake program front up
(4:22:12 PM) Me: if you get hit with an infected popup, there's nothing you can do besides do hard reboot without clicking ANYTHING
(4:22:14 PM) Xxxxx: I do!!
(4:22:16 PM) Me: just mash the power button

Kaboobi fucked around with this message at 22:26 on Dec 6, 2010

Kaboobi
Jan 5, 2005

SHAKE IT BABY!
SALT THAT LADY!

Midelne posted:

This is your most probable venue of infection, given that when people say they "closed" something they usually mean that they clicked the red X in the upper-right of the window. Clicking anything at all on a malicious web page - even something that looks like a big inviting red X - is a bad idea.

Given human response time an infection-in-progress is probably unlikely to be affected by hitting the power button as quickly as possible, so it might be worth teaching them how to use Task Manager to close iexplore.exe or whatever they use to browse.

Yep, well aware. This is a friend though who will probably start doing that in the future.
Anyone at my work will never actually learn to do this, I will have combofix on a locked flash drive until the day I die.

Kaboobi
Jan 5, 2005

SHAKE IT BABY!
SALT THAT LADY!

Pope Guilty posted:

Given that the Apple users I support can't reliably tell the difference between OSX prompting them for their computer's credentials and their school credentials...

It's all going to be the same password anyway.

Kaboobi
Jan 5, 2005

SHAKE IT BABY!
SALT THAT LADY!

Pope Guilty posted:

One of these days the malware authors are going to figure out how to infect System Restore points, and on that day we are so hosed.

They've been doing this for a while, annoying as hell.

Kaboobi
Jan 5, 2005

SHAKE IT BABY!
SALT THAT LADY!

Maybe I'm missing something, but why is "%u%12" on the list?

Kaboobi
Jan 5, 2005

SHAKE IT BABY!
SALT THAT LADY!

Biowarfare posted:

Looks more like it tries personsusername1 and personsusername12 or something

Oh duh, of course.

Adbot
ADBOT LOVES YOU

Kaboobi
Jan 5, 2005

SHAKE IT BABY!
SALT THAT LADY!

mindphlux posted:

in other news, I just reformatted because of that google redirect thing, and changed all my banking passwords just in case. I'm still loving pissed off that a virus won - first time I've given up in a couple years.

I've run into 3 of the same google redirects at work over the last few weeks, and haven't been able to fix it without a reformat.

Would happen in every browser, not just IE, and not on all links.

Nothing in hosts, nothing weird in IP settings, Malwarebytes/Symantec/SuperAntiSpyware/ComboFix/TDSS/loving everything didn't pick up a thing, no weird processes I could see, nothing out of the ordinary in hijack this logs, no corrupted system files, spent a good 4 hours just loving around it with it. If anyone else runs into a redirect and figures out what's going on, let me know.

  • Locked thread