 |
|
 |
| Author |
Message |
blackhack Member

Joined: 28 Nov 2007 Posts: 333 Location: Land Of The Free range Haggis
Thu Jul 29, 2010 2:33 pm |
Post subject: scum virus writers.... |
|
|
After fifteen years on the net the bastards finally got me....
I thought it was strange when I started getting porn pages appearing that I never clicked on (This time anyway ) and strange results when using Google search and did a sweep with AVG internet security...Sure enough there was the pesky varmit hiding in the temp file,(Funny how it missed it when it came in ?) deleted it and ran another sweep and then found a program called antimalware doctor (??) telling me that I'm infected.
I never installed the bloody thing in the first place...
To cut a long story short....ran a anti virus scan again and cleared it out only to find it reappear on the next boot...Into the registry to find it hiding in various places..removed...deleted the temp file cache and cleared out windows restore, only to find it came back on the next reboot
I can see the C drive in explorer but it was hidden in disk management so I couldn't re-format it and when I decided to re-install windows it couldn't find C drive.
After 16 hours of trial and error, I finally managed to get myself back up and running with a clean install...another five hours to do an in depth scan with Malwarebytes and that's it sorted....
All I have to do now is spend a couple of hours re-installing my music player/video player/software etc
moral of this story....No matter how good you think you are you can never be too careful on the net..... |
|
| Back to top |
|
 |
|
 |
| Author |
Message |
sennapod Member

Joined: 27 Nov 2007 Posts: 95
Thu Jul 29, 2010 4:21 pm |
Post subject: |
|
|
imo, essential bits to have:
1. WinPatrol (Plus,if you want)
2. Good Hosts file, I use HostsMan with updates from MVPS hosts & Peter Lowe's Adservers list to update within the app. (i know chip, i know :-)
Easy to update and adding additional entries.
3. Using Opera as preferred browser, with Fanboy's Adblock List for Opera.
| Code: | | http://www.fanboy.co.nz/adblock/opera/ |
Then Firefox with AdBlock Plus & NoScript plugins.
4. Comodo Firewall.
5. Sandboxie, to run various bits of exe's that don't need to be in the installation folder ;-)
at present using Acronis for image creation, running frequently, for quick re-installation if you get tripped up.. (yep, always a possibility)
I still use a lean xp (no AV) and will be doing so into the future for as long as it lasts..
(to hell with 7) |
|
| Back to top |
|
 |
|
 |
| Author |
Message |
JohnWho Member
Joined: 27 Nov 2007 Posts: 47 Location: Denmark
Thu Jul 29, 2010 6:32 pm |
Post subject: |
|
|
Good tools to use would be combofix & gmer.
Combofix can remove a lot of nasty sh!t and gmer can find a lot of root kits and other crap.
I only use these tools and what combofix don't find i identify with GMER and remove it by restoring infected files through the repair console. |
|
| Back to top |
|
| Author |
Message |
chip4brains Member

Joined: 26 Nov 2007 Posts: 4262
Fri Jul 30, 2010 3:37 am |
Post subject: |
|
|
| sennapod wrote: | | Then Firefox with AdBlock Plus & NoScript plugins |
thanx for reminding me that I had been thinking of trying noscript for a while now, but keep forgetting - got around to it today |
|
| Back to top |
|
 |
|
 |
| Author |
Message |
JohnC Member
Joined: 24 Dec 2007 Posts: 93
Fri Jul 30, 2010 5:24 am |
Post subject: |
|
|
They got me the other day as well - very similar scenario. But how dumb am I - they got me TWICE!
Mine got in via an unpatch Java insecurity - there was a thing in the rtay annoying me to update JRE but I had ignored it coz I don't use Java apps. Then I visited a website somewhere and saw a Java alert, but clicked "cancel" - but the nasty got inside anyway (exploit - wouldn't have mattered what I clicked at the alert).
It wasn't a download - simply loaded from an advert banner on a warez site or something similar.
Used ComboFix and Gmer - the first time. The trick is to get rid of the rootkit - or it just comes back again. AV, Malwarebuytes, etc only remove the symptom, but not the cause (the rootkit).
The second time they caught me I did the same Combofix + Gmer, then a Windows Repair installation.
If you even need to fix windows, google "windows repair installation" - there is a trick to it, pressing R at the correct time, and saying "no" to Windiows Repair Console (which is useless). |
|
| Back to top |
|
 |
|
 |
| Author |
Message |
JohnWho Member
Joined: 27 Nov 2007 Posts: 47 Location: Denmark
Fri Jul 30, 2010 12:35 pm |
Post subject: |
|
|
| JohnC wrote: |
If you even need to fix windows, google "windows repair installation" - there is a trick to it, pressing R at the correct time, and saying "no" to Windiows Repair Console (which is useless). |
No it's not useless, i have removed quite a few rootkits with it and it's all done in a matter of minutes :-) |
|
| Back to top |
|
 |
Page 1 of 1 |
All times are GMT
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
|
|