Author Topic: ****ing nasty malware  (Read 1588 times)

0 Members and 2 Guests are viewing this topic.

Offline watsisname

****ing nasty malware
Long story short, I just spend the last 6 hours cleaning my computer of a horrific malware program called "Antivirus XP 2008".  Essentially it looks like a virus scanner/cleaner, and installs several files to the registry that it detects as viruses.  So it scans and tells you "omg 90-some viruses found!" and asks you to pay something like $50 bucks to register the program so you can actually do anything about it.

Well, I'm not dumb and immediately knew this was malware just from the filename.  Antivirus also identified it as "troj renos.zq".  What I wasn't prepared for was just how nasty this one really is.  First I tried the obvious and clean it with my antivirus.  I had it quarentined but nothing else was possible (no surprise there).  A system restore didn't work because apparently there no prior checkpoints (what the hell?)  So I had to do it the hard way and remove the program files in safe mode, identify and kill all the processes associated with it, then clean the registry (shouldn't have to tell you how risky that is.  Always make a backup if you have to try it).

After I cleaned up everything I could I still had random bluescreens, freezes, and restarts.  Chkdsk found some disk errors but repairing it kept freezing up at 60%.  Gah.  Eventually I found a great registry cleaner called RegistryBooster.  You've got to pay a little for it but it works like a charm.  6 hours after I was convinced I should throw the PC out the window, now it's working fine and I'm happy.  I hope none of you have to go through that sort of hell.  If you do, remember Google is your friend. :)

Sleepcycle.
In my world of sleepers, everything will be erased.
I'll be your religion, your only endless ideal.
Slowly we crawl in the dark.
Swallowed by the seductive night.

 

Offline Jeff Vader

  • The Back of the Hero!
  • 212
  • Bwahaha
Re: ****ing nasty malware
Out of curiosity. Just how did you end up with this "Antivirus XP 2008"? Surely you didn' randomly click any "zomg joo has viruzors click herez!!1" banners yourself, right?

And now that you mentioned it, I've had good results with Wise Registry Cleaner.
23:40 < achillion > EveningTea: ass
23:40 < achillion > wait no
23:40 < achillion > evilbagel: ass
23:40 < EveningTea > ?
23:40 < achillion > 2-letter tab complete failure

14:08 < achillion > there's too much talk of butts and dongs in here
14:08 < achillion > the level of discourse has really plummeted
14:08 < achillion > Let's talk about politics instead
14:08 <@The_E > butts and dongs are part of #hard-light's brand now
14:08 <@The_E > well
14:08 <@The_E > EvilBagel's brand, at least

01:06 < T-Rog > welp
01:07 < T-Rog > I've got to take some very strong antibiotics
01:07 < achillion > penis infection?
01:08 < T-Rog > Chlamydia
01:08 < achillion > O.o
01:09 < achillion > well
01:09 < achillion > I guess that happens
01:09 < T-Rog > at least it's curable
01:09 < achillion > yeah
01:10 < T-Rog > I take it you weren't actually expecting it to be a penis infection
01:10 < achillion > I was not

14:04 < achillion > Sometimes the way to simplify is to just have a habit and not think about it too much
14:05 < achillion > until stuff explodes
14:05 < achillion > then you start thinking about it

22:16 < T-Rog > I don't know how my gf would feel about Jewish conspiracy porn

15:41 <-INFO > EveningTea [[email protected]] has joined #hard-light
15:47 < EvilBagel> butt
15:51 < Achillion> yes
15:53 <-INFO > EveningTea [[email protected]] has quit [Quit: http://www.mibbit.com ajax IRC Client]

18:53 < Achillion> Dicks are fun

21:41 < MatthTheGeek> you can't spell assassin without two asses

20:05 < sigtau> i'm mining titcoins from now on

00:31 < oldlaptop> Drunken antisocial educated freezing hicks with good Internet == Finland stereotype

11:46 <-INFO > Kobrar [[email protected]] has joined #hard-light
11:50 < achtung> Surely you've heard of DVDA
11:50 < achtung> Double Vaginal Double ANal
11:51 < Kobrar> ...
11:51 <-INFO > Kobrar [[email protected]] has left #hard-light []

 

Offline watsisname

Re: ****ing nasty malware
I wish I knew exactly how I got it.  The first sign of it was while I was looking at showtimes for a movie on movietickets.com, but I can't believe that's the culprit.  Rumor Mill has it that this malware likes to automatically download itself through infected video codecs.  Hmm.
In my world of sleepers, everything will be erased.
I'll be your religion, your only endless ideal.
Slowly we crawl in the dark.
Swallowed by the seductive night.

 

Offline Nemesis6

  • 28
  • Tongs
Re: ****ing nasty malware
Go to spywarewarrior.com and post post a hijackthis log in their forums just to be safe. But then again, you seem to know what you're doing, so I think you can skip that! :)
By the way, if you know when you got it, you could do a system restore to a time before that if you wanna make absolutely sure you got everything off.

 

Offline Mars

  • I have no originality
  • 211
  • Attempting unreasonable levels of reasonable
Re: ****ing nasty malware
I assume you are the only person who uses this computer?

  

Offline watsisname

Re: ****ing nasty malware
It's the family computer but I'm the most frequent user of it.  I figure it's my fault the thing got on there but I've no idea how -- haven't visited any sketchy websites or run shady programs lately.

Go to spywarewarrior.com and post post a hijackthis log in their forums just to be safe. But then again, you seem to know what you're doing, so I think you can skip that! :)
By the way, if you know when you got it, you could do a system restore to a time before that if you wanna make absolutely sure you got everything off.

That's a pretty good idea.  I use hijackthis pretty regularly and it did find one of the processes associated with this infection.  I'll see what the tech wizards have to say about it. :)
In my world of sleepers, everything will be erased.
I'll be your religion, your only endless ideal.
Slowly we crawl in the dark.
Swallowed by the seductive night.