Author Topic: malware alert! help!  (Read 3446 times)

geronimotwo

  • friend
  • Senior Member
  • ***
  • Posts: 3,796
malware alert! help!
« on: January 20, 2010, 06:06:41 PM »
just went through a malware ordeal.   picked up "antivirus live" which kept wanting me to buy their product as i was "infected" (by them).  would lockup my programs, and spit porn at me every 8-10 minutes.   the next day, my discover card calls me to say they have numerous "suspicious" purchases, none of which were mine.  i think the malware came through on some game sites my daughter was downloading from  (big fish was the most used that day).

i was able to gain control again, but still cannot get online unless in safemode.  i had downloaded the latest spybot upgrade (in regular windows)and then used it to finish debuging my pc. after that i called my isp and they recomended that i remove spybot, which i did (but now i am kicking myself for not using the undo button first). the connection wizard is telling me it is probably due to firewall settings, as windows claims it will not accept any http,  https,  or ftp addresses.  i haven't been able to get anything to come through internet explorer unless in safe mode.  i am using windows xp, and have tried lowering the firewall settings, as well as using the factory defaults.  any thoughts?

i keep wondering if it was that tiny and cheap video camera i was thinking about buying =D
« Last Edit: January 20, 2010, 07:11:30 PM by geronimotwo »
make the world idiot proof.....and you will have a world full of idiots. -g2

Tim L

  • friend
  • Member
  • ***
  • Posts: 206
    • TDLITWILLER
Re: malware alert! help!
« Reply #1 on: January 20, 2010, 06:33:16 PM »
My friend sent me this recently while I was trying to beat some malware into submission and it was blocking internet explorer.  Go into the settings for IE and change the LAN setting. If Proxy is checked, uncheck it.  The one I was fighting had created new user accounts and changed the ownership of all personal files to protect itself.  Talk about wanting to get my hands on someone.

geronimotwo

  • friend
  • Senior Member
  • ***
  • Posts: 3,796
Re: malware alert! help!
« Reply #2 on: January 20, 2010, 06:56:47 PM »
My friend sent me this recently while I was trying to beat some malware into submission and it was blocking internet explorer.  Go into the settings for IE and change the LAN setting. If Proxy is checked, uncheck it.  The one I was fighting had created new user accounts and changed the ownership of all personal files to protect itself.  Talk about wanting to get my hands on someone.

i will check that. i have found a few of my defaults changed, as well as my start menu has been changed.  right now i am running a minimum until i compare the programs to a list i found online.

yup, that did it.  that nasty had ridirected me to a proxy server.

thanks.  

as far as the discover charges,  they said not to pay for anything that we didn't buy, and they were taking care of the rest.  (although they have called me twice to sell me their identity protection plan...hmmm....)
« Last Edit: January 20, 2010, 07:14:05 PM by geronimotwo »
make the world idiot proof.....and you will have a world full of idiots. -g2

TechMan

  • Administrator
  • Senior Member
  • *****
  • Posts: 10,562
  • Yes, your moderation has been outsourced.
Re: malware alert! help!
« Reply #3 on: January 20, 2010, 08:55:56 PM »
geronimotwo,
Try http://www.malwarebytes.org/mbam-download.php (free for personal use.)  Install in safe mode and update the database and then run a full scan in safe mode.
-Andy
Quote
Hawkmoon - Never underestimate another person's capacity for stupidity. Any time you think someone can't possibly be that dumb ... they'll prove you wrong.

Bacon and Eggs - A day's work for a chicken; A lifetime commitment for a pig.
Stupidity will always be its own reward.
Bad decisions make good stories.

Quote
Viking - The problem with the modern world is that there aren't really any predators eating stupid people.

never_retreat

  • Head Muckety Muck
  • friend
  • Senior Member
  • ***
  • Posts: 3,158
Re: malware alert! help!
« Reply #4 on: January 20, 2010, 09:10:33 PM »
I needed a mod to change my signature because the concept of "family friendly" eludes me.
Just noticed that a mod changed my signature. How long ago was that?
A few months-mods

RocketMan

  • Mad Rocket Scientist
  • friend
  • Senior Member
  • ***
  • Posts: 13,689
  • Semper Fidelis
Re: malware alert! help!
« Reply #5 on: January 20, 2010, 10:02:08 PM »
Ditto on the MalwareBytes and Hijack This.  You can reset or delete a lot of the redirects with Hijack This.  It also allows you to delete unwanted startup objects and browser helper objects.
If there really was intelligent life on other planets, we'd be sending them foreign aid.

Conservatives see George Orwell's "1984" as a cautionary tale.  Progressives view it as a "how to" manual.

My wife often says to me, "You are evil and must be destroyed." She may be right.

Liberals believe one should never let reason, logic and facts get in the way of a good emotional argument.

lee n. field

  • friend
  • Senior Member
  • ***
  • Posts: 13,632
  • tinpot megalomaniac, Paulbot, hardware goon
Re: malware alert! help!
« Reply #6 on: January 20, 2010, 10:38:11 PM »
Quote
malwarebytes
hijack this

Now what's fun is when you've got a nasty that actively blocks this stuff.

Hint: right click the task bar.  If "task manager" is greyed out in the pop up menu, you're in for a hard, hard time cleaning that one up.  Better off wiping.
In thy presence is fulness of joy.
At thy right hand pleasures for evermore.

Battle Monkey of Zardoz

  • friends
  • Senior Member
  • ***
  • Posts: 1,915
  • A more Elegant Monkey for a more civilized Forum.
Re: malware alert! help!
« Reply #7 on: January 20, 2010, 10:59:07 PM »
Best option, nuke it from orbit.  DBAN, boot and nuke.  Then re install.  I had to do that last month.  Picked up a nasty that spybot search and destroy would see and fix, but upon reboot it would re manifest itself.  It was in my registry in at least 8 places that I could find.  Back up what data you can, and wipe then re install.  Trust me, it is a pain in the ass, but it will be faster.

“We the people are the rightful masters of both Congress and the courts, not to overthrow the Constitution but to overthrow the men who pervert the Constitution.”

Abraham Lincoln


With the first link the chain is forged. The first speech censored, the first thought forbidden, the first freedom denied, chains us all irrevocably.

TechMan

  • Administrator
  • Senior Member
  • *****
  • Posts: 10,562
  • Yes, your moderation has been outsourced.
Re: malware alert! help!
« Reply #8 on: January 20, 2010, 11:09:23 PM »
Now what's fun is when you've got a nasty that actively blocks this stuff.

Hint: right click the task bar.  If "task manager" is greyed out in the pop up menu, you're in for a hard, hard time cleaning that one up.  Better off wiping.

lee n. field,
I have run into that before, but there is a way around that too.  I use process explorer http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx
It is task manager on steroids and the $&#*heads that program the malware don't usually block it.
-Andy
Quote
Hawkmoon - Never underestimate another person's capacity for stupidity. Any time you think someone can't possibly be that dumb ... they'll prove you wrong.

Bacon and Eggs - A day's work for a chicken; A lifetime commitment for a pig.
Stupidity will always be its own reward.
Bad decisions make good stories.

Quote
Viking - The problem with the modern world is that there aren't really any predators eating stupid people.

RocketMan

  • Mad Rocket Scientist
  • friend
  • Senior Member
  • ***
  • Posts: 13,689
  • Semper Fidelis
Re: malware alert! help!
« Reply #9 on: January 20, 2010, 11:12:55 PM »
Now what's fun is when you've got a nasty that actively blocks this stuff.

Vee haf vays off making chew co-operate.  It can be beaten without nuking, but it does take some effort.
If there really was intelligent life on other planets, we'd be sending them foreign aid.

Conservatives see George Orwell's "1984" as a cautionary tale.  Progressives view it as a "how to" manual.

My wife often says to me, "You are evil and must be destroyed." She may be right.

Liberals believe one should never let reason, logic and facts get in the way of a good emotional argument.

MechAg94

  • friend
  • Senior Member
  • ***
  • Posts: 33,914
Re: malware alert! help!
« Reply #10 on: January 20, 2010, 11:36:28 PM »
I recently discovered the most effective Virus/Spyware blocker ever.  Trend Microsystems!

I have had trouble getting IE or Firefox to connect to any site at all and none of my other programs will update.  I got on the phone with my brother and he got me to ping yahoo.com and such to confirm I did have communications.  After seeing Trend try to block a scan by Spybot, I closed it out and suddenly realized my browsers worked again.  Trend was blocking everything.  I don't know whether to be ticked off or satisfied that it did its job very very well.  :)

I have uninstalled it already.  I need to pick up something else soon.
“It is much more important to kill bad bills than to pass good ones.”  ― Calvin Coolidge

geronimotwo

  • friend
  • Senior Member
  • ***
  • Posts: 3,796
Re: malware alert! help!
« Reply #11 on: January 21, 2010, 08:52:08 AM »
thanks for the suggestions,  still trying to get all the bugs out.  wondering if any other info may have been taken.   last year i did my taxes online with taxact, and am concerned about all that info being abused.
make the world idiot proof.....and you will have a world full of idiots. -g2

lee n. field

  • friend
  • Senior Member
  • ***
  • Posts: 13,632
  • tinpot megalomaniac, Paulbot, hardware goon
Re: malware alert! help!
« Reply #12 on: January 21, 2010, 09:08:21 AM »
Quote
I use process explorer

The ones I've seen block process explorer as well.  Process Explorer can be real handy on the lesser ones.  Note the location of the executable, then "kill process tree".

You have to judge the value of your time here.  At this point it's usually better (IMHO) to cut your losses and set up the system from scratch and restore from backup.  No backup??  Well...
In thy presence is fulness of joy.
At thy right hand pleasures for evermore.

geronimotwo

  • friend
  • Senior Member
  • ***
  • Posts: 3,796
Re: malware alert! help!
« Reply #13 on: January 21, 2010, 12:59:59 PM »
The ones I've seen block process explorer as well.  Process Explorer can be real handy on the lesser ones.  Note the location of the executable, then "kill process tree".

You have to judge the value of your time here.  At this point it's usually better (IMHO) to cut your losses and set up the system from scratch and restore from backup.  No backup??  Well...

the only backup is on my partitioned c drive.   funny how i had just made the decision to purchase a "my passport" backup drive, after reading one of the katrina blogs.  two weeks too late it seems.
make the world idiot proof.....and you will have a world full of idiots. -g2

MechAg94

  • friend
  • Senior Member
  • ***
  • Posts: 33,914
Re: malware alert! help!
« Reply #14 on: January 21, 2010, 01:05:03 PM »
One suggestion I used last year.  I had something on my home computer that was blocking everything including all scanners I could find.  I ended up pulling out the hard drive, getting a USB to SATA converter and used my laptop from work with Norton to scan the hard drive.  Norton cleaned out a handful of things.  After that, I reinstalled the hard drive, updated everything, and was able to clean out a couple of other things. 

If you have the option of another computer, that worked for me once.
“It is much more important to kill bad bills than to pass good ones.”  ― Calvin Coolidge

geronimotwo

  • friend
  • Senior Member
  • ***
  • Posts: 3,796
Re: malware alert! help!
« Reply #15 on: January 23, 2010, 03:03:07 PM »
just wanted to mention that when i received this malware, i was running avg 8.5 with resident shield active, plus daily scans and updates.  i have since switched.
make the world idiot proof.....and you will have a world full of idiots. -g2

RocketMan

  • Mad Rocket Scientist
  • friend
  • Senior Member
  • ***
  • Posts: 13,689
  • Semper Fidelis
Re: malware alert! help!
« Reply #16 on: January 23, 2010, 03:55:42 PM »
I don't know of any anti-virus program that can stop a rogue from installing itself if you click anywhere on the rogue's pop-up window.  Clicking anywhere on a rogue's pop-up, even on the "No" button or on the red [X] in the upper right corner, just gives the rogue access to your system.  The first thing most rogues do after that is disable any security software you have installed.
You have to stop the rogue's process either via Task Manager, or by just pulling the plug on the computer.
There may be a pop-up blocker out there that can stop rogue pop-ups from appearing on your system in the first place, but I have not found one as yet.  I must admit that I have not looked all that hard for one, either.

Be aware, too, that you can encounter rogues most anywhere.  The last one that tried to nail me came from an infected news story page on the Fox News website.  Only that page attempted to infect my system.  I accessed it a few times to confirm the infection.  The others I read that day were clean.
If there really was intelligent life on other planets, we'd be sending them foreign aid.

Conservatives see George Orwell's "1984" as a cautionary tale.  Progressives view it as a "how to" manual.

My wife often says to me, "You are evil and must be destroyed." She may be right.

Liberals believe one should never let reason, logic and facts get in the way of a good emotional argument.

tyme

  • expat
  • friend
  • Senior Member
  • ***
  • Posts: 1,056
  • Did you know that dolphins are just gay sharks?
    • TFL Library
Re: malware alert! help!
« Reply #17 on: January 23, 2010, 04:04:11 PM »
Quote
DBAN, boot and nuke.

Um, not really.  DBAN is for securely erasing sensitive information.  A simple quick format and reinstall is enough to get rid of malware, unless it's extremely advanced (hiding in bios) in which case you could replace the disk and that still wouldn't help.

Malware might remain on the disk, but if it's not in a file, or attached to a file, somewhere in the new filesystem, there's no way for it to become active.  Barring a filesystem bug and some ridiculously improbable (bad) luck, on-disk malware will not survive a simple (quick) filesystem reformat and MBR overwrite.
Support Range Voting.
End Software Patents

"Four people are dead.  There isn't time to talk to the police."  --Sherlock (BBC)

Thor

  • friend
  • Senior Member
  • ***
  • Posts: 1,230
  • US Navy (retired)
Re: malware alert! help!
« Reply #18 on: January 24, 2010, 12:44:12 AM »
There are some viruses that hide in the mbr. a format doesn't always clear them. I've run into a couple of them in the past ( 98SE days) I had to do a wipe of the disk (debug) with some command line stuff and a boot disk. I have run into a few that I had to format and reinstall the OS to get rid of. That always sucks.
" a sword never kills anybody; it's a tool in the killer's hand." - Lucius Annaeus

for Military, Vets, & Supporters, check out:
USMILNET

Conservative Discussion Forum


RocketMan

  • Mad Rocket Scientist
  • friend
  • Senior Member
  • ***
  • Posts: 13,689
  • Semper Fidelis
Re: malware alert! help!
« Reply #19 on: January 24, 2010, 12:49:23 AM »
There are some viruses that hide in the mbr. a format doesn't always clear them.

You can often use the recovery console to do a fixmbr.  That wipes the original mbr and installs a new one.
If there really was intelligent life on other planets, we'd be sending them foreign aid.

Conservatives see George Orwell's "1984" as a cautionary tale.  Progressives view it as a "how to" manual.

My wife often says to me, "You are evil and must be destroyed." She may be right.

Liberals believe one should never let reason, logic and facts get in the way of a good emotional argument.