Author Topic: Blankety blank doggone blank blankety blanks!! Friggin malware.  (Read 1745 times)

Brad Johnson

  • friend
  • Senior Member
  • ***
  • Posts: 18,143
  • Witty, charming, handsome, and completely insane.
Blankety blank doggone blank blankety blanks!! Friggin malware.
« on: February 03, 2010, 03:22:36 PM »
Spent the morning fighting a malware problem on my home machine. 

The lovely folks at Registry Defender need a few body parts placed in a vise.  What an invasive piece of crap.  It just showed up one day, popping up to say 'Hi!' every few minutes.  McAffee apparently doesn't see it at all.  Ad-Aware Pro saw it but wouldn't or couldn't delete it.  Malwarebytes wouldn't even install (the .exe file mysteriously kept "disappearing").  I finally got a random-name MWB executable to stay put and left it running right before lunch.  I'm headed home to check on it now.

I'm seriously thinking about sending the sorry SOBs at Registry Defender a bill for my time and for reimbursment on the additional software (I occasionally bill by the hour and can legitimately hit them for lost time).  When I get back to the office I'm going to search for a few legal precedents, or maybe some applicable statues, that I can throw into the nasty-gram for good measure.  DTPA and a few selected interstate commerce provisions are the first two that come to mind, but I'm sure there are more.

Sorry sonsaleaches.  Hate 'em.

Brad
« Last Edit: February 03, 2010, 03:26:15 PM by Brad Johnson »
It's all about the pancakes, people.
"And he thought cops wouldn't chase... a STOLEN DONUT TRUCK???? That would be like Willie Nelson ignoring a pickup full of weed."
-HankB

Balog

  • Unrepentant race traitor
  • friends
  • Senior Member
  • ***
  • Posts: 17,774
  • What if we tried more?
Re: Blankety blank doggone blank blankety blanks!! Friggin malware.
« Reply #1 on: February 03, 2010, 03:30:46 PM »
Was it something you DL'ed on purpose, or just picked up along the way?
Quote from: French G.
I was always pleasant, friendly and within arm's reach of a gun.

Quote from: Standing Wolf
If government is the answer, it must have been a really, really, really stupid question.

Brad Johnson

  • friend
  • Senior Member
  • ***
  • Posts: 18,143
  • Witty, charming, handsome, and completely insane.
Re: Blankety blank doggone blank blankety blanks!! Friggin malware.
« Reply #2 on: February 03, 2010, 04:50:06 PM »
Just popped up one day, literally.  I was sitting at the computer (on APS, by the way) and started getting the "Your computer may not be protected! Download THIS!" popups.

Looks like Malwarebytes took care of it, though.  It found three seperate trojans, all having multiple embeddings.  One was instance was embedded square in the middle of Ad-Aware.  I suppose I shouldn't be surprised at that, though.  I ran the fix routine, rebooted as instructed, then rebooted again to Safe Mode and am running MWB one more time just to see if anything else pops up.

Brad
« Last Edit: February 03, 2010, 04:55:48 PM by Brad Johnson »
It's all about the pancakes, people.
"And he thought cops wouldn't chase... a STOLEN DONUT TRUCK???? That would be like Willie Nelson ignoring a pickup full of weed."
-HankB

Brad Johnson

  • friend
  • Senior Member
  • ***
  • Posts: 18,143
  • Witty, charming, handsome, and completely insane.
Re: Blankety blank doggone blank blankety blanks!! Friggin malware.
« Reply #3 on: February 03, 2010, 06:12:07 PM »
Well, well...

Mawarebytes found and instance of Hijack on my office machine. Nuked that sucker right off, though.

Brad
It's all about the pancakes, people.
"And he thought cops wouldn't chase... a STOLEN DONUT TRUCK???? That would be like Willie Nelson ignoring a pickup full of weed."
-HankB

RocketMan

  • Mad Rocket Scientist
  • friend
  • Senior Member
  • ***
  • Posts: 13,689
  • Semper Fidelis
Re: Blankety blank doggone blank blankety blanks!! Friggin malware.
« Reply #4 on: February 03, 2010, 08:53:17 PM »
Well, well...

Mawarebytes found and instance of Hijack on my office machine. Nuked that sucker right off, though.

Brad

It wasn't a false positive on Trend Micro's "HijackThis", was it?  HijackThis is a legitimate anti-malware program that is quite handy.
If there really was intelligent life on other planets, we'd be sending them foreign aid.

Conservatives see George Orwell's "1984" as a cautionary tale.  Progressives view it as a "how to" manual.

My wife often says to me, "You are evil and must be destroyed." She may be right.

Liberals believe one should never let reason, logic and facts get in the way of a good emotional argument.

Jim147

  • friends
  • Senior Member
  • ***
  • Posts: 7,611
Re: Blankety blank doggone blank blankety blanks!! Friggin malware.
« Reply #5 on: February 03, 2010, 09:15:54 PM »
Let us know how billing them goes for you. ;/

I stopped working on computers and I'm getting a couple a week in right now with different names of the same crapware.

jim
Sometimes we carry more weight then we owe.
And sometimes goes on and on and on.

BAH-WEEP-GRAAAGHNAH WHEEP NI-NI BONG

Brad Johnson

  • friend
  • Senior Member
  • ***
  • Posts: 18,143
  • Witty, charming, handsome, and completely insane.
Re: Blankety blank doggone blank blankety blanks!! Friggin malware.
« Reply #6 on: February 03, 2010, 10:10:29 PM »
Did some searches and the ONLY way to contact them is via e-mail, and from their web page (which is loaded with all kinds of piggy-backed crap).

Malwarebytes did the job, though.  I'm usually leery of any kind of freeware, especially for stuff like this.  But the program comes highly recommend via a ton of positive web mentions and seemed to work just as advertised.

Brad
It's all about the pancakes, people.
"And he thought cops wouldn't chase... a STOLEN DONUT TRUCK???? That would be like Willie Nelson ignoring a pickup full of weed."
-HankB

Jim147

  • friends
  • Senior Member
  • ***
  • Posts: 7,611
Re: Blankety blank doggone blank blankety blanks!! Friggin malware.
« Reply #7 on: February 03, 2010, 10:20:26 PM »
You know I find it kind of strange that everyone I have talked with one of these crapware programs has been blaming Microsoft or Norton or who ever they are paying for antivirus. [tinfoil] One of them even downloads everything he comes across online. :O But none of them want to take the time to learn about their systems or the real software that is avalible out there. Like Malwarebytes.

I prefer everyone be as selfsuffecent as posible. But then again I need to make a buck somewhere.

jim
Sometimes we carry more weight then we owe.
And sometimes goes on and on and on.

BAH-WEEP-GRAAAGHNAH WHEEP NI-NI BONG

Brad Johnson

  • friend
  • Senior Member
  • ***
  • Posts: 18,143
  • Witty, charming, handsome, and completely insane.
Re: Blankety blank doggone blank blankety blanks!! Friggin malware.
« Reply #8 on: February 03, 2010, 10:24:35 PM »
[tinfoil] One of them even downloads everything he comes across online. :O But none of them want to take the time to learn about their systems or the real software that is avalible out there.

Or to school themselves on the semantics of what is, and isn't a valid email.

Brad
It's all about the pancakes, people.
"And he thought cops wouldn't chase... a STOLEN DONUT TRUCK???? That would be like Willie Nelson ignoring a pickup full of weed."
-HankB

T.O.M.

  • friend
  • Senior Member
  • ***
  • Posts: 6,416
Re: Blankety blank doggone blank blankety blanks!! Friggin malware.
« Reply #9 on: February 04, 2010, 09:37:33 AM »
I've had that one hit me a few times.  The IT guys warned me that the newest game in town is to hijack a link on Yahoo or Google home pages.  You hit the link, and you get where you wanted to go, but also pick up a present along the way.  My last one came from a hijacked Sports Illustrated link.  It was a fun one.  Not only did I get the security warnings and threats, with the "must buy our protection" pop ups, I then started with the hardcore p0rn pop-ups to make me want to buy the protection.  Malwarebytes did the trick.  Although, I'm dealing with a new one now.  It's a new one, which is avoiding all of the detectors (Ad-aware, malwarebuytes, etc.).  Although, this one is pretty lame.  If I use a search engine, and click on a link I get as a result, it re-directs me to somewhere else, most often a company offering domain registry, items for sale, or (I love this one) the FBI home page.
No, I'm not mtnbkr.  ;)

a.k.a. "our resident Legal Smeagol."...thanks BryanP
"Anybody can give legal advice - but only licensed attorneys can sell it."...vaskidmark

Brad Johnson

  • friend
  • Senior Member
  • ***
  • Posts: 18,143
  • Witty, charming, handsome, and completely insane.
Re: Blankety blank doggone blank blankety blanks!! Friggin malware.
« Reply #10 on: February 04, 2010, 11:12:50 AM »
If I use a search engine, and click on a link I get as a result, it re-directs me to somewhere else, most often a company offering domain registry, items for sale, or (I love this one) the FBI home page.

Irony can be pretty ironic sometimes. =D

Brad
It's all about the pancakes, people.
"And he thought cops wouldn't chase... a STOLEN DONUT TRUCK???? That would be like Willie Nelson ignoring a pickup full of weed."
-HankB