Pages: [1] 2   Go Down
  Print  
Author Topic: Arrrgggggg!  (Read 263 times)
0 Members and 1 Guest are viewing this topic.
Thermalsig
American stooge!
Administrator
Alcoholic
*

Good Guy/Gal Points. -65496
Offline Offline

Posts: 6614



« on: October 14, 2010, 11:26:43 AM »

This is just a rant here folks. I visit exactly 4 sights on the web normally and use sandboxed if I'm off in the ether. However, I've got a son who uses this pc to go shit knows where. blink I've got this particularly nasty piece of shit that has evaded removal by Avast and Malwarebytes. It's been a long time since I hooked anything other than the typical BS that flushes easy. Oh well, time to dig in and do it the hard way. Roll Eyes Damn, I'm such a whiner!  laugh
Logged

KingDazza
Guest
« Reply #1 on: October 14, 2010, 11:40:35 AM »

Sorry to hear that mate.  I'm sure you've got a strategy in mind... safe mode / view start up registry / processes etc?
Logged
corroded
Humbug Monkee
Pub regular
*******

Good Guy/Gal Points. 73
Offline Offline

Posts: 3916


Shop Smart, Shop S-Mart.


« Reply #2 on: October 14, 2010, 01:04:39 PM »

God Therm, whine a bit more already!!!!! innocent












facepalm






We all of course get the irony here, right?




« Last Edit: October 14, 2010, 01:21:49 PM by corroded » Logged
keasy
Administrator
Alcoholic
*

Good Guy/Gal Points. 2
Offline Offline

Posts: 92224


Winter is coming!


« Reply #3 on: October 14, 2010, 01:32:29 PM »

Have you done a HiJackThis mate, before you do anything drastic like ?
Logged


"I just think most forums are populated by a rather high percentage of cocks ," - King Dazza.
Wooster
Wall Eyed Wanker
Administrator
Alcoholic
*

Good Guy/Gal Points. -518
Offline Offline

Posts: 5544


'An how faust kin it ging?'


« Reply #4 on: October 14, 2010, 08:54:05 PM »

If you can get a handle on the process then you can suspend it using Procexp (killing them usually just invokes them to start up again) then get ripped into it with HJT as Keasy mentioned.  Cool
Logged

Trippynet
On the teat!
*

Good Guy/Gal Points. 6
Offline Offline

Posts: 52


Official beer taster


« Reply #5 on: October 14, 2010, 08:58:13 PM »

Blimey, it must be a nasty bit of shit if even Malwarebytes is flummoxed by it.  Sad
Logged
Thermalsig
American stooge!
Administrator
Alcoholic
*

Good Guy/Gal Points. -65496
Offline Offline

Posts: 6614



« Reply #6 on: October 14, 2010, 11:28:55 PM »

It's a browser hijacker. It has jumped twice already. Killing several suspected processes with hijack this temp killed it, but it returned on reboot. I think I'm staring at a rootkit and a reformat. First to the pros though.                                                   
Logged

Wooster
Wall Eyed Wanker
Administrator
Alcoholic
*

Good Guy/Gal Points. -518
Offline Offline

Posts: 5544


'An how faust kin it ging?'


« Reply #7 on: October 14, 2010, 11:40:34 PM »

Ahh, they're crafty bastards these days.  confused
Logged

Thermalsig
American stooge!
Administrator
Alcoholic
*

Good Guy/Gal Points. -65496
Offline Offline

Posts: 6614



« Reply #8 on: October 14, 2010, 11:52:54 PM »

Ahh, they're crafty bastards these days.  confused
scratchhead No shit. I looked down the barrel at some ugly things before, but this one seems determined to remain. There is about a billion other posts in the last 3 days about this same malware. I usually laught at this, but I can't get out myself yet.
Logged

bashy
Business Class
Non spill cup.
****

Good Guy/Gal Points. 65
Offline Offline

Posts: 222



WWW
« Reply #9 on: October 14, 2010, 11:58:11 PM »

Give spy-bot and ad-adware a shot too, you never know
Logged

KingDazza
Guest
« Reply #10 on: October 15, 2010, 07:39:40 AM »

So it doesnt show in the start up processes list?  And when disabled via hijack this or equivalent, it still reactivates at start up in safe mode too?
Logged
Glamdring
Global Moderator
Occasional drinker
*****

Good Guy/Gal Points. 78
Offline Offline

Posts: 2236


Imaginary Friend


« Reply #11 on: October 15, 2010, 09:08:49 AM »

You've obviously disabled Restore Points? It can hide in there.
Logged

I exist in a dark place where no light intrudes and none is promised. It's growing yet darker.
I added this sig a year ago. It's a lot worse now...
keasy
Administrator
Alcoholic
*

Good Guy/Gal Points. 2
Offline Offline

Posts: 92224


Winter is coming!


« Reply #12 on: October 15, 2010, 09:10:31 AM »

Good point!
Logged


"I just think most forums are populated by a rather high percentage of cocks ," - King Dazza.
Thermalsig
American stooge!
Administrator
Alcoholic
*

Good Guy/Gal Points. -65496
Offline Offline

Posts: 6614



« Reply #13 on: October 15, 2010, 10:37:37 AM »

So it doesn't show in the start up processes list?  And when disabled via hijack this or equivalent, it still reactivates at start up in safe mode too?
I wasn't able to actually point at one process as the culprit, I just removed all suspect non needed with Hijack in safe mode, but didn't restart in safe mode to check if it didn't again. scratchhead It popped back up in normal restart. It's a browser hijacker, so it's only effect is the redirect. I threw the log file up at hijack this to see if they could spot it and they couldn't see anything either. Do you know somewhere else I could try that might be better?
You've obviously disabled Restore Points? It can hide in there.
No on the first try, tongue2 yes on the second and third. Spybot S&D caught it(the only one to do so) and attempted to delete it. After the start up scan and a clean scan(No Problems Found!), it promptly showed up again.
Logged

KingDazza
Guest
« Reply #14 on: October 15, 2010, 11:46:23 AM »

Not sure what else to suggest really, as tbh its been literally years since I had any malware at all.  The last one I had years ago, I just remember using the usual apps, establishing where it was rejuvenating itself from at start up, then clearing the bugger out in safe mode.  Usually for me in the past, they are always created from another location to where the actual live bugger is.  Hence you delete it, but not the source/creator.  Thats why I was focusing on seeing what ran at start up.  I'd be inclined to install Avira personally as you can select on install, for it to be a priority start up app, i.e it embeds and activates, before nasties should get a chance to do there rejuvenating antics.

In short, try other av/malware progs (start with Avira free)to see if any of them can detect the bastard at start up, after just cleaning the live one with spybot or whatever is succeeding with that part, before the reboot.

All the best with it - I know how infuriating these things can be.  I take an image every 2 weeks, rather than running a mirror, just incase of this kind of malarkey.  

« Last Edit: October 15, 2010, 11:47:57 AM by KingDazza » Logged
Pages: [1] 2   Go Up
  Print  
 
Jump to: