[identity profile] mouser.livejournal.com posting in [community profile] techrecovery
Get a call at 6:15 (I'm barely out of bed) "OMFWTFBBQ!!11! Someone has sent us up the virus!"

Of course they left in ON and connected to all the shares, but it's not that type, fortunately. Just a "Buy our Spyware product! Er, Spyware REMOVER! REALLY!" Smit variant, I think, but the stuff I used on the LAST hit aren't working. God, I hate that damned thing. But I'm not sure because it's not really TELLING me anything! I delete directories of crap, find one that's got

Task manager disabled.
Background changed to Active Desktop (Hate that damned thing too) saying OMGWTFBBQ!!1! YOU BE INFECTED CLICK HERE!!!
Every two minutes one of four windows pops open to tell me to pay their extortion to get this crap off the machine.


Crap, I don't have TIME for this.

Symantec ignores it. Fuck
SpybotS&D kills some of the components, not the re-seeder. Fuck.
All the components keep coming back. Double Fuck.
AdAware2007 is useless. Fuck.

I'm considering telling the cheap bastards they've got to buy a new one because I don't have two days to wipe and reinstall their crap.




I need to find a virus maker so I can kick him in the nuts. Repeatedly.

Date: 2008-05-06 02:11 am (UTC)
From: [identity profile] museology.livejournal.com
Did the start bar disappear too? That happened to my stepdad after he was surfing porn, and he appeared at my door "I was surfing porn.. and I got a virus.. and Norton doesn't recognize it.. Will you fix it?"

I had to manually delete 37 files, discovering along the way that all of the filenames had closely duplicated Windows files. If Windows had "abc.dll," the virus had "abcd.dll" and so on.

Date: 2008-05-06 02:16 am (UTC)
From: [identity profile] museology.livejournal.com
Yeah, my stepdad's startbar disappeared after he tried to "fix it himself," which basically means "I fucked it up worse." He sucks that way, yet he refuses to admit I'm ever right on any tech issue.. ever.

Date: 2008-05-06 02:13 am (UTC)
From: [identity profile] phrogg.livejournal.com
SmitFraudFix (http://siri.geekstogo.com) usually works for me, on those types.

Date: 2008-05-06 02:57 am (UTC)
From: [identity profile] snoopyh42.livejournal.com
Sounds like one I did battle with a couple weeks ago. I ended up having to use a Live Windows CD environment and run the virus scanner from there. I used the one at http://ubdisk.org/. I'm sure you know where you can find a .torrent to get the ISO.

*grumble* 10 hours of my life I'll never get back...
Edited Date: 2008-05-06 02:58 am (UTC)

Date: 2008-05-06 03:08 am (UTC)
From: [identity profile] notthebuddha.livejournal.com
try SuperAntiSpyware.com, they seem to specialize in that sort.

Date: 2008-05-07 12:21 am (UTC)
From: [identity profile] coyoteden.livejournal.com
I hope you're kidding. Some of that scamware pushes SAS!

Date: 2008-05-07 01:04 am (UTC)
From: [identity profile] notthebuddha.livejournal.com
So, if I publish a program that puts up an ad for Symantec, does that make Symantec a scam or my program legit? You are probably thinking of WinAntiSpyware anyway.

I've never had a problem with anything downloaded from superantispyware.com, and meanwhile Superantispyware takes off plenty bad stuff that Spybot and Adaware miss, for example.

Date: 2008-05-07 03:27 am (UTC)
From: [identity profile] coyoteden.livejournal.com
oops. I think you might be right. So let's see, we have

SUPERAntispyware=good
WINAntiSpyware/AntiVirus=scam
GIANTAntiSpyware=...umm... Windows Defender?

Date: 2008-05-06 03:37 am (UTC)
From: [identity profile] pyrtolin.livejournal.com
Make yourself a good Ultimate Boot CD or Reatogo CD. They're priceless when you need to excise root kits or other entrenched viruses like that.

http://www.ubcd4win.com/
http://www.reatogo.de/REATOGO.htm

Date: 2008-05-06 03:42 am (UTC)
From: [identity profile] hisamishness.livejournal.com
Someone at one of our locations seems to have picked up the same dang thing. I've never been happier to be temporarily tied to a desk... ;-)

Date: 2008-05-06 11:08 am (UTC)
From: [identity profile] kallell.livejournal.com
adaware and avg combined got rid of one of those for methe real trick was getting the updated to load with all its issues

Date: 2008-05-06 01:25 pm (UTC)
From: [identity profile] mattcaron.livejournal.com
I need to find a virus maker so I can kick him in the nuts. Repeatedly.

I have guns, knives, and live in the country where folks won't hear the screaming...

Sorry, this turned into an annoyed rant.

Date: 2008-05-06 03:17 pm (UTC)
From: [identity profile] zendequervain.livejournal.com
This is especially relevant to me, because that sounds...very similar to what's on my computer right now. O.<

Spybot is continually denying registry changes (because I told it to based on history) and I can't figure out what to kill to make whatever it is stop trying to change said registry. Boo.

Of course, part of my problem is the Server 2k3 that was forced on me by a more-tech-savvy former roommate. He claimed it was way better than XP, but hey, none of the free antivirus programs will even install because (gasp) it's a server! *hoards links*

ETA: For the record, I am obviously not a tech, but I love reading this community. I try not to be a luser, so I don't want to do anything that could fux stuff up more than it already is.
Edited Date: 2008-05-06 03:28 pm (UTC)

Date: 2008-05-06 06:37 pm (UTC)
From: [identity profile] goose-entity.livejournal.com
type "spyware x scan" into Giggle. Should be one of the first hits.

Date: 2008-05-06 07:30 pm (UTC)
From: [identity profile] azzy23.livejournal.com
Ooooh, Vundo. Nasty business, that. I don't actually know of *any* AV software that can totally clean it. Download Vundofix, and find something for WinFixer. It's one of the two.

(I work for a to-remain-unnamed Anti-Virus vendor).

Date: 2008-05-07 12:27 am (UTC)
From: [identity profile] coyoteden.livejournal.com
ugly stuff, it hooks winlogon and does a bunch of other rootkit-level stuff. You literally can't clean a live system, and finding every file with a boot disk is tedious. I think Windows Defender and some AV can keep it from getting there in the first place, but if it's hooked in, it's too late for any realtime shield.

It's only weakness is that it puts a lot of the per-user browser hijacking back at logon/logoff, but not constantly. Try a system restore (seriously, it often works!) to a point you know is clean, then run Windows Defender (or spybot, or AAW, anything reputable) to clean up the browser-level stuff.

If that fails, nuke it.
Edited Date: 2008-05-07 12:28 am (UTC)

Date: 2008-05-06 08:03 pm (UTC)
ext_130371: (batshit)
From: [identity profile] ravenofdreams.livejournal.com
I think I saw that same little bastard today, and AVG and Spybot together with the SmitFraudFix cleaned it off.

Date: 2008-05-07 02:01 am (UTC)
curmudgn: Caricature of Nikita Krushchev as a top-hatted pig, laughing (Nikita laughs)
From: [personal profile] curmudgn
"Debug format reinstall, doo dah, doo dah . . ."

Date: 2008-05-08 02:45 am (UTC)
From: [identity profile] vorro.livejournal.com
I see nobody mentioning hijackthis. why is that? HJT is the best program evar...
Page generated Mar. 19th, 2026 09:24 pm
Powered by Dreamwidth Studios