[identity profile] coyoteden.livejournal.com posting in [community profile] techrecovery
OK, so this evening I was helping out my former employer with a couple of tricky jobs. One of which was cleaning up his own computer. We're all careful about security, but it got hijacked by CoolWebSearch. Don't ask.

Now, this was one of the nastier variants that loads from HKLM/.../Run like most stuff, but then hides itself from the process list, spawns copies, hides the files on disk, puts all the copies in startup, and deletes the original file. If you remove any of the registry keys, it puts them right back. You can't kill it with the usual tools because you just can't see the fnords. The files change every time you reboot, and if you don't get EVERY file from safe mode, it will come right back.

Well, I thought I killed it. I KNOW I killed it. The files had been deleted and the system had been scanned from safe mode.... but the registry keys just kept coming back. Uh-oh. I loaded up Regmon and took a look at what was writing that key in the registry.

"Ad-watch.exe"

Fucking Ad-Aware. Goat-fucking Ad-Aware Pro to be precise. The real-time protection was restoring the damn CoolWebSearch keys (including the browser hijacks!) every time I removed them! And giving no warning. At all.

Date: 2005-07-07 12:05 pm (UTC)
From: [identity profile] xdownfornowx.livejournal.com
I've found that using multiple A/S apps works the best, and never keep the restore points from them. I will also concur with twitchfetish that the MS app is really good at actively preventing that bullshit in the first place.

Profile

techrecovery: (Default)
Elitist Computer Nerd Posse

April 2017

S M T W T F S
      1
2345678
91011121314 15
16171819202122
23242526272829
30      

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Mar. 20th, 2026 11:42 am
Powered by Dreamwidth Studios