StellarForum
May 22, 2012, 02:17:04 PM *
Welcome, Guest. Please login or register.

Login with username, password and session length
News: Stellar Frontier has moved to the new forum and site at stellarfrontier.com!
Please make a new account there in preparation for SF 2.0 and to chat on the boards!
 
   Home   Help Search Groups Login Register  
Pages: [1]
  Send this topic  |  Print  
Author Topic: Random And Weird  (Read 696 times)
Geo
Experienced Member
***
Posts: 76



« on: December 29, 2008, 10:53:52 PM »

I just did a temporary fix of a virus on my parents computer. The virus that has been on there for a while now decided to do an audio stream in some foreign language and there was no way of stopping the process since it was unknown Undecided. So finally, I just ended explorer.exe and started it back.

Still, veeeerrrrrryy strange...
*Hears Twilight theme in back of head*
Report to moderator   Logged

"It is an undeniable, and may I say fundamental, quality of man, that when faced with extinction, EVERY alternative is preferable." ~Dr. Leonard Church, Director of the Freelancer Project
http://officeofstrategicinfluence.com/spam <--This link kills spam
ChillFactor
Stealth Assasin
The Police
Expert Member
****
Posts: 516


Freeze! It's the forum police!

ppsustancias@hotmail.com
WWW Email
« Reply #1 on: December 30, 2008, 03:57:41 PM »

Russian virus...
I had to work on a way to get it out of hte bank's network on linux... That's how far russians have gone as it goes for viruses... lol
Report to moderator   Logged

Don't take life too serious, you won't get out of it alive...

-=Tribe=- Assassin's Redoubt
Staker
Moderator
Veteran Member
****
Posts: 352



WWW Email
« Reply #2 on: January 04, 2009, 03:41:00 AM »

Go to downloads.com and download Malwarebytes Anti Malware... Should be on the main page.
Report to moderator   Logged

<<GB-C>> King of Death
I am Shiva the King of Death
Relentless
Advanced Member
****
Posts: 111


Formerly Space_Man_1


WWW Email
« Reply #3 on: January 07, 2009, 04:42:38 PM »

Tuenup utilities 2008 also works nicely though it's not 100 percent free. (it's good for system maintenance like defragging, registry repair etc)
Report to moderator   Logged

-Relentless/Space_Man_1
FOA Founder
NiteHawk
<dev></dev>
Administrator
Legendary Member
*****
Posts: 2816



WWW
« Reply #4 on: January 09, 2009, 08:26:14 AM »

If you cannot get rid of it in windows, you may have an issue removing it unless your in safe mode.

I'd get the following two:

Spybot: Search and Destroy - Spyware Removal
Avira AntiVir Personal - Virus Removal

I've used S&D for years now, it's a great program, not only does it remove, it has another two great features:
A. Immunize - This protects your browsers from several spyware issues, thus you have to worry less because we all know how parents are on computers. Basicly, to date now, it protects 123000+ spywares, thus lessening the chance of even getting it in the first place.
B. TeaTimer - This stays on real time, and protects the computer real time. If something tries to get in your registry, it will ask if you wish to allow or disallow. For your parents, if they don't know much, set it to AUTODISALLOW, and they shouldn't see spyware ever again. Else, just tell them to DISALLOW unless there installing something. Mine hardly comes up now though, unless something harsh happens, it has a smart thing now that blocks garbage automatically, and hardly takes up memory.

And for Avira, I just switched to it about a year ago, and I'm quite happy with it. Norton is BLOATED, takes up huge amount of ram, and takes a hour to load even the GUI screen. It's a good scanner in general, but it has issues with alot of installed programs that are 'fine'. I recently had AVG FREE, but they went to the super BLOATED mode. The problem with those two are it takes ages to load at windows startup, well, too long for me anyways. Don't need a bloated scanner.

With Avira, it has several options, and is a light scanner. Protects real time, emails, etc. Doesn't take up much memory at all either.

To remove anything that cannot be removed by normal scan means, first, get both programs, update them, immunize, etc.. Then go into safe mode (Tap the F8 key at bootup), and after it loads, run the scanners in safe mode. Safe mode basicly means that no programs load, so any program that keeps staying in memory even if you taskmanager close it (ALTCTRLDEL the sucker) it should kill it. Sometimes when you do scans and it removes, the virus/spyware comes back because its sitting in the core of the memory, laughing at you, basicly.

After you do safe mode tricks, you shouldn't really need to do it again. Been going strong now without having to scan -- ever.. Bout a year and half now with no scanning, just using the real time protection.

And a note: If they still have IE6, it is a big security risk, get opera or FF (or IE7). If they know how to use IE6 it would be fine, but like my parents, they click install on everything that pops up.. :x If you hate tabs in IE7 etc, you can always disable them so it acts like IE6.

P.S. If that still does not work, get HIJACK THIS!, and post a log up. You'll want to clean hijack this in safe mode too
« Last Edit: January 09, 2009, 08:51:13 AM by NiteHawk » Report to moderator   Logged

http://chrisvall.com - Coding/gaming blog in the works.
Staker
Moderator
Veteran Member
****
Posts: 352



WWW Email
« Reply #5 on: January 09, 2009, 01:42:07 PM »

If you cannot get rid of it in windows, you may have an issue removing it unless your in safe mode.

I'd get the following two:

Spybot: Search and Destroy - Spyware Removal
Avira AntiVir Personal - Virus Removal

I've used S&D for years now, it's a great program, not only does it remove, it has another two great features:
A. Immunize - This protects your browsers from several spyware issues, thus you have to worry less because we all know how parents are on computers. Basicly, to date now, it protects 123000+ spywares, thus lessening the chance of even getting it in the first place.
B. TeaTimer - This stays on real time, and protects the computer real time. If something tries to get in your registry, it will ask if you wish to allow or disallow. For your parents, if they don't know much, set it to AUTODISALLOW, and they shouldn't see spyware ever again. Else, just tell them to DISALLOW unless there installing something. Mine hardly comes up now though, unless something harsh happens, it has a smart thing now that blocks garbage automatically, and hardly takes up memory.

And for Avira, I just switched to it about a year ago, and I'm quite happy with it. Norton is BLOATED, takes up huge amount of ram, and takes a hour to load even the GUI screen. It's a good scanner in general, but it has issues with alot of installed programs that are 'fine'. I recently had AVG FREE, but they went to the super BLOATED mode. The problem with those two are it takes ages to load at windows startup, well, too long for me anyways. Don't need a bloated scanner.

With Avira, it has several options, and is a light scanner. Protects real time, emails, etc. Doesn't take up much memory at all either.

To remove anything that cannot be removed by normal scan means, first, get both programs, update them, immunize, etc.. Then go into safe mode (Tap the F8 key at bootup), and after it loads, run the scanners in safe mode. Safe mode basicly means that no programs load, so any program that keeps staying in memory even if you taskmanager close it (ALTCTRLDEL the sucker) it should kill it. Sometimes when you do scans and it removes, the virus/spyware comes back because its sitting in the core of the memory, laughing at you, basicly.

After you do safe mode tricks, you shouldn't really need to do it again. Been going strong now without having to scan -- ever.. Bout a year and half now with no scanning, just using the real time protection.

And a note: If they still have IE6, it is a big security risk, get opera or FF (or IE7). If they know how to use IE6 it would be fine, but like my parents, they click install on everything that pops up.. :x If you hate tabs in IE7 etc, you can always disable them so it acts like IE6.

P.S. If that still does not work, get HIJACK THIS!, and post a log up. You'll want to clean hijack this in safe mode too


Malwarebytes Anti Malware
Is a free program also. It detects malwares that S&D and a Virus protector will not be able to find or localize. It even scans your registry and deletes any files that is infected. It made my laptop seem like I just took it out of the UPS Box when I bought it directly from Toshiba. XD
Report to moderator   Logged

<<GB-C>> King of Death
I am Shiva the King of Death
AdmiralTigerclaw
Sound Developer
Expert Member
****
Posts: 734


Naval Commander: Forum Sound Admin


« Reply #6 on: January 09, 2009, 03:45:56 PM »

You don't want to 'delete' infected registry files.  Oh hells no. 

You want to REPLACE them with clean versions.

You delete a registry key or file and there's no TELLING what you might have just seriously effed.

Anywho, my best suggestion when it comes to malware is to avoid using P2P programs like limewire.  Just INSTALLING it sticks things onboard your system you shouldn't have.  (I just recently had to re-install the operating system for a lady because her grandkids had limewire on it, and the stuff it picked up effed the OS beyond the ability for it to function.  Not even the administrator could get into the core to manually fix anything in SAFE MODE anymore.)  After that, if you're going to do it anyway, go easy on the rate of downloads.  If you're using a torrent to grab stuff, I suggest at LEAST looking at the file contents before and during download to see what interesting little files it has in the queue.

Oh, and if you happen to notice smitfraudC in the list of things the cleaning programs clean...  UGH... that thing is a twelve step fixing procedure from HELL.  Gotta run a scan, clean the files, then you have to download the smitfraud-Fix utility, then disable the network connection so it doesn't just reinstall the thing, manually delete one of the false malware remover programs it gets, reboot in safe mode, run the utility: scan, clean, scan to confirm, reboot, set Spybot to clean at system start, and then reboot and scan so it confirms the program was cleaned out.

And all you have to do to get it is accept an ActiveX control.  (Which should be set to at least prompt you... If you have it set to accept active X controls without bothering to prompt you... yeah, you're screwed.)

Smitfraud C is a beast because it's a trojan downloader.  On top of itself, it installs a false malware remover that backs itself up.  It also infects the host files so if you clean the system, it'll just auto-grab it again the next time the network is up.  The host files have to be cleaned manually. (That's what the fix utility does) That has to be done in safe mode.

So if you don't get ALL THREE components, you end up right back at step one.  And because of the configuration, the cleaners have a hard time dealing with it.  Even spybot, with the latest updates.  It detects it, but proper cleaning procedure is beastly manual.
The first time I encountered it, it took me FOUR days to fix my sister's laptop.
The second time it took me a day.  And the third time I picked it up for myself here, I had it down to a four hour cycle.  (Scans eat most of the time.)
Report to moderator   Logged

GCFA Naval Commander
Veteran Player - Supreme Spaceforce Agressor
Owner: Samurai Penguin Studios
Listen on Last.FM
Pages: [1]
  Send this topic  |  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.12 | SMF © 2006-2009, Simple Machines LLC Valid XHTML 1.0! Valid CSS!