All times are GMT -4. The time now is 06:02 AM.  

Go Back   Gunco.net > GENERAL Discussion Lobby > General Discussion Lobby

General Discussion Lobby General chit-chat, current events, news and all others...


Reply
 
LinkBack Thread Tools Display Modes
 
Old 11-07-2009, 06:27 PM   #1 (permalink)
Gunco Regular
 
nkluksda's Avatar
 
Join Date: Nov 2005
Location: Houston, TX
Posts: 946
iTrader: 1 / 100%
Default Anyone dealt with Antivirus Pro 2010 malware

My wife's computer has it bad. Really bad. I'm stuck now trying to unravel this POS software. Any help would be appreciated. (BTW, I'm a computer professional, so I know my way around the registry and such well.)
__________________
Q - What is Bambi?

A - Viable Target
nkluksda is online now   Reply With Quote
 
Old 11-07-2009, 08:43 PM   #2 (permalink)
Gunco Member
 
dcorb's Avatar
 
Join Date: Dec 2004
Posts: 177
iTrader: 1 / 100%
Default

Quote:
Originally Posted by nkluksda View Post
My wife's computer has it bad. Really bad. I'm stuck now trying to unravel this POS software. Any help would be appreciated. (BTW, I'm a computer professional, so I know my way around the registry and such well.)
I got nailed with that one on one of PC's. It is a challenge to get rid of. I never got hit with one like that before. I was impressed of how clever the idiot that created it was. Check all the start up location in the registry. I had to rename the EXE's and DLL's that were pointed to in the registry as the files were open and could not be deleted. There was some scheduled explore task registry entry that I thought was clever. Also there is a BHO registry entry that will get you. I learned a few things and I have been around this stuff for too many years.
dcorb is online now   Reply With Quote
 
Old 11-07-2009, 08:55 PM   #3 (permalink)
Gunco Regular
 
nkluksda's Avatar
 
Join Date: Nov 2005
Location: Houston, TX
Posts: 946
iTrader: 1 / 100%
Default

I want the SOB who created this thing dead. Really, really dead. Slowly, agonizingly, painfully dead. A gory lingering sort of "prepare for hell" kind of death. The kind of thing that would make the author wish he were merely having his intestines pulled out of his nostrils an inch every hour with a vise grips.

The damned thing is a variant. The registry keys are changed, the program names are changed - and the damned things keep moving! It's blocking all applications that MIGHT get it - anything that can edit the hosts file (so it can pop up a lot of annoying porn sites), regedit, the task manager, installations - it's managed to block it all. And I thought I had it a whole bunch of times - only to discover that I missed one location and it respawned like a plague from hell. It is a well-executed piece of software, even if it is nasty.

This thing is evil and nasty and I want the author dead. Wait - did I say that already? Too bad - I really really want the author dead.
__________________
Q - What is Bambi?

A - Viable Target
nkluksda is online now   Reply With Quote
 
Old 11-07-2009, 09:05 PM   #4 (permalink)
الفوضى
 
Runaway Shortbus's Avatar
 
Join Date: Sep 2009
Location: Fairfax, VT
Posts: 52
iTrader: 0 / 0%
Default

When in doubt I call in a nuclear strike, aka backup your data and settings, reformat the drive, and reinstall.
I liken the windows OS to a trailer park, it eventually gets so bad that your only solution is to burn it to the ground and start over.
I reinstall my OS about every 2 months, I also use [Only registered and activated users can see links. ] antivirus, its free and its the only one that I trust.

Also I sincerely hope that you are not using Norton or McAfee.
__________________
Disclaimer -- the preceding message was a work of fiction, portrayed by actors over the age of 21.

Quote:
There are varying degrees of evil, we urge you lesser forms of filth not to push the bounds and cross over into true corruption, into our domain. But if you do, one day you will look behind you and you will see we three and on that day you will reap it. And we will send you to which ever god you wish. --The Boondock Saints
Runaway Shortbus is online now   Reply With Quote
 
Old 11-07-2009, 09:06 PM   #5 (permalink)
Gunco Regular
 
nalioth's Avatar
 
Join Date: Feb 2006
Posts: 919
iTrader: 3 / 100%
Default

Quote:
Originally Posted by nkluksda View Post
(BTW, I'm a computer professional, <snip>
Did you mean "windows professional" ?

Get an Ubuntu live CD.

Boot it up.

Use the package manager to install ClamAV.

Run ClamAV against your windows drive.

Profit.
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
|
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
|
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
|
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
nalioth is online now   Reply With Quote
 
Old 11-07-2009, 09:27 PM   #6 (permalink)
Gunco Regular
 
nkluksda's Avatar
 
Join Date: Nov 2005
Location: Houston, TX
Posts: 946
iTrader: 1 / 100%
Default

Quote:
Originally Posted by nalioth View Post
Did you mean "windows professional" ?
No. We don't do windows in the control center. Not going to say more - NASA is a huge target for malware, hackers, and other such crap. Now the office environment - that's another story. But then again, the office computers aren't controlling billions of $$ worth of spacecraft...

Besides - I didn't think there was any such thing as a "windows professional"...
__________________
Q - What is Bambi?

A - Viable Target
nkluksda is online now   Reply With Quote
 
Old 11-08-2009, 09:39 AM   #7 (permalink)
Gunco Member
 
sct1886's Avatar
 
Join Date: Jun 2004
Posts: 113
iTrader: 0 / 0%
Default

I had an earlier version. Ran spyterminator and spybot several times and got rid of it. (Both Freeware) I had a window pop up from The WSJ web site for this, apparently their server was infected.
sct1886 is online now   Reply With Quote
 
Old 11-08-2009, 10:24 AM   #8 (permalink)
Gunco Member
 
frige's Avatar
 
Join Date: Jan 2005
Location: Texas
Posts: 131
iTrader: 2 / 100%
Default

Yeah that thing sucks. Go to Computerhope.com and they have a bunch of downloads to remove it. But its not easy! You have to download the antimalwarebytes program but you have to rename it cause the software knows what your doing. Spooky like AI.....
frige is offline   Reply With Quote
 
Old 11-08-2009, 10:32 AM   #9 (permalink)
TRX
Gunco Regular
 
TRX's Avatar
 
Join Date: Aug 2008
Location: Central Arkansas
Posts: 304
iTrader: 0 / 0%
Default

Quote:
Originally Posted by Runaway Shortbus View Post
When in doubt I call in a nuclear strike, aka backup your data and settings, reformat the drive, and reinstall.
That's the only way I've had success with Windows XP. I boot off a Puppy Linux CD, mount the ntfs partition, blow away /windows and /Program Files, do a recursive delete of all .EXE, .COM, and .DLL files in what's left, then reboot from the Windows install disk and reinstall.

If the machine has ".cab files" in a "restore partition", the last few times I've repaired one, I've had to blow those away, too. because those had also been infected. The lowlife scumbags are getting smarter, and few machines seem to come with install CDs nowadays...

I generally take the opportunity to gloat to the hapless Windows user that I don't even own a copy of Windows...
TRX is online now   Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT -4. The time now is 06:02 AM.
Style By: vBSkinworks

Search Engine Optimization by vBSEO 3.1.0