Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Lamebot
Sep 8, 2005

ロボ顔菌~♡

ProjektorBoy posted:

I work for a large corporation's help desk and the occasional malware infection comes up on the computers of the people who call me. I've been able to scrub these computers clean manually by just a combination of resourcefulness, a good solid knowledge of known-good processes, and having Process Explorer at hand.

Process Explorer is great because it'll let you see every DLL file that an executable loads. Even better, it somehow is able to mark suspect DLL files in the list. It took a combination of using the sword of regsvr32 /u and being able to quickly get to certain file locations. Also there were times where I'd boot up the computer to the login screen, then go delete the bad files remotely because they attach to winlogon.exe. I've been able to defeat everything that came up at me so far.

I'm aware that nastier things are out there, but I already feel pretty competent against the current wave of shitware that's out there.

indeed, process explorer owns. helped me kill some threads attached to winlogon and lsass so i could run some tools without the drat trojan cockblocking it. customers bring in scarier poo poo every day.

Adbot
ADBOT LOVES YOU

Bunny Cuddlin
Dec 12, 2004

Elected by Dogs posted:

CDRW? If it was burned along with the files (dunno if any malware does this kind of insertion) - it would still infect anyways.

so use a finalized CDR? does anyone actually use CDRWs any more?

Midelne
Jun 19, 2002

I shouldn't trust the phones. They're full of gas.
Well, curiosity is killing me. Can anyone actually give a summary of what the hell SPTH stands for / means? After having McAfee throw a fit from the first couple results on Google, it seems like I might be better off just asking if anyone already knows.

Public service: Don't click results for SPTH in Google. :f

nail
Jul 15, 2005

second part to hell

edit here's a cool (albeit old) article with probably-related details

nail fucked around with this message at 22:23 on Dec 30, 2008

coinstarpatrick
May 21, 2007

by T. Finn
Nthing superantispyware.
It seems to be a few days in front of Malwarebytes now consistently, but MWBAM is still a vital tool. Between those two you can pretty much get anything.

A few posts up where it was suggested to run a livecd... is there a way to run SuperAS or MWB off a livecd? That would be unbelievable.

coinstarpatrick
May 21, 2007

by T. Finn
Edit:It sounds stupid to me, but is it possible using wine or something?

(clicked quote instead of edit like an idiot)

Cojawfee
May 31, 2006
I think the US is dumb for not using Celsius

Duck and Cover posted:

I'm enjoying having my ads hijacked so that I can be sold vimax and other lovely products. While I solved the problem of the ads by blocking through the hosts file I'd like to eliminate the problem instead of working around it. Oh and for the hell of it, it seems to block any attempts to update anti virus malware software.

Have you looked to see if TDSServ is in the device manager? That was sending any kind of anti malware related URL to an ad site. In the device manager, show hidden devices, and under non system devices I believe. Just disable it, not uninstall it. If you have to, rename the executable installer for malware bytes or superanti or what have you, sometimes you have to rename the exe when it is installed as well.

^^^^ I believe UBCD4Win comes with Super Antispyware.

List of progams in UBCD For Windows

Midelne
Jun 19, 2002

I shouldn't trust the phones. They're full of gas.

hyperborean posted:

edit here's a cool (albeit old) article with probably-related details

That was a really good article, and I was a bit surprised to find out that a sixteen-year old kid has made enough of a name for himself since that article (assuming it's the same SPTH, which seems likely) to be the subject of a Microsoft blog.

The security side of IT is getting more interesting to me all the time.

WickedMetalHead
Mar 9, 2007
/dev/null
So reading this has made me paranoid again.

Is there any reason not to run multiple Antiviruses on one computer?

Cojawfee
May 31, 2006
I think the US is dumb for not using Celsius
Well, they will bitch at each other. It is best to have one antivirus, and a few antispywares.

Big K of Justice
Nov 27, 2005

Anyone seen my ball joints?
Luck of the draw I guess, but this morning I got hit with malware or something on my windows xp64 workstation for the first time ever [first time since 95 when I switched to windows]. I guess I was overdue at one point but I never use email on my machine or click on stupid bullshit.

I'm currently using avast! 4.8 and it usually catches things once in awhile but this morning was different.

Avast started freaking out about malware, and the next thing I know, windows firewall crashes, and IE fires up right away and starts shooting up pages and pages of banner ads.

I swear, I'd be laughing my rear end off if it wasn't happening to me. It was just so sudden and random.

I turned off my machine and left it for the evening when I could look at it but honestly I'm scratching my head here. I tried to get avast to run in safe mode, but because I run a high resolution desktop, the avast scan window opens off screen and I wind up having to switch to normal boot in order run it. I'm currently running the scanner now and it did find a few things [Its still scanning I can't bring up a verbose list] but most seen to be gen.exe or some form of trojan that's sitting on a old backup drive with files dating back years.

I created a new profile [one with admin and one plain user account] and noticed it just happened again.

I'm 83% on my current scan, and just a minute ago I get IE trying to open, but its asking me if I want to make it the default explorer first [since it was never run on this profile], I killed it in the task manger.

Is avast crap? Or is it because I'm running the 64bit version and won't pick up things running under 32bit?

And is there a way for me just to ensure IE will never ever run?

I'm trying to figure out if I'm getting hit by something coming in over the network or something thats running as a service.

/edit

Avast just blocked something online called antivirusscanneronline but it closed before I could hit edit.. it's still scanning and I can't bring up a log file yet until it's done scanning .. sigh.

I'm checking my hosts file and system32 folder to see if theres anything afoot there.

/edit #2 downloading process explorer

Last time I had to troubleshoot viruses was boot sector amiga poo poo back in the old days. Oh Saddam virus, so funny and topical back in 1991.

Big K of Justice fucked around with this message at 07:16 on Jan 1, 2009

Cojawfee
May 31, 2006
I think the US is dumb for not using Celsius
If Avast doesn't fix it, then try burning the UBCD4Win I linked above. What whatever you want (Asquared and Superanti seem to work the best of the programs included). Then try malware bytes in safe mode.

FloorMatt
Jul 24, 2007

Do a scan in safe mode with Avira and Superantispyware. That should get rid of everything.

Jo
Jan 24, 2005

:allears:
Soiled Meat

coinstarpatrick posted:

Nthing superantispyware.
It seems to be a few days in front of Malwarebytes now consistently, but MWBAM is still a vital tool. Between those two you can pretty much get anything.

A few posts up where it was suggested to run a livecd... is there a way to run SuperAS or MWB off a livecd? That would be unbelievable.

I ran MWB and SuperAS off of a Backtrack 3 liveCD in Wine. It found (and removed) a rootkit on an infected Windows XP machine.

PROTIP: Install MWB and SuperAntispyware, then run winecfg and change your C: drive to /mnt/hda1 (or whatever your C: drive is. /mnt/sda1, whatever.)

darkforce898
Sep 11, 2007

BigKOfJustice posted:



Install SUPERantispyware in normal mode, boot into safe mode and run it

Big K of Justice
Nov 27, 2005

Anyone seen my ball joints?
I'll do that tonight, I"m guessing its sitting somewhere in 32bit space since it seems to want to run IE 32.

Avast scanner picked up 3 or 4 items, but on very old files. It couldn't scan a bunch of jpegs but that was it.

Hillridge
Aug 3, 2004

WWheeeeeee!
I think this may be a side effect of all the cleaning I did to get rid of my infection. Some text comes up like this in firefox. How do I fix this?

Edit: It's not a font or encoding issue either.

Only registered members can see post attachments!

Hillridge fucked around with this message at 20:00 on Jan 1, 2009

darkforce898
Sep 11, 2007

Hillridge posted:

I think this may be a side effect of all the cleaning I did to get rid of my infection. Some text comes up like this in firefox. How do I fix this?

Edit: It's not a font or encoding issue either.

Your system language might have been changed... try and see what it is set to

Jo
Jan 24, 2005

:allears:
Soiled Meat

Hillridge posted:

I think this may be a side effect of all the cleaning I did to get rid of my infection. Some text comes up like this in firefox. How do I fix this?

Edit: It's not a font or encoding issue either.

It would appear several of your vowels have become surprised. Give them time to calm down.

Hillridge
Aug 3, 2004

WWheeeeeee!

darkforce898 posted:

Your system language might have been changed... try and see what it is set to

It looks fine, though Asian languages are unchecked, and I'm almost positive I've installed them before. I don't think it's systemic because IE displays the text fine on that page.

Jo posted:

It would appear several of your vowels have become surprised. Give them time to calm down.

I put on some smooth jazz and lit some candles...no help.

Big K of Justice
Nov 27, 2005

Anyone seen my ball joints?
Thinks for the super anti spyware recommendation. I found the malware that was causing IE to go bonkers at random:

Adware-Prun via PRUNNET.EXE in my system folders..

It's the only thing that was picked up and the time stamp on the files seem to be around 2-3 days ago, right when my firewall crashed. I'm still trying to figure out how I got it, my guess an MSN/messanger exploit or something else.

Adware really really doesn't dig it when you change the home url default for IE, which I think how it works.

SuperAntiSpyware seems to play nice with Avast 64, so I'm ordering the commercial versions for the extra features.

Kaboobi
Jan 5, 2005

SHAKE IT BABY!
SALT THAT LADY!

gently caress you Rapid Antivirus 2.7. Looks like combofix took care of it pretty quick though.

Kaboobi fucked around with this message at 17:13 on Jan 2, 2009

CISADMIN PRIVILEGE
Aug 15, 2004

optimized multichannel
campaigns to drive
demand and increase
brand engagement
across web, mobile,
and social touchpoints,
bitch!
:yaycloud::smithcloud:
I haven't done the clean up thing for anyone in a long time, but a friend needed help and offered to do some of my housework. Whatever was in there was crashing explorer.exe within 60 seconds of launching it and his DVD drive was screwed so I couldn't reinstall windows. For some reason safe mode just hung every time I tried it. I managed to launch the malwarebytes installer through task manager off of a thumb drive which killed enough stuff to make the system usable. Followed that with superantispyware which found a bunch more poo poo and they have a usable computer and I have a sparkling kitchen. They are pretty nice tools.

Otacon
Aug 13, 2002


Most of the time now, the hardest part about killing Spyware is getting the stupid computer to boot into Windows. Our shop sees a lot of BSODs and black screens on boot, and Safe Mode isn't even a sure fire way past that trash. But once you're on the desktop, those viruses and spyware will be gone soon.

abominable fricke
Nov 11, 2003

What does Pottsylvania have more than any other country? Mean! We have more mean than any other country in Europe! We must export mean.

Otacon posted:

Most of the time now, the hardest part about killing Spyware is getting the stupid computer to boot into Windows. Our shop sees a lot of BSODs and black screens on boot, and Safe Mode isn't even a sure fire way past that trash. But once you're on the desktop, those viruses and spyware will be gone soon.

One thing to try is to use an ERD boot CD, and use the system restore function. It will do the same system restore the same way that windows does. The only thing that you need to do beforehand is to backup the %windir%\system32\config folder because sometimes (probably a third of the time) it forgets to restore the registry.

ab0z
Jun 28, 2008

by angerbotSD

Cojawfee posted:

Well, they will bitch at each other. It is best to have one antivirus, and a few antispywares.

Actually, it's best not to download stupid poo poo.
I could run NO antivirus software at all, because I don't download crap from limewarez or whatever.

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

ab0z posted:

Actually, it's best not to download stupid poo poo.
I could run NO antivirus software at all, because I don't download crap from limewarez or whatever.

You're precious, really.

I'd like you to think back to 2003 for why this is amusing.

corgski
Feb 6, 2007

Silly goose, you're here forever.

ab0z posted:

Actually, it's best not to download stupid poo poo.
I could run NO antivirus software at all, because I don't download crap from limewarez or whatever.

My old buddy W32/Blaster would like to have a word with you. Or rather, a 30 second shutdown timer.

Cojawfee
May 31, 2006
I think the US is dumb for not using Celsius

ab0z posted:

Actually, it's best not to download stupid poo poo.
I could run NO antivirus software at all, because I don't download crap from limewarez or whatever.

I was waiting for this to show up. I laugh every time. I also laugh every time someone says it at work.

ab0z
Jun 28, 2008

by angerbotSD
I didn't say that I DON'T run antivirus software, or that you should recommend people to do so.
I'm just saying that with the help of common sense you can avoid most problems.

Cojawfee
May 31, 2006
I think the US is dumb for not using Celsius
*Backpedal* *backpedal*

ab0z
Jun 28, 2008

by angerbotSD

Cojawfee posted:

*Backpedal* *backpedal*

Fine. I'll uninstall AVG and run for 1 year without it or any other antivirus software.

Wubble
Dec 29, 2008
Actually thanks to this thread, I downloaded SUPERantispyware, and ran a scan. It ended up finding a Trojan, without any symptoms. Also while running Avast and Spybot. So you never know.

Big K of Justice
Nov 27, 2005

Anyone seen my ball joints?

ab0z posted:

I didn't say that I DON'T run antivirus software, or that you should recommend people to do so.
I'm just saying that with the help of common sense you can avoid most problems.

I never had a virus since 1991 on an Amiga.

Until last week when, out of the blue, via no prompt or action on my own, avast flips out with 2-3 error messsages, crashes, followed by the firewall crashing and IE launching and firing up all sorts of ads.

Common sense can only help so much, what happens if some joker uses a jpeg exploit and hotlinks it to a thread?

Hillridge
Aug 3, 2004

WWheeeeeee!

BigKOfJustice posted:

I never had a virus since 1991 on an Amiga.

Until last week when, out of the blue, via no prompt or action on my own, avast flips out with 2-3 error messsages, crashes, followed by the firewall crashing and IE launching and firing up all sorts of ads.

Common sense can only help so much, what happens if some joker uses a jpeg exploit and hotlinks it to a thread?

Same here, I got infected through a Java exploit before they patched it. The only way to be sure you never get anything is to unplug your network cable/kill wireless.

Elected by Dogs
Apr 20, 2006

Hillridge posted:

Same here, I got infected through a Java exploit before they patched it. The only way to be sure you never get anything is to unplug your network cable/kill wireless.

flash drives, cd's, any kind of interface that lets you talk to anything else through anything

The only way to be sure you never get anything is to not have a computer.

Hillridge
Aug 3, 2004

WWheeeeeee!
ugh. I just spent 45 minutes on the phone with my dad trying to talk him through some fixes. combofix.exe won't even run in safemode. I sent him an email with some other things to try like SDfix, so we'll see if he gets anywhere.

slidebite
Nov 6, 2005

Good egg
:colbert:

I didn't want to start a thread on this, but I thought this would be a good place to ask.

My wife just sent my mother-in-law a bunch of jpgs attached to an email. They were not zipped or anything, just 12 or so .jpgs @ 200KB each or so.

My wife uses Yahoo email, as does my in-law.

As you guys probably know Yahoo does a virus scan when you upload/download attachments. They came out clean when uploaded... which isn't a big surprise as they were just resized/uploaded right from our camera.

So, here is where it gets interesting. When my mother-in-law got the email, the individual files seem fine (jpgs) to download but if she tried to download them ALL (a yahoo option which zips them together), her free Anti-Vir (the one with the umbrella) detects a virus in the zip file, a feebs.gen

I ran a deep scan on my PC (the one she used for the email) and I didn't find anything. Yahoo didn't find anything when the photos were uploaded. I logged into her email acct and tried to download them all and I found no problem either. I downloaded them combined (yahoo made zip) and the Yahoo scan didn't find anything, nor did my PC. I forwarded them to my gmail acct and nothing was found.

This is making me think the feebs is on her local PC but her antivir can't seem to find it automatically unless the .zip is being "created" on her PC. Any ideas on what to do? She's a distance away and not very computer saavy.

I can upload the .zip

nail
Jul 15, 2005

BigKOfJustice posted:

I never had a virus since 1991 on an Amiga.

Until last week when, out of the blue, via no prompt or action on my own, avast flips out with 2-3 error messsages, crashes, followed by the firewall crashing and IE launching and firing up all sorts of ads.
Well in that case you would have known there was a problem without antivirus software; and since your antivirus software crashed instead of fixing the problem, it's obviously pointless anyway.

No, I am not being serious.

Adbot
ADBOT LOVES YOU

Otacon
Aug 13, 2002


Oh boy, interesting day at the office.

Sony Vaio laptop, stuck in a bootloop. 0xB4, which is a video init error. Instantly restarts. Can't get into safemode, same problem. Can't get into VGA mode, same problem. Of course the owner doesn't have any system restore points, nor does she have the Vaio recovery CDs. She refuses to let me back up her computer, because she is cheap, and concerned that our company will "store copies" of her data.

I tried doing an XP Home repair install, and of course, that doesn't work either. Same problem, 0xB4.

Finally, I tried mashing F# keys at boot up, and found one (either F9, F10, or F11, one of the three) that enters into the Vaio Recovery Mode.

The only option that I'm allowed to select is to do a factory reset, which would wipe the data.

I have no other options at this point, other than spending 45 minutes on the phone with her assuring her that we won't keep copies of the 500 pictures of her dog and grandkids.

INFURIATING. I can't even boot into Windows to run any scans. I'm out of ideas. Anyone have something for me? LiveCDs work, I tried ERD Commander 2007, but can't make heads or tails of the 200 drivers, ~75% of them which are set to Manual or Disabled.

Please, someone must have some advice on replacing the erroring video driver with a Vaio approved one. The installer won't run on any PC other than the Vaio it's supposed to be used on, and it won't run in ERD.

The chipset is Intel Alviso-Gi915G, video is Mobile Intel(R) 915GM/GMS, 910GML Express, and the model is VGN-FS640-W. Anyone? Bueller? Please?

------------

The other case was a Toshiba laptop that freezes upon the insertion of any USB plug. All of the plugs freeze the system. Flashdrives, Printers, anything USB will freeze it. This sounds like hardware to me, but she claims it just started happening a few weeks ago. Any ideas on this one? I've never experienced these problems before. Please help.

Otacon fucked around with this message at 22:48 on Jan 3, 2009

  • Locked thread