Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
President Ark
May 16, 2010

:iiam:
Getting a hell of a nasty bug on a desktop I'm trying to fix - it's running such that trying to run virtually any program other than web browsers or do anything that would require admin access is blocked by group policy. If this were a corporate computer I'd flatten and reimage it, but it's a residential computer and doing that is the absolute last resort. Kaspersky rescue disk detected a bunch of poo poo but hasn't fixed the GPO issue and running the variations of rkill/combofix/tdsskiller that don't use .exe extensions doesn't work either.

Any ideas?

Adbot
ADBOT LOVES YOU

President Ark
May 16, 2010

:iiam:
Oh cool, I did more google and apparently this is a symptom of Alureon. :suicide:

President Ark
May 16, 2010

:iiam:
Does anyone know of any tools to deal with Conduit Search-protect? I'm getting tired of having to run scans to remove the actual program then digging through internet options for all their browsers digging out the settings changes that'd reinfect the computer.

e: That is to say, I can remove it myself, it's just time consuming because of how much it does to dig into your browser settings which standard AV programs tend to not touch.

President Ark
May 16, 2010

:iiam:

Ynglaur posted:

I'm unsure where else in SA to ask, but this thread seems like it has people who know what they're doing?

What is the Goon consensus on the best antivirus for a local machine? I've been using MSE but anytime my laptop is near idle it spins everything up, which spins the fans on, which is loud, annoying, etc. I can get McAfee for free through my ISP (Cox): is it as terrible as YouTube parody videos suggest? I had a horrible experience with BitDefender a couple years ago. After uninstalling it, it leaves a pre-boot checker, which fails because it's not installed. Basically, I had to re-image two laptops because of this.

Thoughts, comments, and you-don't-really-know-what-you're-talking-about replies welcome.

Probably Avast! if you don't like MSE.

President Ark
May 16, 2010

:iiam:
ADWcleaner is rapidly becoming my go-to choice for a first run on infected machines, especially ones that do stuff like proxy/DNS redirection. It's a self-contained .exe so it can run directly off of a flash drive, it's fast, it's efficient, and it doesn't just remove the garbage but it also cleans up all the little hooks they love putting in so you don't have to do manual cleanup. I love it.

Probably the only downside it has is that as soon as you confirm that it can clean off all the junk it found, it force-restarts immediately after it finishes.

President Ark
May 16, 2010

:iiam:
I reformatted a computer (customer's request) and when I reinstalled MSE it started going nuts telling me it's detecting Alureon on the system. I googled and apparently this poo poo creates hidden sectors to reinstall itself off of. :psyboom:

Adbot
ADBOT LOVES YOU

President Ark
May 16, 2010

:iiam:
Goddamn, I've been fighting with a computer that has that all week. I'll give roguekiller a shot, and if that doesn't work I might have to flatten the goddamn thing.

e: Roguekiller looks like it did it, thank christ.

President Ark fucked around with this message at 17:34 on Nov 6, 2014

  • Locked thread