Overclockers Australia Forums
OCAU News - Wiki - QuickLinks - Pix - Sponsors  

Go Back   Overclockers Australia Forums > General Topics > Newbie Lounge

Notices


Sign up for a free OCAU account and this ad will go away!
Search our forums with Google:
Reply
 
Thread Tools
Old 22nd June 2012, 12:41 PM   #1
Akh-Horus Thread Starter
Member
 
Join Date: Feb 2008
Location: Western Vic
Posts: 5,587
Default Annoying spyware

Picked up an annoying little bugger of spyware - it highlights some words and links them off to all sorts of stuff. Malwarebytes doesnt see it nor does Nortons.

Ideas?
__________________
[Logitech 'G' Owners Club Member #1]
OCAU Fishing Club Member #43
i5 2500K stock, 256GB SSD, 16GB 1600 DDR3, 2TB WD Black, 7950OC
People I wont trade with: treeplant & OJR
Akh-Horus is offline   Reply With Quote

Join OCAU to remove this ad!
Old 22nd June 2012, 12:44 PM   #2
Creekin
Member
 
Creekin's Avatar
 
Join Date: Jun 2003
Posts: 10,196
Default

Quote:
Originally Posted by Akh-Horus View Post
nor does Nortons.


super anti spyware
and Kaspersky
Creekin is offline   Reply With Quote
Old 22nd June 2012, 12:47 PM   #3
power
Member
 
power's Avatar
 
Join Date: Apr 2002
Location: brisbane
Posts: 27,307
Default

Quote:
Originally Posted by Akh-Horus View Post
Picked up an annoying little bugger of spyware - it highlights some words and links them off to all sorts of stuff. Malwarebytes doesnt see it nor does Nortons.

Ideas?
try resetting your browser and clean everything out with CCleaner.
__________________
this is who we are.
power is online now   Reply With Quote
Old 22nd June 2012, 12:57 PM   #4
Creekin
Member
 
Creekin's Avatar
 
Join Date: Jun 2003
Posts: 10,196
Default

Quote:
Originally Posted by power View Post
and clean everything out with CCleaner.
or you could just randomly delete system files and rebuild registry entries with no clue as to what they are
run crapcleaneriscrap in manual mode some time and actually have a look at what it does...
Quote:
hmm ive found a broken registry entry here for ms word...better point it at norton av...



norton/adobe/avg are targeted by virus writers because they are so popular..
i have NEVER seen a pc come into my shop with norton that did not have infections..and norton always says all is good with big green ticks and dots..
they admitted a few years ago it was broken and they tried to fix it and have failed.
besides the fact they charge a fortune for useless sw...

if you want to spend money get Kaspersky.
if you dont, get MS Security Essentials and run a known trusted free anti spyware prog like superanti or malwarebytes..
if super anti cant remove the problem then its format c: time..
even if it can its usually best...

its kinda like termites...removing the problem does not repair the damage it has already done.
Creekin is offline   Reply With Quote
Old 22nd June 2012, 12:58 PM   #5
Psychotria
(Banned or Deleted)
 
Join Date: Apr 2012
Posts: 445
Default

Backup personal docs and reinstall from scratch is what I'd being doing.
Psychotria is offline   Reply With Quote
Old 22nd June 2012, 12:59 PM   #6
power
Member
 
power's Avatar
 
Join Date: Apr 2002
Location: brisbane
Posts: 27,307
Default

Quote:
Originally Posted by Creekin View Post
or you could just randomly delete system files and rebuild registry entries with no clue as to what they are
run crapcleaneriscrap in manual mode some time and actually have a look at what it does...



norton/adobe/avg are targeted by virus writers because they are so popular..
i have NEVER seen a pc come into my shop with norton that did not have infections..and norton always says all is good with big green ticks and dots..
they admitted a few years ago it was broken and they tried to fix it and have failed.
besides the fact they charge a fortune for useless sw...

if you want to spend money get Kaspersky.
if you dont, get MS Security Essentials and run a known trusted free anti spyware prog like superanti or malwarebytes..
if super anti cant remove the problem then its format c: time..
even if it can its usually best...

its kinda like termites...removing the problem does not repair the damage it has already done.
So helpful, I didn't say use the registry cleaner....
__________________
this is who we are.
power is online now   Reply With Quote
Old 22nd June 2012, 1:03 PM   #7
Akh-Horus Thread Starter
Member
 
Join Date: Feb 2008
Location: Western Vic
Posts: 5,587
Default

Everything links to easyonline or similar - wants me to get an iphone lol.
__________________
[Logitech 'G' Owners Club Member #1]
OCAU Fishing Club Member #43
i5 2500K stock, 256GB SSD, 16GB 1600 DDR3, 2TB WD Black, 7950OC
People I wont trade with: treeplant & OJR
Akh-Horus is offline   Reply With Quote
Old 22nd June 2012, 1:08 PM   #8
Creekin
Member
 
Creekin's Avatar
 
Join Date: Jun 2003
Posts: 10,196
Default

Quote:
Originally Posted by power View Post
So helpful,
your welcome
Quote:
Originally Posted by power View Post
I didn't say use the registry cleaner....
errr yeah u did..
Quote:
Originally Posted by power View Post
try resetting your browser and clean everything out with CCleaner.
all CC does is delete temp files and edit the registry..badly!
u suggested op manually clean his browser then run cc....what else would there be for it to do but edit the reg?

im just sick of ppl recommending such a well known crap, noob program, esp here on ocow.. wp maybe
if you have a spyware infection, which op does..running CC will have no beneficial effect what so ever...in fact it will probably make things a LOT worse as it has NFI what it is doing...
nor will clearing ur net temp files most likely...

if a decent anti spyware/av program cant remove it(rescanning after reboot to confirm) then nuke it.
Creekin is offline   Reply With Quote
Old 22nd June 2012, 1:11 PM   #9
Psychotria
(Banned or Deleted)
 
Join Date: Apr 2012
Posts: 445
Default

Quote:
Originally Posted by Creekin View Post
if a decent anti spyware/av program cant remove it(rescanning after reboot to confirm) then nuke it.
I agree with everything you said except for this. I'd be scanning from a boot disk or some other "offline" method. Probably easier to reinstall and make a disk image so next time an infection occurs the OP can just restore from the image (which is, generally, a lot quicker than a full reinstall)
Psychotria is offline   Reply With Quote
Old 22nd June 2012, 1:15 PM   #10
Creekin
Member
 
Creekin's Avatar
 
Join Date: Jun 2003
Posts: 10,196
Default

Quote:
Originally Posted by Psychotria View Post
I agree with everything you said except for this. I'd be scanning from a boot disk or some other "offline" method. Probably easier to reinstall and make a disk image so next time an infection occurs the OP can just restore from the image (which is, generally, a lot quicker than a full reinstall)
def do it offline on a 2nd machine...
but like i said removing the infection is only half the problem
if its broken IE ur better off reinstalling
and i disagree with using an image..sure it may be a few mins quicker
but they can have their own problems...mbr repair for one
always best to do a fresh clean install imho
Creekin is offline   Reply With Quote
Old 22nd June 2012, 1:18 PM   #11
Psychotria
(Banned or Deleted)
 
Join Date: Apr 2012
Posts: 445
Default

Quote:
Originally Posted by Creekin View Post
... and i disagree with using an image..sure it may be a few mins quicker
but they can have their own problems...mbr repair for one
Well, yeah that's true. But if you take a disk image after installing all your common software it can be heaps quicker. But it does obviously take a bit of setting up and there is the MBR issue (although the software I use does overwrite the MBR... *but* there is always a but it can get complicated if you have multiple OSs and/or drives), so yeah... maybe disk imaging is not quicker for everyone
Psychotria is offline   Reply With Quote
Old 22nd June 2012, 1:21 PM   #12
imajican
Member
 
imajican's Avatar
 
Join Date: Feb 2002
Location: Geraldton WA
Posts: 105
Default

Hitman pro has been working well on customers machines lately and then combofix if needed , run ccleaner first to clean out temp files etc

Hitman pro - http://www.surfright.nl/en

combofix - http://www.bleepingcomputer.com/download/combofix/
__________________
I5 2500k,16Gb,ASUS 7870 2 Gb

ASUS N61 520M,8GB,ATI5730
imajican is offline   Reply With Quote
Old 22nd June 2012, 1:33 PM   #13
Holland_BFG
Member
 
Join Date: Aug 2007
Posts: 76
Default

Quote:
Originally Posted by imajican View Post
Hitman pro has been working well on customers machines lately and then combofix if needed , run ccleaner first to clean out temp files etc

Hitman pro - http://www.surfright.nl/en

combofix - http://www.bleepingcomputer.com/download/combofix/
Yeah I've been using Hitman pro as well at work.

We have had 3 Trojans in the last month or 2. Same one just modified a little.

Malwarebytes and Symantec Endpoint protection picked up the second file but not the first one that was creating it. Did a scan with Hitman Pro and found the first one. Sent file to both Malwarebytes and Symantec. Malwarebytes added it to the next definition but Symantec didn't add it for about 2 weeks...

Found out later on in the week it was a ex-employee that was adding it to the system... All fix now.

on topic.

+1 Hitman Pro and submit it to Malwarebytes

if that don't find it try Kaspersky Rescue Disk 10 http://support.kaspersky.com/faq/?qid=208282173

Last edited by Holland_BFG; 22nd June 2012 at 2:44 PM.
Holland_BFG is offline   Reply With Quote
Old 22nd June 2012, 2:46 PM   #14
Akh-Horus Thread Starter
Member
 
Join Date: Feb 2008
Location: Western Vic
Posts: 5,587
Default

HitmanPro is churning away and theres all sorts of files being identified.
__________________
[Logitech 'G' Owners Club Member #1]
OCAU Fishing Club Member #43
i5 2500K stock, 256GB SSD, 16GB 1600 DDR3, 2TB WD Black, 7950OC
People I wont trade with: treeplant & OJR
Akh-Horus is offline   Reply With Quote
Old 22nd June 2012, 2:58 PM   #15
power
Member
 
power's Avatar
 
Join Date: Apr 2002
Location: brisbane
Posts: 27,307
Default

Quote:
Originally Posted by Creekin View Post
blah blah blah
a lot of this stuff hides in temp files and running CCleaner to clear out temp files is a good start.

It also means any future scans will run quicker.

anyway sounds like a browser hijack or rootkit.

be sure to run TDSSKiller as well.

I've heard quite a few people recommending Hitman Pro but I'm yet to see it do that much for me,

Don't forget to check msconfig for any weird startup items and services as well.
__________________
this is who we are.
power is online now   Reply With Quote
Reply

Bookmarks

Sign up for a free OCAU account and this ad will go away!

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +10. The time now is 3:30 AM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd. -
OCAU is not responsible for the content of individual messages posted by others.
Other content copyright Overclockers Australia.
OCAU is hosted by Internode!