![]() |
![]() OCAU News - Wiki - QuickLinks - Pix - Sponsors |
|
|||||||
| Notices |
|
Sign up for a free OCAU account and this ad will go away! Search our forums with Google: |
![]() |
|
|
Thread Tools |
|
|
#1 |
|
Member
Join Date: Feb 2008
Location: Western Vic
Posts: 5,587
|
Picked up an annoying little bugger of spyware - it highlights some words and links them off to all sorts of stuff. Malwarebytes doesnt see it nor does Nortons.
Ideas?
__________________
[Logitech 'G' Owners Club Member #1] OCAU Fishing Club Member #43 i5 2500K stock, 256GB SSD, 16GB 1600 DDR3, 2TB WD Black, 7950OC People I wont trade with: treeplant & OJR |
|
|
|
| Join OCAU to remove this ad! |
|
|
#2 |
|
Member
Join Date: Jun 2003
Posts: 10,196
|
|
|
|
|
|
|
#3 |
|
Member
Join Date: Apr 2002
Location: brisbane
Posts: 27,307
|
try resetting your browser and clean everything out with CCleaner.
__________________
this is who we are. |
|
|
|
|
|
#4 | |
|
Member
Join Date: Jun 2003
Posts: 10,196
|
or you could just randomly delete system files and rebuild registry entries with no clue as to what they are
![]() run crapcleaneriscrap in manual mode some time and actually have a look at what it does... Quote:
![]() norton/adobe/avg are targeted by virus writers because they are so popular.. i have NEVER seen a pc come into my shop with norton that did not have infections..and norton always says all is good with big green ticks and dots.. ![]() they admitted a few years ago it was broken and they tried to fix it and have failed. besides the fact they charge a fortune for useless sw... if you want to spend money get Kaspersky. if you dont, get MS Security Essentials and run a known trusted free anti spyware prog like superanti or malwarebytes.. if super anti cant remove the problem then its format c: time.. even if it can its usually best... its kinda like termites...removing the problem does not repair the damage it has already done.
|
|
|
|
|
|
|
#5 |
|
(Banned or Deleted)
Join Date: Apr 2012
Posts: 445
|
Backup personal docs and reinstall from scratch is what I'd being doing.
|
|
|
|
|
|
#6 | |
|
Member
Join Date: Apr 2002
Location: brisbane
Posts: 27,307
|
Quote:
__________________
this is who we are. |
|
|
|
|
|
|
#7 |
|
Member
Join Date: Feb 2008
Location: Western Vic
Posts: 5,587
|
Everything links to easyonline or similar - wants me to get an iphone lol.
__________________
[Logitech 'G' Owners Club Member #1] OCAU Fishing Club Member #43 i5 2500K stock, 256GB SSD, 16GB 1600 DDR3, 2TB WD Black, 7950OC People I wont trade with: treeplant & OJR |
|
|
|
|
|
#8 | |
|
Member
Join Date: Jun 2003
Posts: 10,196
|
your welcome
errr yeah u did.. Quote:
u suggested op manually clean his browser then run cc....what else would there be for it to do but edit the reg? ![]() im just sick of ppl recommending such a well known crap, noob program, esp here on ocow.. wp maybe ![]() if you have a spyware infection, which op does..running CC will have no beneficial effect what so ever...in fact it will probably make things a LOT worse as it has NFI what it is doing... nor will clearing ur net temp files most likely... if a decent anti spyware/av program cant remove it(rescanning after reboot to confirm) then nuke it. |
|
|
|
|
|
|
#9 |
|
(Banned or Deleted)
Join Date: Apr 2012
Posts: 445
|
I agree with everything you said except for this. I'd be scanning from a boot disk or some other "offline" method. Probably easier to reinstall and make a disk image so next time an infection occurs the OP can just restore from the image (which is, generally, a lot quicker than a full reinstall)
|
|
|
|
|
|
#10 | |
|
Member
Join Date: Jun 2003
Posts: 10,196
|
Quote:
but like i said removing the infection is only half the problem if its broken IE ur better off reinstalling and i disagree with using an image..sure it may be a few mins quicker but they can have their own problems...mbr repair for one always best to do a fresh clean install imho
|
|
|
|
|
|
|
#11 | |
|
(Banned or Deleted)
Join Date: Apr 2012
Posts: 445
|
Quote:
|
|
|
|
|
|
|
#12 |
|
Member
Join Date: Feb 2002
Location: Geraldton WA
Posts: 105
|
Hitman pro has been working well on customers machines lately and then combofix if needed , run ccleaner first to clean out temp files etc
Hitman pro - http://www.surfright.nl/en combofix - http://www.bleepingcomputer.com/download/combofix/
__________________
I5 2500k,16Gb,ASUS 7870 2 Gb ASUS N61 520M,8GB,ATI5730 |
|
|
|
|
|
#13 | |
|
Member
Join Date: Aug 2007
Posts: 76
|
Quote:
We have had 3 Trojans in the last month or 2. Same one just modified a little. Malwarebytes and Symantec Endpoint protection picked up the second file but not the first one that was creating it. Did a scan with Hitman Pro and found the first one. Sent file to both Malwarebytes and Symantec. Malwarebytes added it to the next definition but Symantec didn't add it for about 2 weeks... Found out later on in the week it was a ex-employee that was adding it to the system... All fix now. on topic. +1 Hitman Pro and submit it to Malwarebytes if that don't find it try Kaspersky Rescue Disk 10 http://support.kaspersky.com/faq/?qid=208282173 Last edited by Holland_BFG; 22nd June 2012 at 2:44 PM. |
|
|
|
|
|
|
#14 |
|
Member
Join Date: Feb 2008
Location: Western Vic
Posts: 5,587
|
HitmanPro is churning away and theres all sorts of files being identified.
__________________
[Logitech 'G' Owners Club Member #1] OCAU Fishing Club Member #43 i5 2500K stock, 256GB SSD, 16GB 1600 DDR3, 2TB WD Black, 7950OC People I wont trade with: treeplant & OJR |
|
|
|
|
|
#15 |
|
Member
Join Date: Apr 2002
Location: brisbane
Posts: 27,307
|
a lot of this stuff hides in temp files and running CCleaner to clear out temp files is a good start.
It also means any future scans will run quicker. anyway sounds like a browser hijack or rootkit. be sure to run TDSSKiller as well. I've heard quite a few people recommending Hitman Pro but I'm yet to see it do that much for me, Don't forget to check msconfig for any weird startup items and services as well.
__________________
this is who we are. |
|
|
|
![]() |
| Bookmarks |
|
Sign up for a free OCAU account and this ad will go away! |
| Thread Tools | |
|
|