Bay 12 Games Forum

Please login or register.

Login with username, password and session length
Advanced search  
Pages: [1] 2

Author Topic: Strange Malware  (Read 3102 times)

Ioric Kittencuddler

  • Bay Watcher
  • Multiclass Bard/Kitten trainer
    • View Profile
Strange Malware
« on: February 11, 2009, 12:26:31 am »

I've gotten this strange malware on my computer that keeps trying to get me to download a fake malware cleaning tool.

It's made a weird little red icon with a white X in my taskbar's running processes that keeps saying, "Your computer is infected!  It is recommended to start spyware cleaner tool."

And now it's replaced my desktop background with an image saying "Warning!" in flashing red and yellow, then "Dangerous Spyware" in white.  It's actually hard to read the warning since one of the things the malware program did was make all the text under my icons have a solid background.  ::)

It says something about being careful that you valueble information doesn't fall into "the third hands"...  ???
Logged
Come see the MOST interesting Twitter account on the internet!  Mine!

Don't worry!  Be happy!  It's the law!

Cheeetar

  • Bay Watcher
  • Spaceghost Perpetrator
    • View Profile
Re: Strange Malware
« Reply #1 on: February 11, 2009, 12:30:25 am »

Does it do anything else? It sounds like a joke virus.
Logged
I've played some mafia.

Most of the time when someone is described as politically correct they are simply correct.

inaluct

  • Bay Watcher
    • View Profile
Re: Strange Malware
« Reply #2 on: February 11, 2009, 12:33:08 am »

Shit, you should be worried. The Third Hands are a secretive group of hacker terrorists on steroids based in Ukraine. They were the ones responsible for that 2002 Moscow theater hostage crisis. They probably know where you live by now.

If I were you, I'd be very worried.
Logged

Ioric Kittencuddler

  • Bay Watcher
  • Multiclass Bard/Kitten trainer
    • View Profile
Re: Strange Malware
« Reply #3 on: February 11, 2009, 12:36:13 am »

I cleaned it with a real malware cleaning program. :P

Now I just have to worry about the little weird virus I got that disables on access scan for McAfee at start up.  Course for now all I have to do is enable it again, but it's still annoying.
« Last Edit: February 11, 2009, 12:39:45 am by Ioric Kittencuddler »
Logged
Come see the MOST interesting Twitter account on the internet!  Mine!

Don't worry!  Be happy!  It's the law!

Flashzom

  • Bay Watcher
    • View Profile
Re: Strange Malware
« Reply #4 on: February 11, 2009, 12:42:32 am »

Usually the end process tab and Avast will take care of anything, it's like a one two punch.
Logged
And as the fires licked and roared over his skin, Urist realized that the hustle and bustle of being on fire really tired him out.

Ioric Kittencuddler

  • Bay Watcher
  • Multiclass Bard/Kitten trainer
    • View Profile
Re: Strange Malware
« Reply #5 on: February 11, 2009, 12:44:15 am »

Only if you can find the process.
Logged
Come see the MOST interesting Twitter account on the internet!  Mine!

Don't worry!  Be happy!  It's the law!

mainiac

  • Bay Watcher
  • Na vazeal kwah-kai
    • View Profile
Re: Strange Malware
« Reply #6 on: February 11, 2009, 06:19:50 am »

Kill them all.  Heaven will sort the sinners and the righteous.
Logged
Ancient Babylonian god of RAEG
--------------
[CAN_INTERNET]
[PREFSTRING:google]
"Don't tell me what you value. Show me your budget and I will tell you what you value"
« Last Edit: February 10, 1988, 03:27:23 pm by UR MOM »
mainiac is always a little sarcastic, at least.

Yanlin

  • Bay Watcher
  • Legendary comedian.
    • View Profile
Re: Strange Malware
« Reply #7 on: February 11, 2009, 08:06:58 am »

Here's how to make sure you don't nix anything you don't want.

Make sure the computer is not infected with ANYTHING. Scan with EVERYTHING POSSIBLE.

Start it in safe mod without networking.

Ctrl+Alt+Del

Processes

Write all of them down. There shouldn't be too many. Most of them should have the user name of SYSTEM. Some should have LOCAL SERVICE or NETWORK SERVICE. But those might not appear in safe mode. Basically shut down EVERYTHING that's not one of the ones you noted and doesn't have one of the above user name origins. You should be OK then.
Logged
WE NEED A SLOGAN!

Gantolandon

  • Bay Watcher
  • He has a fertile imagination.
    • View Profile
Re: Strange Malware
« Reply #8 on: February 11, 2009, 08:26:44 am »

ComboFix.
Logged

Duke 2.0

  • Bay Watcher
  • [CONQUISTADOR:BIRD]
    • View Profile
Re: Strange Malware
« Reply #9 on: February 11, 2009, 09:07:44 am »


 I think my old computer had this. Naturally Norton didn't give a crap and let it continue on it's merry way. Thus I had to invest in some... specialized tools. Like unlocker to nuke the files this virus is based around. Then closing all processes that it uses. Then going deep into dangerous territory to delete any and all references to this damn thing. Then I cleared all caches and such to make sure it was not hiding in some temporary storage somewhere.

 A week later, I claimed victory over it. It might still be there, but at least I chopped off all it's limbs and senses.
Logged
Buck up friendo, we're all on the level here.
I would bet money Andrew has edited things retroactively, except I can't prove anything because it was edited retroactively.
MIERDO MILLAS DE VIBORAS FURIOSAS PARA ESTRANGULARTE MUERTO

qwertyuiopas

  • Bay Watcher
  • Photoshop is for elves who cannot use MSPaint.
    • View Profile
    • uristqwerty.ca, my current (barren) site.
Re: Strange Malware
« Reply #10 on: February 11, 2009, 10:01:02 am »

Viruses can hide themselves from windows, making it think they don't exist to the point that they aren't even scanned by antivirus programs.

The solution is to boot to linux(if installed, otherwise boot it from the CD because linux can do that) and look again. Any file visible from linux but not from windows could be an issue.
Logged
Eh?
Eh!

Sergius

  • Bay Watcher
    • View Profile
Re: Strange Malware
« Reply #11 on: February 11, 2009, 10:17:55 am »

You can't shut down a process if it's a virus installed as a rootkit. Those are damn hard to remove (not impossible, of course).

Also, a lot of these virus don't have one but two processes, each one making sure the other one is loading and even copying itself again the nanosecond you delete one of them.

I've cleaned some of these with specialized removal tools, or at least a specific set of instructions. I've never had any luck using my own antivirus or a generic ad removal tool.
Logged

woose1

  • Bay Watcher
  • Yay for bandwagons!
    • View Profile
Re: Strange Malware
« Reply #12 on: February 11, 2009, 11:07:18 am »

A week later, I claimed victory over it. It might still be there, but at least I chopped off all it's limbs and senses.
Thats what I did with Vundo.
Logged

Bromor Neckbeard

  • Bay Watcher
    • View Profile
Re: Strange Malware
« Reply #13 on: February 11, 2009, 02:35:04 pm »

Duke 2.0 goes into the hive to confront the beast in its lair.  My pulse rifle's as rusty as my registry editing skills, so I nuke from orbit.
Logged

Tormy

  • Bay Watcher
  • I shall not pass?
    • View Profile
Re: Strange Malware
« Reply #14 on: February 11, 2009, 02:39:44 pm »

I've gotten this strange malware on my computer that keeps trying to get me to download a fake malware cleaning tool.

It's made a weird little red icon with a white X in my taskbar's running processes that keeps saying, "Your computer is infected!  It is recommended to start spyware cleaner tool."

And now it's replaced my desktop background with an image saying "Warning!" in flashing red and yellow, then "Dangerous Spyware" in white.  It's actually hard to read the warning since one of the things the malware program did was make all the text under my icons have a solid background.  ::)

It says something about being careful that you valueble information doesn't fall into "the third hands"...  ???

I've had this malware also in the past. Just download some spyware/malware killer, that will remove it from your computer. Basically this won't damage your OS itself, it's just plain annoying.  >:(
Logged
Pages: [1] 2