Spyware! Spyware everywhere!
Moderator: Thanas
Spyware! Spyware everywhere!
I got AVG, malwarebytes and spybot installed on my laptop, all fully updated and semi-frequently scanning. But lately it has been slower than usual, using way too much ram and cpu on idle, spybot always finds a dozen various malware even in nearly consecutive scans, and avg occasionally shows a popup about detecting a tracking cookie or another that it won't move to the vault, leaving me to delete them manually. But they always reappear, so whatever this thing is, it's gotten its roots deep within my system. How can I root it out, preferably avoiding a full format of the hd?
Dunno if it's relevant, but I've never been able to install the SP2 (Win Vista) on the machine. It always blurts out an unknown error, and has to revert the changes a little before finishing.
Dunno if it's relevant, but I've never been able to install the SP2 (Win Vista) on the machine. It always blurts out an unknown error, and has to revert the changes a little before finishing.
Re: Spyware! Spyware everywhere!
The first and easiest step is to redo the scans with each program while running in Safe Mode. Basically what this does is start up Windows without starting up most of the programs that would otherwise run automatically (which probably includes the bad programs), which will make your attempts to root out the malware that much more likely to succeed.
Re: Spyware! Spyware everywhere!
Another thing would be to ditch AVG for something better. MSE, Avira and Avast are all superior alternatives.
Warwolf Urban Combat Specialist
Why is it so goddamned hard to get little assholes like you to admit it when you fuck up? Is it pride? What gives you the right to have any pride?
–Darth Wong to vivftp
GOP message? Why don't they just come out of the closet: FASCISTS R' US –Patrick Degan
The GOP has a problem with anyone coming out of the closet. –18-till-I-die
Why is it so goddamned hard to get little assholes like you to admit it when you fuck up? Is it pride? What gives you the right to have any pride?
–Darth Wong to vivftp
GOP message? Why don't they just come out of the closet: FASCISTS R' US –Patrick Degan
The GOP has a problem with anyone coming out of the closet. –18-till-I-die
- White Haven
- Sith Acolyte
- Posts: 6360
- Joined: 2004-05-17 03:14pm
- Location: The North Remembers, When It Can Be Bothered
Re: Spyware! Spyware everywhere!
Edi is quite correct. My personal recommendation goes towards MSE, but any of the above would be good options. Additionally, I've seen a huge torrent of boot sector viruses in the past year or so, so if you have an actual Vista disc it's time to blow up the boot sector on speculation. Also: Combofix is your lord and master.
Chronological Incontinence: Time warps around the poster. The thread topic winks out of existence and reappears in 1d10 posts.
Out of Context Theatre, this week starring Darth Nostril.
-'If you really want to fuck with these idiots tell them that there is a vaccine for chemtrails.'
Fiction!: The Final War (Bolo/Lovecraft) (Ch 7 9/15/11), Living (D&D, Complete)
Out of Context Theatre, this week starring Darth Nostril.
-'If you really want to fuck with these idiots tell them that there is a vaccine for chemtrails.'
Fiction!: The Final War (Bolo/Lovecraft) (Ch 7 9/15/11), Living (D&D, Complete)
- Agent Sorchus
- Jedi Master
- Posts: 1143
- Joined: 2008-08-16 09:01pm
Re: Spyware! Spyware everywhere!
Are you using File Assassin to do the manual deletions? Cause it should be able to permanently delete any file that you can find. (warning: that does mean any file, and can trash the computer if you aren't certain of the files use> only kill with it what you are reasonably certain is bad.)
the engines cannae take any more cap'n
warp 9 to shroomland ~Dalton
warp 9 to shroomland ~Dalton
- Dalton
- For Those About to Rock We Salute You
- Posts: 22637
- Joined: 2002-07-03 06:16pm
- Location: New York, the Fuck You State
- Contact:
Re: Spyware! Spyware everywhere!
Huh. I am way behind on antivirus programs. I still use AVG.
Narkis, Have you done a HijackThis scan?
Narkis, Have you done a HijackThis scan?
To Absent Friends
"y = mx + bro" - Surlethe
"You try THAT shit again, kid, and I will mod you. I will
mod you so hard, you'll wish I were Dalton." - Lagmonster
May the way of the Hero lead to the Triforce.
- Torben
- Padawan Learner
- Posts: 159
- Joined: 2008-11-21 10:16pm
- Location: Somewhere just to the left of reality, or SW Florida
Re: Spyware! Spyware everywhere!
If you've got something that nasty on the system, it really is time for a nuke and pave. Back up all of your data (you do have it all on a separate partition, correct?), format the hard drive, reinstall Windows, use MSE as your main antivirus. Get all of your programs installed, get everything patched. Use CloneZilla to create a disk image. Should this happen in the future, all you need do is reload from the image. Oh, update it from time to time (but keep the original as you know it's 100% clean) so you don't have as long to patch after reimaging. Does it suck? Yes. Will it guarantee your malware issue is resolved? Yes. Will it put you in a better position for future issues? Yes.
Also, make sure all of your data is backed up to an external hard drive, and preferably offsite as well (if any of it is important to you). I like Crashplan personally. Encrypts data either with a key shared with them, or a private key shared only with you, prior to transmittal to their datacenter. Truly unlimited backups - no throttling after 100gb like some others. Can use external hard drives, and I think NAS, runs on Linux, Windows, Mac, has Android/iOS apps. Multiple computers can get a discount. Can use their free service to back up to external hard drive or to someone else who uses crashplan and provides you with a link to their system.
my $.02.
Also, make sure all of your data is backed up to an external hard drive, and preferably offsite as well (if any of it is important to you). I like Crashplan personally. Encrypts data either with a key shared with them, or a private key shared only with you, prior to transmittal to their datacenter. Truly unlimited backups - no throttling after 100gb like some others. Can use external hard drives, and I think NAS, runs on Linux, Windows, Mac, has Android/iOS apps. Multiple computers can get a discount. Can use their free service to back up to external hard drive or to someone else who uses crashplan and provides you with a link to their system.
my $.02.
“I prefer Gary,” the Centurion said. - Centurion GRY-237427, "The Hunted"
“This sucks,” Gary said, as the Land-Rams to either side exploded. “I will request a transfer from your command in our next life, Commander.” - Centurion GRY-237427, "The Hunted"
Give a man a match, you warm him for a day. Set him on fire, you warm him for the rest of his life - Terry Pratchett
“This sucks,” Gary said, as the Land-Rams to either side exploded. “I will request a transfer from your command in our next life, Commander.” - Centurion GRY-237427, "The Hunted"
Give a man a match, you warm him for a day. Set him on fire, you warm him for the rest of his life - Terry Pratchett
- Sea Skimmer
- Yankee Capitalist Air Pirate
- Posts: 37390
- Joined: 2002-07-03 11:49pm
- Location: Passchendaele City, HAB
Re: Spyware! Spyware everywhere!
If all else fails, and you have good backups, Combofix has removed several nasty viruses for me. Backups are key, since Combofix just deletes every single file doesn't like and that might include key system files, making the machine unbootable. Its a good last resort before reformatting. Its best to run a bunch of other anti virus programs, one at a time, beforehand to ensure that Combofix sees a need to destroy as little of your hard drive as possible. Its been a while since I used it though, so I dunno if its kept pace with the very latest problems.
"This cult of special forces is as sensible as to form a Royal Corps of Tree Climbers and say that no soldier who does not wear its green hat with a bunch of oak leaves stuck in it should be expected to climb a tree"
— Field Marshal William Slim 1956
— Field Marshal William Slim 1956
- White Haven
- Sith Acolyte
- Posts: 6360
- Joined: 2004-05-17 03:14pm
- Location: The North Remembers, When It Can Be Bothered
Re: Spyware! Spyware everywhere!
Combofix is most definitely still the wind of death as far as malware is concerned. And frankly, if Combofix is deleting your system files, it's because they were subverted and/or replaced by viruses anyway, so you're just as fucked, but now your hard drive is probably clean for you to recover data from, rather than running the risk of grabbing viruses off it too. It doesn't kill everything, but it tends to focus on the most brutally unpleasant viruses out there, so it's an invaluable tool.
Chronological Incontinence: Time warps around the poster. The thread topic winks out of existence and reappears in 1d10 posts.
Out of Context Theatre, this week starring Darth Nostril.
-'If you really want to fuck with these idiots tell them that there is a vaccine for chemtrails.'
Fiction!: The Final War (Bolo/Lovecraft) (Ch 7 9/15/11), Living (D&D, Complete)
Out of Context Theatre, this week starring Darth Nostril.
-'If you really want to fuck with these idiots tell them that there is a vaccine for chemtrails.'
Fiction!: The Final War (Bolo/Lovecraft) (Ch 7 9/15/11), Living (D&D, Complete)
Re: Spyware! Spyware everywhere!
Alright, I replaced AVG with MSE, had it perform a full scan (10 frigging hours), redid all scans in safe mode, even ran combofix (without a backup, thanks for the warning White Haven ) and it found some files it didn't like. But the problem persists. Spybot still finds stuff that should probably not be there every time I run a scan. The poor computer isn't getting any better. Both MSE and Malwarebytes find nothing. And HJT spits out an error after a bit of scanning, and I don't know enough to decrypt the results. Error and log are here, if anyone wants to have a look: https://docs.google.com/document/d/1Xw0 ... fee2Y/edit
Guess it's time for a nuke. I'd better find my vista cd soon.
Guess it's time for a nuke. I'd better find my vista cd soon.
- White Haven
- Sith Acolyte
- Posts: 6360
- Joined: 2004-05-17 03:14pm
- Location: The North Remembers, When It Can Be Bothered
Re: Spyware! Spyware everywhere!
If you have an actual OS CD and not a restore set of some kind, I can give you the procedure to blow up your boot sector and MBR; I've seen a ton of boot sector viruses of late.
Chronological Incontinence: Time warps around the poster. The thread topic winks out of existence and reappears in 1d10 posts.
Out of Context Theatre, this week starring Darth Nostril.
-'If you really want to fuck with these idiots tell them that there is a vaccine for chemtrails.'
Fiction!: The Final War (Bolo/Lovecraft) (Ch 7 9/15/11), Living (D&D, Complete)
Out of Context Theatre, this week starring Darth Nostril.
-'If you really want to fuck with these idiots tell them that there is a vaccine for chemtrails.'
Fiction!: The Final War (Bolo/Lovecraft) (Ch 7 9/15/11), Living (D&D, Complete)
- Dalton
- For Those About to Rock We Salute You
- Posts: 22637
- Joined: 2002-07-03 06:16pm
- Location: New York, the Fuck You State
- Contact:
Re: Spyware! Spyware everywhere!
Take a look at this. If a virus is blocking HJT from scanning system.ini, you may have to take a look at it yourself and see what's going on.
To Absent Friends
"y = mx + bro" - Surlethe
"You try THAT shit again, kid, and I will mod you. I will
mod you so hard, you'll wish I were Dalton." - Lagmonster
May the way of the Hero lead to the Triforce.
Re: Spyware! Spyware everywhere!
I checked my system.ini, and nothing seems out of place. It doesn't contain much anyway. I could cp it if you want to have a look.
And I have no idea what my Vista CD is, as I haven't been able to find it anywhere. Will check back if I do.
And I have no idea what my Vista CD is, as I haven't been able to find it anywhere. Will check back if I do.
- Dalton
- For Those About to Rock We Salute You
- Posts: 22637
- Joined: 2002-07-03 06:16pm
- Location: New York, the Fuck You State
- Contact:
Re: Spyware! Spyware everywhere!
You should do so.
To Absent Friends
"y = mx + bro" - Surlethe
"You try THAT shit again, kid, and I will mod you. I will
mod you so hard, you'll wish I were Dalton." - Lagmonster
May the way of the Hero lead to the Triforce.
- SCRawl
- Has a bad feeling about this.
- Posts: 4191
- Joined: 2002-12-24 03:11pm
- Location: Burlington, Canada
Re: Spyware! Spyware everywhere!
It's possible that you never got an installation CD; many new computers contain the means to make "recovery" disks, but not actual physical media.Narkis wrote:I checked my system.ini, and nothing seems out of place. It doesn't contain much anyway. I could cp it if you want to have a look.
And I have no idea what my Vista CD is, as I haven't been able to find it anywhere. Will check back if I do.
73% of all statistics are made up, including this one.
I'm waiting as fast as I can.
I'm waiting as fast as I can.