Spyware! Spyware everywhere!

GEC: Discuss gaming, computers and electronics and venture into the bizarre world of STGODs.

Moderator: Thanas

Post Reply
Narkis
Padawan Learner
Posts: 391
Joined: 2009-01-02 11:05pm
Location: Greece

Spyware! Spyware everywhere!

Post by Narkis »

I got AVG, malwarebytes and spybot installed on my laptop, all fully updated and semi-frequently scanning. But lately it has been slower than usual, using way too much ram and cpu on idle, spybot always finds a dozen various malware even in nearly consecutive scans, and avg occasionally shows a popup about detecting a tracking cookie or another that it won't move to the vault, leaving me to delete them manually. But they always reappear, so whatever this thing is, it's gotten its roots deep within my system. How can I root it out, preferably avoiding a full format of the hd?

Dunno if it's relevant, but I've never been able to install the SP2 (Win Vista) on the machine. It always blurts out an unknown error, and has to revert the changes a little before finishing.
Grumman
Jedi Council Member
Posts: 2488
Joined: 2011-12-10 09:13am

Re: Spyware! Spyware everywhere!

Post by Grumman »

The first and easiest step is to redo the scans with each program while running in Safe Mode. Basically what this does is start up Windows without starting up most of the programs that would otherwise run automatically (which probably includes the bad programs), which will make your attempts to root out the malware that much more likely to succeed.
User avatar
Edi
Dragonlord
Dragonlord
Posts: 12461
Joined: 2002-07-11 12:27am
Location: Helsinki, Finland

Re: Spyware! Spyware everywhere!

Post by Edi »

Another thing would be to ditch AVG for something better. MSE, Avira and Avast are all superior alternatives.
Warwolf Urban Combat Specialist

Why is it so goddamned hard to get little assholes like you to admit it when you fuck up? Is it pride? What gives you the right to have any pride?
–Darth Wong to vivftp

GOP message? Why don't they just come out of the closet: FASCISTS R' US –Patrick Degan

The GOP has a problem with anyone coming out of the closet. –18-till-I-die
User avatar
White Haven
Sith Acolyte
Posts: 6360
Joined: 2004-05-17 03:14pm
Location: The North Remembers, When It Can Be Bothered

Re: Spyware! Spyware everywhere!

Post by White Haven »

Edi is quite correct. My personal recommendation goes towards MSE, but any of the above would be good options. Additionally, I've seen a huge torrent of boot sector viruses in the past year or so, so if you have an actual Vista disc it's time to blow up the boot sector on speculation. Also: Combofix is your lord and master.
Image
Image
Chronological Incontinence: Time warps around the poster. The thread topic winks out of existence and reappears in 1d10 posts.

Out of Context Theatre, this week starring Darth Nostril.
-'If you really want to fuck with these idiots tell them that there is a vaccine for chemtrails.'

Fiction!: The Final War (Bolo/Lovecraft) (Ch 7 9/15/11), Living (D&D, Complete)Image
User avatar
Agent Sorchus
Jedi Master
Posts: 1143
Joined: 2008-08-16 09:01pm

Re: Spyware! Spyware everywhere!

Post by Agent Sorchus »

Are you using File Assassin to do the manual deletions? Cause it should be able to permanently delete any file that you can find. (warning: that does mean any file, and can trash the computer if you aren't certain of the files use> only kill with it what you are reasonably certain is bad.)
the engines cannae take any more cap'n
warp 9 to shroomland ~Dalton
User avatar
Dalton
For Those About to Rock We Salute You
For Those About to Rock We Salute You
Posts: 22637
Joined: 2002-07-03 06:16pm
Location: New York, the Fuck You State
Contact:

Re: Spyware! Spyware everywhere!

Post by Dalton »

Huh. I am way behind on antivirus programs. I still use AVG.

Narkis, Have you done a HijackThis scan?
Image
Image
To Absent Friends
Dalton | Admin Smash | Knight of the Order of SDN

"y = mx + bro" - Surlethe
"You try THAT shit again, kid, and I will mod you. I will
mod you so hard, you'll wish I were Dalton." - Lagmonster

May the way of the Hero lead to the Triforce.
User avatar
Torben
Padawan Learner
Posts: 159
Joined: 2008-11-21 10:16pm
Location: Somewhere just to the left of reality, or SW Florida

Re: Spyware! Spyware everywhere!

Post by Torben »

If you've got something that nasty on the system, it really is time for a nuke and pave. Back up all of your data (you do have it all on a separate partition, correct?), format the hard drive, reinstall Windows, use MSE as your main antivirus. Get all of your programs installed, get everything patched. Use CloneZilla to create a disk image. Should this happen in the future, all you need do is reload from the image. Oh, update it from time to time (but keep the original as you know it's 100% clean) so you don't have as long to patch after reimaging. Does it suck? Yes. Will it guarantee your malware issue is resolved? Yes. Will it put you in a better position for future issues? Yes.

Also, make sure all of your data is backed up to an external hard drive, and preferably offsite as well (if any of it is important to you). I like Crashplan personally. Encrypts data either with a key shared with them, or a private key shared only with you, prior to transmittal to their datacenter. Truly unlimited backups - no throttling after 100gb like some others. Can use external hard drives, and I think NAS, runs on Linux, Windows, Mac, has Android/iOS apps. Multiple computers can get a discount. Can use their free service to back up to external hard drive or to someone else who uses crashplan and provides you with a link to their system.

my $.02.
“I prefer Gary,” the Centurion said. - Centurion GRY-237427, "The Hunted"

“This sucks,” Gary said, as the Land-Rams to either side exploded. “I will request a transfer from your command in our next life, Commander.” - Centurion GRY-237427, "The Hunted"

Give a man a match, you warm him for a day. Set him on fire, you warm him for the rest of his life - Terry Pratchett
User avatar
Sea Skimmer
Yankee Capitalist Air Pirate
Posts: 37390
Joined: 2002-07-03 11:49pm
Location: Passchendaele City, HAB

Re: Spyware! Spyware everywhere!

Post by Sea Skimmer »

If all else fails, and you have good backups, Combofix has removed several nasty viruses for me. Backups are key, since Combofix just deletes every single file doesn't like and that might include key system files, making the machine unbootable. Its a good last resort before reformatting. Its best to run a bunch of other anti virus programs, one at a time, beforehand to ensure that Combofix sees a need to destroy as little of your hard drive as possible. Its been a while since I used it though, so I dunno if its kept pace with the very latest problems.
"This cult of special forces is as sensible as to form a Royal Corps of Tree Climbers and say that no soldier who does not wear its green hat with a bunch of oak leaves stuck in it should be expected to climb a tree"
— Field Marshal William Slim 1956
User avatar
White Haven
Sith Acolyte
Posts: 6360
Joined: 2004-05-17 03:14pm
Location: The North Remembers, When It Can Be Bothered

Re: Spyware! Spyware everywhere!

Post by White Haven »

Combofix is most definitely still the wind of death as far as malware is concerned. And frankly, if Combofix is deleting your system files, it's because they were subverted and/or replaced by viruses anyway, so you're just as fucked, but now your hard drive is probably clean for you to recover data from, rather than running the risk of grabbing viruses off it too. It doesn't kill everything, but it tends to focus on the most brutally unpleasant viruses out there, so it's an invaluable tool.
Image
Image
Chronological Incontinence: Time warps around the poster. The thread topic winks out of existence and reappears in 1d10 posts.

Out of Context Theatre, this week starring Darth Nostril.
-'If you really want to fuck with these idiots tell them that there is a vaccine for chemtrails.'

Fiction!: The Final War (Bolo/Lovecraft) (Ch 7 9/15/11), Living (D&D, Complete)Image
Narkis
Padawan Learner
Posts: 391
Joined: 2009-01-02 11:05pm
Location: Greece

Re: Spyware! Spyware everywhere!

Post by Narkis »

Alright, I replaced AVG with MSE, had it perform a full scan (10 frigging hours), redid all scans in safe mode, even ran combofix (without a backup, thanks for the warning White Haven :P) and it found some files it didn't like. But the problem persists. Spybot still finds stuff that should probably not be there every time I run a scan. The poor computer isn't getting any better. Both MSE and Malwarebytes find nothing. And HJT spits out an error after a bit of scanning, and I don't know enough to decrypt the results. Error and log are here, if anyone wants to have a look: https://docs.google.com/document/d/1Xw0 ... fee2Y/edit

Guess it's time for a nuke. I'd better find my vista cd soon.
User avatar
White Haven
Sith Acolyte
Posts: 6360
Joined: 2004-05-17 03:14pm
Location: The North Remembers, When It Can Be Bothered

Re: Spyware! Spyware everywhere!

Post by White Haven »

If you have an actual OS CD and not a restore set of some kind, I can give you the procedure to blow up your boot sector and MBR; I've seen a ton of boot sector viruses of late.
Image
Image
Chronological Incontinence: Time warps around the poster. The thread topic winks out of existence and reappears in 1d10 posts.

Out of Context Theatre, this week starring Darth Nostril.
-'If you really want to fuck with these idiots tell them that there is a vaccine for chemtrails.'

Fiction!: The Final War (Bolo/Lovecraft) (Ch 7 9/15/11), Living (D&D, Complete)Image
User avatar
Dalton
For Those About to Rock We Salute You
For Those About to Rock We Salute You
Posts: 22637
Joined: 2002-07-03 06:16pm
Location: New York, the Fuck You State
Contact:

Re: Spyware! Spyware everywhere!

Post by Dalton »

Take a look at this. If a virus is blocking HJT from scanning system.ini, you may have to take a look at it yourself and see what's going on.
Image
Image
To Absent Friends
Dalton | Admin Smash | Knight of the Order of SDN

"y = mx + bro" - Surlethe
"You try THAT shit again, kid, and I will mod you. I will
mod you so hard, you'll wish I were Dalton." - Lagmonster

May the way of the Hero lead to the Triforce.
Narkis
Padawan Learner
Posts: 391
Joined: 2009-01-02 11:05pm
Location: Greece

Re: Spyware! Spyware everywhere!

Post by Narkis »

I checked my system.ini, and nothing seems out of place. It doesn't contain much anyway. I could cp it if you want to have a look.

And I have no idea what my Vista CD is, as I haven't been able to find it anywhere. Will check back if I do.
User avatar
Dalton
For Those About to Rock We Salute You
For Those About to Rock We Salute You
Posts: 22637
Joined: 2002-07-03 06:16pm
Location: New York, the Fuck You State
Contact:

Re: Spyware! Spyware everywhere!

Post by Dalton »

You should do so.
Image
Image
To Absent Friends
Dalton | Admin Smash | Knight of the Order of SDN

"y = mx + bro" - Surlethe
"You try THAT shit again, kid, and I will mod you. I will
mod you so hard, you'll wish I were Dalton." - Lagmonster

May the way of the Hero lead to the Triforce.
User avatar
SCRawl
Has a bad feeling about this.
Posts: 4191
Joined: 2002-12-24 03:11pm
Location: Burlington, Canada

Re: Spyware! Spyware everywhere!

Post by SCRawl »

Narkis wrote:I checked my system.ini, and nothing seems out of place. It doesn't contain much anyway. I could cp it if you want to have a look.

And I have no idea what my Vista CD is, as I haven't been able to find it anywhere. Will check back if I do.
It's possible that you never got an installation CD; many new computers contain the means to make "recovery" disks, but not actual physical media.
73% of all statistics are made up, including this one.

I'm waiting as fast as I can.
Post Reply