PDA

View Full Version : Ugg ... Malware



Vertigo
12-23-2006, 08:51 PM
So, I managed to get this bundle of spyware. I've gotten rid of all of it except "SystemAlert!" it shows an icon in my taskbar and tells me occasionally it's found virus activity, click here to remove. If you click remove ... it uninstalls AVG Antivirus, AdAware, Spybot S&D, Spyware Blaster, Ccleaner, and I assume other similar programs. I've ran a full scan with everything and it won't go away. I'm not finding much on google, any ideas?

Zephik
12-23-2006, 09:00 PM
Have you tried system restore? Restore to an earlier date, one where you did not have spyware.

-SnowFire

DRece
12-23-2006, 09:06 PM
what about "hijack this!", I heard that removes the stuff that seems to be hot-wiring your system sometimes. I personally have not gotten it to work for me.

Vertigo
12-23-2006, 09:48 PM
Forgot about HijackThis, seeing what I can find now. So far, found:

Sasser Worm - C:\WINDOWS\system32\lsass.exe

jdbnsn
12-23-2006, 10:22 PM
You website is cool, clicked projects and laughed my ass off when it showed a "modified" error page. Are those sketches Davinci?

Vertigo
12-23-2006, 10:25 PM
Yeah, sorta. Based off the Da'vinci sketchbooks, actually done in Photoshop 7 with a Waccom tablet. And thanks ^_^


Ok, so tragedy averted. I managed to get rid of the offending malware, RogueScanFix put the kung fu grip on all of it.

jdbnsn
12-23-2006, 10:28 PM
They look nice, you know Davinci often snuck into morgues and hospitals to do those sketches. His series of studies on anatomy were not really "cool" with the opinion of the church at the time. But I recognize those anywhere, nice work.

Vertigo
12-23-2006, 10:31 PM
Hehe, yeah there was a good special on The History Channel about Da'vinci a couple nights ago. I'm actually planning on doing something in place of the fetuses on the site. But right now I'm more concerned about getting the coding done for the projects section, right now I've just got my DeviantArt account to use for all my art, but I want to do something a little different than what their gallery does.

jdbnsn
12-23-2006, 10:37 PM
I missed the show on THC, but studied him at length in college. Aside from possibly Archamedes I think he was one of the most impressive thinkers of history. Did they talk about the rivalry between Davinci and Michaelangelo? They took lots of shots at one another, there is a fountain somewhere in Florence that Leo designed that is covered with sculpted portraits telling some story like all the rest of the sculputes of the time. But apparently there is one face in particular that seems to be staring directly at one of the buildings Mike designed and the face has a look of horrow on it. It went un-noticed for ages.

Vertigo
12-24-2006, 01:08 AM
They didn't talk much about that, it was on Man Moment Machine, so they were discussing him at first, then it went to his work on various war machines, most importantly the improved firearms he designed.

Vertigo
12-24-2006, 04:07 PM
Ok, so here's the info incase anyone else runs into this. This will save you some time possibly trying to find a fix.

First, this particular bit of annoyance comes from the good folks at antivermins.com, this particular piece of malware works by clicking a link. Seriously, that's all you have to do. Often, it's reported that it's a driver or audio/video codec. But one click, and the malware is all installed with absolutely no prompt.

Basically this is a bundle of malware, that redirects you to the antivermin site, and attempts to delete all antivirus software on your computer: Norton, McAfee, AdAware, etc. There are possibly other trojans, keyloggers, etc that "could" be attached to this. So, if you DO run accross this get rid of it ASAP. The one I got was from a hijacked MySpace account (friend's account was swiped and is spitting out spam now, yay)

Aside from the antivermins pop ups, there is also a SystemAlert! that appear in the system tray. Usually as a yellow triangle with an ! and alternates to a hard drive icon, ? or a variation. Periodically, a balloon comes up with a warning about viruses = very yes on your computer.

Most of the malware can be nuked with AdAware, Spybot S&D, AVG Free Edition, etc.

First thing to do, is download RogueScanFix. Restart your computer in SafeMode and run RSF. RSF will very likely fix the problem entirely. It is important to note, the dialog that runs while RSF is active will say it's deleting files from WindowsSYSTEM32, etc. You can relax, this malware actually is installed there to make it a little more difficult to fix. RSF isn't deleting Windows, so don't worry.

Anyhow, hopefully nobody else gets stuck with this. But considering how easy it is, I figured I'd post this. After you run RSF, you can reboot Windows normally, run AdAware, etc to make sure everything's clear. In Add/Remove programs if you see AntiVermin definitely remove it. Other than that, you should be good.

DaveW
12-24-2006, 04:12 PM
+5 Rep for coming back with a solution!

-Dave

SgtM
12-24-2006, 04:30 PM
Useful info. +rep