| View previous topic
:: View next topic |
| Author |
Message |
Rainer1
Mallcore Kid
Joined: 10 Mar 2007
Posts: 28
Location: Canada
|
Posted: Wed Jan 21, 2009 3:13 am Post subject: Crapware Removal Help for Windows |
|
|
In light of the recent hacker attack on MA; I thought I'd offer some crapware removal and prevention tips to my fellow MA users. It’s basic but should be helpful. Everything in this post is free some have payment options but none require it.
First Run a Full Service Scan from Windows Live One Care.
http://onecare.live.com/site/en-US/default.htm
It’s completely free, reasonably effective and works on at least some versions of the fake antivirus crapwares.
Note 1: On the results page for the scan it will ask if you want to get the full program just click “I’m not ready to be protected yet” (or whatever they are saying now)
Note 2: If it says it needs to restart to remove something after you click restart, Pull ALL internet and/or network connections immediately and do NOT reconnect them until your computer is fully restarted. Don’t question it just do its important.
----------------------------
Now update and run full scans with your antivirus/antispyware program(s)
----------------------------
The following helps prevent future infections and as a side effect blocks a lot of ads
Now Download, Install and Update SpywareBlaster ( http://www.javacoolsoftware.com/spywareblaster.html ) make sure all the protections in SpywareBlaster are enabled
Now Download and Install ZonedOut ( Link.). Next go download ie-spyad ( http://www.spywarewarrior.com/uiuc/resource.htm#IESPYAD ) I like the zip version but both work.
Open ZonedOut change you current key to “local machine” and your current zone to “Restricted Zone” now Click Menu->Import/Export Sites->Import from File then find the text files from ie-spyad and import at a bare minimum ie-ads but ie-nfe and adult in the adult folder are a good idea as well since if they block a site you really want you can unblock it by finding it’s URL in the list and click that entry to select it then right click it then go to “Remove Sites” ->Delete Entry(s). Once you have imported the list(s) change your current key back to current user and close ZonedOut.
Now open Internet Explorer. Click Tools->Internet Options->Security then click “Restricted Sites” Set that to High if you have the option make sure that your “Enable Protected Mode” box is checked.
Note 3: If you followed my steps above ZonedOut works for everyone that uses the computer BUT SpywareBlaster MUST be installed for each user.
This is a quick help file I tossed together if you guys want it I’ll write up a proper guide at a less ungodly hour.
Rainer1 |
|
|
Back to top |
|
 |
anticipate
Mallcore Kid
Joined: 13 Dec 2007
Posts: 1
Location: Poland
|
Posted: Thu Jan 22, 2009 4:19 am Post subject: Another antispyware solution for FREE |
|
|
I'm using FREE Dr.Web CureIt! Utility to clean my PC from any spyware and malware or other infections.
You can find it here: http://www.freedrweb.com/cureit/.
The utility contains the most up-to-date add-ons to the Dr.Web virus databases going up to twice per hour frequency at periods of high malware submissions.
Dr.Web CureIt! automatically detects the language of the OS it is installed to and sets the scanner interface accordingly (if the local language is not supported, English is enabled). The utility supports the following 34 languages: Russian, Arabic, Armenian, Belarusian, Bulgarian, Chinese (Simpl.), Chinese (Trad.), Czech, Dutch, English, Esperanto, Estonian, Finnish, French, Georgian, German, Greek, Hungarian, Italian, Japanese, Korean, Latvian, Lithuanian, Norwegian, Persian (Farsi), Polish, Portuguese, Slovak, Slovenian, Spanish, Thai, Turkish, Ukrainian, Vietnamese.
Dr.Web CureIt! detects and removes
* Rootkits * Mass-mailing worms * E-mail viruses * Peer-to-peer viruses * Internet worms * File viruses * Trojans * Stealth viruses* Polymorphic viruses * Bodiless viruses * Macro viruses * MS Office viruses * Script viruses * Spyware * Spybots * Password stealers * Keyloggers* Paid Dialers * Adware * Riskware* Hacktools * Backdoors * Joke programs * Malicious scripts * Other malware*
You have nothing to install, just download the file and launch it.
So, stay protected and Keep Metal Alive!
ANTICIPATE |
|
|
Back to top |
|
 |
Zythifer
RP's left nut tastes like breastmilk
Joined: 03 Apr 2007
Posts: 404
|
Posted: Thu Jan 22, 2009 7:19 am Post subject: |
|
|
It could just be a coincidence, but around the time this site was attacked I experienced a rootkit infection. The symptoms were google links redirecting me to spam/spyware sites and all firewall/antivirus/anti-spyware programs being unable to update themselves.
If this sounds like you, check out http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/
Run combofix and follow its instructions for a quick and painless removal |
|
|
Back to top |
|
 |
mrchris
Metalhead
Joined: 28 Sep 2005
Posts: 2430
Location: United States of America
|
Posted: Thu Jan 22, 2009 5:01 pm Post subject: |
|
|
| What was the malware called that affected MA? |
|
|
Back to top |
|
 |
Willie_Blades
Mallcore Kid
Joined: 09 Dec 2008
Posts: 1
Location: United States of America
|
Posted: Sat Jan 24, 2009 11:03 am Post subject: combo fix is a virus itself. |
|
|
| Zythifer wrote: | It could just be a coincidence, but around the time this site was attacked I experienced a rootkit infection. The symptoms were google links redirecting me to spam/spyware sites and all firewall/antivirus/anti-spyware programs being unable to update themselves.
If this sounds like you, check out http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/
Run combofix and follow its instructions for a quick and painless removal |
|
|
|
Back to top |
|
 |
Ozenrol
Metal newbie
Joined: 04 May 2008
Posts: 175
Location: United States of America
|
Posted: Sat Jan 24, 2009 1:07 pm Post subject: |
|
|
Out of morbid curiosity, did anyone catch the Vundo/Virtumonde trojan? I seem to have been smote with it around when MA went down.
This thing is a pain in the ass. Hardly any anti-virus programs (avast!, AVG, etc. etc.) are able to remove it.
Not sure if that's just me, or if anyone else caught it. If anyone did, and your Antivirus doesn't catch/remove it, SpywareDoctor is said to be able to get it off. Or Ad-Aware, which I am using right now in an attempt to find and delete it. Ad-Aware has a free version, and SpywareDoctor has a demo (you can scan, but you can't remove).
Edit:
Symptoms for Vundo/Virtumonde include:
-Various to large amount of pop-ups urging you to download a fake anti-virus program
-Slow site loading (even though your download/upload speeds are fine). Some sites also won't load at all.
Here are some files associated with it (the trojan will create hidden folders and stow some of these files in them, which is why you may not be able to find them):
- c:\\windows\system32\WIXWQN.DLL
- difodime.dll
- vundo.ds
- yeneriho.dll |
|
|
Back to top |
|
 |
Rainer1
Mallcore Kid
Joined: 10 Mar 2007
Posts: 28
Location: Canada
|
Posted: Sat Jan 24, 2009 4:59 pm Post subject: Vundo |
|
|
I've had Vundo. It made me want to take a sludge hammer to my computer and get a new one.
If you're using a Windows operating system this online scanner can remove it ( http://onecare.live.com/site/en-US/default.htm ) and it's free.
One thing about the Vundo family of viruses is that they have an online component. Which is what makes them so hard to remove and why when the scan finishes and it asks you to restart you should unplug the you network and/or internet as soon as your computer starts shutting down.
Tech Support Forum ( http://www.techsupportforum.com/ ) has a good virus removal help section as well. |
|
|
Back to top |
|
 |
Noktorn
Metal freak
Joined: 11 Feb 2005
Posts: 8122
Location: United States of America
|
Posted: Sat Jan 24, 2009 5:45 pm Post subject: |
|
|
| Ozenrol wrote: | Out of morbid curiosity, did anyone catch the Vundo/Virtumonde trojan? I seem to have been smote with it around when MA went down.
This thing is a pain in the ass. Hardly any anti-virus programs (avast!, AVG, etc. etc.) are able to remove it. |
Virtumonde is an absolute son of a bitch. I've only been able to find ONE program that gets rid of it, and since I got mine I've been swearing by it:
http://www.malwarebytes.org/mbam.php
Malwarebyte's Anti-Malware. Ridiculously powerful, even the free version. _________________ Nokturnal Transmissions Records - www.nokturnaltransmissionsrecords.com
Septic Tomb - www.myspace.com/septictomb
Bonescraper - www.myspace.com/bonescraper666
Member #1 of Zarach 'Baal' Tharagh Crew - Fuck off the musical black metal! |
|
|
Back to top |
|
 |
weakling_goat
Metalhead
Joined: 26 Mar 2008
Posts: 621
Location: United States of America
|
Posted: Sat Jan 24, 2009 7:08 pm Post subject: |
|
|
| Noktorn wrote: | | Ozenrol wrote: | Out of morbid curiosity, did anyone catch the Vundo/Virtumonde trojan? I seem to have been smote with it around when MA went down.
This thing is a pain in the ass. Hardly any anti-virus programs (avast!, AVG, etc. etc.) are able to remove it. |
Virtumonde is an absolute son of a bitch. I've only been able to find ONE program that gets rid of it, and since I got mine I've been swearing by it:
http://www.malwarebytes.org/mbam.php
Malwarebyte's Anti-Malware. Ridiculously powerful, even the free version. |
I had Virtumonde and I used that software to get rid of it too. |
|
|
Back to top |
|
 |
Ozenrol
Metal newbie
Joined: 04 May 2008
Posts: 175
Location: United States of America
|
Posted: Sat Jan 24, 2009 8:15 pm Post subject: |
|
|
| using MWB right now. Many thanks. Hopefully this will get rid of it. |
|
|
Back to top |
|
 |
unclevladistav
Metalhead
Joined: 03 Mar 2008
Posts: 857
Location: United States of America
|
Posted: Sat Jan 24, 2009 11:15 pm Post subject: |
|
|
I downloaded Malwarebytes' Anti-Malware as it's on the main page, the quick scan and removal seems to have gotten rid of whatever I had (scan showed a couple hundred trojans, malware files, and fake/ad alerts). _________________ Decaying Citadel - Extreme Doom Metal
www.myspace.com/decayingcitadel
New demo out now.
Buy it here:
http://www.bubonicprod.pt.vu/ |
|
|
Back to top |
|
 |
Evenfiel
Heavy Metal Hunter
Joined: 27 May 2003
Posts: 4333
Location: Brazil
|
Posted: Sun Jan 25, 2009 7:16 am Post subject: |
|
|
| Hundreds? Seriously, what do you guys do with your computer? Last time I got one was years ago. |
|
|
Back to top |
|
 |
Morrigan
Midnight Rider
Joined: 10 Aug 2002
Posts: 6208
Location: Canada
|
Posted: Sun Jan 25, 2009 12:36 pm Post subject: |
|
|
Ten bucks they're IE users.  |
|
|
Back to top |
|
 |
messiah88
Mallcore Kid
Joined: 06 Nov 2008
Posts: 1
Location: Germany
|
Posted: Mon Jan 26, 2009 10:17 am Post subject: |
|
|
There is no program I can download. I downloaded MBAM from an other PC and now I transported via USB stick to this computer... Clicked on the icon but it won't start...
What can I do? Spywareguard is blocking everything... |
|
|
Back to top |
|
 |
oneyoudontknow
Cum insantientibus furere necesse est.
Joined: 21 May 2006
Posts: 4833
Location: Germany
|
Posted: Mon Jan 26, 2009 10:32 am Post subject: |
|
|
ever tried the Kapersky online scanner?
or:
HiJack This
Autoruns
gmer
SpyBot Search and Destroy _________________ If you find any typing errors or ironical comments, then you can keep them.
"Mountains of concrete give the impression humans are in control."
"Talk of heaven! ye disgrace earth." |
|
|
Back to top |
|
 |
aaronmb666
Metalhead
Joined: 03 Jan 2005
Posts: 710
|
Posted: Tue Feb 03, 2009 7:51 am Post subject: |
|
|
| I use Malmarebytes Anti-malware and Symantec Antivirus. I highly recommend both. Just click automatic updates and it does everything else |
|
|
Back to top |
|
 |
EnjoyCoke
Mallcore Kid
Joined: 07 Nov 2007
Posts: 7
Location: Denmark
|
Posted: Sat Apr 11, 2009 6:41 am Post subject: |
|
|
I love FAQs
www.majorgeeks.com
Check out their anti-shitware section.
Also, www.opera.com
Download, enjoy, be safe. |
|
|
Back to top |
|
 |
|
|