Encyclopaedia Metallum: The Metal Archives Forum Index Encyclopaedia Metallum: The Metal Archives
Message board
 
 FAQFAQ   SearchSearch   MemberlistMemberlist     RegisterRegister RulesBoard Rules
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in

Crapware Removal Help for Windows

 
Post new topic   Reply to topic    Encyclopaedia Metallum: The Metal Archives Forum Index -> Suggestions and complaints
View previous topic :: View next topic  
Author Message
Rainer1
Mallcore Kid


Joined: 10 Mar 2007
Posts: 28
Location: Canada

PostPosted: Wed Jan 21, 2009 3:13 am    Post subject: Crapware Removal Help for Windows Reply with quote

In light of the recent hacker attack on MA; I thought I'd offer some crapware removal and prevention tips to my fellow MA users. It’s basic but should be helpful. Everything in this post is free some have payment options but none require it.

First Run a Full Service Scan from Windows Live One Care.
http://onecare.live.com/site/en-US/default.htm

It’s completely free, reasonably effective and works on at least some versions of the fake antivirus crapwares.

Note 1: On the results page for the scan it will ask if you want to get the full program just click “I’m not ready to be protected yet” (or whatever they are saying now)

Note 2: If it says it needs to restart to remove something after you click restart, Pull ALL internet and/or network connections immediately and do NOT reconnect them until your computer is fully restarted. Don’t question it just do its important.

----------------------------

Now update and run full scans with your antivirus/antispyware program(s)

----------------------------

The following helps prevent future infections and as a side effect blocks a lot of ads

Now Download, Install and Update SpywareBlaster ( http://www.javacoolsoftware.com/spywareblaster.html ) make sure all the protections in SpywareBlaster are enabled

Now Download and Install ZonedOut ( Link.). Next go download ie-spyad ( http://www.spywarewarrior.com/uiuc/resource.htm#IESPYAD ) I like the zip version but both work.

Open ZonedOut change you current key to “local machine” and your current zone to “Restricted Zone” now Click Menu->Import/Export Sites->Import from File then find the text files from ie-spyad and import at a bare minimum ie-ads but ie-nfe and adult in the adult folder are a good idea as well since if they block a site you really want you can unblock it by finding it’s URL in the list and click that entry to select it then right click it then go to “Remove Sites” ->Delete Entry(s). Once you have imported the list(s) change your current key back to current user and close ZonedOut.

Now open Internet Explorer. Click Tools->Internet Options->Security then click “Restricted Sites” Set that to High if you have the option make sure that your “Enable Protected Mode” box is checked.

Note 3: If you followed my steps above ZonedOut works for everyone that uses the computer BUT SpywareBlaster MUST be installed for each user.

This is a quick help file I tossed together if you guys want it I’ll write up a proper guide at a less ungodly hour.

Rainer1
Back to top
View user's profile Send private message Send e-mail Visit poster's website
anticipate
Mallcore Kid


Joined: 13 Dec 2007
Posts: 1
Location: Poland

PostPosted: Thu Jan 22, 2009 4:19 am    Post subject: Another antispyware solution for FREE Reply with quote

I'm using FREE Dr.Web CureIt! Utility to clean my PC from any spyware and malware or other infections.
You can find it here: http://www.freedrweb.com/cureit/.

The utility contains the most up-to-date add-ons to the Dr.Web virus databases going up to twice per hour frequency at periods of high malware submissions.

Dr.Web CureIt! automatically detects the language of the OS it is installed to and sets the scanner interface accordingly (if the local language is not supported, English is enabled). The utility supports the following 34 languages: Russian, Arabic, Armenian, Belarusian, Bulgarian, Chinese (Simpl.), Chinese (Trad.), Czech, Dutch, English, Esperanto, Estonian, Finnish, French, Georgian, German, Greek, Hungarian, Italian, Japanese, Korean, Latvian, Lithuanian, Norwegian, Persian (Farsi), Polish, Portuguese, Slovak, Slovenian, Spanish, Thai, Turkish, Ukrainian, Vietnamese.

Dr.Web CureIt! detects and removes
* Rootkits * Mass-mailing worms * E-mail viruses * Peer-to-peer viruses * Internet worms * File viruses * Trojans * Stealth viruses* Polymorphic viruses * Bodiless viruses * Macro viruses * MS Office viruses * Script viruses * Spyware * Spybots * Password stealers * Keyloggers* Paid Dialers * Adware * Riskware* Hacktools * Backdoors * Joke programs * Malicious scripts * Other malware*

You have nothing to install, just download the file and launch it.

So, stay protected and Keep Metal Alive!

ANTICIPATE
Back to top
View user's profile Send private message Visit poster's website
Zythifer
RP's left nut tastes like breastmilk


Joined: 03 Apr 2007
Posts: 404

PostPosted: Thu Jan 22, 2009 7:19 am    Post subject: Reply with quote

It could just be a coincidence, but around the time this site was attacked I experienced a rootkit infection. The symptoms were google links redirecting me to spam/spyware sites and all firewall/antivirus/anti-spyware programs being unable to update themselves.

If this sounds like you, check out http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/

Run combofix and follow its instructions for a quick and painless removal
Back to top
View user's profile Send private message
mrchris
Metalhead


Joined: 28 Sep 2005
Posts: 2430
Location: United States of America

PostPosted: Thu Jan 22, 2009 5:01 pm    Post subject: Reply with quote

What was the malware called that affected MA?
Back to top
View user's profile Send private message Visit poster's website
Willie_Blades
Mallcore Kid


Joined: 09 Dec 2008
Posts: 1
Location: United States of America

PostPosted: Sat Jan 24, 2009 11:03 am    Post subject: combo fix is a virus itself. Reply with quote

Zythifer wrote:
It could just be a coincidence, but around the time this site was attacked I experienced a rootkit infection. The symptoms were google links redirecting me to spam/spyware sites and all firewall/antivirus/anti-spyware programs being unable to update themselves.

If this sounds like you, check out http://www.myantispyware.com/2007/10/08/combofix-another-free-anti-spyware-tool/

Run combofix and follow its instructions for a quick and painless removal
Back to top
View user's profile Send private message Visit poster's website
Ozenrol
Metal newbie


Joined: 04 May 2008
Posts: 175
Location: United States of America

PostPosted: Sat Jan 24, 2009 1:07 pm    Post subject: Reply with quote

Out of morbid curiosity, did anyone catch the Vundo/Virtumonde trojan? I seem to have been smote with it around when MA went down.
This thing is a pain in the ass. Hardly any anti-virus programs (avast!, AVG, etc. etc.) are able to remove it.



Not sure if that's just me, or if anyone else caught it. If anyone did, and your Antivirus doesn't catch/remove it, SpywareDoctor is said to be able to get it off. Or Ad-Aware, which I am using right now in an attempt to find and delete it. Ad-Aware has a free version, and SpywareDoctor has a demo (you can scan, but you can't remove).

Edit:
Symptoms for Vundo/Virtumonde include:

-Various to large amount of pop-ups urging you to download a fake anti-virus program
-Slow site loading (even though your download/upload speeds are fine). Some sites also won't load at all.


Here are some files associated with it (the trojan will create hidden folders and stow some of these files in them, which is why you may not be able to find them):

- c:\\windows\system32\WIXWQN.DLL
- difodime.dll
- vundo.ds
- yeneriho.dll
Back to top
View user's profile Send private message
Rainer1
Mallcore Kid


Joined: 10 Mar 2007
Posts: 28
Location: Canada

PostPosted: Sat Jan 24, 2009 4:59 pm    Post subject: Vundo Reply with quote

I've had Vundo. It made me want to take a sludge hammer to my computer and get a new one.

If you're using a Windows operating system this online scanner can remove it ( http://onecare.live.com/site/en-US/default.htm ) and it's free.

One thing about the Vundo family of viruses is that they have an online component. Which is what makes them so hard to remove and why when the scan finishes and it asks you to restart you should unplug the you network and/or internet as soon as your computer starts shutting down.

Tech Support Forum ( http://www.techsupportforum.com/ ) has a good virus removal help section as well.
Back to top
View user's profile Send private message Send e-mail Visit poster's website
Noktorn
Metal freak


Joined: 11 Feb 2005
Posts: 8122
Location: United States of America

PostPosted: Sat Jan 24, 2009 5:45 pm    Post subject: Reply with quote

Ozenrol wrote:
Out of morbid curiosity, did anyone catch the Vundo/Virtumonde trojan? I seem to have been smote with it around when MA went down.
This thing is a pain in the ass. Hardly any anti-virus programs (avast!, AVG, etc. etc.) are able to remove it.


Virtumonde is an absolute son of a bitch. I've only been able to find ONE program that gets rid of it, and since I got mine I've been swearing by it:

http://www.malwarebytes.org/mbam.php

Malwarebyte's Anti-Malware. Ridiculously powerful, even the free version.
_________________
Nokturnal Transmissions Records - www.nokturnaltransmissionsrecords.com
Septic Tomb - www.myspace.com/septictomb
Bonescraper - www.myspace.com/bonescraper666

Member #1 of Zarach 'Baal' Tharagh Crew - Fuck off the musical black metal!
Back to top
View user's profile Send private message Send e-mail Visit poster's website
weakling_goat
Metalhead


Joined: 26 Mar 2008
Posts: 621
Location: United States of America

PostPosted: Sat Jan 24, 2009 7:08 pm    Post subject: Reply with quote

Noktorn wrote:
Ozenrol wrote:
Out of morbid curiosity, did anyone catch the Vundo/Virtumonde trojan? I seem to have been smote with it around when MA went down.
This thing is a pain in the ass. Hardly any anti-virus programs (avast!, AVG, etc. etc.) are able to remove it.


Virtumonde is an absolute son of a bitch. I've only been able to find ONE program that gets rid of it, and since I got mine I've been swearing by it:

http://www.malwarebytes.org/mbam.php

Malwarebyte's Anti-Malware. Ridiculously powerful, even the free version.

I had Virtumonde and I used that software to get rid of it too.
Back to top
View user's profile Send private message
Ozenrol
Metal newbie


Joined: 04 May 2008
Posts: 175
Location: United States of America

PostPosted: Sat Jan 24, 2009 8:15 pm    Post subject: Reply with quote

using MWB right now. Many thanks. Hopefully this will get rid of it.
Back to top
View user's profile Send private message
unclevladistav
Metalhead


Joined: 03 Mar 2008
Posts: 857
Location: United States of America

PostPosted: Sat Jan 24, 2009 11:15 pm    Post subject: Reply with quote

I downloaded Malwarebytes' Anti-Malware as it's on the main page, the quick scan and removal seems to have gotten rid of whatever I had (scan showed a couple hundred trojans, malware files, and fake/ad alerts).
_________________
Decaying Citadel - Extreme Doom Metal
www.myspace.com/decayingcitadel
New demo out now.
Buy it here:
http://www.bubonicprod.pt.vu/
Back to top
View user's profile Send private message Send e-mail Visit poster's website
Evenfiel
Heavy Metal Hunter


Joined: 27 May 2003
Posts: 4333
Location: Brazil

PostPosted: Sun Jan 25, 2009 7:16 am    Post subject: Reply with quote

Hundreds? Seriously, what do you guys do with your computer? Last time I got one was years ago.
Back to top
View user's profile Send private message Send e-mail
Morrigan
Midnight Rider


Joined: 10 Aug 2002
Posts: 6208
Location: Canada

PostPosted: Sun Jan 25, 2009 12:36 pm    Post subject: Reply with quote

Ten bucks they're IE users. Big grin
Back to top
View user's profile Send private message Visit poster's website MSN Messenger
messiah88
Mallcore Kid


Joined: 06 Nov 2008
Posts: 1
Location: Germany

PostPosted: Mon Jan 26, 2009 10:17 am    Post subject: Reply with quote

There is no program I can download. I downloaded MBAM from an other PC and now I transported via USB stick to this computer... Clicked on the icon but it won't start...

What can I do? Spywareguard is blocking everything...
Back to top
View user's profile Send private message Send e-mail
oneyoudontknow
Cum insantientibus furere necesse est.


Joined: 21 May 2006
Posts: 4833
Location: Germany

PostPosted: Mon Jan 26, 2009 10:32 am    Post subject: Reply with quote

ever tried the Kapersky online scanner?

or:
HiJack This
Autoruns
gmer
SpyBot Search and Destroy
_________________
If you find any typing errors or ironical comments, then you can keep them.

"Mountains of concrete give the impression humans are in control."

"Talk of heaven! ye disgrace earth."
Back to top
View user's profile Send private message Send e-mail
aaronmb666
Metalhead


Joined: 03 Jan 2005
Posts: 710

PostPosted: Tue Feb 03, 2009 7:51 am    Post subject: Reply with quote

I use Malmarebytes Anti-malware and Symantec Antivirus. I highly recommend both. Just click automatic updates and it does everything else
Back to top
View user's profile Send private message Send e-mail
EnjoyCoke
Mallcore Kid


Joined: 07 Nov 2007
Posts: 7
Location: Denmark

PostPosted: Sat Apr 11, 2009 6:41 am    Post subject: Reply with quote

I love FAQs

www.majorgeeks.com
Check out their anti-shitware section.
Also, www.opera.com
Download, enjoy, be safe.
Back to top
View user's profile Send private message Send e-mail Visit poster's website
Display posts from previous:   
Post new topic   Reply to topic    Encyclopaedia Metallum: The Metal Archives Forum Index -> Suggestions and complaints All times are GMT - 5 Hours
Page 1 of 1

 
Jump to:  

Back to the Encyclopaedia Metallum


Powered by phpBB © 2001 phpBB Group
-- EQ graphic from www.freeclipart.nu/ --