Malware help please -Killerbyte

Viruses, hackers and crackers
KillerByte
G3AR Staff Member
Posts: 5790
Joined: 08 Mar 2003, 02:00
Location: PCFormat HQ
Contact:

Malware help please -Killerbyte

Post by KillerByte »

hey guys

so it seems that I have picked up a nasty bit of malware.

what does this little nasty do? very simple. it starts up IE when I'm online and then directs to a number of sites. this is random in its choosing of which sites.

i have run spybot search and destroy and avast and neither pick up the nasty. I even ran the win xp version of Defender and nothing was detected
What I type has nothing to do with the people that employ me.
User avatar
hamin_aus
Forum Moderator
Posts: 18363
Joined: 28 Aug 2003, 02:00
Processor: Intel i7 3770K
Motherboard: GA-Z77X-UP4 TH
Graphics card: Galax GTX1080
Memory: 32GB G.Skill Ripjaws
Location: Where beer does flow and men chunder
Contact:

Post by hamin_aus »

hijackthis log :?:
Image
liep
Registered User
Posts: 84
Joined: 27 Jul 2007, 02:00

Post by liep »

lolz didnt yo mama tell u not to browse t3h pornz with IE? Opera/firefox is da best...

Its evil is spybot didnt help, try maybe adaware also for good measure and yea after that its all hjt.
jee
Registered User
Posts: 19336
Joined: 03 Jun 2003, 02:00
Location: a hole so deep...

Post by jee »

Killerbyte, i suggest you change your title to something that will make people want to help you...,.
"Integrity" and "integer" both contain a Latin root meaning "whole; complete." The root sense, then, is that people may be said to be acting with integrity when their beliefs, words, and actions have a sense of unity or wholeness.
neon_chameleon
Moderator Emeritus
Posts: 6098
Joined: 27 Feb 2004, 02:00
Location: Durban
Contact:

Post by neon_chameleon »

Why would putting your nick after the topic title it make any difference?

Killerbyte, malware is using under the adware category, try an adware scanner.
Qualifications: BSc Computer Science & Information Technology, BCom Information Systems Honours, ISACA CISA, ISACA CRISC
Experience: Web Design, IT Auditing, IT Governance, Computer Retail, IT Consulting
Interests: Technology, Nutrition, Toasters, BBM, Facebook, Colourful Diagrams
Screeper
Registered User
Posts: 3692
Joined: 04 Apr 2003, 02:00
Contact:

Post by Screeper »

Download/install Ad-Aware - update and run.
Download/install AVG's rootkit remover and run.
If they fail
Download Task Manager 1.7 or above and run TaskMan.exe (no need to install) - find the process/app that is causing the headache and close it down.

@Neon - posting at 04:47am 8O respect - now that's a dedicated Mod :wink:
There are 10 types of people in this world.
Those who understand binary and those who do not.
User avatar
rustypup
Registered User
Posts: 8872
Joined: 13 Dec 2004, 02:00
Location: nullus pixius demonica
Contact:

Post by rustypup »

play with fire...

get burned...

dial 911...

"Your call is important to us... Please hold"

R300+- and all your problems vanish... (there is a 30 day trial...)
Most people would sooner die than think; in fact, they do so - Bertrand Russel
Frozenfireside
Registered User
Posts: 2618
Joined: 26 Apr 2007, 02:00
Location: Westcliff, Johannesburg
Contact:

Post by Frozenfireside »

Ok you should be able to pick up the fix for the malware on the web.
Please tell me the actual name of the malicious .exe running in your memory.

Is it a random number.exe or such? If you are not sure what .exe it is, google the suspect ones.

I love spybot but, yep, it doesn't cope with hectic malware such as spyquake.

Hope this helps :D
Soon Google will know everything...including how to divide by zero :(
Image
maxxis
Moderator Emeritus
Posts: 8307
Joined: 30 Jun 2004, 02:00
Location: ( . Y . )
Contact:

Post by maxxis »

Format.

You will always wonder what that file is or why you machine is not responding like it did.
capanno
Registered User
Posts: 5727
Joined: 17 Apr 2004, 02:00
Location: PTA
Contact:

Post by capanno »

R5 says its because of browsing questionable sites...
Image
Josh Dies is my hero! |50,000,601.375 forum points
maxxis
Moderator Emeritus
Posts: 8307
Joined: 30 Jun 2004, 02:00
Location: ( . Y . )
Contact:

Post by maxxis »

Ones where names end in .jpg perhaps?
Anakha56
Forum Administrator
Posts: 22136
Joined: 14 Jun 2004, 02:00
Processor: Ryzen 1700K
Motherboard: Asus X370
Graphics card: Asus 1060 Strix
Memory: 16GB RAM
Location: Where Google says

Post by Anakha56 »

capanno wrote:R5 says its because of browsing questionable sites...
R10 says its because he downloads and uses illegal programs as well as hacking people's ISP accounts :wink: :lol:

have you tried a virus scan?
JUSTICE, n A commodity which is a more or less adulterated condition the State sells to the citizen as a reward for his allegiance, taxes and personal service.
capanno
Registered User
Posts: 5727
Joined: 17 Apr 2004, 02:00
Location: PTA
Contact:

Post by capanno »

Maxxis: Very likely yes!

google images finds the perfect combo :lol:
Image
Josh Dies is my hero! |50,000,601.375 forum points
User avatar
rustypup
Registered User
Posts: 8872
Joined: 13 Dec 2004, 02:00
Location: nullus pixius demonica
Contact:

Post by rustypup »

Anakha56 wrote:have you tried a virus scan?
R50 says AVG freeware.....

the hidden cost of the alternate software-aquisition philosophy...
Most people would sooner die than think; in fact, they do so - Bertrand Russel
capanno
Registered User
Posts: 5727
Joined: 17 Apr 2004, 02:00
Location: PTA
Contact:

Post by capanno »

OT

I heard AVG is kinda crappy. I'm using it now... It says my system is clean, but I'm skeptical. What else can I use?
Image
Josh Dies is my hero! |50,000,601.375 forum points
M1K3
Registered User
Posts: 809
Joined: 13 Sep 2005, 02:00

Post by M1K3 »

A friend of mine has the following on a Vista PC and has Norton's 2k7: w32.rontobkro@mm and is having trouble removing it... It just keeps re appearing... has anyone ever had experience with this virus? If so any suggestions? I have done the google thing and followed Norton's instructions and from what I understand Norton's should have had no hassles clearing it up.
User avatar
rustypup
Registered User
Posts: 8872
Joined: 13 Dec 2004, 02:00
Location: nullus pixius demonica
Contact:

Post by rustypup »

@cappano: NOD32 or AntiVir..

NOD32 carries the best certification while its scan has got to be the lightest i've seen to date... and it's updates are tiny...

<edit>
@M1K3: don't you mean rontokbro?
</edit>

<edit2>
modified the comparatives link, (appears direct linking is disabled) - browse to the latest online results/report...
</edit2>
Last edited by rustypup on 30 Jul 2007, 15:42, edited 1 time in total.
Most people would sooner die than think; in fact, they do so - Bertrand Russel
capanno
Registered User
Posts: 5727
Joined: 17 Apr 2004, 02:00
Location: PTA
Contact:

Post by capanno »

Thanks rusty
Image
Josh Dies is my hero! |50,000,601.375 forum points
Xiphan
Registered User
Posts: 1435
Joined: 27 Feb 2007, 02:00
Location: Durban, South Africa

Post by Xiphan »

Have you ever thought about using a-squared Free for removal of malware/ adware? :?:
a-squared Free wrote:Security must not be a privilege. Under this motto, Emsi Software provides the Malware scanner a-squared Free completely free of charge for private use. But it is not a very limited version, it is a full tool to clean your computer from Malware. Not only Spywares, as detected by classic Anti-Spyware programs, but also especially Trojans, Backdoors, Worms, Dialers, Keyloggers and a lot of other destructive pests, which makes it dangerous to surf the web.
Sounds like it can remove quite a lot of nasties?
Image
Gatsby
Registered User
Posts: 1294
Joined: 14 Dec 2005, 02:00
Location: with stupid.

Post by Gatsby »

capanno wrote:R5 says its because of browsing questionable sites...
lolpr0n
Image

Lazarus - Shattered Halls

ek se hosh. dala kulids. ghle, ho! oom, atts! hoe lyk die kambotcha? gwallafest 2007
Gatsby
Registered User
Posts: 1294
Joined: 14 Dec 2005, 02:00
Location: with stupid.

Post by Gatsby »

capanno wrote:OT

I heard AVG is kinda crappy. I'm using it now... It says my system is clean, but I'm skeptical. What else can I use?
Nod32 my friend.
Image

Lazarus - Shattered Halls

ek se hosh. dala kulids. ghle, ho! oom, atts! hoe lyk die kambotcha? gwallafest 2007
1080
Registered User
Posts: 25
Joined: 18 Aug 2005, 02:00
Contact:

Post by 1080 »

I had a problem about a month ago

search forums and found SmitfraudFix its a small app no installation though there is a process to follow.
its a cross between a registry scanner and virus scanner
but it was pretty good in sorting out my problem ( continuous browser loads )

alternative you can try dss

google them for the download
Xiphan
Registered User
Posts: 1435
Joined: 27 Feb 2007, 02:00
Location: Durban, South Africa

Post by Xiphan »

I would love to use NOD32, but I'm also thinking of using Zone Alarm Internet Security Suite? Anyone know if it's any good?
Image
User avatar
Rid1
Registered User
Posts: 10339
Joined: 03 Sep 2004, 02:00

Post by Rid1 »

1080 wrote:I had a problem about a month ago

search forums and found SmitfraudFix its a small app no installation though there is a process to follow.
its a cross between a registry scanner and virus scanner
but it was pretty good in sorting out my problem ( continuous browser loads )

alternative you can try dss

google them for the download
Smitfraud is a crap piece of thing to be stuck with!!! For some reason it neevr wants to leave a PC at all - even after many hectic fixes and processes to be followed for its removal!!! Its also associated with virtumonde both of which are on this pc im using now! Gave up getting rid of it !
Image
viceroy
Registered User
Posts: 3565
Joined: 27 Mar 2006, 02:00
Location: I forget

Re: Malware help please -Killerbyte

Post by viceroy »

KillerByte wrote:hey guys

so it seems that I have picked up a nasty bit of malware.

what does this little nasty do? very simple. it starts up IE when I'm online and then directs to a number of sites. this is random in its choosing of which sites.

i have run spybot search and destroy and avast and neither pick up the nasty. I even ran the win xp version of Defender and nothing was detected
You really gotta stop going to those dodgy porn sites!!
Image
Locked