Jump to content

Recommended Posts

Posted

Had a laptop given to me this week by someone at a charity where I do support. Turned it on and discovered Norton AntiV was last updated May 2005......

 

....so say hello to 30-odd trojans and god-knows-what-else with all sorts of weird and wonderful Windows behaviour. Stripped everything off but it was still acting like a lame horse that needed shooting so I went for the easy option and re-installed the OS. Life's to short to bu@@er about with this kind of cr@p anymore and that's why I use Macs at home and Ubuntu as well.

 

:troll:

  • 2 weeks later...
Posted

I recently experienced problems very similar to what is described here. In the beginning, I got a popup from Windows firewall that it had blocked "netsky.q" a well-known worm...gave a little info, and had 3 buttons at the bottom - keep blocking, stop blocking, or enable protection. All but enable protection was greyed out. This threw up a flag at me, as this was a work computer with our own firewall, and windows firewall is disabled. I started getting wierd messages, but they looked very convincing if it hadn't been for this realization. I have several browsers, and all of them either crashed when trying to navigate, or in IE part of the time gave a warning page of unsafe browsing. Links were skinned if it allowed you to do a search. Other programs connecting to the internet also crashed, like email, or excel if using a file from the network. I booted into safe mode, and looked at the startup, finding a file fhexj......, which i disabled, and also found several instances in the registry, one by the same name, one named windpipe, and a few others. Searching for the files with the string fhexj came up with a folder named "google" that contained the file, which stole the icon from windows firewall. This had nothing to do with Google at all...and I deleted the entire folder.

 

Getting rid of the reg keys, startup value, and google folder brought back functionality to browsing...however, it is very slow. My process list keeps showing exes running with a random string name, which are located in the temp folder. Scanning with virus protection finds instances containing tdss in all of them, like bkdr_tdss.au, but can only clean or delete some of them, even in safe mode. I'm still looking for the end solution, but for now everything at least works. I'll repost if I find what's the culprit.

  • 4 weeks later...
Posted
Yeah, TDSS is hideous. Just been cleaning a staff home machine which was rife with nasties. Windows Defender, Sophos and AdAware found 2 each, then MalwareBytes Antimalware found 6 more. I too highly recommend MBAM, seems to find stuff that nothing else does. Even getting MBAM to install was fun though as one infection killed the installer - solution on their forum here : MBAM will not run - Malwarebytes Forum. The original and worst infection was the same one detailed in this fine article : Anatomy of a malware scam ? The Register. The fake Windows Security Center is a nice touch and would probably fool (or certainly confuse) a lot of even our more clued up customers...
Posted
Cop out. Don't learn anything that way.

Depends if you are doing it for fun or profit. :)

 

I had a similar problem a while back, was a bugger to fix. The winsock fix sounds familiar.

Posted
I recently experienced problems very similar to what is described here. In the beginning, I got a popup from Windows firewall that it had blocked "netsky.q" a well-known worm...gave a little info, and had 3 buttons at the bottom - keep blocking, stop blocking, or enable protection. All but enable protection was greyed out. This threw up a flag at me, as this was a work computer with our own firewall, and windows firewall is disabled. I started getting wierd messages, but they looked very convincing if it hadn't been for this realization. I have several browsers, and all of them either crashed when trying to navigate, or in IE part of the time gave a warning page of unsafe browsing. Links were skinned if it allowed you to do a search. Other programs connecting to the internet also crashed, like email, or excel if using a file from the network. I booted into safe mode, and looked at the startup, finding a file fhexj......, which i disabled, and also found several instances in the registry, one by the same name, one named windpipe, and a few others. Searching for the files with the string fhexj came up with a folder named "google" that contained the file, which stole the icon from windows firewall. This had nothing to do with Google at all...and I deleted the entire folder.

 

Getting rid of the reg keys, startup value, and google folder brought back functionality to browsing...however, it is very slow. My process list keeps showing exes running with a random string name, which are located in the temp folder. Scanning with virus protection finds instances containing tdss in all of them, like bkdr_tdss.au, but can only clean or delete some of them, even in safe mode. I'm still looking for the end solution, but for now everything at least works. I'll repost if I find what's the culprit.

 

Had a very similar thing happen to my laptop. I am well seasoned at removing nasties from computers and this one gave me no end of grief. Short of removing the hard disk and then scanning it from another PC I was stumped. In the end I just put Ubuntu on it instead. Since everyone seems to think my Laptop is for communal use this has been the only way to keep nasties off of it.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...