#$$^*&^%#$%^ Virus!!!
12 years ago
General
My computer is acting very strangely and slow. I'm pretty sure I got a virus, so if I disappear for a while that's why. Gonna play around and see what I can do but if it gets beyond me (which doesn't take much) I'll have to take it to the doctor. There's only one computer guy here and he tends to be pretty busy so........wish me luck.
FA+

Anyway...I THINK I'm okay.
The biggest problem is that basically all antivirus/antimalware programs are like Russian Roulette: you either win (i.e. you don't get infected) or you loose. And you don't see if chambers are spinning or not...
http://www.bleepingcomputer.com/download/rkill/
This is a little program that they have which I've used many times in cleaning my old computer, which essentially locks down and shuts off any program known to be malicious within your registry. After using this program you won't have Ransom ware pop up on your screen, so keeping it on the desktop where it's quick access is very nice to have. Mind you, this isn't a virus removal program, it's merely a "blocking agent" so you can truly remove a program that's being an ass with Malwarebytes. :)
I'd say get Linux and be immune, but my box got nailed with FoxAcid from an infected server
Now turn Javascript off when you surf those.... art sites. Yeah, art sites >_>
I scanned my box from my laptop and confirmed the infection with both Trend Micro and Avast.
There is no way to clean it. I just switched to FF3.0.6, which is immune to it and FF >24 is immune to it. Given I run such an old distro of *nix that I can't run the newer versions of FF, I just am going to wipe-and-reinstall.
What makes FoxAcid and the other NSA bugs so annoying is they are OS independent - Mac, *nix, BSD, Windows are all vulnerable.
Trend Micro has a Linux version? I never knew.
Can you please describe the symptoms?
I got suspicious when all my BW was being gobbled up whenever I fired up FF. I used Wireshark to sniff the packets and the computer was trying to connect to a Google run proxy. They had blocked the ports, so nothing was really getting out. But at the same time, the file-access-time for the files in my /home/ folder were attempting to be transferred to those IP address.... it was trying to upload my entire computer! I kill FF and it stopped.
Weird thing was on a program trace, nothing seemed unusual and the process tree was normal. Uninstalling and re-installing FF had no affect.
Chrome, Opera and Dillo aren't affected.
Only other thing I can suggest is to clean out the browser cache since that can get a bit clogged up over time. Also see if your hard drive needs defragging too.
All the basic maintenance stuff really.
If none of that works, it might be worth doing a quick check with another program called "HijackThis". It's more of a malware detector than an antivirus, but it's useful for its ability to show you everything that's running on your system as well as any registry keys that may have been altered. (Not that I'm recommending messing around in the registry though, as doing that has the potential to irreparably shaft your OS!)
Registry cleaners are usually ok, assuming you know which keys to tell it NOT to delete.
Normally the way they work is they have a record of the way your OS sets up the registry when first installed, so it looks for any changes to that (normally new registry keys added by installed programs rather than user customisation to the OS itself) and it'll flag them up. It's basically saying: "This registry key wasn't put here by your OS. Is it supposed to be here?"
So as long as you know which ones are supposed to be there, you can tell it to kill everything else.
HijackThis does something similar, by listing all changed registry keys and all currently running processes on the system (including ones that are capable of hiding from the Windows Task Manager!)
It can remove things that it's found, but I think most people tend to use its log-file function as a handy guide to seeing if there's anything unwanted that's managed to sneak onto their system.
If the registry thing is bothering you though, you could always run a check on it and note me with what it finds, and I'll tell you if anything there is suspicious.
Just don't accidentally tell it to delete everything it finds. That would likely screw up most of your installed programs!
But thanks for the offer. :)
I'm more than happy to play with your equipment anytime! hehe
*stares cutely at you, twitching his bunny nose and trying to look all sweet and innocent...*
Errr, I'm sure I have no idea what you mean! hehe
hehe
(Oh, also, might want to stop downloading all that midget elder porn, that stuff is not always reliable.)