ChiefsPlanet

ChiefsPlanet (https://www.chiefsplanet.com/BB/index.php)
-   Media Center (https://www.chiefsplanet.com/BB/forumdisplay.php?f=2)
-   -   Computers The Official Malware/Antivirus Thread - Need help or general advice? Read this first! (https://www.chiefsplanet.com/BB/showthread.php?t=232173)

The Franchise 06-24-2014 11:09 AM

Quote:

Originally Posted by Fish (Post 10712290)
Dude, that system is a mess.

Looks like it's infected with Snap.Do, according to this line:

C:\Users\dcbrummer\AppData\Local\LPT\srptm.exe

That will take over your browser and change your browser settings/homepage/search/etc.
Manually remove Snap.Do: http://www.pcthreat.com/parasitebyid-24962en.html

Likely related, but your browser search is already hosed, according to this line:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://feed.helperbar.com/?p=mKO_AwF...YQICtkYCoZLrIj PJfQr0xIk08q-vF_N19VuJ-xynJ4wg,,&q={searchTerms}

The following lines very likely could be a rootkit:

O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')

Are you in a managed corporate environment or something? You've also got a program called DesktopAuthority running. It's a pretty powerful IT Admin app that can give the admin pretty much complete control of your computer. It can even monitor keystrokes and shit if the admin chose to use it that way. If you're in a corporate managed environment, it's probably OK. But if not, that could be serious trouble. I notice it's an Alienware with lots of normal consumer stuff, but also some admin stuff and Papercut client.

Regardless, your system need to be cleaned ASAP. I'd recommend a complete reimage or reinstall if possible. It might already be too far gone. But you might be able to resuscitate it. I'd run the malware cleaners listed in the OP. I'd also include Malwarebytes Anti-malware.

Considering all the unnecessary stuff running in the background, your system would feel like a new machine if you would format and reinstall. If you're in a corp environment, tell your IT to backup and reimage that mofo.

Yeah....work environment. I ran Malwarebytes and removed around 20 different ****ing things. I've now run it two more times just to make sure it didn't miss anything. Desktop Authority and Papercut are mandated by my work....so they aren't going anywhere.

Fish 06-24-2014 11:57 AM

I'd run EliteKiller as well. Or Spybot/Superantispyware. Just to be sure.

You might also consider deleting your old restore points. Shit can reinfect a system that way.

Quote:

To delete all restore points

Open System by clicking the Start button Picture of the Start button, right-clicking Computer, and then clicking Properties.

In the left pane, click System protection. Administrator permission required If you're prompted for an administrator password or confirmation, type the password or provide confirmation.

Under Protection Settings, click Configure.

Under Disk Space Usage, click Delete.

Click Continue, and then click OK.
Tell your IT to get a real antivirus client that can prevent that shit. McAfee sucks goat balls.

The Franchise 06-24-2014 12:05 PM

Quote:

Originally Posted by Fish (Post 10712397)
Tell your IT to get a real antivirus client that can prevent that shit. McAfee sucks goat balls.

I tell them that all the time. It's the government....so it comes down to "whatever is cheaper to run".

DaveNull 06-24-2014 06:16 PM

Unless you got infected doing something on your work computer that you shouldn't have been doing, it's not your ****ing problem.

ROYC75 09-04-2014 02:16 PM

Pepper zip ? WTF ?
 
My file extensions are trying to be sent as a Pepper Zip now ? I have scanned the pc, found the uninstall icon, done that but there is still an intact file attachment somewhere. I can not compress a file to email out to a client.

Anybody have any info on a pepper zip ?

Fish 09-04-2014 02:19 PM

Quote:

Originally Posted by ROYC75 (Post 10879023)
My file extensions are trying to be sent as a Pepper Zip now ? I have scanned the pc, found the uninstall icon, done that but there is still an intact file attachment somewhere. I can not compress a file to email out to a client.

Anybody have any info on a pepper zip ?

Follow these instructions, and it should take care of it:

http://botcrawl.com/remove-pepperzip-virus/

ROYC75 09-04-2014 02:44 PM

Quote:

Originally Posted by Fish (Post 10879028)
Follow these instructions, and it should take care of it:

http://botcrawl.com/remove-pepperzip-virus/

I had already did this first, used the Hitman then followed it up with Malwarebytes, of which it is scanning a 2nd time now after rebooting.

Any file I try to send out as a zip is a pepper file attachment, of which is not going through. I can't find a damn thing that is still linked up to holding it up.
I even went in and tried to restore the previous file I want to send, but it is coming back as a pepper file, no matter how far I go back.

Again, I am still awaiting for Malwarebytes & Hitman Pro to scan a 2nd time.

Fish 09-04-2014 03:34 PM

Quote:

Originally Posted by ROYC75 (Post 10879103)
I had already did this first, used the Hitman then followed it up with Malwarebytes, of which it is scanning a 2nd time now after rebooting.

Any file I try to send out as a zip is a pepper file attachment, of which is not going through. I can't find a damn thing that is still linked up to holding it up.
I even went in and tried to restore the previous file I want to send, but it is coming back as a pepper file, no matter how far I go back.

Again, I am still awaiting for Malwarebytes & Hitman Pro to scan a 2nd time.

When you say "Any file I try to sent out", what are you talking about? What program are you using for that?

ROYC75 09-04-2014 06:12 PM

Quote:

Originally Posted by Fish (Post 10879265)
When you say "Any file I try to sent out", what are you talking about? What program are you using for that?

Just documents in a pdf that I send out to new carriers for a set up process. I had it in a zip folder and everything worked great for 14 years. Now the damn folder is a pepper file zip and I have no clue as to why and when we tried to clean it up it leaves a folder with a padlock on it that that has the impression of a busted file.

I can delete it, copy a new file, zip it and it goes to another pepper file, that looks the same. I can not go back to a previous version of that file to change anything.

I can't find anything that is listed to do with pepper except that pdf file that I make when I zip it. I'm thinking it came along with the chrome that was downloaded one day while I was away.

Fish 09-04-2014 10:11 PM

That file might be hosed then. The padlock means you don't have permission to it. Don't you have a backup copy of that?

You can try and change the permissions on the file, but there's a likelihood that it's infected and you surely don't want to risk sending a potentially infected file to your carriers.

DaveNull 09-05-2014 06:50 AM

If these forms have info on the carriers like EINs or drivers license numbers you sure should be taking this seriously to back your stuff up and reinstall Windows.

ROYC75 09-05-2014 08:01 AM

Quote:

Originally Posted by Fish (Post 10880811)
That file might be hosed then. The padlock means you don't have permission to it. Don't you have a backup copy of that?

You can try and change the permissions on the file, but there's a likelihood that it's infected and you surely don't want to risk sending a potentially infected file to your carriers.

File is not damaged, when I click to compress it, it goes to a Pepper Zip file. I have never heard of it, Pepper Zip ? I can open it up, do anything I want except compress it to send out.

I downloaded a free trial on winzip, I can send it that way, but I don't want to buy winzip and it's a pain in the ass anymore to use.


Quote:

Originally Posted by DaveNull (Post 10881057)
If these forms have info on the carriers like EINs or drivers license numbers you sure should be taking this seriously to back your stuff up and reinstall Windows.

Nothing personal, just basic company information that needs to be exchanged before a contract is written in place.

ThaVirus 09-06-2014 12:37 PM

Hey, peops, I could use some help.

I just logged on Google Chrome on my computer a minute ago and a little pop up told me something along the lines of "Your internet connection is being controlled" and some other jazz. It prompted me to go into the settings and return them to normal. When I clicked on the settings to 'learn more' it says that I have to delete the extension and then restore my settings.

Problem is, I don't remember downloading any extensions and don't know exactly how to find it because I wouldn't even know what belongs and what doesn't.

So I ask you guys: for one, is this some kind of thing that's trying to get me to adjust my settings or do I actually need to find and delete this "extension"? And if so, how would I go about finding it?

I have Microsoft Security Essentials, for the record. The last time I had my computer on it said it had located and quarantined some malware. I then deleted it..

ThaVirus 09-06-2014 12:44 PM

Hmmm. Well, looks like I had two extensions on Chrome. I just deleted them both and now I'll run a virus check... I really wish I was more computer literate but hopefully I don't have any issues from this point forward..

ROYC75 09-10-2014 09:39 AM

Quote:

Originally Posted by ThaVirus (Post 10884405)
Hmmm. Well, looks like I had two extensions on Chrome. I just deleted them both and now I'll run a virus check... I really wish I was more computer literate but hopefully I don't have any issues from this point forward..


Have you ran malwarebytes to check for anything else?

ThaVirus 09-10-2014 10:01 AM

The Official Malware/Antivirus Thread - Need help or general advice? Read thi...
 
I ran a Microsoft Security Essentials check but not Malware Bytes.

I'll do that one as well next time I get on my computer.

Fairplay 09-21-2014 10:51 AM

I have an issue with my iPhone lately my battery has been running down all the time I think a program must be on but I think they are all off but not sure.

Any suggestions?

ThaVirus 09-22-2014 01:25 PM

Do you close all of your apps periodically?

Fairplay 10-10-2014 07:22 PM

I need professional help.

I have an iPhone 5, I rebooted it about a month ago and now I can't retrieve any text messages before then.

Is there a way I can retrieve past text/pic messages.

Arrowhead Thunder 10-12-2014 01:53 PM

Xfinity speed?

Just got xfinity a few weeks ago, supposed to be 25 Mbps.
Regularly getting <5 down and as much as 8 up. Have to reset the router 2-3 times/day. After I reset it get up to 30 down. Anyone else have these problems know a fix? A tech is supposed to come out later this week, but the dude on the phone basically said resetting the router is the only way.

L.A. Chieffan 10-27-2014 09:23 AM

Stupid computer question: How do I have multiple windows open at the same time without them closing when I click around? In other words my Samsung Note 3 has a feature where I can watch a youtube video and surf chiefsplanet at the same time, I should be able to do it on my PC too but Im a reerun and cant figure it out. I know how to minimize and open up other tabs and what not but as soon as I click on one window the other one collapses. Any help for dummy

TheUte 10-29-2014 01:35 PM

ALT+TAB goes through your open programs, does that answer the question.

DaveNull 10-30-2014 02:14 PM

LA Chieffan is still on Windows for Workgroups. Pass it on.

Arrowhead Thunder 11-17-2014 08:44 AM

Anyone have experience with open source GIS software? Any suggestions on a particular product that has worked well?

durtyrute 01-14-2015 02:45 PM

Does anyone know how to get into a password protected computer without the password?
My uncle died and we can't get into two of his three laptops.

Mr. Plow 01-15-2015 08:50 AM

Quote:

Originally Posted by durtyrute (Post 11269151)
Does anyone know how to get into a password protected computer without the password?
My uncle died and we can't get into two of his three laptops.


I think this is what I've used a few times. Someone else may have something that works better.

http://ophcrack.sourceforge.net/

durtyrute 01-15-2015 09:02 PM

Quote:

Originally Posted by Mr. Plow (Post 11270151)
I think this is what I've used a few times. Someone else may have something that works better.

http://ophcrack.sourceforge.net/

Hey, thanks man. This is for my sister. I've passed it on and I'll let you know how it works.

Rep to you kind sir

Mr. Plow 01-15-2015 10:45 PM

Quote:

Originally Posted by durtyrute (Post 11271426)
Hey, thanks man. This is for my sister. I've passed it on and I'll let you know how it works.

Rep to you kind sir

No problem. Hope it works out for you guys.

DaveNull 01-16-2015 07:23 AM

Quote:

Originally Posted by durtyrute (Post 11269151)
Does anyone know how to get into a password protected computer without the password?
My uncle died and we can't get into two of his three laptops.

No offense to Plow, but it's going to be a lot easier to just go buy a SATA to USB adapter at Micro Center and plug the drives from these two laptops into one that you can use. You won't be able to boot the computer, but you can get to all the data that was on there.

Mr. Plow 01-16-2015 08:28 AM

Quote:

Originally Posted by DaveNull (Post 11271706)
No offense to Plow, but it's going to be a lot easier to just go buy a SATA to USB adapter at Micro Center and plug the drives from these two laptops into one that you can use. You won't be able to boot the computer, but you can get to all the data that was on there.

None taken.

Bearcat 01-16-2015 05:50 PM

Another option that's free, but requires a bit more work, is to create an Ubuntu DVD or bootable USB... you can then boot to it and use the preview feature, which won't install anything, but will give you access to all of your files in Windows.

But, if all of that is Greek, then yeah, just buy the adapter for $15-20.

BWillie 01-17-2015 02:00 AM

Don't really want to make a thread for this, so I'll just leave this here...

Looking to buy another desktop computer, that MUST support my 30 inch 2560 x 1600 resolution monitor via DVI. Want to find out if the computer I have now is worse or better than the one I am trying to buy. And/or what the cheapest comparable computer I could get in today's market to the one I have now.

My current computer is an HP with Windows 7, Hitachi HD S721010CLA332 SATA Disk, SSD G2 series 64GB, AMD Phenom II X4 840T Processor 2.90 GHz, 6 GB ram.

I am thinking about buying this computer for $200

Core 2 Quad Q9650 3.0GHz
- 8GB of RAM DDR2 800MHz
- 250GB Samsung SSD
- ATI HD 3450 Graphics

Hammock Parties 08-05-2015 10:29 PM

Why are my images loading corrupted?

http://i.imgur.com/CrS9Wqq.png

Bowser 08-17-2015 10:20 AM

So why do I get this prompts from Adobe Flash (and they are pretty much constant), and what do I do to fix this?

TypeError: Error #1010: A term is undefined and has no properties.
at com.ensemble.customUnits::DynamicDesign_728x90/init()
at com.ensemble.suif.widgets::DynamicAdWidget/onTddInit()
at flash.events::EventDispatcher/dispatchEventFunction()
at flash.events::EventDispatcher/dispatchEvent()
at com.ensemble.suif.models::AdModel/set dataModel()
at com.ensemble.suif.components::TumriBase/onInit()
at flash.events::EventDispatcher/dispatchEventFunction()
at flash.events::EventDispatcher/dispatchEvent()
at com.tumri.tada.components::TumriLibrary/reDispatchEvent()
at flash.events::EventDispatcher/dispatchEventFunction()
at flash.events::EventDispatcher/dispatchEvent()
at com.tumri.tada.components::TumriLocalRuntime/fireTumriInitEvent()
at com.tumri.tada.components::TumriLocalRuntime/contentLoaded()
at com.tumri.tada.components::TumriLocalRuntime/onLibraryInit()
at flash.events::EventDispatcher/dispatchEventFunction()
at flash.events::EventDispatcher/dispatchEvent()
at com.tumri.tada.components::TumriRuntime/onDataUtilComplete()
at flash.events::EventDispatcher/dispatchEventFunction()
at flash.events::EventDispatcher/dispatchEvent()
at com.tumri.tada.utils::DataUtil/dispatchCompleteEvent()
at com.tumri.tada.utils::DataUtil/init()
at com.tumri.tada.components::TumriRuntime/finishedInit()
at flash.events::EventDispatcher/dispatchEventFunction()
at flash.events::EventDispatcher/dispatchEvent()
at com.tumri.tada.components::TumriLocalRuntime/onRuntimeLibraryLoaded()

blaise 09-03-2015 02:17 PM

For some reason my twitter account only shows hashtag topics on the trending topic list. Some setting must have changed. But it's annoying because generally hashtags are dumb.

Anyone know how to change it?

Mr. Plow 11-11-2015 10:41 AM

Alright guys, hoping you all can help me.

Got a couple computers on my network that have the Cryptowall Virus.

I haven't successfully removed it, but all indications are that Malwarebytes will take care of it. Can't seem to find anything online about decrypting the files - all seems to point to that it can't be done.

So, I turn to you guys - is there a way that I haven't located yet to decrypt the files or am I screwed on these couple machines?

Fish 11-11-2015 11:39 AM

Quote:

Originally Posted by Mr. Plow (Post 11876361)
Alright guys, hoping you all can help me.

Got a couple computers on my network that have the Cryptowall Virus.

I haven't successfully removed it, but all indications are that Malwarebytes will take care of it. Can't seem to find anything online about decrypting the files - all seems to point to that it can't be done.

So, I turn to you guys - is there a way that I haven't located yet to decrypt the files or am I screwed on these couple machines?

If data has already been encrypted, you're ****ed.

Mr. Plow 11-11-2015 12:20 PM

Quote:

Originally Posted by Fish (Post 11876474)
If data has already been encrypted, you're ****ed.

That's what I was afraid of.

Fairplay 01-23-2017 07:55 PM

My computer is six years old, I'm not much of gamer but want a computer to play the games that people play these days. Because I need a little play time like 10 hours a week.

Limited budget, I don't want to go the build route.

I'm thinking of one of these with maybe a 8 gig memory upgrade to 16.
Thoughts on which one is to go with?

https://www.amazon.com/CYBERPOWERPC-...ds=computer+pc

or

https://www.amazon.com/dp/B01LAG8KEK?psc=1

DaneMcCloud 01-24-2017 02:38 PM

Quote:

Originally Posted by Fairplay (Post 12705790)
My computer is six years old, I'm not much of gamer but want a computer to play the games that people play these days. Because I need a little play time like 10 hours a week.

Limited budget, I don't want to go the build route.

I'm thinking of one of these with maybe a 8 gig memory upgrade to 16.
Thoughts on which one is to go with?

https://www.amazon.com/CYBERPOWERPC-...ds=computer+pc

or

https://www.amazon.com/dp/B01LAG8KEK?psc=1

IMO, both are too much money for the value. i5, no SSD's, at $719?

Whew, that's bank.

I'd buy this before either of those computers:

https://www.amazon.com/dp/B01F3R9H7Q...019TTJDY6?th=1

Fairplay 01-24-2017 07:17 PM

Quote:

Originally Posted by DaneMcCloud (Post 12706996)
IMO, both are too much money for the value. i5, no SSD's, at $719?

Whew, that's bank.

I'd buy this before either of those computers:

https://www.amazon.com/dp/B01F3R9H7Q...019TTJDY6?th=1

Interesting, I'll have to check into that, thanks for your opinion Dane.

DaneMcCloud 01-24-2017 08:37 PM

Quote:

Originally Posted by Fairplay (Post 12707371)
Interesting, I'll have to check into that, thanks for your opinion Dane.

I'd grab the Dell, upgrade the RAM and throw in at least 250 gig SSD for your system drive, then move the installed drive to SATA 1 and use it as backup.

Rasputin 02-16-2017 02:16 PM

Well shit **** damn. My home PC got the AIDS Virus and it said call this free number and I couldn't understand the India Indian so I got a tad mad through my new phone at hard drive and I think my computer is fubar now. But my phone is working.

This is new for me to post via phone.

This pisses me off. Now going have to get new computer i can't afford next week.

Fish 02-16-2017 07:54 PM

Quote:

Originally Posted by KC Tattoo (Post 12743989)
Well shit **** damn. My home PC got the AIDS Virus and it said call this free number and I couldn't understand the India Indian so I got a tad mad through my new phone at hard drive and I think my computer is fubar now. But my phone is working.

This is new for me to post via phone.

This pisses me off. Now going have to get new computer i can't afford next week.

If it says call any number, good ****ing grief, do not call the number. It's a scam. Run the recommended scanners from this thread.

Bearcat 06-20-2017 09:58 PM

So, this post is almost 7 years old, and beyond this thread, I don't know how much demand there is for this type of stuff around here. If someone wants to take over the OP, feel free to post updates or redo the entire thing (a few links don't even work any longer) and I'll edit mine... or start your own thread and dive into the brave new world of Windows 8/10 and ransomware, etc; and I'll unsticky this one and sticky your thread.

Mr. Plow 06-29-2017 07:18 AM

Quote:

Originally Posted by Bearcat (Post 12924769)
So, this post is almost 7 years old, and beyond this thread, I don't know how much demand there is for this type of stuff around here. If someone wants to take over the OP, feel free to post updates or redo the entire thing (a few links don't even work any longer) and I'll edit mine... or start your own thread and dive into the brave new world of Windows 8/10 and ransomware, etc; and I'll unsticky this one and sticky your thread.

How about no?

Bowser 06-29-2017 10:59 AM

Quote:

Originally Posted by Mr. Plow (Post 12936391)
How about no?

Everyone send Mr. Plow a PM when you have an antivirus question from here on out. Thanks in advance.

Mr. Plow 06-29-2017 11:34 AM

Quote:

Originally Posted by Bowser (Post 12936635)
Everyone send Mr. Plow a PM when you have an antivirus question from here on out. Thanks in advance.

I'll be tech support.

"Oh, how do you get rid of pop ups? Sorry bro, computer is toast. Gotta throw it out and get a new one."

"Excel keeps screwing up? Yup, that's fatal man. Get you a new computer."

Bearcat 06-30-2017 11:15 PM

Quote:

Originally Posted by Mr. Plow (Post 12936693)
I'll be tech support.

"Oh, how do you get rid of pop ups? Sorry bro, computer is toast. Gotta throw it out and get a new one."

"Excel keeps screwing up? Yup, that's fatal man. Get you a new computer."

https://media.giphy.com/media/ZZiLDJ98R2GOY/giphy.gif

Fansy the Famous Bard 04-16-2018 01:05 PM

Bump for reuse!

Hammock Parties 01-22-2019 06:20 PM

Taking the CompTIA A+ 901 Certification on Friday.

Passed all my practice tests.

https://media.giphy.com/media/4KxeicCUTvhrW/giphy.gif

vailpass 01-22-2019 07:38 PM

Quote:

Originally Posted by Hammock Parties (Post 14065325)
Taking the CompTIA A+ 901 Certification on Friday.

Passed all my practice tests.

https://media.giphy.com/media/4KxeicCUTvhrW/giphy.gif

Cool, good luck. You thinking of teching for a side hustle? Run your own business?

Hammock Parties 01-22-2019 07:40 PM

Quote:

Originally Posted by vailpass (Post 14065549)
Cool, good luck. You thinking of teching for a side hustle? Run your own business?

Maybe, but I'm going to start the network security career path and see how it goes.

At the very least I should be able to get a job at some PC repair shop. Not sure what else the A+ alone will get you. Anyone has any leads I'd appreciate them.


All times are GMT -6. The time now is 10:02 AM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2024, vBulletin Solutions, Inc.