PSA: Behold the Resurrection of EPIC THREAD

Page 3 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.
Status
Not open for further replies.

IronWing

No Lifer
Jul 20, 2001
72,834
33,878
136
I too caught something from the link. I got an oddball popup ad for a survey which just about never happens to me, setting off alarm bells. I tried running Ad Aware but it wouldn't load, which further freaked me out. I ran virus scan which came back clean. I installed the latest version of Ad Aware but it still won't run. Of course, in the mean time VirusScan and Flash decide that now looks like a good time to install an update...

Anyway, I'll run a full Virus Scan and see what comes up.
 

Bignate603

Lifer
Sep 5, 2000
13,897
1
0
I too caught something from the link. I got an oddball popup ad for a survey which just about never happens to me, setting off alarm bells. I tried running Ad Aware but it wouldn't load, which further freaked me out. I ran virus scan which came back clean. I installed the latest version of Ad Aware but it still won't run. Of course, in the mean time VirusScan and Flash decide that now looks like a good time to install an update...

Anyway, I'll run a full Virus Scan and see what comes up.

The laptop that I was on just finished up running malwarebytes and so far it seems to have killed the files BUT it didn't catch the registry edits that it did that blocked task manager from opening and prevents a normal login after you delete the files. Fix those first BEFORE you reboot or you might end up stuck in an endless login cycle.
 

MSCoder610

Senior member
Aug 17, 2004
831
0
71
The laptop that I was on just finished up running malwarebytes and so far it seems to have killed the files BUT it didn't catch the registry edits that it did that blocked task manager from opening and prevents a normal login after you delete the files. Fix those first BEFORE you reboot or you might end up stuck in an endless login cycle.

Any links to more info about the registry edits? I hardly reboot but I don't want to suddenly be locked out of my PC in a couple weeks after I've forgotten about this.
 

yh125d

Diamond Member
Dec 23, 2006
6,886
0
76
petition to bring it back or something?




whatever it is, add me to the list
 

Bignate603

Lifer
Sep 5, 2000
13,897
1
0
Any links to more info about the registry edits? I hardly reboot but I don't want to suddenly be locked out of my PC in a couple weeks after I've forgotten about this.

http://www.symantec.com/connect/forums/wormwin32netsky?page=1

It's not actually the netsky worm, that's just the fake warning that it spits out. The registry issues are there on that page but it's a relatively long read.

I found that while malwarebytes got some things I've still got something parading as srss.exe and I think as csrss.exe. The suspicious smss.exe is in the i386 directory (everything I've read says it should be in windows/system32) and when if I try to do anything with it it says the drive can't be read.
 

ElFenix

Elite Member
Super Moderator
Mar 20, 2000
102,402
8,574
126
The laptop that I was on just finished up running malwarebytes and so far it seems to have killed the files BUT it didn't catch the registry edits that it did that blocked task manager from opening and prevents a normal login after you delete the files. Fix those first BEFORE you reboot or you might end up stuck in an endless login cycle.

my sister got a fake virus scanner that mimicked windows security center and then decided to install a second fake virus scanner (paladin). took a couple runs of malwarebytes and her regular antivirus to clean all that crap out. she said all she had been browsing was facebook.
 

lokiju

Lifer
May 29, 2003
18,526
5
0
I got a background pop-up also but guess since I'm on Os X it's a non issue.

I'd say it's a megaupload issue, not an issue of the OP though.
 

JulesMaximus

No Lifer
Jul 3, 2003
74,580
982
126
Believe it, the laptop I owned it on is currently running malwarebytes because it got something nasty after hitting the link. It keeps on popping up warnings that I've got a virus (all fake, from the malware itself), it sticks things in the registry to screw with your login, and to prevent you from opening task manager.

That happened to me too. Fucking pain in the ass getting that malware off my computer too.
 

DrPizza

Administrator Elite Member Goat Whisperer
Mar 5, 2001
49,601
167
111
www.slatebrookfarm.com
We just had a message at work from our IT guy last week - apparently there's a pop up out there that if you click on the "x" to close the window - that's conveniently the install button. Sounds like that could possibly be what happened?
 

szechuanpork

Senior member
Aug 24, 2003
455
0
76
Was there a dutch rudder involved?

dutchruddertshirt.gif
 

destrekor

Lifer
Nov 18, 2005
28,799
359
126
I got a background pop-up also but guess since I'm on Os X it's a non issue.

I'd say it's a megaupload issue, not an issue of the OP though.

Yeah I have NO idea how that damn popup sneaked through. I never get popups.
megaupload does suck something fierce though.
 

Kelvrick

Lifer
Feb 14, 2001
18,422
5
81
We just had a message at work from our IT guy last week - apparently there's a pop up out there that if you click on the "x" to close the window - that's conveniently the install button. Sounds like that could possibly be what happened?

That is pretty convenient. Now that I think about it, I think there was a popup, but I did a right click on the task bar and close. Almost second nature and I didn't even realize it until now.
 

destrekor

Lifer
Nov 18, 2005
28,799
359
126
That is pretty convenient. Now that I think about it, I think there was a popup, but I did a right click on the task bar and close. Almost second nature and I didn't even realize it until now.

Hmm.
I closed the pop-under ad with the X button.
Using Windows 7, have Microsoft Security Essentials installed, but more importantly, NoScript and ABP on Firefox 3.5.7 (still haven't upgraded to 3.6, don't know why...)
If this ad was indeed a nasty bitch, I think NoScript saved my PC.

I didn't think to look if NoScript blocked any actions of the ad, I think I was just more in shock at "wait, WTF is this? Aw hell no!"
 
Status
Not open for further replies.