2/28/2013 - Update on Thumb
12/31/2012 - There's a New Comic
12/12/2012 - The "Lost" Holiday Ornament (and Child's Play)
11/26/2012 - Leftover OOTS Swag on Sale (+Thumb Report)
Frequently Asked Questions (FAQ)

Order of the Stick 889 Get Real
Erfworld 163 The End of Book One
Erfworld Now at Erfworld.com!
RSS Feeds: OOTS

The Duke's Wolf, Part Four by Amber E. Scott
The Duke's Wolf, Part Three by Amber E. Scott
The Duke's Wolf, Part Two by Amber E. Scott

The New World, Part 9: Barbarians by Rich Burlew
The New World, Part 8: Gnomes by Rich Burlew
The New World, Part 7: Names and Cultures by Rich Burlew
Looking for the Gaming Articles?

 



Welcome back! Be sure you have read and understand the Forum Rules.


Go Back   Giant in the Playground Forums > Discussion > Friendly Banter
Register FAQ Members List Mark Forums Read End

Friendly Banter Hellos, goodbyes, and other casual conversation goes here. Especially if it doesn't fit better into one of the other forums.

Reply
 
Thread Tools
Old 12-04-2011, 01:17 AM   Top  -  End  -  #1
Lorn
Barbarian in the Playground
 
 
Join Date: Oct 2007
Default So looks like I've been virused.

And, because I figure someone else might have had a similar problem, I'm posting here.

Stuff:
OS is Windows 7
Antivirus is AVG, scanning now
Browser that I use is Firefox

What happened:

Visited http://www.minecraftdl.com/sky-block-survival-map/ to download a minecraft map.

Hit the download button, skipped the ad etc.

At this point, I'm hit by a metrick ****ton of popups. Screenshot of History is here:

Spoiler


At this point, computer slows to a crawl, and Internet Explorer opens for some reason. The "webpage cannot be displayed while offline" notice comes up, I try to close IE down, and it fullscreens - as in, completely. No toolbars, no nothing. I press Ctrl+Alt+Del, and it comes up as normal - except no Task Manager.

I restart the computer, and notice that it flashes back to my normal desktop etc before closing down.

Turn it back on, and as soon as I log on, internet explorer comes straight back up with the same message. Same fullscreen thing happens. Shut down as with the previous time, except this time, I manage to hit start>run and type in shutdown -a to prevent the computer shutting down as soon as my normal desktop appears.

Which brings us to here and now.

Other stuff: While AVG is scanning, does not appear in system tray.
AVG, Notepad - neither is appearing on the standard taskbar.
I tried opening task manager through start>run, and apparently it has been "disabled by my administrator" - which is a load of rubbish, because I am the admin, and I've not disabled it :p
I have managed to use tasklist to get the following list of processes running:

Spoiler

I recognise about half of these, meaning there isn't too much to go on...
Also, there is a shortcut to a program that I do not recognise in my startup folder - 0.5257090694921712.exe. I have no idea what this is, and have deleted the shortcut after having saved the target - full target is
Code:
C:\Windows\System32\rundll32.exe C:\Users\ADMINI~1\AppData\Local\Temp\0.5257090694921712.exe,SuppS

Anyone got any ideas, heard of anything like this before, got any kind of baseline for me to start doing things with?

Thanks a lot.
Lorn is offline   Reply With Quote
Old 12-04-2011, 01:58 AM   Top  -  End  -  #2
Bhu
Ettin in the Playground
 
 
Join Date: Mar 2008
Location: 
Hell itself (Ohio)
Gender: Male
Default Re: So looks like I've been virused.

You tried restarting in safe mode?
__________________
Revised avatar by Trixie, New avvie by Crisis21!
Mah Fluffy Death Critters
Orcs and Goblins
Behold the Power of Kitteh!
Backup threads available here
Bhu is offline   Reply With Quote
Old 12-04-2011, 02:43 AM   Top  -  End  -  #3
Savannah
Ettin in the Playground
 
 
Join Date: Feb 2010
Location: 
Texas. It's too hot here.
Gender: Female
Default Re: So looks like I've been virused.

If AVG doesn't clear it up, you might want to try MalwareBytes -- it's free and it saved me from my last virus. (Not the same as yours, but still nasty.)
__________________
Playing: Rána, Jarek
DMing: Beginners game (OOC); Dungeoncrawl (OOC)


Savannah is online now   Reply With Quote
Old 12-04-2011, 03:38 AM   Top  -  End  -  #4
Lorn
Barbarian in the Playground
 
 
Join Date: Oct 2007
Default Re: So looks like I've been virused.

Ok, update.

After about four and a half hours of working at it, I think I've got it sorted.

Managed to unblock taskmgr, deleted the obviously dodgy .exe file, and there's no dodgy looking processes running.

AVG can find nothing, and I've fixed everything that MBAM found (thanks for the recommendation, Savannah, someone else said the same, it found a couple things that I'd managed to fix and more importantly it found a shortcut to the disable-task-manager-thing.)

So, looks like I'm OK.

Just going to be real careful on here for the next two weeks just in case there's something left over, then when I go home over New Years I'll be reformatting anyway, so it will totally cease being an issue.


Thanks for the help :)

Last edited by Lorn : 12-04-2011 at 03:43 AM.
Lorn is offline   Reply With Quote
Old 12-04-2011, 09:18 PM   Top  -  End  -  #5
H Birchgrove
Bugbear in the Playground
 
 
Join Date: Jan 2011
Location: 
Växjö, Sweden
Gender: Male
Default Re: So looks like I've been virused.

Can one use the program Savannah linked to without disturbing the anti-virus program you already have?
__________________
Viking/Paladin by Astrella

Gender Bender by Geomancer.

In love with Skeppio.

Contact me:
Spoiler


H Birchgrove is offline   Reply With Quote
Old 12-04-2011, 09:32 PM   Top  -  End  -  #6
Savannah
Ettin in the Playground
 
 
Join Date: Feb 2010
Location: 
Texas. It's too hot here.
Gender: Female
Default Re: So looks like I've been virused.

I have Microsoft Security Essentials as my main antivirus, but also have MalwareBytes and SuperAntiSpyware on there -- the free versions of both don't do real-time scanning, so I just use them to scan the computer once a week. In short, yes, you can.
__________________
Playing: Rána, Jarek
DMing: Beginners game (OOC); Dungeoncrawl (OOC)


Savannah is online now   Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off



All times are GMT -5. The time now is 08:03 PM.



Powered by vBulletin®
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Usage of this site, including but not limited to making or editing a post or private message or the creation of an account, constitutes acceptance of the Forum Rules.