[a / b / c / d / e / f / g / gif / h / hr / k / m / o / p / r / s / t / u / v / vg / vr / w / wg] [i / ic] [r9k] [s4s] [cm / hm / lgbt / y] [3 / adv / an / asp / cgl / ck / co / diy / fa / fit / gd / hc / int / jp / lit / mlp / mu / n / out / po / pol / sci / soc / sp / tg / toy / trv / tv / vp / wsg / x] [rs] [status / q / @] [Settings] [Home]
Board
SettingsHome
4chan
/g/ - Technology
Text Boards: /tech/ & /prog/

oznzb Usenet Indexing Community

Posting mode: Reply
Name
E-mail
Subject
Comment
Verification
4chan Pass users can bypass this CAPTCHA. [Learn More]
File
Password (Password used for deletion)
  • Supported file types are: GIF, JPG, PNG
  • Maximum file size allowed is 3072 KB.
  • Images greater than 250x250 pixels will be thumbnailed.
  • Read the rules and FAQ before posting.
  • Japanese このサイトについて - 翻訳
  • You may highlight syntax and preserve whitespace by using [code] tags.

oznzb Usenet Indexing Community

Toggle

For the first time in over 5 years, we're running two Contests—one for new Rotating Banners, and the other for our House Ads.

Thanks in advance to everyone who submits banners!

File: 1371603842132.jpg-(538 KB, 1600x1200, 2013-06-18 19.54.45.jpg)
538 KB
538 KB JPG
so /g/ today I came across a bit of a problem on my laptop. Apparently it got infected with one of those bullshit scam lockdown screens which means I can't do shit now.

I tried accessing the regedit but obviously I couldn't do that. I also looked online and I found all these fucking spyware/malware removal tools but I'm not too fond of using those either

So how exactly do I go about removing this shit? I don't have any restore points for a system restore and I'm certainly not going to do a clean windows install or a HDD format just for this

I do have hijackthis downloaded to a USB stick but I have no idea how to use it to get rid of this crap
>>
Are you implying that you didn't install all programs to a separate partition?
>>
enter windows in safe mode, to start with.
>>
You should probably use Ubuntu if you are stupid enough to get this shit on your computer.
>>
>>34679913 (OP)
What I did last time I saw anything like I just booted up into a linux livedisk and deleted the file that holds all the start up files.

I think it was like here
C:\Users\Username\AppData\Roaming\Microsoft\Windows\Start Menu\Program\Startup\ctfmon.lnk
>>
>>34679913 (OP)

do you never learn?! This happens when you don't use free software.

simply boot a linux distro, make a backup of your files, format drive, install something sane.
>>
Safe boot.
Backup your shit.
Flatten and rebuild. (Microsoft recommendation)
>>
Safe Mode
Malwarebytes, both Anti-Malware and Anti-Rootkit
Combofix
Hitman Pro
>>
>>34679991
>>34679996

I usually never get this kind of crap on my computer but somehow this slipped past my radar

>>34680006

I had read about hitman pro, do I need to bott it with a USB stick?

Also, I ran hijackthis to check for any suspicious looking stuff but so far I didn't really find much, save for a vbc.exe on my accounts temp files that has been appearing for the past week or so
>>
>>34680069
That vbc.exe in your temp files sounds a lot like the virus you're looking for.
>>
>>34680095

yes that's what I was thinking

It went around creating folders and temp files by itself all week which is what leads me to believe this is the malware on my computer
>>
>>34680148
Did you get rid of it?
>>
File: 1371605047340.png-(14 KB, 430x318, bot.png)
14 KB
14 KB PNG
>>34680169

I also found this though

It seems to be the application and all the files pertaining to the lockscreen. I'll have to go ahead and delete them as well as look for any other crap that's loading up during boot
>>
File: 1371605107114.jpg-(15 KB, 553x351, 1348017296272.jpg)
15 KB
15 KB JPG
>>34680250
>tixati
you dont deserve our help
>>
>>34680250

Tuneup software. My god this computer is likely riddled with aids by now.
>>
File: 1371605238765.png-(115 KB, 535x350, 1371079590348.png)
115 KB
115 KB PNG
Use Kaspersky rescue disk and dont be an idiot next time.

tbh, you deserve what you get if you are dumb enough to get one of these things. Not even gonna talk about your lacking of ability to remove it.
>>
>>34680292
>>34680269

I share the laptop with my roommate. Generally I don't have any of that shit installed but he insists on it. Doesn't bother me since I still have my desktop but I have important stuff on the laptop as well

Anyway with hijack this I detected both pBot.exe and vbc.exe running on startup.

I'm going to go ahead and delete both, but I'm not so sure about the pBot.exe since it's listed as

"AUDIO DRIVERS C:\Users\Name\AppData\Roaming\pBot.exe"

And the audio drivers part worries me a bit
>>
>>34680269
>tixati
>not good
Dont tell me you actually pay attention to tier lists designed to mislead and misinform.
>>
>>34680408
just delete it and reinstall sound driver if it doesnt work
>>
>>34680408
deleting sound driver will not stop your pc from working.
>>
>>34680408

Doesn't fucking matter if you can download new drivers now is it?
>>
>>34680311

Ironically Kaspersky rescue disk is based on gentoo.
>>
>>34680292

why is exactly tuneup so bad? I mean it can be kinda useless but it helps with cleaning up a lot of unnecessary crap on your computer
>>
Install Gentoo


oznzb Usenet Indexing Community

Delete Post [File Only] Password
Style
[a / b / c / d / e / f / g / gif / h / hr / k / m / o / p / r / s / t / u / v / vg / vr / w / wg] [i / ic] [r9k] [s4s] [cm / hm / lgbt / y] [3 / adv / an / asp / cgl / ck / co / diy / fa / fit / gd / hc / int / jp / lit / mlp / mu / n / out / po / pol / sci / soc / sp / tg / toy / trv / tv / vp / wsg / x] [rs] [status / q / @] [Settings] [Home]
[Disable Mobile View / Use Desktop Site]

[Enable Mobile View / Use Mobile Site]

- futaba + yotsuba -
All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.
Thread WatcherR