PDA

View Full Version : Crappy Malware-ish Issue



Mike
12-23-2010, 11:25 PM
I had one of those HDD Repair-esque rogues crop up on my home system, and already kicked out the bulk of it with RKill and Malware Bytes.

The Problem: It rehashes the irritating Windows Security display popups telling me I don't have a hard drive and whatnot. I assume this is due to rootkits or whatever, as I've heard this is the case.

The display issue disappears after one more run of rkill until the system is rebooted, so it seems easily manageable, but I don't know if this is as plain and shallow as the situation really is.

Anyone care to weigh in? I doubt Geek Squad folk would know enough about it to make it worth my money, and I am unaware if the default system restore (not recovery/reformat) would help, either.

Short Version
HDD Repair clone got me. I removed it (the actual popup application complete with false positives and all) with Rkill followed by Malware Bytes.
(presumably fake) Windows Security popup persists until hit with a new rkill on each reboot.

Devessi
12-23-2010, 11:30 PM
Which one in particular is it?

Mike
12-23-2010, 11:33 PM
It just came up as "Scanner". An absolute clone of this (http://www.bleepingcomputer.com/virus-removal/remove-hdd-rescue) but with the word "Scanner" as it's window title and label in the textbox.

Sam
12-24-2010, 01:36 AM
Happy Christmas, douchebag?!?

Mike
12-24-2010, 01:51 AM
Fixed already. Merry Christmas to you, aswell.

g++
12-24-2010, 04:57 AM
Thats usually a sign the underlying trojan has not been taken care of. Sounds like bloodhound. I would turn off system restore if you have not already and look for registry entries for the files rkill is closing. Bloodhound will usually introduce randomly named executables in your profile.

4a6c1
12-24-2010, 06:30 AM
This is very sad news. Very sad. My condolences to your computer.

Mike
12-25-2010, 07:51 AM
I deleted the app that ran the process entirely on each startup.

Problem solved, and laugh at lazy douchenozzles who half-ass stuff so badly that a novice like me can completely disable it.