SurfSideKick: Pwnt

Posted by Firebird on July 16, 2006, 6:35 a.m.

Alright, so I was away for a few days. Why? Well, because I was infected by a virus after *somebody* (probably the techie) decided to use Internet Explorer to surf around the web and managed to get some malware onto my machine by ActiveX. Now, usually, this is just one scan by NOD32/Defender/SpyRemover/whatever I decide to use and it's gone. For the more stubborn ones, I manually clear the registry of all traces of it and delete it's files. But not Adware.SurfSideKick or Adware.Look2Me or Trojan.Win32 Small Buy Trojan (or something along those lines). Anyway, It has its own little defender program that defends against removal. So I do a root around the Registry editor and find it in the HKEY_LOCAL_MACHINE/Software/Microsoft/Windows/CurrentVersion/Run Reg key and a few others. Then I delete the files in the root of C: and in the Temporary Internet Files. God damn, it was hard to wipe out. Anyone know much about these things?

drsmartload (I took a look around and found that this probably means dollar revenue smartload, a spyware program, which sends back data to dollarrevenue)

dfndrad_5 (The defender program… I might have spelt it incorrectly =/)

nwnmad ('newname'. I don't know what the hell that is meant to mean)

kybrdad (Keyboard thing… probably a keylogger. I don't know if I spelt that right either)

MTE3NDI60DoxNg[1] (that Trojan.Win32 Small Buy Trojan thingo)

Anyway, I think it's gone now… exept a process is running index.dat (Temporary Internet Files/Content.IE5) and that contains the links to virus files and stuff. I can't delete it… through explorer or cmd…

And thats it. I was planning to do something about Shadowgrounds, but that will have to wait.

Keep leet! (And virus-free)

P.S. Any ideas on how to advertise my site more?

Comments

SixWinged 18 years, 4 months ago

if you cant delete the index.dat, rename it to index.dat.backup and see if that helps

melee-master 18 years, 4 months ago

Quote:

Why? Well, because I was infected by a virus after *somebody* (probably the techie) decided to use Internet Explorer to surf around the web and managed to get some malware onto my machine by ActiveX

Good job exaggerating. =P

Polystyrene Man 18 years, 4 months ago

Quote:
P.S. Any ideas on how to advertise my site more?
If you make an 81x33px banner I'll make you an affiliate on my new site (when it is finished).

Firebird 18 years, 4 months ago

I've already got a banner that fits those descriptions. I also have a site that has been around for a while. I just need more traffic :P.

@Nick: I've already tried that.

Firebird 18 years, 4 months ago

God damn, I even tried safe mode XD. It must be in use by a system process.