Jump to content

HiWire

Manufacturer/MoT
  • Posts

    2,045
  • Joined

  • Last visited

  • Days Won

    2

Everything posted by HiWire

  1. Good question – the version I downloaded (HitmanPro 3.7 x64) gave me an option to run the program as a one-shot deal or as a perpetual scanner. I chose the one-shot option and it seems to be completely gone from my system. The only thing it left was the scan log I saved on my desktop. I didn't realize it was a Sophos product, either. The screenshot on the MalwareTips site shows the SurfRight name, which Wikipedia says Sophos acquired in 2015. Maybe they realized the original product was too much like malware itself – they'll probably lose the questionable name as they incorporate the technology into their other products.
  2. Testing almost every free anti-virus/malware app wasn't exactly my plan for the weekend – it definitely woke me from a state of complacence. I've seen friends, family, and co-workers suffer though this kind of stuff and I'm glad the damage wasn't much worse. There's no way I would have thought an app called HitmanPro would be legit Running all the security software also seemed to uncover various little creepy-crawlies that crept into my system and data over the years... some of my files go back to the 1990s.
  3. My computer got hit by malware yesterday, which took all day to eliminate. Since there wasn't a lot of specific info online, I thought I'd post this in case it hits anyone else. Most of the web results point to 2012 recommendations that are out of date. This particular redirect hijacks your address bar and search results (for all your browsers) to SearchMagnified or SearchingMagnified, obvious bogus domains that will no doubt take you to further exploit sites. It also redirected direct links and bookmarks to these sites. I looked through the list of browser settings and add-ons (I don't run any), running processes, installed software, and even the hosts file and DNS settings, after dumping cache files and cookies in the browsers and refreshing them. Nothing obvious showed in the list of add-ons, processes, startup entries, or the Registry. It went right through Avira Antivirus and Malwarebytes Anti-Malware – neither was able to detect anything wrong with a full scan. Windows Defender was, of course, useless. First, I downloaded and installed (sequentially) a bunch of free antivirus apps, all of which have relatively good standing in their industry – Bitdefender, Avast, AVG, Kaspersky. I updated definitions and ran a full scan with each, which took all day and turned up nothing. I also uninstalled each app before trying the next one, which meant a lot of restarting. I also used the following anti-malware apps – Malwarebytes AdwCleaner and Spybot Search & Destroy. No results there, either. Eventually, I found a general help page on browser hijacks at the MalwareTips website (dodgy-sounding, I know, but I was at my wits' end by that point). Going directly to the applications the page referenced (rather than clicking through their links), I followed their recommendations step by step: 1. Kaspersky TDSSKiller (rootkit detection and removal) – no results 2. RKill (process blocker removal) – no results 3. Malwarebytes Anti-Malware – no results 4. HitmanPro – we have a winner! HitmanPro listed a small number of tracking cookies (low threat), and removed 1 malware from a 2016 archive file. Deleting these fixed the browsers. 5. Zemana Anti-Malware – did not try 6. Reset browser to default settings – already tried. No effect Takeaway lessons and reminders (most of these are pretty obvious): 1. Have up-to-date backups of your critical data as well as a system image 2. Make sure you know if System Restore is working if you have to revert Windows 3. Consider changing your user level down from Administrator 4. None of the browsers were safe. Modern hijacks are able to affect all of them. Windows 10 is obviously still vulnerable to drive-by website exploits 5. Have a second computing device, and at least a large flash drive or external hard drive to boot from in extremis 6. Hard drives are slow... the painful process of scanning the entire system (many hours) would have been much less painful on an SSD 8. Hybrid vigor: if you have the resources, experiment with multiple operating systems and virtualization to reduce your exposure 9. Keep a variety of these free anti-virus and anti-malware tools on an easily-accessible disk, and update them regularly. None of them are guaranteed to find all your viruses, spyware, adware, malware, and ransomware by themselves, so keep your options open. Paid security software (Norton, McAfee, premium versions of the vendors listed above) probably has the same pitfalls. 10. Update all your passwords and login information after an attack. Scan other volumes (e.g., external and networked drives) to ensure data security 11. Using cloud services reduces your reliance on a single device/system, but can introduce new weaknesses 12. Prepare for the worst-case scenario. Know what steps you would take if you lost all your data and possibly the entire computer (e.g., comparable to a theft, loss, or hardware failure) Conclusions: I suspected from the start that it was a simple browser hijack, but doing a thorough inspection with multiple programs confirmed the system and its data is essentially clean (I am running free Sophos Home now). I hadn't heard of a lot of the tools listed above, but they obviously vary in their effectiveness. In the end, I didn't lose any data and I only lost a day. It is important to act as quickly as possible against system security problems. You can't always rely on a previous set of security tools, so stay up to date and limit your vulnerabilities.
  4. Goldie – Timeless
  5. My Life with the Thrill Kill Kult – Sexplosion! Various Artists – Verve Unmixed 4
  6. Patrick Rothfuss – The Wise Man's Fear I was excited to start this book but it turned out to be an epic fail. Started this one immediately afterwards to get the bad taste out: Guy Gavriel Kay – A Song for Arbonne
  7. Shivaree – I Oughtta Give You A Shot in the Head for Making Me Live in This Dump The Stranglers – Rattus Norvegicus
  8. Matthew Sweet – Kimi Ga Suki * Raifu
  9. Tricky – Pre-Millenium Tension I'm not sure if anything he's done since this one has reached the same heights (or lows, depending on your mood)...
  10. Behind the curtain: http://www.emusician.com/artists/1333/flying-lotus-records-youre-dead/49594
  11. Yeah, but even more so, if that is possible. I was doing a bit more reading and I'm pretty sure he is hitting those levels on purpose... it sounds like crap on my gear. I enjoy his music, but the distortion is awful.
  12. I bought Cosmogramma a few years ago and I noticed it is recorded at a deafening level. Other people seemed to have picked up on this as well. Does anyone else think his albums are too loud? I have to turn the volume to nearly zero just to listen to the CD. Some people think the clipping is intentional...
  13. Shpongle – Museum of Consciousness
  14. Oppo added some details to the UDP-205 page: http://oppodigital.com/blu-ray-udp-205/blu-ray-udp-205-Overview.aspx
  15. Who says millenials are lazy?
  16. Ninja Gaiden: http://www.theverge.com/2017/4/13/15259958/ninja-gaiden-remastered-soundtrack-retro-game-music
  17. Funny – I just put Supernature in the CD player and now I must buy Silver Eye. A glass of Knappogue Castle doesn't hurt the experience, either.
  18. DJ Shadow – Endtroducing
  19. I was saying "boo urns."
  20. Not sure if the Apple AirPods present a similar risk.
  21. I think I'll stick with wired headphones for now: http://www.theverge.com/2017/3/15/14938788/headphones-explosion-airplane-sleeping-woman
  22. Kylie Minogue – Light Years
  23. A strangely late review of the Oppo BDP-105D: http://www.theabsolutesound.com/articles/oppo-bdp-105d-audiophile-blu-ray-disc-player/ They probably should have reviewed it before it went out of production.
  24. The Violinist's Thumb by Sam Kean
  25. Groove Armada – Vertigo I'm late to the afterparty, as usual...
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.