News:

If you need instructions on how to get through the hotels, check out the enclosed instruction book.

Main Menu

ITT: Chernobyl, FakeAV et al

Farted by The Spoiler, January 21, 2009, 03:52:24 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

The Spoiler

So, while engaging in certain activities that aren't  supposed to be mentioned on the forums, it seems I infected my computer with a menagerie of viruses and other goodies. While running the fruit of the aforementioned activity, my computer crashed and when I booted it up again the screen had graphical artifacts (in specific, 32 vertical broken columns of pixels arranged in eight groups of four columns each spaced so that there were alternating areas of asdf and normal imagery) from the first BIOS screen to the windows load screen (As in the one with logo and load bar) after a certain amount of loading my computer hanged, became unresponsive and the monitor turned off.  

After turning it off I booted it up and to my relief safe mode worked (without the aforemention 32 broken columns of pixels, as far as I can tell). The first thing I did was start backing up old files with my flash drive(all my flash is now safely on my laptop) and then I ran a virus scan. McAfee didn't find anything (big surprise) and neither did Malwarebyte's (slightly larger surprise) so I downloaded some trial versions of different antiviruses. (after uninstalling McAfee)  I tried installing the different ones. NOD32 and Panda didn't install, but Avast! did, and after running a rather long scan it reported that I had the following malware (these aren't the full names it gave, just what I could remember):

Pakes
OpenStream
CIH (a.k.a Chernobyl)
HTML:iframe
FakeAV

For those of you who don't know, CIH is not only about a decade old (and supposed incapable of incapable of infecting XP), but also a total dickweed. It overwrites the first megabyte of the hard drive, which kinda sorta contains the Master Boot Record and pretty much everything a computer needs to run. I saw on a website that with larger filesystems it only gets partially through the MBR or file table or something or other and it makes recovery easier. Since my computer has 300 GB of shit (and it's a RAID setup, by the way) I think immense bloat may have actually saved my computer. If so, I may never complain about long downloads again.

Which I promptly deleted because the quarantine feature wasn't working. After that I moved some more of my old flash junk to my laptop and rebooted. The same 32 broken-up columns of pixels organized into groups of 4 columns appeared but after it hanged when it loaded Windows, a screen came up (kind of like the one when Windows figures out everything went to hell and runs a consistency check) and avast! decided starting scanning again to fight the cyber-aids that most likely are still there. Right now it's probably about a fifth done, so my questions to you, clockcrew, are:

Did I actually get my master boot record infected or am I just an idiot (not that the first often happens without the second)?
If it has got CIH (and I don't think avast! is lying), what do you recommend I use to clean the files that it has no doubt infected?
How the fuck was my computer vulnerable to a virus that's over a decade old?
If it turns out avast! is toying with me and my computer crashes, what do you recommend to save my ass (I've already got AVG, F-Secure, CA, Clamwin, BitDefender, SUPERAntiSpyware,Threatfire,  and maybe a few other things ready to install in addition to the stuff I've already mentioned)?
How long are you going to laugh at my idiocy? (and by all means, do.)
If my hunch is right and CIH half-raped my computer before crashing it, shouldn't I probably flash my BIOS or something?

So yeah, I'm gonna go pass time and see how long it takes to finish scanning, because it's way to late to go to sleep and wake up on time.

RomanClock

Kaspersky seems good to me if you want to use a proactive defense (though it may be annoying sometimes).
But if you're "PILLAGING THE INTERNETS" then there's probably not much you can do about it because it will be well hidden in whatever you think you're getting.
Why do you think lots of security software and things tell you NOT to use those types of software?
lemayo lol :soups:

The Spoiler

I didn't say I wasn't expecting this kind of thing to happen.

I know I downloaded Kaspersky but I can't remember whether I tried to install it yet. If it turns out avast! didn't do much good, then I'll definitely give it a go.

Update: Seems avast! didn't do that much good. Windows still does its routine of the screen going asdf and becoming unresponsive when not in safe mode. I guess today I'm going to try some more anti-viruses. I've read there are some tools especially for fixing CIH, so I might give one of them a try. There's always the option of reinstalling if nothing works.