View Full Version : New Viruses/Spyware/Annoyances


khat17
06-29-2008, 09:22 AM
There has been an increasing number of new viruses and spyware and annoyances. The worst of these I'd say is the BRONTOK virus and it's variants. It has a nasty habit of renaming all files - especially EXE's - to a numerical file. So, MSWORD.EXE would probably be renamed to 65487856963.EXE and it does so to text files, office files, and basically any file it gets to. The only prevention is an antivirus that will stop it (or an OS besides Windows).

Next on the list of annoyances is the OPENFOLDER.EXE annoyance. I almost caught this from someone's hard disk that I was doing some repairs to in my machine. The path it had installed itself to when it couldn't get access to my machine was

"C:\TEMP01\userFiles\dataFiles\AlmostThere\keepGoin g\Here\openFolder.exe"

which I found really cheeky. After deletion that was it. You may need to run a search if you have multiple drives, as it also creates an AUTORIN.INF file which is dropped in the root of each drive so that the program can install itself to your machine every chance it gets. But it doesn't normally show up until it runs, which it had placed itsef in my autostart in the Windows Registry (HKLM/RUN).

Other things similar to the OPENFOLDER annoyance cause multiple things to go wrong with your machine. Stuff like you can't get to TURN OFF YOUR COMPUTER, or the LOG OFF icon isn't there, or there is no MY COMPUTER icon, and a host of other things. The most annoying one I've seen (aside from being unable to shut down the PC) is you can't get to TOOLS or FOLDER OPTIONS in the TOOLS menu from MY COMPUTER or WINDOWS EXPLORER.

Fortunately, I did find a fix online (it is adware/payware) but you don't necessarily need to buy it. Just deal with the annoying ads for the program (will route you to their site) which isn't too much of a bad deal, considering it will still clean the problem. Only thing is, it has a SCAN function to SCAN AND CLEAN the annoyances that caused the problems, but that is only available if you buy the program - aptly named REMOVE RESTRICTIONS TOOL.

http://en.sergiwa.com/modules/mydownloads/singlefile.php?cid=2&lid=1

See the link for info, and there is a screenshot below as well so you can see some of the problems that the machine may have.

http://i162.photobucket.com/albums/t263/khat17/RRT.jpg

Please bear in mind that some of the options that will be available may not be an infection. The option to hide file extensions and such are default settings in Windows that are only changed by someone who knows what he/she is doing. If you're using the tool I'd suggest consulting someone if you're not sure what to do. Example, you'll see on my PC - FIREWALL SHARED ACCESS - can be enabled. I have it disabled though, because I am not sharing an internet connection across my network, and it doesn't needs be firewalled. Hope the info was helpful.

PeAcE.

death_knight
06-29-2008, 01:59 PM
bwoy..if it wasn't photography i'ld never run windows.. ms lucky seh them dont make the tools i need on linux..i cant bother with the anti virus this that and the other man.