Infeced by Punch's Virus? Helpful tips on removal

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts
  • kineda
    Fuck your Subaru
    • Apr 2004
    • 29884

    Infeced by Punch's Virus? Helpful tips on removal

    Ok a bunch of us seemed to have been infected by that russian website from the "Big Hole" thread in pics/vids. The virus is win32/clspring.fa not a real dangerous infection but a pain in the ass to remove. After initially scanning the pc it removed 2 files as being the virus, spybot found a few entries as did adaware. i manually browsed through the registry removing added garbage from hklm>sw and hkc>sw thought i had it beat, booted up today and started getting more command prompt scripts running from %userprofile%\local settings\temp. scanned those files with antivirus and spyware but were not detected! ended up running filemon from sysinternals and found 2 running processes that seemed a little odd, c:\program files\common files\{24-8e5529-0257-1033-1029-040408190001}\ update.exe and services.dll these seemed to be what was propegating the scripts. i also went back and removed any references to that dir from the registry. if you are still fighting this little bastard take a look for what i listed and let me know if you find anything different...

    -philip
    Originally posted by LTDpower
    You are not Philip to me, you are customer #88306-B to me.
    Originally posted by ProRauder
    I submit that more I.T. people have disposable income to waste on making cars go fast
  • worduphomefry
    no fat chicks
    • Nov 2002
    • 11982

    #2
    pwned

    Comment

    • Xtort
      TCS Homer
      • Dec 2004
      • 6968

      #3
      Heh, would have just did the ol' F12 just for shits and giggles. But thats on other peoples comps, heh.


      http://youtu.be/GTQnarzmTOc

      Comment

      • sturte30
        400hp and AWD....Droooool
        • Oct 2002
        • 3392

        #4
        Weird...I clicked the link the other day and didn't get a virus. Hooray for me

        "There is a fine line between a hobby and a mental illness"

        Comment

        • HopAlong
          ??Handcuffs??
          • Aug 2005
          • 7184

          #5
          Im not sure what happened with the computer I was on yesterday but IT here at the clinic has yet to contact me.

          Comment

          • D3thM3tal
            IT Pro / Mechanic
            • May 2006
            • 3665

            #6
            It came from a xbox 360 popup. The link was taken down, but I was cleverly able to find where he got the link and got the popup at school... I dunno if the pc is infected, I even clicked on the popup, but no virus warning... Maybe those compys dont have protection...
            08' Focus Coupe MTX 2.0 / 00' Contour SVT 3.0 / 95' F150 5.0 / 86' F350 6.9IDI / 74' Bronco EFI 5.8 / 74' Bronco Ranger EFI 5.8 / 66' Mercury Monterey 352FE / 64' Galaxy 500 390 FE
            I bleed blue

            Comment

            • Xtort
              TCS Homer
              • Dec 2004
              • 6968

              #7
              heh, maybe you just haven't found out your infected yet. Maybe our virus software doesn't completely suck after all.


              http://youtu.be/GTQnarzmTOc

              Comment

              • CleanLX
                sno pro
                Admin
                • Mar 2003
                • 35005

                #8
                I got a virus from Punch.

                ......it burns real bad.

                Comment

                • mnstang
                  Bookending TCS
                  • Oct 2002
                  • 33500

                  #9
                  no virus protection here.

                  you get the full effect this way.

                  Comment

                  • LES
                    Doing more with Les!
                    • Apr 2006
                    • 33157

                    #10
                    Got it here too , spyware shit. I tried to use WINDOWS to get rid of and my office client scan couldnt do it either, soi I did a Windows Return to previous settings for 2 days B4 i got it, wich was on Monday and its GONZO now.
                    It is a damn poor mind indeed which can't think of at least two ways to spell any word.
                    Andrew Jackson

                    Comment

                    • punch
                      I'm back, what did I miss?
                      Admin
                      • Oct 2002
                      • 23979

                      #11
                      If you used Firefox you sould be fine, IE.

                      When I origonaly posted the link there was no malware, the link got on digg and then whoever runs that site added some malware after the fact.

                      Sorry for the bad link, but this is why you use Firefox + antivirus + antispyware at all times!
                      About Me :: Yes, I'm on twitter.

                      Comment

                      • Video_Master
                        Kickin it Hybrid Style
                        • Jun 2003
                        • 10524

                        #12
                        Hmmm, I didn't have an issue with the site.

                        Comment


                        • #13
                          i HAD NO PROBLEMS

                          Comment

                          • StangerJon
                            esse jay
                            TCS Auto-X Driver
                            • Oct 2003
                            • 16655

                            #14
                            my computer is bullet proof, not even free internet porn can phase this bad boy.

                            Comment

                            • LX Sport
                              Murdered
                              • May 2003
                              • 15323

                              #15
                              Originally posted by Stock GT
                              i HAD NO PROBLEMS
                              except it some how turned put your caps lock in reverse mode...

                              Comment

                              Working...
                              X
                              😀
                              😂
                              🥰
                              😘
                              🤢
                              😎
                              😞
                              😡
                              👍
                              👎