Welcome, Guest. Please login or register.
July 04, 2025, 08:18:12 AM

Login with username, password and session length

Search:     Advanced search
we're back, baby
*
Home Help Search Login Register
f13.net  |  f13.net General Forums  |  General Discussion  |  Topic: Holy shit, this anti-virus is awesome. 0 Members and 1 Guest are viewing this topic.
Pages: [1] Go Down Print
Author Topic: Holy shit, this anti-virus is awesome.  (Read 8006 times)
WindupAtheist
Army of One
Posts: 7028

Badicalthon


on: June 23, 2010, 11:49:53 PM

Kid brother picked up something somewhere that was causing all his search results to redirect elsewhere. Googled f13, clicked a link to the front page, ended up at some site trying to sell penny stocks. And so forth. Spent a ridiculous amount of time trying to get rid of it. Norton, nothing. AdAware, nothing. A bunch of other shit, nothing. I'm not expert enough to use HijackThis to it's full potential, but the suspicious looking shit I removed with it didn't do any good either.

A couple forum posts and shit I turned up said this was good, so I gave the free trial a shot.
http://en.wikipedia.org/wiki/Hitman_Pro

Here was the entire experience.

Me: *installs program*
Program: Click next to detect bad stuff.
Me: *clicks*
Program: Hey, a rootkit. Click next to remove bad stuff.
Me: *clicks*
Program: Bad stuff fixed, reboot to get rid of it.
Me: *reboots*

Done. Fixed. The scan took just over 3 minutes. The entire process involved like 3 clicks and took 5 minutes. I've never had an easier time removing something that the usual programs couldn't get at. I am blatantly talking it up because, at least in this particular case, it was just that fucking good. Has anyone else used this?

"You're just a dick who quotes himself in his sig."  --  Schild
"Yeah, it's pretty awesome."  --  Me
Ratman_tf
Terracotta Army
Posts: 3818


Reply #1 on: June 24, 2010, 12:09:18 AM

Huh. If AVG and Adaware can't get rid of it, I usually wipe the hard drive. This sounds promising. Thanks for the link.



 "What I'm saying is you should make friends with a few catasses, they smell funny but they're very helpful."
-Calantus makes the best of a smelly situation.
WindupAtheist
Army of One
Posts: 7028

Badicalthon


Reply #2 on: June 24, 2010, 12:20:35 AM

It wasn't just the fact that it got rid of something the others programs didn't, it was the fact that it took 5 minutes and was ridiculously simple. There was none of that "start a scan, go watch TV" shit. From installation to success it really was just a matter of clicking next a couple of times. Your technologically hapless grandmother could use it.

I almost wish I had more problems to test it on. If this little experience was typical, it's the best thing out there.
« Last Edit: June 24, 2010, 12:24:10 AM by WindupAtheist »

"You're just a dick who quotes himself in his sig."  --  Schild
"Yeah, it's pretty awesome."  --  Me
Trippy
Administrator
Posts: 23657


Reply #3 on: June 24, 2010, 03:25:02 AM

It sounds like your brother picked up the TDL3 rootkit. That just happens to be something Hitman Pro specializes in detecting and removing (many traditional AV programs have trouble detecting it). The reason why Hitman is so fast is because it doesn't scan everything. From what I can tell reading between the lines of the Web site it basically just compiles a list of likely infection spots and just scans those. I like its approach of using multiple AV scanners but because it doesn't give you the option of scanning everything it's not a complete replacement for a traditional AV scanner.

Edit: I'm assuming it doesn't have an option to scan everything as passing each and every file on your computer up to the cloud to be scanned would take forever not to mention being an incredible privacy problem.
« Last Edit: June 24, 2010, 11:11:00 AM by Trippy »
lac
Terracotta Army
Posts: 1657


Reply #4 on: June 24, 2010, 04:45:42 AM

Heh, good to hear it actually does something. I was afraid it was scareware. A couple of years ago hit man pro was a fully automated script that downloaded trials and free antispyware software from the net and ran them in succession on the infected host. It was an approach that yielded great results for almost no effort. Sometime after it becoming popular the script vanished and the website started offering the current program. I had always assumed the domainname got sold to a scareware provider.
Lantyssa
Terracotta Army
Posts: 20848


Reply #5 on: June 24, 2010, 06:59:01 AM

The best AV tool is using a bunch in combination.  Hitman is good in that it does hit the likely infection points and uses multiple engines, so it's at least likely to get critical areas clean.  It's still a good idea to a full scan with other products after a known infection to be safe.

Hahahaha!  I'm really good at this!
IainC
Developers
Posts: 6538

Wargaming.net


WWW
Reply #6 on: June 24, 2010, 07:17:43 AM

I always used HijackThis for stuff like that. Works in the same way.

- And in stranger Iains, even Death may die -

SerialForeigner Photography.
Lantyssa
Terracotta Army
Posts: 20848


Reply #7 on: June 24, 2010, 09:37:52 AM

HijackThis requires a lot of computer knowledge to do anything with though.

Hahahaha!  I'm really good at this!
Der Helm
Terracotta Army
Posts: 4025


Reply #8 on: June 24, 2010, 10:20:17 AM

This thing identified the Alganon Installer as a rootkit. Sounds legit to me.  awesome, for real

edit: -k+g
« Last Edit: June 24, 2010, 03:13:39 PM by Der Helm »

"I've been done enough around here..."- Signe
dusematic
Terracotta Army
Posts: 2250

Diablo 3's Number One Fan


Reply #9 on: June 24, 2010, 12:12:53 PM

I use MalwareBytes. 
WindupAtheist
Army of One
Posts: 7028

Badicalthon


Reply #10 on: June 24, 2010, 12:38:31 PM

The best AV tool is using a bunch in combination.  Hitman is good in that it does hit the likely infection points and uses multiple engines, so it's at least likely to get critical areas clean.  It's still a good idea to a full scan with other products after a known infection to be safe.

Yeah, though to be fair it does specifically pitch itself as a "second opinion" program to be used when the others aren't finding anything. In any case, I'm glad SOMETHING specializes, as Trippy said, in this particular rootkit. Because Norton, AdAware, MalwareBytes, and Housecall had all accomplished squat.

"You're just a dick who quotes himself in his sig."  --  Schild
"Yeah, it's pretty awesome."  --  Me
Fabricated
Moderator
Posts: 8978

~Living the Dream~


WWW
Reply #11 on: June 24, 2010, 12:53:19 PM

I usually use MalwareBytes and HijackThis when I'm on computer janitor duty.

"The world is populated in the main by people who should not exist." - George Bernard Shaw
WindupAtheist
Army of One
Posts: 7028

Badicalthon


Reply #12 on: June 24, 2010, 01:12:10 PM

I'm just really happy that I didn't have to reformat my kid brother's PC and then figure out what drivers it needs. Of course this isn't the first time he's had a problem. My other brother ended up reformatting the kid brother's hard drive a few months ago while I was out of town, because he'd picked up something bad. I think I'm just going to make him use the AdBlock/FlashBlock/NoScript combo and force him to specifically enable whatever he wants to see.

And again, I just gotta say, the combination of those three Firefox additions keeps away 90% of everything. I ran an AdAware scan for the first time in months the other day, and found a total of 10 objects to be deleted, none above level 3 on their threat scale. Back in the bad old days of using IE, I could go a week between scans and find a hundred things each time.
« Last Edit: June 24, 2010, 01:15:50 PM by WindupAtheist »

"You're just a dick who quotes himself in his sig."  --  Schild
"Yeah, it's pretty awesome."  --  Me
Numtini
Terracotta Army
Posts: 7675


Reply #13 on: June 25, 2010, 07:31:03 AM

More is always good. So far though, I've never found anything that Malwarebytes didn't kill.

If you can read this, you're on a board populated by misogynist assholes.
Morat20
Terracotta Army
Posts: 18529


Reply #14 on: June 25, 2010, 08:30:10 AM

HijackThis requires a lot of computer knowledge to do anything with though.
True, but it's good for disabling a bunch of obvious shit -- plus, if nothing else, it can point you to likely culprits.

I mostly use it for those goddamn "Your computer is infected" popups that people KEEP FUCKING CLICKING ON that install some fake anti-Spyware shit. 80% of the time I can disable the fucker and it's little reloading dlls through HijackThis and then simply nuke it.

My wife seems to have a fondness for virtumonde trojans, and HijackThis is invaluable there. Although the last time I had to drag out VundoFix and CTFShredder I was seriously contemplating nuking her damn hard drive.

I've been happy enough with Kaspersky. I pair that with Spybot and rarely have any problems.
Threash
Terracotta Army
Posts: 9171


Reply #15 on: June 25, 2010, 09:03:04 AM

A few weeks ago i picked up a nasty virus that Hitman Pro couldn't fix, it took combofix to get rid of it.

I am the .00000001428%
Morat20
Terracotta Army
Posts: 18529


Reply #16 on: June 25, 2010, 10:59:41 AM

A few weeks ago i picked up a nasty virus that Hitman Pro couldn't fix, it took combofix to get rid of it.
Ah, yeah, that one lays around in my "Security Tools" folder too. Gets those nasty fuckers that randomly assign dll names, reverse them, and hide all over your fucking computer and infect your registry.

That's my "Fuck it, if this doesn't get it I'm reformatting" tool. :)
jakonovski
Terracotta Army
Posts: 4388


Reply #17 on: June 28, 2010, 03:33:55 AM

Gargh, someone from China tried to hijack my gmail account, but I managed to reset the pw on my work computer. Any idea how to get rid of a keylogger? MSE and Hitman Pro are showing nothing. I suspect the SO picked up something while surfing the WoW forums.

edit: d/ling AVG on the infected laptop as we speak.
NiX
Wiki Admin
Posts: 7770

Locomotive Pandamonium


Reply #18 on: June 28, 2010, 05:09:42 AM

Gargh, someone from China tried to hijack my gmail account, but I managed to reset the pw on my work computer. Any idea how to get rid of a keylogger? MSE and Hitman Pro are showing nothing. I suspect the SO picked up something while surfing the WoW forums.

edit: d/ling AVG on the infected laptop as we speak.

I got a message about South Korea. I haven't really been on my computer for the past 2 weeks, so not sure how it would even happen.
Tarami
Terracotta Army
Posts: 1980


Reply #19 on: June 28, 2010, 07:35:29 AM



Anyone surprised? (The second hit is unrelated.)

- I'm giving you this one for free.
- Nothing's free in the waterworld.
Der Helm
Terracotta Army
Posts: 4025


Reply #20 on: June 28, 2010, 02:10:18 PM

This thing identified the Alganon Installer as a rootkit. Sounds legit to me.  awesome, for real

Not me.  awesome, for real

"I've been done enough around here..."- Signe
Tarami
Terracotta Army
Posts: 1980


Reply #21 on: June 28, 2010, 02:50:39 PM

Oh. Bloodworth made me do it.


- I'm giving you this one for free.
- Nothing's free in the waterworld.
Pages: [1] Go Up Print 
f13.net  |  f13.net General Forums  |  General Discussion  |  Topic: Holy shit, this anti-virus is awesome.  
Jump to:  

Powered by SMF 1.1.10 | SMF © 2006-2009, Simple Machines LLC