my encounter with a malicious website
Ok....so, as you may have guessed, I had a close encounter with a malicious website. I was using a WinXP box with SP1...no patches beyond that. No firefox was installed, so I used an unprotected copy of IE to hit a website...and I hit a malicious one.
I got a crapload of pages open, my desktop filled with links to porn sites and shit, and I knew I'd been whacked. So, I deleted the icons and closed all the windows.
I then right-clicked to go to task manager and see what was running. However, task manager was grayed out. so I hit ctrl-shift-escape (the task manager hotkey) and was told that it was disabled by policy. Great.
Whatever, I went back online, grabbed firefox, then used it to hit the systeinternals website to download . For anyone that doens't know about it, that's an awesome app...I use it all the time. Kind of like task manager, but on some sort of mega-steroid crack.
Anyway, I unzip it, run it....crash. Something was fucking with it. Fine. I download adaware next. I figure I'm mainly looking at spyware/adware. The application downloads, but when I try to launch the installer, it crashes.
Wonderful. So I reboot into safe mode. Adaware installs now, but of course I don't have internet capability. so I scan with 107 day old definitions and nab around 100 items. Woooo. After cleaning, I reboot back into regular mode.
Adaware launches ok, but process explorer still craps. So I update adaware and run it again. More crap is nabbed, but I still can't access task manager and I still can't launch process explorer.
so I grab spybot S&D. This one installs ok in normal mode, but hung when downloading updates. so I rebooted back into safe mode, scanned the system, cleaned some more crap up (we're at around 120 objects now), then rebooted back into regular mode. I'm now able to update the application, so I do that and scan again.
However, shit is still fucked up. Getting a bit agitated, I download AVG antivirus from GRISoft. After installation, it immediately freaks out about a trojan, which I let it kill. I do all the updates, then run a scan...around 80 objects detected, most of them various trojan horses.
After cleaning with AVG, I reran adaware and spybot S&D, cleaning up a few more items. After another reboot, I do some more scans (AVG, adaware and spybot) and everything is coming up clean. I can now run task manager, and I can run process explorer. Using those apps. I see a process running that's bad, so I killed it and downloaded hijackthis.
Hijackthis finds a few more bad things floating around, including a DLL I had to whack on reboot. However, at long last, it looks like I've managed to completely clean my system. For a bit I was tempted to wipe the box and just reload, since everything important was already saved on DVD. However, I'm pretty confident everything is good to go now.
BTW...I think I may right this experience up into a guide, with screenshots and instructions on using the various apps. I feel fairly powerful now.