7
« Last post by DU-BB on November 09, 2018, 07:09:35 AM »
Is one of the most fucked up bits of code ever written. Whoever wrote that should be boiled in a public venue. Saliny writes itself into every program on your computer that it can write itself into. It puts trojans on all your removable drives, and gets running in memory, it's very hard to get rid of. Another thing that it does is disable your task manager, so you can't try shutting it off. Then it disables your registry tools so you can't turn your task manager back on (this is the sure way to know you have saliny: no task manager!). I wrote a program I just call "fix" that enables those, but if you have saliny it will just disable them again. The best way to stop saliny is to run the malicious software removal tool. If you use Windows Updates, it downloads new versions of MRT all the time, and runs them silently whenever it does. But run it yourself, so you can watch it. In the RUN box (winkey+R) type "MRT" (without the quotes) and that will start it. Run my "fix" after the MRT does it's thing, and you restart Windows, to get your task manager and registry tools working again. If they stay working, it worked. There is another tool you should run afterwards, that really gets down and dirty and cleans saliny off everything on your computer, it gets the stuff that the MRT misses. What it doesn't do is stop saliny, so run the MRT FIRST, or saliny will just copy itself back into everything the removal tool cleans.
Here is another tip: When saliny infects removable drives, it does it by writing a hidden file in the root of the drive called AUTORUN.INF. I like to put my own autorun.inf file there, usually with an icon of my choosing. Then, I set the file security, the ACL up so that not even system is allowed to modify it, and of course, make it read only. It doesn't always work, but at least you'll know that you have been infected because your icon will go away. I'll put up another program (that doubles as an icon) that just unpacks a copy of it's own autorun.inf you can use to replace saliny's, should you get it. It will keep your drive from infecting any other computer (including your own again) with saliny. There will also be a copy of the saliny program with a randomly generated name in the root of the drive, but it won't be active once you replace the autorun.inf. Just put the two files in the root of the drive. It's for USB drives in particular, but will work on any drive partition, as long as it's in the root of the drive.