Recently I have been attacked by a Malware also known as malicious software. I don’t really know how I got this virus on my computer but this annoyed me for so long. I would get popups every time I would go on to the internet. In task manager it would say iexplorer.exe is using the most amount of processor so I’d end process it however the Trojan kept reinstalling itself. For all of you that don’t know what a Malware is here is the meaning. Malware includes computer viruses, worms, trojan horses, most rootkits, spyware, dishonest adware, and other malicious and unwanted software. Malware should not be confused with defective software, that is, software which has a legitimate purpose but contains harmful bugs.
The term computer virus is used for a program which has infected some executable software and which causes that software, when run, to spread the virus to other executable software. Viruses may also contain a payload which performs other actions, often malicious.
A worm, on the other hand, is a program which actively transmits itself over a network to infect other computers. It too may carry a payload.
A Trojan horse, or simply trojan, is a piece of software which appears to perform a certain action but in fact performs another such as transmitting a computer virus.
The program I was infected with was called REF SUPPORT.EXE. The filename REF SUPPORT.EXE refers to many versions of an executable program. The most common file size is 2,411,520 bytes. The unsafe files using this name are associated with the malware group Adware.Lop. These files have no vendor, product or version information specified in the file header.
REF SUPPORT.EXE has been seen to perform the following behavior(s):
- Executes a Process
- Writes to another Process’s Virtual Memory (Process Hijacking)
REF SUPPORT.EXE has been the subject of the following behavior(s):
- Added as a Registry auto start to load Program on Boot up
- Executed as a Process
- Executed by Internet Explorer
Removal Instructions:
After many attempts to scan with NOD32, Spybot and Ad-Aware 2008, we soon found out they could not detect the malware and all attempts at scanning where hopeless. I then realized iexplorer.exe was running everytime I booted my computer, however this was no ordinary iexplorer.exe as this was a hijacked iexplorer.exe due to the malware above. I then thought well if it is being started everytime, I might as well have a look in the startup registry by selecting run from the start menu and entering, ‘regedit’ and pressing ok. I then navigated to [HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Run] and looked for a ridiculous name on the right hand side of the registry editor. Sure enough we found it and located where this file was then deleted it. As simple as that!
Key Steps:
Locate run in the ‘start menu’
Type ‘regedit’
Press ok
Navigate to [HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Run]
Look for a ridiculous name on the right hand side of the registry editor
Go to the location of this file in My Computer
Delete the file (may have to end process)