Infected!

Updated.  See below.

I don’t know how, but I somehow managed to get the Malware Defense “anti-spyware” program on my system at home.  Fortunately for me, it doesn’t do anything malicious like delete files or install botnet sofware.  It just continually pops up virus warnings and giving opportunities to install.  For a price, of course.  If you pay, they go away.

The removal instructions I came across weren’t complete, as I completed those steps, rebooted the system, and the thing came right back.  I finally tracked down and eliminated the richtx64.exe trojan, which I think is what was re-running Malware Defense.

I’ve been running my computer for years without any kind of active anti-virus or such, and this is the first time I’ve ever been infected.  Now I’m not sure what to do.  I certainly won’t go back to Norton after the troubles I’ve had with them, and I don’t hear good reports about McAfee’s offering, either.  Is there a good anti-virus, anti-malware package that works, is inexpensive, and doesn’t take inordinate amounts of CPU time?

Update 12/28:

It took a while, but with some research and downloading and running a few cleanup utilities, it looks like I was successful in disinfecting the computer.  The thing kept getting re-infected whenever I’d reboot, and it would prevent me from installing or running common anti-malware utilities.  I found a program called rkill that kills common malware processes, and then I could install and run cleanup software.  This morning, a complete scan with Malwarebytes’ Anti-Malware reported zero problems.  I then installed Microsoft Security Essentials from a file that I downloaded from a different (uninfected) computer.  It reports no problems.

Darrin Chandler brings up an interesting point in the comments:  it’s all a matter of weighing the risks.  I’ve gone years without any kind of malware problems.  Even when I had anti-malware applications installed, they never reported that they’d blocked anything.  And those programs are very quick to notify whenever they see anything even vaguely suspicious.  So, as Darrin points out, my risk of being infected is pretty small.  However, the cost of being infected is fairly high.  It cost me most of a day to get rid of it.  And I was fortunate that it doesn’t seem to have deleted any files.  I have no idea if it copied anything from me.  I’m not too worried since I don’t keep financial information on this machine.

I’m hoping that Microsoft Security Essentials works well and doesn’t cause problems by being too chatty or sucking down too many resources.  We’ll see how it goes.

4 comments to Infected!

  • Microsoft Security Essentials. Free.

  • Roy Harvey

    I use ESET NOD32 Antivirus. I started using it at the suggestion of some very experienced system administrators responsible for thousands of computers. They said that, unlike Norton and some other big names, it did not make system administration a nightmare. I find it unobtrusive and not too demanding of resources. I like that it updates the virus database every day.

    Before that I used the free version of AVG, and then the paid version. There is no free version of NOD32. The first year I used it I got it at no charge, but when that ran out I chose to pay for it, though it is not all that cheap and I am a notorious cheapskate.

    Of course, YMMV.

  • Darrin Chandler

    It seems your probability of infection is relatively low. Multiplied by the cost of dealing with an infection, you may well be ahead of the game by not messing with anti-virus.

    You might also consider doing web surfing, etc., on a machine separate from where you do work or keep anything valuable. Then if it gets infected you do a clean install.

    I’m not advocating anything here except for weighing the options explicitly for your particular usage. One size doesn’t fit all.

  • botter

    I have used the freebie version of avira for several years, and it works for me. Only complaint is the nag screen that appears after each update. It wants you to upgrade to the paid for version. A mouse click and it goes awy, so not so bad.