Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Latest Virus: Security Tool

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
Home » Discuss » DU Groups » Computers & Internet » Computer Help and Support Group Donate to DU
 
Capn Sunshine Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jan-30-10 07:19 PM
Original message
Latest Virus: Security Tool
It appears these cheese weasels locate on Italian and Italian restaurant websites, since that seems to be when it happened. Although I understand it can squat for 90 days then release. It hijacks your desktop and task manager. It's ransomware. It's on one of my work PCs that runs Windows 2000.

Smitfruad doesn't get it.
I tried deleting it from the My Documents authorized user window. The files deleted ok but must be hiding somewhere else as well.

Malwarebites finds it and deletes it but it returns.

any fixes for this thing yet, gurus?
Refresh | 0 Recommendations Printer Friendly | Permalink | Reply | Top
hobbit709 Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jan-30-10 08:23 PM
Response to Original message
1. Turn OFF System Restore
reboot in Safe Mode with Networking, run Malwarebytes.
Printer Friendly | Permalink | Reply | Top
 
pengillian101 Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jan-30-10 10:04 PM
Response to Reply #1
2. I hate being so dumb...
But I am also infected with this same thing, I believe, seeing as I visited the same cooking sites, I bet.

How do you "Turn OFF System Restore"? It's Windows XP office version that I use. Thanks in advance.

I will try that, along with downloading and running Malwarebytes.
Printer Friendly | Permalink | Reply | Top
 
pengillian101 Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jan-30-10 11:03 PM
Response to Reply #2
3. Yup, ran the malwarebytes. Infections just one day after cleaning.
Yikes - I hate this crap!

Printer Friendly | Permalink | Reply | Top
 
hobbit709 Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jan-30-10 11:32 PM
Response to Reply #2
4. Right click on My Computer, select Properties
Edited on Sat Jan-30-10 11:33 PM by hobbit709
Go to the System Restore tab, uncheck and click OK you want to turn it off. Then run Malwarebytes and disinfect. Reboot the system back to normal and scan again with Malwarebytes and your Antivirus.

If everything checks clean, then turn System Restore back on.

One of the problems with Windows is that System Restore will put the infection back in on bootup if it isn't wiped beforehand.
Printer Friendly | Permalink | Reply | Top
 
Capn Sunshine Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Feb-01-10 12:00 AM
Response to Reply #4
7. no system restore tab in Win 2000
?
Printer Friendly | Permalink | Reply | Top
 
MyNameGoesHere Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Jan-31-10 09:44 AM
Response to Original message
5. If one had an inffected computer
and the virus returns, 2 things should be done. 1 has already been mentioned, turn off system restore. 2 never ever hope that an infected computer can be cleaned in Normal or safe mode. Ge an AV software that does boot mode scans. Avast does it, and several others.
Printer Friendly | Permalink | Reply | Top
 
RC Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Jan-31-10 09:30 PM
Response to Original message
6. Check what home page all of your browsers are set to.
Disconnect the network from the computer first.
These things can hijack your home page and make them look like the real thing.
If you have google for instance, make sure it is set to www.google.com Anything after the .com is asking for trouble.
If you have some odd ball home page, check EACH character to make sure it is correct.
Printer Friendly | Permalink | Reply | Top
 
Capn Sunshine Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Feb-01-10 02:00 AM
Response to Original message
8. OK, guys, Malwarebytes does not work.
I ran it in secure mode, and I downloaded a killprocesss program to shut Security Tool off. I ran it twice. It said that there was nothing wrong.

I tried finding the host folder because it must be hiding there; it won't allow that. It says the file is missing. Fuck. Good thing I have other machines.
Printer Friendly | Permalink | Reply | Top
 
pokerfan Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Feb-11-10 09:37 AM
Response to Reply #8
14. You actually should run Malwarebytes in normal mode
unless safe mode is the only way you can get into your system. MWB is designed to run in normal mode as safe mode can prevent some malware from loading.
Printer Friendly | Permalink | Reply | Top
 
pengillian101 Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Feb-01-10 02:45 AM
Response to Original message
9. Have you tried Ad-Aware?
It's good also. Maybe it will find whatever infection you have. Best to ya! I'm just in the same boat as you.

http://www.lavasoft.com/products/ad_aware_free.php
Printer Friendly | Permalink | Reply | Top
 
Capn Sunshine Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Feb-02-10 12:06 PM
Response to Original message
10. I will post here once I encounter a solution
so far, nothing works. All the suggestions here have not removed this but there's several solutions floating around out there.

One problem is running Windows 2000 Pro. Many of the solutions aren't designed for this. If I replace it with XP will the infection remain?
Printer Friendly | Permalink | Reply | Top
 
Raffi Ella Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Feb-04-10 11:46 AM
Response to Reply #10
11. Hi Capn Sunshine,
If I were you I would go to one of the online free help sites and let them guide you through ridding this thing from your computer.

I just had them help me get a really nasty trojan off mine and now my PC is back to normal.

Some trusted ones:



http://forums.techguy.org/54-malware-removal-hijackthis-logs/

http://www.geekstogo.com/forum/Virus-Spyware-Trojan-Removal-f37.html




Printer Friendly | Permalink | Reply | Top
 
laylah Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Feb-09-10 05:14 PM
Response to Original message
12. HELLLLLLLLLLLLP...
this is happening to me and I am SO ignorant of technical situations. I am now scanning with malwarebytes after turning off restore. Have run adaware, avg, and malwarebytes earlier. I don't have a clue. All help will be appreciated!

Accessed the links at the bottom of this thread but I have no idea how to form the question.
Printer Friendly | Permalink | Reply | Top
 
Raffi Ella Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Feb-10-10 07:51 PM
Response to Reply #12
13. Hi
yeah, I know that feeling! It's awful. Did you get help at one of those forums?
Printer Friendly | Permalink | Reply | Top
 
Capn Sunshine Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Feb-28-10 11:18 PM
Response to Reply #13
15. no, it was seriously embedded, even the step by step didn't work
I finally just wiped the damn computer and installed XP. Much of the problem was the OS was Win2000 and there's not much antivirus support. Now, I'm running Microsoft Security Essentials. Best AV I've used . And I've had them all, Kapersky, Norton, Webroot, you name it. The Borg triumphs again.
Printer Friendly | Permalink | Reply | Top
 
Lasher Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Mar-01-10 11:22 AM
Response to Original message
16. Run SUPERAntiSpyware
Edited on Mon Mar-01-10 11:57 AM by Lasher
Long story short, it detected and quarantined an infection on my computer called Trojan.Smitfraud.Variant/IE Anti-Spyware. Microsoft Security Essentials, Spybot Search & Destroy, & Malwarebytes all failed to detect it. SmitFraud is now being used to term infections wherein users receive fake alerts from software luring the user into installing some affiliated fake/rogue anti-spyware with or without user's knowledge.

http://en.wikipedia.org/wiki/SmitFraud

Like I said this is the short story. I kept notes, so I can give you the long version if you want it. There's a lot of this going around. If you witness an attack, physically disable your internet connection. For the time being I have blocked all internet connections in Windows Firewall.
Printer Friendly | Permalink | Reply | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Thu May 02nd 2024, 12:31 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » DU Groups » Computers & Internet » Computer Help and Support Group Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC