Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

New nasty.

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
Home » Discuss » DU Groups » Computers & Internet » Computer Help and Support Group Donate to DU
 
hobbit709 Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Sep-24-11 08:18 AM
Original message
New nasty.
Had customer bring in her laptop. She got one of the USPS emails and clicked on the link since she was expecting an email from them. About the time she clicked on it she realized it wasn't the .pdf it should have been-too late. Started out as a variation of all the CyberDefender crap.
It even blocked Malwarebytes in Safe Mode. Used my Avira boot disk to clean it out enough to go into Safe Mode and run Malwarebytes. Found about 2 dozen items in the boot disk scan, about 8 more in Safe mode.
booted back into normal desktop and ran full scans with both Malwarebytes and MSE. Came up clean.
went online with Mozilla and immediately got Threat Detected-trying to link to Russian porn sites. Rescanned everything-nada.
Installed Sophos and ran scans-found trojans embedded in svchost and quarantined them. Went online again-same Threat Detected.
After spending all day on it, I said fuck it and saved all the data and wiped drive and reinstalled Windoze.
Appears to be clean now. Ran scans on saved data files with Malwarebytes, AVG, MSE and Sophos-they all checked clean.
Refresh | 0 Recommendations Printer Friendly | Permalink | Reply | Top
lpbk2713 Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Sep-24-11 09:28 AM
Response to Original message
1. Sounds nasty alright.



As bad as it sounds you might want to tell her to check any external media (USB drives,
external drives etc) or she will soon be in the same situation all over again.


Printer Friendly | Permalink | Reply | Top
 
hobbit709 Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Sep-25-11 11:09 AM
Response to Reply #1
2. Everything was backed up the day before.
I scanned it before copying it back on the drive.
Printer Friendly | Permalink | Reply | Top
 
canetoad Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Sep-26-11 02:24 AM
Response to Original message
3. Think I had a phish for this one recently
I keep four or five email accounts, using them for particular purposes. For example one is only family and friends, one is for anything involving a financial transaction, one for forums etc etc.

This means that if I receive virus or phishing emails I have a fair idea of where the breach occurred.

Recently had an email purportedly from NACHA the online payment association with a pdf attachment. YEAH, RIGHT I'm going to open files tagged ......pdf.exe lol.

Bad luck your client was expecting an email Hobbit but geez, after all these years of dodgy attachments has she not twigged that anything .exe is dangerous?
Printer Friendly | Permalink | Reply | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Wed May 01st 2024, 09:09 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » DU Groups » Computers & Internet » Computer Help and Support Group Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC