Register - Login
Views: 99801432
Main - Memberlist - Active users - Calendar - Wiki - IRC Chat - Online users
Ranks - Rules/FAQ - Stats - Latest Posts - Color Chart - Smilies
05-03-22 06:51:50 AM
Jul - Computers and Technology - My Security Shield New poll - New thread - New reply
Next newer thread | Next older thread
Pandaren
Still something.
Level: 108


Posts: 2491/3196
EXP: 13244035
For next: 276464

Since: 08-17-07

From: Finland

Since last post: 1.3 years
Last activity: 105 days

Posted on 09-12-10 03:54:15 PM Link | Quote
It is a nasty virus / malware and it seems that our family computer just got it.

I got rid of it by HijackThis, Avast full scan and a specific program aimed for it, but for now it seems that the computer is still quite screwed up. Task Manager won't pop up, not even with "taskmgr" - command or Ctrl + Alt + Del, the computer is awfully slow and some programs refuse to start (including World of Warcraft, which my sister is very fond to remind me of).

I'm tempted to reinstall Windows XP...

____________________
Layout Base stolen from Gunstar Green (derp)
Zero One
5170
And as we fall the spirit carries on,
That a hero'll come and save us all,
As we call the ones we left below,
We all dream of the day we rise above
Level: 129


Posts: 1489/5173
EXP: 24571702
For next: 477952

Since: 05-24-10

From: Delta Quadrant

Since last post: 1.6 years
Last activity: 130 days

Posted on 09-12-10 03:56:10 PM Link | Quote
System Restore? Bring it back to a date before the virus.

____________________
"The last Metroid is in captivity."
And yet, the galaxy is STILL fucked.
Thanks Xkeeper, Bagel and Sanky for the help!
Bagel

Giant Red Paratroopa
without music life would Bb
Level: 75


Posts: 742/1446
EXP: 3802201
For next: 24703

Since: 03-30-09

Pronouns: he/him
From: bear

Since last post: 190 days
Last activity: 6 days

Posted on 09-12-10 06:00:50 PM (last edited by Bagel at 09-12-10 03:01 PM) Link | Quote
My Security Shield often comes with other malware built in. Sometimes it comes with things to harvest information, or sets your machine up as part of a botnet. There are a lot of small variants so whatever tool you used to remove it doesn't sound like it got all of it. This one looks like a really well-done phishing scam, and it's quite a nasty piece of work.

Malwarebytes is supposed to be the best (at the time of this writing) at removing MSS and its components, and can normally detect it and remove the base infection but there are a lot of minor variations on this one. If you can't get to the malwarebytes download page, you'll have to transfer the executable from another machine or attempt to download it in safe mode (and rename the setup application; MSS can delete known anti-malware apps or their installers.)

Don't depend on System Restore either; sometimes old restore points can be compromised (and ... well to be honest, from experience, System Restore isn't all that reliable or useful even under normal circumstances.)

It might be faster to do an OS reinstallation in this case than to try to undo all the damage, especially if the infection reaches a point where it's days old -- entire system components can be replaced, removed, or simply disabled in the registry, such as Internet Explorer, msconfig, or the task manager. Your hosts file will also probably be set up to block legitimate security software sites. The slowness is because the infection is *constantly* active and using CPU time doing whatever it's been coded to do.

http://www.bleepingcomputer.com/virus-removal/remove-my-security-shield

____________________
Zero One
5170
And as we fall the spirit carries on,
That a hero'll come and save us all,
As we call the ones we left below,
We all dream of the day we rise above
Level: 129


Posts: 1494/5173
EXP: 24571702
For next: 477952

Since: 05-24-10

From: Delta Quadrant

Since last post: 1.6 years
Last activity: 130 days

Posted on 09-12-10 06:02:48 PM Link | Quote
Originally posted by Bagel
Don't depend on System Restore either; sometimes old restore points can be compromised (and ... well to be honest, from experience, System Restore isn't all that reliable or useful even under normal circumstances.)



It helped me with a really bad virus a few months ago.

____________________
"The last Metroid is in captivity."
And yet, the galaxy is STILL fucked.
Thanks Xkeeper, Bagel and Sanky for the help!
Bagel

Giant Red Paratroopa
without music life would Bb
Level: 75


Posts: 743/1446
EXP: 3802201
For next: 24703

Since: 03-30-09

Pronouns: he/him
From: bear

Since last post: 190 days
Last activity: 6 days

Posted on 09-12-10 06:12:29 PM (last edited by Bagel at 09-12-10 03:13 PM) Link | Quote
Originally posted by Zero One
It helped me with a really bad virus a few months ago.


That's fine, if it worked for you. What I'm saying is that from experience, System Restore is better at undoing legitimate user-made changes than it is removing malware, but in either case it's still only very occasionally successful. For example, on some systems that are not infected I've run System Restore (to remove a buggy, stubborn device driver that Device Manager can't get rid of, or something similar) I've seen restores fail for seemingly no reason, leaving me to hunt for old driver installation media or waste time googling around for some other solution.

To date I think I have only run a successful System Restore once, intended mainly to roll back a friend's laptop to some older graphics drivers that weren't available for download anymore.

____________________
Xkeeper

Level: 263


Posts: 17644/25353
EXP: 297140816
For next: 1819637

Since: 07-03-07

Pronouns: they/them/????????

Since last post: 3 days
Last activity: 1 hour

Posted on 09-12-10 06:14:51 PM Link | Quote
System Restore is not meant to fix malware.

I will just leave it at that.

____________________
Zero One
5170
And as we fall the spirit carries on,
That a hero'll come and save us all,
As we call the ones we left below,
We all dream of the day we rise above
Level: 129


Posts: 1498/5173
EXP: 24571702
For next: 477952

Since: 05-24-10

From: Delta Quadrant

Since last post: 1.6 years
Last activity: 130 days

Posted on 09-12-10 06:16:01 PM Link | Quote
Oh, ok. I've only ever need to use it once.

____________________
"The last Metroid is in captivity."
And yet, the galaxy is STILL fucked.
Thanks Xkeeper, Bagel and Sanky for the help!
Pandaren
Still something.
Level: 108


Posts: 2492/3196
EXP: 13244035
For next: 276464

Since: 08-17-07

From: Finland

Since last post: 1.3 years
Last activity: 105 days

Posted on 09-12-10 06:22:27 PM Link | Quote
I'm not sure if I can do that, since there probably isn't any system restore points available.

____________________
Layout Base stolen from Gunstar Green (derp)
Zero One
5170
And as we fall the spirit carries on,
That a hero'll come and save us all,
As we call the ones we left below,
We all dream of the day we rise above
Level: 129


Posts: 1499/5173
EXP: 24571702
For next: 477952

Since: 05-24-10

From: Delta Quadrant

Since last post: 1.6 years
Last activity: 130 days

Posted on 09-12-10 06:25:04 PM Link | Quote
Mine had them set up automatically since installation, but apparently it isn't too good

____________________
"The last Metroid is in captivity."
And yet, the galaxy is STILL fucked.
Thanks Xkeeper, Bagel and Sanky for the help!
Pandaren
Still something.
Level: 108


Posts: 2494/3196
EXP: 13244035
For next: 276464

Since: 08-17-07

From: Finland

Since last post: 1.3 years
Last activity: 105 days

Posted on 09-12-10 08:02:08 PM Link | Quote
Meh, yeah. Probably the best to reinstall whole Windows XP.

And teach my sister not to update / install stuff / visit shady sites while I'm away. This is, what, the third time I'm reinstalling Win?

____________________
Layout Base stolen from Gunstar Green (derp)
Lyskar
12210
-The Chaos within trumps the Chaos without-
Level: 192


Posts: 6453/12211
EXP: 99321052
For next: 552519

Since: 07-03-07

From: 52-2-88-7

Since last post: 7.4 years
Last activity: 7.3 years

Posted on 09-12-10 09:31:32 PM Link | Quote
Stats
Time/Date
09-12-10 03:31:32 PM
Posts
6453
Days Here
1167
Level
117
Metal_Man88's Post
It's possible to painstakingly undo the damage piece by piece, but after a point it becomes a waste of time--and should just reinstall.

____________________

Eisnaught - SSQ² - Mobius Roleplay - SSS
dirbaio
For future reference, "Responsible disclosure" isn't "acting like a douche about an exploit and demanding compensation".
Level: NaN


Posts: 848/-1288
EXP: NaN
For next: 0

Since: 07-28-09

From: Spain

Since last post: 10.8 years
Last activity: 9.9 years

Posted on 09-13-10 05:44:04 PM Link | Quote
Yep.
Spending time trying to take viruses out of Windows is definitely a waste of time.

I use Linux as my main OS. So, as soon as something goes wrong on Windows, I copy everything to the Linux partition and do a fresh install... Usually, backing up, reinstalling, downloading drivers, installing them and getting software (firefox, izarc, visual c++ and c#, etc) usually takes me only an afternoon.

However, I remember spending weeks trying to delete viruses some years ago.

(Of course, that depends on your setup. Maybe you don't have a Linux partition, then doing the backup is a much more complicated process...)

Another thing you could try is booting from an Ubuntu live CD / USB and fixing the problem from there. I'm not sure about this, but you probably can delete/restore all the infected files if you find instructions for that particular virus.

____________________
Aerakin
Ye Olde Layout
Level: 98


Posts: 2114/2550
EXP: 9475889
For next: 178464

Since: 07-06-07

From: From the future

Since last post: 8.0 years
Last activity: 1.2 years

Posted on 09-13-10 06:09:06 PM (last edited by Aerakin at 09-13-10 03:10 PM) Link | Quote
What?

To me, reinstalling Windows every single time you have a problem seems like more of a waste.

I got a similar kind of malware not long ago. Yes it was annoying to get rid of, but I'd rather do that than having to set up yet another install of Windows, with every darn applications + settings I like.

(at least it's not a virus that destroys your MBR, those are always fun)
Gabu

Star Mario
Placeholder Ikachan until :effort: is found
Level: 172


Posts: 3772/9981
EXP: 67989346
For next: 112888

Since: 08-10-09

Pronouns: they/them, she/her
From: Santa Cruisin' USA

Since last post: 56 days
Last activity: 4 days

Posted on 09-13-10 10:21:11 PM (last edited by Gabu at 09-13-10 07:23 PM) Link | Quote
If you can get onto another computer, use a USB flash drive and install MalwareBytes on it, then change the name of the mbam.exe file to something else so that it can't be deleted, then try to run it on the infected machine, update it, and run a scan. It should help free Task Manager if anything.

I should probably get around to making a folder full of virus combating programs. Googlefix is excellent to stop the redirecting BS, but I have a very hard time finding the actual program online nowadays.

____________________

Xkeeper

Level: 263


Posts: 17663/25353
EXP: 297140816
For next: 1819637

Since: 07-03-07

Pronouns: they/them/????????

Since last post: 3 days
Last activity: 1 hour

Posted on 09-14-10 12:18:34 AM Link | Quote
Originally posted by Aerakin
(at least it's not a virus that destroys your MBR, those are always fun)

One nice thing about the advance of the internet is that destructive viruses are a lot less common.


I usually reserve a reinstall of the OS for things that are bad. Totally unrecoverable, or just so clogged with crap that it's time to start over and take better precautions.

____________________
Pandaren
Still something.
Level: 108


Posts: 2497/3196
EXP: 13244035
For next: 276464

Since: 08-17-07

From: Finland

Since last post: 1.3 years
Last activity: 105 days

Posted on 09-14-10 11:31:18 AM Link | Quote
I'll have to give Malwarebytes a try when I head home for the weekend again. :/

____________________
Layout Base stolen from Gunstar Green (derp)
Aerakin
Ye Olde Layout
Level: 98


Posts: 2115/2550
EXP: 9475889
For next: 178464

Since: 07-06-07

From: From the future

Since last post: 8.0 years
Last activity: 1.2 years

Posted on 09-14-10 04:30:22 PM Link | Quote
Originally posted by Pandaren
I'll have to give Malwarebytes a try when I head home for the weekend again. :/


That's what I used recently when I got that kind of virus.

I can't remember the name, but it was definitely of the same scam-ish type.
Gabu

Star Mario
Placeholder Ikachan until :effort: is found
Level: 172


Posts: 3781/9981
EXP: 67989346
For next: 112888

Since: 08-10-09

Pronouns: they/them, she/her
From: Santa Cruisin' USA

Since last post: 56 days
Last activity: 4 days

Posted on 09-14-10 08:37:30 PM Link | Quote
Originally posted by Pandaren
I'll have to give Malwarebytes a try when I head home for the weekend again. :/


I'll also try and see if I can get together my collection of virus/annoying unwanted changes programs together and upload it somewhere. You might need a couple more as well, though these things are a bitch to find sometimes. LIke I said, Googlefix is very useful.

____________________

Pandaren
Still something.
Level: 108


Posts: 2499/3196
EXP: 13244035
For next: 276464

Since: 08-17-07

From: Finland

Since last post: 1.3 years
Last activity: 105 days

Posted on 09-17-10 09:30:55 AM Link | Quote
Malwarebytes seems to be SUPER EFFECTIVE!

It found 788 infected files, got rid of them. Scanned for a second time, found My Security Shield again. Durable little bastard Now I'm running avast! scan again, but at least ZoneAlarm started up again, avast! isn't shutting down on itself and Task Manager can be opened again. The computer seems faster as well.

____________________
Layout Base stolen from Gunstar Green (derp)
Gabu

Star Mario
Placeholder Ikachan until :effort: is found
Level: 172


Posts: 3795/9981
EXP: 67989346
For next: 112888

Since: 08-10-09

Pronouns: they/them, she/her
From: Santa Cruisin' USA

Since last post: 56 days
Last activity: 4 days

Posted on 09-17-10 11:13:35 PM Link | Quote
788?!

Holy shit, my attack earlier this year only had about 50, 100 tops. :U

Yeah, keep running the scanners, one at a time, restart, update, scan again, etc. If anything, it should keep the bug down.

Also, you mentioned ZoneAlarm. This family has had that program for over 10 years now, and if I recall correctly, the aforementioned attack was the only major event that has happened, security-wise. Great program, and I highly recommend it to anybody who doesn't have a low-end machine (So anyone with above 750 MB of RAM and more than 1.25 GHz processing power, if I recall my dad's specs correctly. It works, but it slows down the computer significantly.)

Anyway, there may be things that keep coming back, so first make sure you're doing the deepest scan ZA has to offer (For me, it's under Anti-Virus> Advanced Options Button> Scan Modes> Then the radio button for Super Scan, which includes a root kit scan). If things are still popping up or if you already have that on, go into Firewall, then Advanced Options for Internet Zone. Under Medium Security settings, check and select the following options and ports to block traffic from:

Incoming NetBIOS from ports 9-137 to 445
Incoming ping (ICMP echo)
Other incoming ping
Block incoming IGMP
Incoming UDP ports: 9-137, 445
Incoming TCP ports: 9-137, 445

There may be programs that you use that may need certain ports in the blocked ranges to function, so check on all the major ones and which port they normally connect to the Internet on, and see if you can change it. If not, you can simply edit your settings to allow it. For some reason, I kept getting backdoor things popping up, but once I blocked these ports and killed those files with a scan, they didn't come back. But for whatever reason, your preferences are deleted whenever you reconnect to the network with a new IP (such as when replugging the modem when Comcast decides to be an jerk and kill the connection), and I just learned about this just now, so keep a text file of your settings so if that does happen, you can just retype it all in.

The best thing to do is to make sure all three scans are scanning each day (again, not simultaneous). I went for a near-constant scan attack, but daily can be fine as well. I'd also suggest Spybot S&D (on a flash drive, but I didn't have a problem with it on my machine), and depending on your browser to use the Immunize function, which works on Exploder, Firefox, and Opera. But it does eat away at resources, luckily there an option that can undo Immunization.

I hope any bit of this information can help you at all.

____________________

Next newer thread | Next older thread
Jul - Computers and Technology - My Security Shield New poll - New thread - New reply


Rusted Logic

Acmlmboard - commit 47be4dc [2021-08-23]
©2000-2022 Acmlm, Xkeeper, Kaito Sinclaire, et al.

29 database queries, 3 query cache hits.
Query execution time: 0.088323 seconds
Script execution time: 0.042516 seconds
Total render time: 0.130839 seconds