Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

HELP-Nasty Computer virus attacking - "MS Spyware"

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Archives » General Discussion (1/22-2007 thru 12/14/2010) Donate to DU
 
FreakinDJ Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Feb-16-09 11:25 AM
Original message
HELP-Nasty Computer virus attacking - "MS Spyware"
Edited on Mon Feb-16-09 11:30 AM by FreakinDJ
I think I'm screwed

Been fighting some Phisher Virus disquised as Microsoft Anti-Spyware

Can't turn it off
Dis-ables the "Task Manager"
Endless Pop-ups saying it can't read memory location "FFFFFFF9"
Directs me to some Non-Microsoft Website wanting me to enter my "Credit Card" information

"-ttp://xp-police-av.com/go.php?id=232127&n=0"

It was disquised as an "Update for Vid-player"

Anyone got any advice

HELP !!!!!!

Virus writers have created a malicious program that can disable Microsoft's new anti-spyware application, security experts warned on Wednesday.
Antivirus experts, who are calling the Trojan "Bankash-A," say it is the first piece of malicious software to attack Windows AntiSpyware, which is still in beta.

"This appears to be the first attempt yet by any piece of malware to disable Microsoft AntiSpyware," Graham Cluley, a senior technology consultant at Sophos, said in a statement. "As Microsoft's product creeps out of beta and is adopted more by the home user market, we can expect to see more attempts by Trojan horses, viruses and worms to undermine its effectiveness."

http://news.cnet.com/Trojan-attacks-Microsofts-anti-spyware/2100-7349_3-5569429.html


This does a whole lot more then "Disable" it wants my credit card
Printer Friendly | Permalink |  | Top
indie_voter Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Feb-16-09 11:29 AM
Response to Original message
1. Have you tried Malwarebytes?
mho, it's a good anti malware scanner.

http://www.malwarebytes.org/


Printer Friendly | Permalink |  | Top
 
geckosfeet Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Feb-16-09 11:30 AM
Response to Reply #1
3. I second this. I downloaded and installed the freeware version -
liked it so much I bought it. I also use spybot search and destroy as well as ESET.
Printer Friendly | Permalink |  | Top
 
FreakinDJ Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Feb-16-09 11:36 AM
Response to Reply #3
8. I use SpyBot too
and I'm running Norton right now

but what I'm seeing is some one took an existing virus and turned it into a "Phisher". Trying to find if this version has been addressed by the Anti-Virus Mfgs
Printer Friendly | Permalink |  | Top
 
hobbit709 Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Feb-16-09 11:44 AM
Original message
Norton is crap
Get AVG or Avast-both free. Get Spybot Search and Destroy and Malwarebytes Antimalware-also free. You may have to turn off System Restore to totally disinfect the computer.
Printer Friendly | Permalink |  | Top
 
KoKo Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Feb-16-09 11:43 AM
Response to Reply #3
12. It saved me from a vicious attack a few weeks ago. "Malwarebytes" free
was easy to dowload even while my computer was going crazy with things like the OP mentioned I managed to download, install quickly and it killed the sucker off.
Printer Friendly | Permalink |  | Top
 
flvegan Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Feb-16-09 11:34 AM
Response to Reply #1
5. Thirded.
Love that program.
Printer Friendly | Permalink |  | Top
 
MindPilot Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Feb-16-09 11:34 AM
Response to Reply #1
6. thirded-- Malwarebytes is the BEST crapware killer ever!!111! n/t
Printer Friendly | Permalink |  | Top
 
Joanne98 Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Feb-16-09 12:21 PM
Response to Reply #1
25. I just downloaded that and I had malware in my computer. Thanks for the link!
:hi:
Printer Friendly | Permalink |  | Top
 
cliffordu Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Feb-16-09 11:30 AM
Response to Original message
2. You are not screwed. Get Linux.
Failing that, shoot your current computer full of holes and then go get yourself another one and load Linux on it.
Printer Friendly | Permalink |  | Top
 
FreakinDJ Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Feb-16-09 11:33 AM
Response to Reply #2
4. This computer has about 1 year of MasterCam work on it
Is Linux compatible with MasterCam X

MasterCam is $17K by itself and I was paid over $100K for the work on thios computer

I have extra Mirrored Drives containing all the work but DAMMMMM....... I need to finish this project
Printer Friendly | Permalink |  | Top
 
cliffordu Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Feb-16-09 11:55 AM
Response to Reply #4
17. I gotta say that if MY massive $$ and talent and time investments
had been taken over and completely fucked up by criminals because 20 years after the first DOS virus M$ STILL hadn't learned to safeguard the shit they sell, I'd be looking for work arounds.

How much is your time worth? How much is your work worth?

Printer Friendly | Permalink |  | Top
 
FreakinDJ Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Feb-16-09 12:19 PM
Response to Reply #17
23. Of course all the "Working Files" are on a dedicated computer
in the shop that is not even connected to the internet.

but this my "Underware Machine" located in the study at home.

I like the freedom of a a little distraction such as "Democratic Underground" while doing my work. Can't stare at numbers and lines ALL day long without going batty in the head.

My 11 year old was searching the internet last night and perhaps that is what planted the seed. I thought I was uploading an update for a video player on the computer because the Cam program has been acting very unstable since last night. Cam software is heavily Video driver dependent and I was hoping this would stabilize the Graphics drivers
Printer Friendly | Permalink |  | Top
 
BadgerKid Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Feb-16-09 12:11 PM
Response to Reply #4
21. Maybe, if you use a virtual machine.
Edited on Mon Feb-16-09 12:12 PM by BadgerKid
I run Ubuntu linux on my hardware, and then I use virtual machine software to run Windows XP in its own window.

I'm currently using VMWare Server, but there are other options.
Printer Friendly | Permalink |  | Top
 
Tandalayo_Scheisskopf Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Feb-16-09 11:35 AM
Response to Original message
7. Goto another computer.
Download a copy of Trinity Rescue Kit. It will be in an .iso file. You can burn it to a CD with a Free program called "ImgBurn". Once burned to a CD, put it in your CD drive and boot the machine. It will boot to a Linux command line. Make sure the computer is hooked to the Internet and type in the following, sans quote marks: "virusscan -a avg" Hit return. Let it run to the end. Then, type in the following command: "virusscan -a bde" . It will ask for certain yes or no answers from you before working. Answer them, then let it run. Then reboot the machine.

If the machine reboots and allows you access to online, then download "A Squared Anti-Malware Free". Install and run it. Finally, a run with Spybot Search & Destroy will never hurt.

And stop clicking on anti-spyware popups that occur while you are browsing.

Printer Friendly | Permalink |  | Top
 
FreakinDJ Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Feb-16-09 11:41 AM
Response to Reply #7
9. I got the Virus to stop running
I went into

C:\WINDOWS\Prefetch

and changed "A EXE.OCOAC950" from a .pf to a .tx file

now I need to clean it up without trashing my computer
Printer Friendly | Permalink |  | Top
 
Tandalayo_Scheisskopf Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Feb-16-09 11:48 AM
Response to Reply #9
15. Well, if you want to clean it up...
I told you how. And please: start saving ALL work product off the machine, if that work product is as valuable as you say.

Also, make sure you check the work product on the external storage. Them things can get around.
Printer Friendly | Permalink |  | Top
 
FreakinDJ Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Feb-16-09 12:11 PM
Response to Reply #15
20. Thanks - Norton got it some how
Like I said it appeared to be an adaptation of an existing Virus that was redirecting me to a "Phisher Site"

Here was Norton's analogy of the Virus

Name: RealAV
Publisher: http://real-av.com
Risk Impact: Medium
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Vista, Windows XP

BehaviorRealAV is a misleading application that may give exaggerated reports of threats on the computer.


I guess the adaptation was close enough to the original for Norton to pick up. I don't see any thing in Norton's description saying it directed you to a phishing site

Printer Friendly | Permalink |  | Top
 
Tandalayo_Scheisskopf Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Feb-16-09 05:56 PM
Response to Reply #20
28. I cannot stress enough...
The necessity for someone like you, who has important stuff on his computer, to download Trinity Rescue Kit. I have rescued a lot of computers from the gaping maw of the abyss with that thing. In fact, were I where you are, I would run it, even though you got rid of the KNOWN threat. There may be others and Trinity gets them goddamned good.

This is a no-shitter alert.
Printer Friendly | Permalink |  | Top
 
wroberts189 Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Feb-16-09 11:41 AM
Response to Original message
10. Avast is good to. Go to download.com..you will find them all
Printer Friendly | Permalink |  | Top
 
dogday Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Feb-16-09 11:42 AM
Response to Original message
11. Same thing happened to me.. I fixed it with this
SmithFraudFix will do the trick....


http://forums.cnet.com/5208-6142_102-0.html?forumID=5&threadID=182891&messageID=1995815

Follow the instructions...

Let me know how it goes..
Printer Friendly | Permalink |  | Top
 
BlooInBloo Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Feb-16-09 11:44 AM
Response to Original message
13. lol!
Printer Friendly | Permalink |  | Top
 
blogslut Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Feb-16-09 11:47 AM
Response to Original message
14. Go here
http://housecall.trendmicro.com/

Get an online scan. Trend Micro is going to ask you to install a bit of software. It's okay. Trend Micro is a reputable company. Perform the scan and hopefully the software will detect it and show you exactly where the baddie is located. It's been a while but I'm pretty sure Trend Micro's scanner will delete/disable the virus for you.

After you've done that go get and install a collection of anti-spyware/PC protection programs. Use a trustworthy site like Download.com for your searches.
Printer Friendly | Permalink |  | Top
 
lies and propaganda Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Feb-16-09 11:49 AM
Response to Original message
16. marking thsi because I think its what it happening to my machine...
my google has been totally 'hacked' if you will.

All the links for your searchs are to spam sites, so my google is comepletely broken.
Printer Friendly | Permalink |  | Top
 
Mr. Sparkle Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Feb-16-09 12:00 PM
Response to Original message
18. Use Smitfraudfix to fix it.
Goto http://siri.geekstogo.com/SmitfraudFix.php and download SmitfraudFix.exe

then boot into safe mode and go through steps 1 and 2. That should fix it.
I used this on a friends computer a few months ago and it worked like a charm.
Printer Friendly | Permalink |  | Top
 
dogday Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Feb-16-09 12:03 PM
Response to Reply #18
19. I posted the same thing in Post # 11
It really works great... I know people who have had to reformat because they did not know how to remove this trojan....
Printer Friendly | Permalink |  | Top
 
FreakinDJ Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Feb-16-09 12:12 PM
Response to Reply #19
22. Thanks for all the help Guys
I'm working on the clean up now

I guess the mock up phishing site scared me
Printer Friendly | Permalink |  | Top
 
Mr. Sparkle Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Feb-16-09 12:21 PM
Response to Reply #19
24. My Bad, i didnt see your post!
Anyway, Great minds think alike :)
Printer Friendly | Permalink |  | Top
 
Gman Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Feb-16-09 12:23 PM
Response to Original message
26. You may need HijackThis
Get it here

However, USE WITH CAUTION! You should know something about the editing your system registry and know the line(s) to delete for this infection which can be tricky.
Printer Friendly | Permalink |  | Top
 
OwnedByFerrets Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Feb-16-09 12:30 PM
Response to Original message
27. Combofix is also a good thing to have handy....
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Fri Apr 26th 2024, 02:07 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Archives » General Discussion (1/22-2007 thru 12/14/2010) Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC