Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

FYI reemergence of a nasty Trojan "deepdive" disguises itself as "System Tool 2011"

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » General Discussion Donate to DU
 
DainBramaged Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Mar-14-11 02:33 PM
Original message
FYI reemergence of a nasty Trojan "deepdive" disguises itself as "System Tool 2011"
Edited on Mon Mar-14-11 02:34 PM by DainBramaged
Great description on You Tube here

http://www.youtube.com/watch?v=XhUEGHi8AMQ


And it puts this awful background with crappy English on your computer




Malwarebytes removes it in safe mode, then you have to rescan in normal start up mode once it finds the Trojan.

Nasty fuckers. I just burned it out of a critical system here. Hidden in an image in an email, and the sender doesn't even know it was in there.
Printer Friendly | Permalink |  | Top
democraticinsurgent Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Mar-14-11 02:39 PM
Response to Original message
1. I got this 2 weeks ago
Malwarebytes in safe mode was the only salvation. It blocks every executable file. Nasty indeed.
Printer Friendly | Permalink |  | Top
 
ET Awful Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Mar-14-11 02:40 PM
Response to Original message
2. Yeah, one of the computers at work got that a week or two ago . . . I had to laugh at the
"could break your life!" though :).
Printer Friendly | Permalink |  | Top
 
DainBramaged Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Mar-14-11 02:42 PM
Response to Reply #2
4. "could break your life!"
We had a great laugh at that, but this one was different from the fake anti-virus going around, Iobit 360 and Emco didn't get it which surprised me, but I found the file in safe mode and deleted it. Last time these guys were using files in Application data, now it's moved.
Printer Friendly | Permalink |  | Top
 
Initech Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Mar-14-11 02:41 PM
Response to Original message
3. Coworker's computer caught it. Removing it was a pain in the ass.
Printer Friendly | Permalink |  | Top
 
DainBramaged Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Mar-14-11 02:42 PM
Response to Reply #3
5. They moved it's hiding place
it's in the video for the rest of us geeks.
Printer Friendly | Permalink |  | Top
 
Initech Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Mar-14-11 07:02 PM
Response to Reply #5
22. Most of the time you wind up doing a total reformat and that sucks.
Printer Friendly | Permalink |  | Top
 
hobbit709 Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Mar-14-11 02:44 PM
Response to Original message
6. I've removed this from about 5 computers in the last couple of weeks.
And talked about 4 more through it on the phone
Printer Friendly | Permalink |  | Top
 
dkofos Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Mar-14-11 02:47 PM
Response to Original message
7. Malware , virus, and trojan free for 10 years.
Linux rules.
Printer Friendly | Permalink |  | Top
 
AlabamaLibrul Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Mar-14-11 05:44 PM
Response to Reply #7
13. That just usually causes a schmegstorm in these sorts of threads
but hey, I'm posting from Ubuntu 10.10 dual booted with Crunchbang Statler, and my desktop is always my photos, not some hyped up rogue anti-spyware BS.
Printer Friendly | Permalink |  | Top
 
ET Awful Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Mar-14-11 05:51 PM
Response to Reply #7
14. On my personal computers, I've been malware, virus and trojan free since I bought my first one.
And they've all been Windows PC's.

The only time I have to clean anything of the sort is off of other people's machines.
Printer Friendly | Permalink |  | Top
 
ikri Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Mar-14-11 02:50 PM
Response to Original message
8. Removed it from about 6 PCs already
Piece of piss to get rid of - restart in safe mode & delete the folder in the C:\Users\All Users\ folder with the glaringly obvious random string of letters & numbers, reboot & do a full AV scan.

1 guy at work got it on 3 different computers (his, his wife's & his son's), the only thing they all seem to have in common though is that they'd all recently visited facebook, otherwise there were no similarities in their browsing behaviour. I'd guess that it gets dropped by a rogue script or advert on facebook (at least in the cases I've seen).

What's really bad though is that all the computers had antivirus running, none of them were the usual expired OEM install of McAfee or Symantec crap. All the antivirus software was up to date but they still managed to miss the initial infection.
Printer Friendly | Permalink |  | Top
 
formercia Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Mar-14-11 03:02 PM
Response to Original message
9. I remember this one.
After 'getting rid of it.', I created another user account to make sure. It was a pain.
Printer Friendly | Permalink |  | Top
 
DainBramaged Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Mar-14-11 03:08 PM
Response to Original message
10. What bothers me is that some of us knew about this and said nothing to DU.....
And when I do these PSA's I get shit most of the time.


I do not understand the lack of information being spread about important shit like this.


Meh meh and meh.
Printer Friendly | Permalink |  | Top
 
ET Awful Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Mar-14-11 05:52 PM
Response to Reply #10
16. In all honesty, for me, cleaning this stuff is routine at work, so it never even
occurs to me to post anything about it here.
Printer Friendly | Permalink |  | Top
 
DainBramaged Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Mar-14-11 06:06 PM
Response to Reply #16
19. It's what I do also, but I never hesitate to post (check my journal)
Maybe it's the way I feel about Du that makes me care about this shit.
Printer Friendly | Permalink |  | Top
 
toddwv Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Mar-14-11 03:36 PM
Response to Original message
11. Just removed that from my niece's computer.
It pretty much shuts everything down, no internet etc...
Printer Friendly | Permalink |  | Top
 
DainBramaged Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Mar-14-11 05:42 PM
Response to Original message
12. Kick for those who aren't geeks.
and don't get to remove this from 4 or 5 computers a week.
Printer Friendly | Permalink |  | Top
 
walldude Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Mar-14-11 05:52 PM
Response to Original message
15. Oh shit. Spy Sheriff all over again...
I hate these. The really fuck up your system. Kill your admin rights, disable msconfig, disable right clicking, disable system restore, if I weren't a power user trojans like this would have knocked me out a couple of times...
Printer Friendly | Permalink |  | Top
 
ET Awful Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Mar-14-11 05:54 PM
Response to Original message
17. As a PSA that fixes this and many other infections . . .
I recommend Combofix.

It is updated pretty much daily and I have yet to encounter something it couldn't clean when used properly.
Printer Friendly | Permalink |  | Top
 
DainBramaged Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Mar-14-11 05:59 PM
Response to Reply #17
18. Takes too long, once you know where it hides, zap in safe mode
Edited on Mon Mar-14-11 06:01 PM by DainBramaged
or MWB in safe mode.


And it amazes me people are unreccing this, DU is certainly pushing my 'end help' button.
Printer Friendly | Permalink |  | Top
 
Egnever Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Mar-14-11 06:11 PM
Response to Reply #17
21. last time I checked
Combofix doesnt work on vista or 7 that may have changed though I havent checked in a while. This thing is ridiculously easy to get rid of though Combofox is overkill for this one IMHO.
Printer Friendly | Permalink |  | Top
 
Egnever Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Mar-14-11 06:07 PM
Response to Original message
20. This thing is a joke as far as removal
its freakishly easy to get rid of but thanks for the video I am sure it wil help many. I almost feel bad charging people to remove this thing its so easy.
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Wed Apr 17th 2024, 08:25 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » General Discussion Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC