Pelican Parts
Parts Catalog Accessories Catalog How To Articles Tech Forums
Call Pelican Parts at 888-280-7799
Shopping Cart Cart | Project List | Order Status | Help



Go Back   Pelican Parts Forums > Miscellaneous and Off Topic Forums > Off Topic Discussions


Reply
 
LinkBack Thread Tools Rate Thread
Author
Thread Post New Thread    Reply
Registered
 
Join Date: Jul 2005
Location: Seattle
Posts: 5,823
Another fresh XP install - and a WARNING

Yay. A month ago I did a fresh XP install when something went haywire. Now I get to do it again, thanks to a bit of MALWARE called "XP Internet Security 2010"

I had downloaded a trial of Kaspersky Internet Security 2010 about a month ago when I did the fresh install.
It ran out tonight before I could purchase a license key.
IMMEDIATELY on it's runout, I was hit with a bogus Malware warning from "XP Internet Security 2010" It performed a fake scan, saying I was loaded with virrii. I saw it for what it was....
I was surfing a less than desireable site when Kaspersky ran out.

No attempt to remove it proved successfull.
It blocked attempts to install the Anti-malware program that was suggested to remove it, save one. After cleaning, any .exe program access was blocked...
Regedit was blocked so I could not manually remove reg entries.

So yeah, I get to reinstall XP again.

Be on the lookout for XP Internet Security 2010. It's nasty. A family member reports that a friends got it a couple months ago and had to have his system wiped. Even the pros coulnd't get rid of it...

__________________
'85 911. White - 53,000 miles bought 3-16-07. "Casper"
'88 924S. Blue - 120k miles bought with 105k miles.
'94 968 Coupe - White - 108,000 miles bought 9-28-17
'09 Cayman - Grey - bought 9-8-20
Old 02-07-2010, 01:48 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #1 (permalink)
Registered
 
Join Date: Jul 2000
Posts: 5,728
"less than desirable site" you can even run into this on good sites. Once something like this pops up, best you can do is Crtl Alt Delete, & don't go back to site.

If I was a hacker, I would take the offensive & shut down those sites spreading this stuff.
__________________
drew1

wife has 924 turbo
Old 02-07-2010, 04:34 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #2 (permalink)
Senior Member
 
Join Date: Jun 2000
Location: N. Phoenix AZ USA
Posts: 28,943
What do you mean "I was hit?"

How did it come? In an email, link you opened or ???

Have seen lots of this crap sent around in emails and they ALL are virus crap. MS is not going to send things like this out...

Joe A
__________________
2013 Jag XF, 2002 Dodge Ram 2500 Cummins (the workhorse), 1992 Jaguar XJ S-3 V-12 VDP (one of only 100 examples made), 1969 Jaguar XJ (been in the family since new), 1985 911 Targa backdated to 1973 RS specs with a 3.6 shoehorned in the back, 1959 Austin Healey Sprite (former SCCA H-Prod), 1995 BMW R1100RSL, 1971 & '72 BMW R75/5 "Toaster," Ural Tourist w/sidecar, 1949 Aeronca Sedan / QB
Old 02-07-2010, 06:25 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #3 (permalink)
Hilbilly Deluxe
 
emcon5's Avatar
 
Join Date: Nov 2000
Location: Reno
Posts: 6,492
Garage
Most professionals aren't. Unless your hard drive is encrypted, they are all cleanable.

Once infected it's a little late, but here is a recipe that had served me well for years, including ~15 years working in IT.

Make sure Windows automatic updates is on, set to install critical updates automatically. Let the PC phone home and patch itself.

Don't use Internet Explorer. It is a lot better than it was, but it is still has the most market share, therefore more malware targets vulnerabilities in it.

Instead of IE, use the latest version of Firefox, and let it check for updates. Install the Adblock plus firefox extension.

As added protection, install Spybot Search and destroy and run the "Immunize" tool. Update and re-immunize once a month.

Use anti-virus software, and keep it updated. In reality, it doesn't matter which one, they are only as good as their current virus definitions, and since they come out pretty much daily, who is best is a moving target. I am a fan of AVG free., it is free, with no subscription required.

And last, install Malwarebytes anti malware and update and run it periodically. Malwarebytes is the best removal tool out there at the moment, in fact a lot of malware knows this and includes code to prevent the installer for Malwarebytes from running.

This should cover 99.9% of problems, assuming you aren't regularly surfing/downloading from Russian porn/warez sites, and of course, practice smart browsing.
__________________
82 911SC Coupe
GTI Cup #43
Old 02-07-2010, 07:29 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #4 (permalink)
Alii&Maui
 
Jesset100's Avatar
 
Join Date: May 2004
Location: Kentucky
Posts: 1,253
Garage
Get this
http://www.microsoft.com/Security_Essentials/
__________________
1982 SC Coupe
SCWDP#0087
KCSSL#0082
Old 02-07-2010, 07:58 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #5 (permalink)
Banned
 
m21sniper's Avatar
 
Join Date: Sep 2006
Location: South of Heaven
Posts: 21,159
Wolfe that sounds like something malwate bytes would eat for a living.

You just have to change the .exe name to something else, to fool the virus.
Old 02-07-2010, 09:06 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #6 (permalink)
 
Registered
 
exitwound's Avatar
 
Join Date: Oct 2003
Location: State College, PA
Posts: 1,499
Garage
MSE is by far the best one I've ever used. It's caught a few malformed .jpgs which were trojans and doesn't slow the system down at all. Using it on Win7. Don't think there's an XP version. Perhaps I'm wrong.
__________________
-Patrick
Black 1986 944
Old 02-07-2010, 10:04 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #7 (permalink)
Did you get the memo?
 
onewhippedpuppy's Avatar
 
Join Date: Mar 2003
Location: Wichita, KS
Posts: 32,368
Just stay away from the donkey porn.
__________________
‘07 Mazda RX8-8
Past: 911T, 911SC, Carrera, 951s, 955, 996s, 987s, 986s, 997s, BMW 5x, C36, C63, XJR, S8, Maserati Coupe, GT500, etc
Old 02-07-2010, 10:19 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #8 (permalink)
D idn't E arn I t
 
RANDY P's Avatar
Hell I tried to remove that stuff and couldn't - it even protected the registry so I couldn't erase the registry link that started the trojan.

next time, start a seperate admin profile - that can install just for installing programs and updates and change your current profile to User only so next time you surf your porn the malware can't execute..

rjp
__________________
AOC/Hogg 2028
Old 02-07-2010, 11:03 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #9 (permalink)
dtw dtw is offline
GAFB
 
Join Date: Dec 1999
Location: Raleigh, NC, USA
Posts: 7,842
As long as you can boot into safe mode, this crap can be defeated.

I had in infection of the same thing you had, two weeks ago. The only non-work related thing I had open was a music lyrics site. It had to have spawned from there.

Only problem: I was at work WAYYYY after hours (IT guys gone) and am unable to boot into safe mode. Nonetheless, I still managed to beat the sucker. Using my iPhone, I surfed for some information on the plague and found the locations of the executables. I have an emergency utility called "RemoveOnReboot" which adds a "Remove on Reboot" (duh) option to the context menu. The trojan tried hard to keep me from selecting the executables for deletion - it blocks all other .exes from running. However, after a couple tries, the two major trojan executables were flagged for deletion.

I rebooted and kept on eye on process manager; the offenders did not load into memory. Then I ran CCleaner, then ran a full scan with MalwareBytes. By the time I got done with the manual deletions and the CCleaner wipe, there wasn't even anything left for MWB to clean, but I ran it just in case.

If you still have this going on and want to try the RemoveOnReboot tool, pm me and I'll email you the install file (it is only 35kb). If you can somehow get it onto the zombie system, you can fight the thing off.

In my case, a re-image wasn't an option since I had way too much going on at work. I had to clean it out of the existing image. That, and I consider it a failure as a techno-geek if I succumb to the urge to re-image.
__________________
Several BMWs
Old 02-07-2010, 11:24 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #10 (permalink)
dtw dtw is offline
GAFB
 
Join Date: Dec 1999
Location: Raleigh, NC, USA
Posts: 7,842
Some other notes - this infection is extremely aggressive and attacks on multiple fronts. There are reports of it doing keylogging and password attacks, then 'phoning home' with the information. As soon as I knew I was zombied, I unplugged my network cable.

Your IE session, while seemingly functional, is hacked using a malicious proxy server. It re-routes you to all sorts of nasty sites. You can cancel the proxy server usage, but the trojan will just re-route it immediately afterward.

Chrome and Safari are of no use, as the trojan will not let them load. Best as I could tell, the only exe allowed to run is IE, and that is useless due to the malicious proxy.
__________________
Several BMWs
Old 02-07-2010, 11:28 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #11 (permalink)
Cogito Ergo Sum
 
Join Date: Jul 2007
Posts: 29,791
Garage
Quote:
Originally Posted by m21sniper View Post
Wolfe that sounds like something malwate bytes would eat for a living.

You just have to change the .exe name to something else, to fool the virus.
Malwarebytes ain't that great either.... I've got a pc that about to get wiped b/c malwarebytes can't find the virus.... The windows onecare scanner finds something... and the locks down the computer.....
Old 02-07-2010, 12:01 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #12 (permalink)
 
Banned
 
m21sniper's Avatar
 
Join Date: Sep 2006
Location: South of Heaven
Posts: 21,159
MW Bytes won't find everything, but it's the best thing going right now. And i'd bet that whatever it is that it won't find right now, after a few more updates, it would.

It's a great product.
Old 02-07-2010, 02:02 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #13 (permalink)
Banned
 
m21sniper's Avatar
 
Join Date: Sep 2006
Location: South of Heaven
Posts: 21,159
Quote:
Originally Posted by dtw View Post
As long as you can boot into safe mode, this crap can be defeated.

I had in infection of the same thing you had, two weeks ago. The only non-work related thing I had open was a music lyrics site. It had to have spawned from there.

Only problem: I was at work WAYYYY after hours (IT guys gone) and am unable to boot into safe mode. Nonetheless, I still managed to beat the sucker. Using my iPhone, I surfed for some information on the plague and found the locations of the executables. I have an emergency utility called "RemoveOnReboot" which adds a "Remove on Reboot" (duh) option to the context menu. The trojan tried hard to keep me from selecting the executables for deletion - it blocks all other .exes from running. However, after a couple tries, the two major trojan executables were flagged for deletion.

I rebooted and kept on eye on process manager; the offenders did not load into memory. Then I ran CCleaner, then ran a full scan with MalwareBytes. By the time I got done with the manual deletions and the CCleaner wipe, there wasn't even anything left for MWB to clean, but I ran it just in case.

If you still have this going on and want to try the RemoveOnReboot tool, pm me and I'll email you the install file (it is only 35kb). If you can somehow get it onto the zombie system, you can fight the thing off.

In my case, a re-image wasn't an option since I had way too much going on at work. I had to clean it out of the existing image. That, and I consider it a failure as a techno-geek if I succumb to the urge to re-image.
Hey bro, i'd love that file. Where can i get it?
Old 02-07-2010, 02:04 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #14 (permalink)
dtw dtw is offline
GAFB
 
Join Date: Dec 1999
Location: Raleigh, NC, USA
Posts: 7,842
Quote:
Originally Posted by m21sniper View Post
Hey bro, i'd love that file. Where can i get it?
Let me google that for you!

__________________
Several BMWs
Old 02-07-2010, 02:26 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #15 (permalink)
Registered
 
slodave's Avatar
 
Join Date: Sep 2005
Location: Encino Man
Posts: 22,394
Garage
Send a message via Skype™ to slodave
Quote:
Originally Posted by m21sniper View Post
MW Bytes won't find everything, but it's the best thing going right now. And i'd bet that whatever it is that it won't find right now, after a few more updates, it would.

It's a great product.
Sidney's pc has a boot sector virus. It will be a long time before Malwarebytes can fix these issues. The only ones that can, are true virus detection programs and they are having a hard time with it. This type of situation is better for a format and clean install anyway. Any virus that can modify the bootstrap/MBR has done real damage.

Most malware is aggravating, not really destructive to the OS or boot records.
__________________
Make sure to check out my balls in the Pelican Parts Catalog! 917 inspired shift knobs.

'84 Targa - Arena Red - AX #104
'07 Toyota Camry Hybrid - Yes, I'm that guy...
'01 Toyota Corolla - Urban Camouflage - SOLD
Old 02-07-2010, 03:06 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #16 (permalink)
Registered
 
ruf-porsche's Avatar
 
Join Date: Feb 2000
Location: no where
Posts: 4,390
Garage
Quote:
Originally Posted by onewhippedpuppy View Post
Just stay away from the donkey porn.
Oh you mean YouTube? LMFAO

Old 02-07-2010, 05:06 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #17 (permalink)
Registered
 
Join Date: Jul 2005
Location: Seattle
Posts: 5,823
Quote:
Originally Posted by dtw View Post
As long as you can boot into safe mode, this crap can be defeated.
.
No safe mode, either!

Quote:
Originally Posted by RANDY P View Post
Hell I tried to remove that stuff and couldn't - it even protected the registry so I couldn't erase the registry link that started the trojan.

rjp
Yep, same here. No regedit access.

Quote:
Originally Posted by m21sniper View Post
Wolfe that sounds like something malwate bytes would eat for a living.

You just have to change the .exe name to something else, to fool the virus.
Tried that. Didn't work.
__________________
'85 911. White - 53,000 miles bought 3-16-07. "Casper"
'88 924S. Blue - 120k miles bought with 105k miles.
'94 968 Coupe - White - 108,000 miles bought 9-28-17
'09 Cayman - Grey - bought 9-8-20
Old 02-07-2010, 09:47 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #18 (permalink)
Registered
 
slodave's Avatar
 
Join Date: Sep 2005
Location: Encino Man
Posts: 22,394
Garage
Send a message via Skype™ to slodave
Here's a link that deals with Wolf's issue...

How to remove XP Internet Security 2010, Antivirus Vista 2010, and Win 7 Antispyware 2010
__________________
Make sure to check out my balls in the Pelican Parts Catalog! 917 inspired shift knobs.

'84 Targa - Arena Red - AX #104
'07 Toyota Camry Hybrid - Yes, I'm that guy...
'01 Toyota Corolla - Urban Camouflage - SOLD
Old 02-07-2010, 10:21 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #19 (permalink)
Registered
 
jmaxwell's Avatar
 
Join Date: Apr 2006
Location: Tornado alley
Posts: 276
Slo Dave, if you're ever in Tulsa, I'll buy you at least a beer. That site worked so well that my son was able to clean his computer without having to bring it home (a 240 mile round trip). And his computer knowledge is limited to browsing and Microsoft office. Thanks a bunch!

Jack

__________________
Jack
'70 914/6
Old 02-11-2010, 09:31 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #20 (permalink)
Reply


 


All times are GMT -8. The time now is 03:49 PM.


 
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0
Copyright 2025 Pelican Parts, LLC - Posts may be archived for display on the Pelican Parts Website -    DMCA Registered Agent Contact Page
 

DTO Garage Plus vBulletin Plugins by Drive Thru Online, Inc.