Might be a malware problem

Status
Not open for further replies.

CES

optimistic cynic
ECF Veteran
Verified Member
Jan 25, 2010
22,181
61,133
Birmingham, Al
i got it on my work computer :facepalm: through ie9 (i usually use ff, but was checking the skins in ie9). I'd gotten busy and ignored ignored the java update at work. The warning popped up, and like an idiot i clicked on it without looking closely. When i called IT (at 5pm on a Friday!) and told them i had gotten the virus, the first thing they asked was whether it was the fake warning virus. I now think that the the virus got a foothold because i clicked on the trojan " warning" on my bottom toolbar and installed it myself.
 

Majestic

Super Member
ECF Veteran
Verified Member
Apr 11, 2009
956
269
N.E. Wisconsin
I picked up the Windows Recovery fake trojan alert the other day when I was on with my laptop. I was on the forums here and opened a new window to view a vendor's site that was mentioned in a post. The vendor's site wasn't linked in the thread so I copied and pasted the address. While viewing that site I got the alert and the offending file that was put on my hard drive had a date and time corresponding with my viewing of that site. My laptop hadn't been used on FB in quite a while and had Java version 6 update 24 installed.
 

Scottitude

Ultra Member
ECF Veteran
Verified Member
Aug 18, 2010
1,496
1,379
Metro Detroit
scottitude.net
I run frequent AV, registry and malware scans and have never encountered anything that could be even indirectly related to ECF.

Any Facebook user that gets a virus most likely got it from Facebook. If you want your system to be secure, don't Facebook; if you Facebook, your system will, eventually, become infected.
 

Majestic

Super Member
ECF Veteran
Verified Member
Apr 11, 2009
956
269
N.E. Wisconsin
Care to share what vendor website that would be so we all know?

At this point, no. Since I've haven't seen any additional complaints related to that site or any mention of malware infections in the vendor's sub-forum I just as soon not throw any bad PR their way. There is always the faint possibility I could be wrong as to the source since I had two browser windows open at the time.
 
Last edited:

Alex

Code Monkey
ECF Veteran
Apr 6, 2010
298
18
37
California
When something malicious attacks, it tries to access something that can write to the file system, in short C:\

Targets include the browser itself and plugins to that browser like: ActiveX, Java, Flash, PDF (Adobe Acrobat), Silverlight, and whatever else is installed on your computer.

If you're concerned about security or want to minimize your risk of such attack, disable what you never use!!

That being said if you do keep such plugins active, keep them updated. Make sure to update the browser too! (And ditch IE, it's prone to attacks mainly because it is so popular [and buggy])
 

Godzilla

Unregistered Supplier
ECF Veteran
Sep 3, 2010
2,624
1,024
Northern California
www.foxyboxmods.com
Same thing happend to me on my work computer 8 days ago. Thank god IT was cool and did not investigate my browsing habits, otherwise they would have seen how much I love ECF. Not sure if I had been into facebook the same day or not.

i got it on my work computer :facepalm: through ie9 (i usually use ff, but was checking the skins in ie9). I'd gotten busy and ignored ignored the java update at work. The warning popped up, and like an idiot i clicked on it without looking closely. When i called IT (at 5pm on a Friday!) and told them i had gotten the virus, the first thing they asked was whether it was the fake warning virus. I now think that the the virus got a foothold because i clicked on the trojan " warning" on my bottom toolbar and installed it myself.
 

Tinki

Senior Member
Feb 22, 2011
72
8
Texas
:blink:This is the trojan I got from fb and I am only assuming this is where I got it since I had two tabs open-fb and ecf that day. I had first went to fb than ecf when I got a McAfee window warning which was fake. I have ran several malware patches and it looked as if I had gotten rid of the trojans. (Yes the one trojan opens the gate for several others to enter.) After the removal I got back online and the first place I went was here, ecf and I immediately got the windows recovery trojan back again. I am in the long process of getting rid of it again. Be careful it leaves problems on your pc once you get rid of it. And it is a possibility it is coming through from here, ecf to more vulnerable pc. I have At&t McAfee, Malwarebytes Antimalware, Super Anti-spyware, windows and mcafee firewalls. All I have is apparently sub-standard in blocking trojans. Thanks Rolygate for the tip, I will try the online security scan when I am through with cleaning my laptop and desktop of this trojan.
 

0xDeadC0de

Full Member
Dec 24, 2010
37
1
41
Colorado
Malware scans? Antivirus? What are these things? Oh wait, hmm, it's coming back to me.. about 9 yrs ago I dealt with those problems, then switched to the scary Linux..
--informative rant--
Nowadays people can just download an iso, burn it, boot from the cd, and with 6 very simple steps erase the virus (I do mean MS Windows), and have a safe and fast operating system, all for free. It's even easier than installing windows, no need to input a cdkey. Just make sure to backup all your images, documents, and videos on a seperate drive (cd, external, flash drive, secondary hard drive, whatever) first.
The _ONLY_ group of people that (CAN'T) do what they "NEED" in linux are hardcore gamers that only play the latest and greatest games. Web browsing, flash (youtube etc), yes - even porn sites, torrents, office work (Full featured spreadsheet applications, document writing programs, light to heavy duty database applications, scientific calculators), are all standard features.
With wine one can even run many many "windows only" programs, including MS office, world of warcraft, and tons of other stuff. Kubuntu is my preferred, but many like the gnome feel of regular Ubuntu. Did you know KDE had widgets long before windows? Did you know compiz (Now compiz-fusion) was doing advanced desktop graphics stuff (Like wobbly windows, window previews, desktop zoom, previews in alt+tab, window transparency, and tons of other features) years before windows? I only mention Ubuntu and not any of the plethora of others simply because it's the easiest to set up and use with very little messing around (best for beginners, and people who don't want to waste their time).
--end informative rant--

--Useful information on fixing most common windows problems following--
All that being said like a (wonderful) commercial, to many people are to scared to run anything else. "It's all I know." or "I don't have time to learn to point and click in another OS". Which makes me money because, I go out with a cd(or flash drive) containing hijackthis!, combofix, google-chrome installer (Because IE is so crap), and one or two other tiny utilities from bleepingcomputer, and typically make $50USD a pop for an hour (With only about 5 minutes actually interacting with the computer). Once in a long while I need to open the registry and find the RunOnce section to locate a piece of malware that's not detected due to somebody changing a few bits in the header of the program with a hex editor..
And for that, I thank you all.

Sorry for going on so long. It's a passion, if you can't tell.
 
Last edited:

Zelphie

Ultra Member
ECF Veteran
Apr 29, 2010
1,483
554
S.E. Michigan
Sure. I got 2 viruses on 4-24 of the same type: trojen horse sheur.3.bwbb
and I got 1 on 5-4 of a different type: virus exploit.pdf.js

Now, I dont know exactly what those names mean (other than removal obviously) but all of them where immediately detected opon arriving here.

@Tinki
Try this online scanner: OSI - Consumer - Products

Please post here with your Windows version, firewall, anti-malware apps. Thanks.

@Zelphie
Would like to know exactly what your AV reported? Thanks.
 

Tinki

Senior Member
Feb 22, 2011
72
8
Texas
Zelphia, I have several viruses and a few trojans. Some from here and some from fb. I am not sure from which site I got them first or maybe a few from each. I have just about got them all killed and my system restored. It has been a pain in the ..... Thank God I have this little Android tablet to search my pc problems out.
Oxdeadcode, I for one am not afraid of change and would not mind trying Linux/Ubuntu out. I don't know anything about it, but if it is virus/malware free than it sounds great.
I hope ecf checks this trojan crap out and sees if it is coming from their site.
 

Majestic

Super Member
ECF Veteran
Verified Member
Apr 11, 2009
956
269
N.E. Wisconsin
5-5 exploit blackhole exploit kit (2008 type)
This is my 4th thread to date, and I dont even use FB

Zelphie, If you are using Internet Explorer as your web browser make sure that Java is updated to the latest version which is Java 6 Update 25. Most of these trojan alerts get through using older versions of Java. The link below is for the latest version of Java......

Download Free Java Software

What I've been doing is view ECF using Internet Explorer "with no add-ons." This option gives you the basic browser that works just fine on the ECF website without using any Java, ActiveX, toolbars, etc. These add-ons are exploited by malware . Just do this.........

Click Start -> All Programs -> Accessories -> System Tools, and then click Internet Explorer (No Add-ons).

 

Tinki

Senior Member
Feb 22, 2011
72
8
Texas
Majestic is right, keep Java updated as well as Windows, virus protection, ect... I didn't have anything updated except my virus protections. I was using windows firewall which is useless. I am now typing this from my previously infected laptop. The programs I ran to cure whichever trojan or trojans I had, don't even know which one it was, never seen a name for them so I just had to go on my witts: RKill, Unhide.dll, TDSSKiller, Combofix all in safe mode. I than updated Java, etc.. and I downloaded a recommended firewall, an awesome Anti Malware program called Emsisoft for a 3 day trail which when ran found another trojan. So far everything is doing fine. So the game plan is keep updated!!!!!
 
This is caused by a very sneaky and actually pretty smart malware. All sites are basically effected until action is taken by the webmaster. It locked down my mom's laptop when she was browsing chinese shows on a streaming website. Thing is, she actually thought it looked legit and clicked ok anyways. I wiped her lappy and tossed in windows 7.

Turns all programs into hidden and if you try and do anything, a makeshift windows saying windows security etc. AFAIK, it's a hijack attempt to hold your programs and system for ransom, but not personal files (he's a genius, not a complete ....). I don't know a way to recover a compromised syste, without dual booting linux and using that as a means of wiping away the problem. You either pay the dude or wipe and reinstall os.
 

0xDeadC0de

Full Member
Dec 24, 2010
37
1
41
Colorado
DynamiteShikoku, I recently fixed a computer with that same virus. I ran the rkill named iexplore.exe since that virus won't let any other named program run, which killed it. Then I opened up the registry editor, found the RunOnce section which contained only one entry - the entry for the virus. Opened the directory it pointed to in RunOnce, deleted the virus, and removed the entry from RunOnce. That's all it takes to kill that virus. Linux is still better. :p

if that virus were to "mutate" and not even let iexplore.exe to run, I would have booted a livecd of linux with wine on it, mounted the hard drive with windows on it, and used a registry editor to remove the entry from RunOnce, so the virus can't start.

The worst kind of virus is not this kind, the worst kind uses dll's and hooks itself into every single program that you run on your computer. They can be VERY hard to detect, and cause all kinds of weird behaviors. The only time I ever found one I was compiling my own programs and noticed a .dll being loaded that should not have been, did some digging, found it was a trojan.. Well, okay, some virii can inject themselfs into existing files and the only way to find them is to compare against the original files from say, the installation cd...
 
Last edited:
Status
Not open for further replies.

Users who are viewing this thread