Personal computing discussed

Moderators: askfranklin, renee, emkubed, Captain Ned

 
SpotTheCat
Gerbilus Supremus
Topic Author
Posts: 12292
Joined: Wed Jan 29, 2003 12:47 am
Location: Minnesota

First virus in about a decade

Wed Dec 14, 2011 10:20 pm

What the hell. My wife caught a virus, it makes "windows 7 antivirus" pop up like crazy. I haven't seen a virus for real in a long time. I'm sure I've had them, but I haven't actually seen such an annoying one in a while.

It's probably her computer illiterate family sending all sorts of warnings (with links) about computer viruses.
 
bthylafh
Maximum Gerbil
Posts: 4320
Joined: Mon Dec 29, 2003 11:55 pm
Location: Southwest Missouri, USA

Re: First virus in about a decade

Wed Dec 14, 2011 11:01 pm

It's quite possible they visited a legit site with an infected ad server. Happens to my users a lot.

Make sure Java, Flash, Acrobat, and Quicktime are all up to date if they're installed; IIRC the biggest infection vectors are those four more or less in order.
Hakkaa päälle!
i7-8700K|Asus Z-370 Pro|32GB DDR4|Asus Radeon RX-580|Samsung 960 EVO 1TB|1988 Model M||Logitech MX 518 & F310|Samsung C24FG70|Dell 2209WA|ATH-M50x
 
SpotTheCat
Gerbilus Supremus
Topic Author
Posts: 12292
Joined: Wed Jan 29, 2003 12:47 am
Location: Minnesota

Re: First virus in about a decade

Wed Dec 14, 2011 11:06 pm

Huh, good point. Those are the most annoying things to update, too.
 
JustAnEngineer
Gerbil God
Posts: 19673
Joined: Sat Jan 26, 2002 7:00 pm
Location: The Heart of Dixie

Re: First virus in about a decade

Wed Dec 14, 2011 11:38 pm

Try MBAM on it.
 
JJCDAD
Gerbil Jedi
Posts: 1867
Joined: Fri Sep 17, 2004 3:11 pm
Location: Is this heaven? No, it's Iowa.
Contact:

Re: First virus in about a decade

Thu Dec 15, 2011 12:43 am

I just tackled this bastard today at work. The instructions and tools on this page worked really well.


Side note: I actually sat and watched my own personal pc succumb to a very similar virus/malware. It caused a system tray popup message that warned of a failing hard drive. When I clicked the "X" to close the popup, all hell broke loose. Turns out the virus came from an infected ad server on the page of a Facebook flash game I was playing. So it is not necessarily computer illiterates doing stupid things to welcome viruses onto their systems (yes, I know that playing flash games on Facebook may qualify as a stupid thing lol).
 
MadManOriginal
Gerbil Jedi
Posts: 1533
Joined: Wed Jan 30, 2002 7:00 pm
Location: In my head...

Re: First virus in about a decade

Thu Dec 15, 2011 12:59 am

SpotTheCat wrote:
What the hell. My wife caught a virus, it makes "windows 7 antivirus" pop up like crazy. I haven't seen a virus for real in a long time. I'm sure I've had them, but I haven't actually seen such an annoying one in a while.

It's probably her computer illiterate family sending all sorts of warnings (with links) about computer viruses.


Just curious if there's any anti-virus on her computer?

Also, what settings do you have for UAC?
 
evilpaul
Gerbil
Posts: 61
Joined: Mon Jan 11, 2010 6:59 pm

Re: First virus in about a decade

Thu Dec 15, 2011 1:37 am

Two things. First, UAC should be at the maximum level. It's not at all annoying unless you're setting up a new Windows installation. Second, your day to day user account shouldn't have Administrator access. Limited User+Maxxed UAC means your Windows 7 box doesn't get malware-smacked in any significant way.

To be specific, there's some malware that pops up a fake "anti-virus scanner" and auto-kills Task Manager and you can mostly keep it from starting via msconfig and then remove when it's not running. I forget the name of it, so you in your thing and you'll find it.
 
Krogoth
Emperor Gerbilius I
Posts: 6049
Joined: Tue Apr 15, 2003 3:20 pm
Location: somewhere on Core Prime
Contact:

Re: First virus in about a decade

Thu Dec 15, 2011 5:27 am

This form of malware is known as smutware. It is basically a phishing scam that depends on users who pay the writers for fake anti-virus software (which is really a backdoor trojan) and use the financial information to commit identify theft. The fake anti-virus generates nothing but false positives to make it look like that your entire system has been compromise. In reality, it is the program itself that is the infection. It likes to duplicate itself within your Users and temp directories using random strings like "$G35787" and "DGMDTG@".

My first action is to completely isolate the infect system from the network/internet and do anti-malware updates via sneakernet. Obtain the aforementioned updates from a clean system. Do the anti-malware scans and then search for traces of the malware in the registery/HDD and remove it manually. If this all fails, you have little choice but to nuke everything from orbit. ;)
Gigabyte X670 AORUS-ELITE AX, Raphael 7950X, 2x16GiB of G.Skill TRIDENT DDR5-5600, Sapphire RX 6900XT, Seasonic GX-850 and Fractal Define 7 (W)
Ivy Bridge 3570K, 2x4GiB of G.Skill RIPSAW DDR3-1600, Gigabyte Z77X-UD3H, Corsair CX-750M V2, and PC-7B
 
SuperSpy
Minister of Gerbil Affairs
Posts: 2403
Joined: Thu Sep 12, 2002 9:34 pm
Location: TR Forums

Re: First virus in about a decade

Thu Dec 15, 2011 10:03 am

One of my biggest praises of WIndows 7 is that most of this type of malware has been forced to become simple user-level annoyance apps, which makes it extremely easy to remove by simply logging in as a different user with admin access, and picking apart the infected user's user directory while the malware is inactive.

Much, much better than the days of Windows XP letting everything into the system with either an admin account, or a privilege-escalation attack, then having to clean it out of a hundred different possible hiding places.
Desktop: i7-4790K @4.8 GHz | 32 GB | EVGA Gefore 1060 | Windows 10 x64
Laptop: MacBook Pro 2017 2.9GHz | 16 GB | Radeon Pro 560
 
PeregrineFalcon
Gerbil
Posts: 14
Joined: Mon Oct 03, 2011 8:54 am

Re: First virus in about a decade

Thu Dec 15, 2011 10:52 am

Krogoth wrote:
This form of malware is known as smutware.


PeregrineFalcon is not impressed with Krogoth's incorrect terminology. Scamware or scareware.

Smutware would be porn pop-ups. ;)
 
SpotTheCat
Gerbilus Supremus
Topic Author
Posts: 12292
Joined: Wed Jan 29, 2003 12:47 am
Location: Minnesota

Re: First virus in about a decade

Thu Dec 15, 2011 7:43 pm

The culprit is many things. Mostly, I've assumed she has the same computer decision making skills as I do.
1. I always update my software.
2. I never even open emails from my relatives. It's 99% chain/spam anyways. (I also don't listen to voice mail, who wouldn't just text if I don't pick up?)
3. I avoid ad-plagued websites like... well... the plague.
4. Other habits I have that pretty much eliminate problems.
5. I do virus scans about quarterly, I don't like running real-time software because they make everything so slow and interrupt so many common actions.

I found a guide to uninstall the virus, it seems to have worked. I'll run a gauntlet of AV software suites to make sure.

Changes to her policy
1. I will enforce her use of google docs for her work. She works from home (she is a writer!) and I've been insisting that google docs will provide safer storage for her work for months. Nothing I can do will be as robust and safe as the cloud.
2. I have made a separate work account for her in windows. If something asks for the admin password she will not have it!
3. I will either find a way to safely update all of the weaker software (Java etc.) automatically, or will make a point of checking it often.
4. I will (reluctantly) have avast or AVG (or another?) running constantly "in the background." I hate them, they slow everything down and befuddle you with constant questions that you eventually just ignore. Does anybody have a better idea?

Is there anything else I need to do or something I should do differently? I'm not a corporate IT policy guy, but I feel like I need one considering the mission-critical nature of this computer.
 
Palek
Gerbil
Posts: 35
Joined: Thu Oct 28, 2004 4:26 am

Re: First virus in about a decade

Thu Dec 15, 2011 8:14 pm

3. I will either find a way to safely update all of the weaker software (Java etc.) automatically, or will make a point of checking it often.

I would recommend Secunia PSI. It scans all installed applications and checks them against Secunia's vulnerability database. It will notify you if any of your software has known vulnerabilities and if there are patches for it. It will also automatically patch weak links like Flash, Adobe Reader and Quicktime (I think). It's another thing to run in the background, but a newish computer should be able to handle it without slowing down too much. It does a start-up scan and then mostly stays out of the way.
4. I will (reluctantly) have avast or AVG (or another?) running constantly "in the background." I hate them, they slow everything down and befuddle you with constant questions that you eventually just ignore. Does anybody have a better idea?

Yes, just use Microsoft Security Essentials. It's free, fairly light and non-intrusive.

Also, I would recommend installing Opera as the default browser. You can disable JS and plug-ins by default and then only enable them for individual websites via custom website settings. (I'm sure you can do this with other alternative browsers as well, but I'm only familiar with Opera.) This will stop compromised ad servers from infecting your machine (unless you enable JS and plug-ins for the ad servers, that is).
 
bthylafh
Maximum Gerbil
Posts: 4320
Joined: Mon Dec 29, 2003 11:55 pm
Location: Southwest Missouri, USA

Re: First virus in about a decade

Thu Dec 15, 2011 8:32 pm

SpotTheCat wrote:
1. I will enforce her use of google docs for her work. She works from home (she is a writer!) and I've been insisting that google docs will provide safer storage for her work for months. Nothing I can do will be as robust and safe as the cloud.


What if Docs lacks a feature she uses often enough for its omission to be annoying? It's a bit light on features compared to Word. John Scalzi (sf writer) tried writing a book in Docs on his Cr-48 for a time early this year and gave up because it didn't do what he wanted.
Hakkaa päälle!
i7-8700K|Asus Z-370 Pro|32GB DDR4|Asus Radeon RX-580|Samsung 960 EVO 1TB|1988 Model M||Logitech MX 518 & F310|Samsung C24FG70|Dell 2209WA|ATH-M50x
 
Neutronbeam
Gerbil XP
Posts: 460
Joined: Mon Mar 20, 2006 10:07 am
Location: Dunwoody, Georgia USA
Contact:

Re: First virus in about a decade

Thu Dec 15, 2011 10:02 pm

A few very minor suggestions--

AVG Free just got a very positive review from Maximum PC and it does NOT pop up with annoying messages much--I am using it on two machines.

Consider ZoneAlarm Free Firewall as an addition.

Have her do WEEKLY scans.

Use Ninite--free or paid service at $10/year--to update a group of apps at once, including QuickTime, Adobe Flash, etc. Highly recommended. For the free version you run the downloaded file periodically and it updates all the apps. The paid service scans and does it daily. http://ninite.com/

Have her use the Chrome browser since it is sandboxed. Alternatively, buy her Sandboxie--http://www.sandboxie.com/--and set it up so her browser (and other programs if desired) are automatically sandboxed.
"the work goes on, the cause endures, the hope still lives, and the dream shall never die." -- Senator Ted Kennedy, 1980 Democratic National Convention speech
 
pedro
Gerbil First Class
Posts: 176
Joined: Fri May 11, 2007 6:13 am

Re: First virus in about a decade

Thu Dec 15, 2011 11:03 pm

SpotTheCat wrote:
The culprit is many things. Mostly, I've assumed she has the same computer decision making skills as I
1. I will enforce her use of google docs for her work. She works from home (she is a writer!) and I've been insisting that google docs will provide safer storage for her work for months. Nothing I can do will be as robust and safe as the cloud.


I love Google Docs but I recently lost a diary I'd been keeping on there for ages. Moral of the story: It seems easier to nuke a document in the cloud than it does locally.
Ubuntu 12.04 AMD64: E8200 // P35 // HD 4850 // 4GB
OS X 10.8.x: iMac12,2, MacBook 5,2
 
bthylafh
Maximum Gerbil
Posts: 4320
Joined: Mon Dec 29, 2003 11:55 pm
Location: Southwest Missouri, USA

Re: First virus in about a decade

Fri Dec 16, 2011 9:07 am

axeman wrote:
I'm not sure what support Google gives for Docs if you aren't paying for the service, but doubtless it could be recovered from a backup somewhere.


Your naivete is cute. Google doesn't provide /any/ support, basically, so if you want a backup that's your lookout.
Hakkaa päälle!
i7-8700K|Asus Z-370 Pro|32GB DDR4|Asus Radeon RX-580|Samsung 960 EVO 1TB|1988 Model M||Logitech MX 518 & F310|Samsung C24FG70|Dell 2209WA|ATH-M50x
 
just brew it!
Administrator
Posts: 54500
Joined: Tue Aug 20, 2002 10:51 pm
Location: Somewhere, having a beer

Re: First virus in about a decade

Fri Dec 16, 2011 9:35 am

axeman wrote:
...
3) why the hate towards a FREE service? Same people that bitch about Facebook I guess.

IMO much (though not all) of the ire directed at Facebook is deserved. It is a malware cesspool, and a major contributor to the "dumbing down" of the Internet.
Nostalgia isn't what it used to be.
 
bthylafh
Maximum Gerbil
Posts: 4320
Joined: Mon Dec 29, 2003 11:55 pm
Location: Southwest Missouri, USA

Re: First virus in about a decade

Fri Dec 16, 2011 9:36 am

I'm not hating on Docs, it's good for what it is, but the point is that you can't trust them to never lose your data, and you can't expect a free service to be assiduous about restoring your backup.

You want a backup, you keep your own damn backups and take responsibility for them. You might never have a problem with THE CLOUD, but then again you might and your data could disappear forever if you don't have an offline copy, same as for anything else.
Hakkaa päälle!
i7-8700K|Asus Z-370 Pro|32GB DDR4|Asus Radeon RX-580|Samsung 960 EVO 1TB|1988 Model M||Logitech MX 518 & F310|Samsung C24FG70|Dell 2209WA|ATH-M50x
 
just brew it!
Administrator
Posts: 54500
Joined: Tue Aug 20, 2002 10:51 pm
Location: Somewhere, having a beer

Re: First virus in about a decade

Fri Dec 16, 2011 9:51 am

bthylafh wrote:
You want a backup, you keep your own damn backups and take responsibility for them. You might never have a problem with THE CLOUD, but then again you might and your data could disappear forever if you don't have an offline copy, same as for anything else.

"The Cloud" is really just a euphemism for migrating back to the datacenter/mainframe/terminal model of computing (with web browsers taking the place of the terminals). Letting someone else manage your data for you means you no longer *control* your data.
Nostalgia isn't what it used to be.
 
Ryu Connor
Global Moderator
Posts: 4369
Joined: Thu Dec 27, 2001 7:00 pm
Location: Marietta, GA
Contact:

Re: First virus in about a decade

Fri Dec 16, 2011 11:31 am

just brew it! wrote:
Letting someone else manage your data for you means you no longer *control* your data.


Very well put. I'd also note this presents more danger than just losing your data. It also represents a risk of the compromise of your data too.

The cloud should not be the goto solution without some real thought about what you can afford to lose.
All of my written content here on TR does not represent or reflect the views of my employer or any reasonable human being. All content and actions are my own.
 
Hance
Darth Gerbil
Posts: 7775
Joined: Mon Sep 29, 2003 1:58 pm
Location: Grace Idaho
Contact:

Re: First virus in about a decade

Fri Dec 16, 2011 11:18 pm

just brew it! wrote:
axeman wrote:
...
3) why the hate towards a FREE service? Same people that bitch about Facebook I guess.

IMO much (though not all) of the ire directed at Facebook is deserved. It is a malware cesspool, and a major contributor to the "dumbing down" of the Internet.



So did you bitch about the move away from BBS and newsgroups dumbing down the internet back in the day to :lol:


My parents got hit by this same virus today. I will know more tomorrow when I go to fix the problem. Going from memory they have a fully updated version of windows 7 64 bit, running chrome, and Microsoft Security Essentials.
 
SpotTheCat
Gerbilus Supremus
Topic Author
Posts: 12292
Joined: Wed Jan 29, 2003 12:47 am
Location: Minnesota

Re: First virus in about a decade

Sat Dec 17, 2011 9:07 pm

FWIW, I was able to bring up task manager (I had to ctrl+alt+delete, any other route to the task manager was blocked), find the location of the process, kill the process, delete the file the process was run from, and then I used a spyware removal tool to change the registry back. I hope that's all of it!
 
Captain Ned
Global Moderator
Posts: 28704
Joined: Wed Jan 16, 2002 7:00 pm
Location: Vermont, USA

Re: First virus in about a decade

Sat Dec 17, 2011 9:12 pm

SpotTheCat wrote:
FWIW, I was able to bring up task manager (I had to ctrl+alt+delete, any other route to the task manager was blocked), find the location of the process, kill the process, delete the file the process was run from, and then I used a spyware removal tool to change the registry back. I hope that's all of it!

http://windows.microsoft.com/en-US/wind ... er-offline

MS has a beta version of Windows Defender (looks just like MSE) available as an offline product one can install as bootable to CD/DVD or USB. I gave it a whirl and it seems to work pretty well. You do have to run the wizard as admin, though, if you want the USB stick reformat to work (using XPSP 3 here).
What we have today is way too much pluribus and not enough unum.
 
lonleyppl
Gerbil XP
Posts: 380
Joined: Wed Jan 26, 2011 2:59 pm

Re: First virus in about a decade

Sat Dec 17, 2011 10:03 pm

My mom got hit by this. Not entirely updated version of Vista with FF. Adobe reader and java both needed updates, flash probably does too. I booted into safe mode, cleaned up registry and start-up with CCleaner, ran MBAM several times then booted into windows normally and am running AVG and MBAM scans. She was using AVGFree, just doesn't know what to click on and what not to click on apparently. It's a good thing this only happened 2 or 3 days ago as I just got home yesterday and nobody else here would've looked at it.
Lenovo W520
IBM dx340
Nokia Lumia 928
Sony a7 with far too many lenses to list or even count

Who is online

Users browsing this forum: No registered users and 1 guest
GZIP: On