!!!! SECURITY WARNING !!!!

Started by Duck · 22 posts · 5,354 views

  1. #1
    Hey all, since 8 am this morning (13:00 now) I have been fighting the virus.

    Nasty assed thing made it past my Linksys router, my Linksys VPV box and was detected by the Microsoft anti-spyware Beta I have been running.

    Here's what happened FYI. Where the Anti-Spyware Beta target Icon is in the systray, it changed to a red circle with a white X all fancy Windows XP looking and a pop up window displays the following:

    System Intrusion Deteccted!

    Dangerous infection was detected on your pc.
    The system will now download and install most efficient antimalware program to prevent data loss and private information theft.

    Click here to protect your computer from the biggest malware threats.


    WHen you click on the pop up baloon to "down load" the software (still thinking it was Microsoft redirecting me) it pretends to down load an application called

    SpywareStrike 2.5

    and you get what looks like a Adaware type scan, but it's don in 5 or less seconds!

    What it really is, is the other 1/2 of the malicous

    SmitFraud.G

    virus.


    Important things to do/remember. DISCONNECT from the internet A.S.A.P. That's what saved my bacon and clued me in to the "download" remark With my internet disconnected, how could it have downloaded a removal program.

    By clicking on the "download" pop up it completes the virus instalationand installs the following nastys:


    Trojan Horse: antivirus.gold
    Trojan Horse: trojan_backdoor_retro64
    Adware: Popuper
    Trojan Horse: Trojan-Downloader-zlob
    Adware: security2khyjacker

    I'm working on getting out of my PC (typing this on my lap top while a take a cool down break)
    But I just wanted to give you all a heads up on a trojan that makes it thru hard ware fire walls.

    Will let you know how it turns out later.
  2. #2
    ouch. sounds like a nasty one. Did I read that correctly in that it spoofed the microsoft anti-spyware app into helping it?
  3. #3
    hmmm. Sounds like fun. O you didn't know I used to love removing viruses, don't do it much anymore though. At one point I beat Mcafee to a fix for a new virus and got quite a few downloads of it.
  4. #4
    Duck, I told you to stop going to those websites..... :bigshock:
  5. #5
    LOL Yah busted Attom.
    Yes Sarge on initial warning it turned off MS Anti Spy ware and placed an icon in it's place.

    I have so far removed the offending items that are trying to access the internet, so E.T. is no longer trying to phone home, but they are still resident in the PC some where.

    I have been able to upload the latest version of Webroot Spy Sweeper along with the latest definitions. It has found 3 more locations where
    Trojan Horse: antivirus.gold
    Trojan Horse: Trojan-Downloader-zlob
    are hiding and a new one called
    Adware:psguard

    The fight continues......
  6. #6
    Do you have SpyBot as well?
  7. #7
    Here is a list of things that we look at at work back in the day before we locked down IE.
    CODE
    Spyware removal checklist

    Regestry Keys to check, must be administrator to clean

    Must be cleaned under the profile infected.  It is profile based on start.

    HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun

    HKEY_LOCAL_MACHINESOFTWAREMicrosoftCode Store DatabaseDistribution Units = clear all download information keys  Delete the distribution unit is unauthorized.

    HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerToolbar = clear all

    HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects =clear all

    HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun = selective clear

    HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunOnce = selective clear

    HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionRun = selective clear

    HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionRunOnce = selective clear

    HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonNotifyGuardian of any kind, Run the program under \mp-okc-01softwarecommon_softwareabetterinternet needs to be ran clean, reboot rerun clean/ clear the hives.

    Start - Settings - Control Panel - Inernet Options - Settings Button - View Objects = everything other than shockwave, and things you installed.

    Start - Settings - Control Panel - Inernet Options - Settings Button - delete cookies/delete files

    1) Spybot

    2) www.spywareguide.com

    Great for finding out how to get rid of certain spyware
  8. #8
    Thanks Raze.... will start at top of the list.
  9. #9
    It's a start, hope it helps.
  10. #10
    HKEY_LOCAL_MACHINESOFTWAREMicrosoftCode Store DatabaseDistribution Units = clear all download information keys Delete the distribution unit is unauthorized.

    In English please.

    A typical Distribution unit onmy pc has 3 folders
    Folder 1) Name: Contains has a reg entry called (Default) with 0 as a value

    a) sub folder: Files. 2 entries 1 called (Default) 1 called C:WindowsDownloaded program filesMSNMessengerSetrupDownloader.ocx

    Next folder
    DownlaodInformation (no sub folders)
    3 enteries.
    #1) (Default)
    #2) CODEBASE is the .cab file for the MSNMessenger set up
    #3) INF is the.INF of the file

    LAst folder InstalledVersion
    2 entries
    #1)(Default)
    #2) LastModified Date MSN was last modified,

    SO... What your instructions are teelling me is go to DownloadInformation and claer what, just the CODEBASE key.
    Delete it entierly, or open it up and delete the path in the value data: leving the key empty when I am done?

    Will continue working on other examples.
  11. #11
    By what you said you should be fine. For items that you know as "questionable", i'd delete the whole cabinet for that codebase. the part that looks like {n2vnnb5pv8nwy58pvwn45878458q4n} and that will clean up the underlying stuff.
  12. #12
    K good most are normal things, but one is an unknow and I will delete.

    All other items on you rlist are complete.

    Here goes...
  13. #13
    Well I cleaned them all out the one that I did not know was Wild3dExtreme It went.

    I restarted and it took like 3 min before the pop up about the bad software happened.,
    So I'm getting closer, in that it's not there when windows starts up, but takes a while to load.,
  14. #15
    Fixed it!!!


    Format C:
    Reinstall XP Pro.

    Done!

    Purchased Norton System Works Premier 2006, getting all my updates and service packs and then I'm Ghosting my clean set up.

    No more worries.

    See ya soon.
  15. #16
    Well that is always a pain, but the best approach
  16. #17
    speaking of which, for someone that usually does that every 3 months. I haven't done that since......???? thinking...???? Can't remember more than 6 months. I'm off tomorrow. I may do the same thing. I think I will start with a LOW LEVEL this time. :leet: start off with all 0's.
  17. #18
    heheh, I do about every 4-6 mo. I am not super special like Raze, I haven't done a low level in a while. I am not normally that patient
  18. #19
    Feh, on teh Norton. System resource hog and Mal-wear that it is. But teh Ghost is teh Good. On the other hand with AV, the same company does release a decent version Symantec AV Corp Edition. Not looked at the pricetag, but for all the bells and wistles and no where near the resource consumption... After all resource consumption effects the bottom line. Otherwise myself, I'll stick with AVG for now because I'm a cheap bastard, And it works well.
  19. #20
    I'm from the format and reinstall when it dies camp. I actually used my computer for 6 months with constant blue screens of death. I hate reinstalling.....
  20. #21
    urrrg thats no good atomm
  21. #22
    Yah I was a huge AVG fan, but it completely missed the Trojans dropped nortons on, re-canned my back up DVD that I burnt and they were on the back up.

    AVG was clueless. And it use to up date its' defs every day at start up....... Used a free servvice, I guess I got what I paid for.....

    Any way working again