unbelieveable infestation in an hour

Discussion in 'malware problems & news' started by larryb52, Feb 6, 2008.

Thread Status:
Not open for further replies.
  1. larryb52

    larryb52 Registered Member

    Joined:
    Feb 16, 2006
    Posts:
    1,131

    good tip found a couple hidden malware types, looks like it's back to normal, I browsed for about an hour before work & it runs fine & speed back to normal, thanks to all for the tips & support.
     
  2. CogitoErgoSum

    CogitoErgoSum Registered Member

    Joined:
    Aug 22, 2005
    Posts:
    641
    Location:
    Cerritos, California
    Last edited: Feb 7, 2008
  3. Mrkvonic

    Mrkvonic Linux Systems Expert

    Joined:
    May 9, 2005
    Posts:
    10,224
    Hello,
    Indeed, why not use Firefox and solve all the problems?
    Mrk
     
  4. lucas1985

    lucas1985 Retired Moderator

    Joined:
    Nov 9, 2006
    Posts:
    4,047
    Location:
    France, May 1968
    WilliamP reported something similar with Defensewall. Interesting to say the least.
     
  5. Chuck57

    Chuck57 Registered Member

    Joined:
    Sep 2, 2002
    Posts:
    1,770
    Location:
    New Mexico, USA
    Very similar and, after hitting the reset button, DF put everything back in place. All I know is that it was in MySpace where it happened. The entire thing took barely a second. The screen snapped to black and then the blue screen appeared.

    What annoys me is that I was there for the purpose of collecting malware to play with. Geswall has always been rock solid, based on past usage. Wish I could find that site again, but maybe it's better that I don't. Also, I did not have either Returnil or Sandboxie running.

    Credit to DeepFreeze, though. Whatever happened didn't break it.
     
  6. Dark Shadow

    Dark Shadow Registered Member

    Joined:
    Oct 11, 2007
    Posts:
    4,553
    Location:
    USA
    @larry congrats glad to here everything worked at for you good job.
     
  7. Empath

    Empath Registered Member

    Joined:
    Nov 13, 2002
    Posts:
    178
    Returnil, Shadow Defense or some other boot to restore utility could be installed, with an access password. You don't even have to run it ordinarily. Then when someone needs to borrow your computer, initiate a password protected session with your boot to restore utility. Since the user has no need to save or leave anything on your drive, it will be no inconvenience to them.

    What you get back when they return it, is only what they borrowed.
     
  8. quasim

    quasim Registered Member

    Joined:
    Feb 8, 2008
    Posts:
    3
  9. larryb52

    larryb52 Registered Member

    Joined:
    Feb 16, 2006
    Posts:
    1,131
    rest of the story ran superantispyware & it found 12 more nasties, I reran it again & with counterspy & it finally looks clean, thanks all...11 were registry entries...
     
    Last edited: Feb 9, 2008
  10. larryb52

    larryb52 Registered Member

    Joined:
    Feb 16, 2006
    Posts:
    1,131
    well I owe my daughter an apology. I asked for her laptop & ran a couple programs & all it found was adware cookies & the usual ones nothing crazy or nasty & she does go to Facebook, My Space but if anything had come up Nod eliminated it.. I'm sorry to stretch this thread but I like to know where & how something get's on one of my machines, I don't care who runs it, they trust me to put protection on it. My daughter claimed at the time she went to a hair product's page (I won't name it) as she wanted the coupon & than stuff started hitting. Perhaps as they say just one of those things, thanks to all and thanks to SAS & I'm running it in protection mode as it did find alot of bad stuff and I'd rather NOT have it on anyones machine. The internet use to be fun not as much as years ago, thanks again for listening...
     
  11. Threedog

    Threedog Registered Member

    Joined:
    Mar 20, 2005
    Posts:
    1,125
    Location:
    Nova Scotia, Canada
    Glad you got things cleaned up OK Larry. And don't worry about dragging the story out. Interesting and learning reading. Glad the SAS worked out good for you. It's a heck of a good program.
     
  12. Espresso

    Espresso Registered Member

    Joined:
    Aug 1, 2006
    Posts:
    976
    I believe it was myspace that gave me a bsod a couple weeks ago. I don't recall if it was with the geswall driver but I was running a Geswalled browser. In any case, I keep *.myspace.com in my restricted zones now.
     
  13. lucas1985

    lucas1985 Retired Moderator

    Joined:
    Nov 9, 2006
    Posts:
    4,047
    Location:
    France, May 1968
    LOL, I don't even visit MySpace.
     
  14. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Is it possible in anyway to reproduce it by just visiting myspace etc?
     
  15. Carver

    Carver Registered Member

    Joined:
    Feb 5, 2006
    Posts:
    1,910
    Location:
    USA
    I just visted facebook.com, just to look around. After I closed the page I did a scan with my AV..nothing. The next morning I bootup everything is normal, I have to go out for a couple of hours so I computer off and go out. When I come back I bootup, I start getting error messages that the computer can't find this file...its one that I never even heard of before. This happens 5 or 6 times..very quickly..like one a second. At that point my screen just goes blank and I get the error message Windows was shut down to protect the system. First thing I did was try to put the computer in safe mode to do scans with SuperAntispyware and Spybot and my AV from the page you get from taping F-8, I tried all the options..every single one ended up in the same thing...windows being shut down. I finally got in with Acronises Boot Disk and did a restore from a full backup I had done a month before. I had to do a little updating since then but it back up. Now I am doing a tuneup before I do another Full backup.
     
  16. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    @Chuck57
    @Carver


    Ok, I will try to reproduce it with GW. Can u guide me further:

    What browser u used?
    What sort of activities on face book?
    Did u login or simple visting here n there?
     
  17. Carver

    Carver Registered Member

    Joined:
    Feb 5, 2006
    Posts:
    1,910
    Location:
    USA
    I used opera browser and I just randomly clicked through the different tabs. No login of any sort, I am not registered there.
     
  18. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Yesterday, I regustered on facebook and went here n there, so far nothing. Will try more.
     
    Last edited: Feb 18, 2008
  19. Carver

    Carver Registered Member

    Joined:
    Feb 5, 2006
    Posts:
    1,910
    Location:
    USA
    The infection didn't happen the same day, but the next day. I suspect it might have been a trojan Dropper of some type. When I went to Face book my AV resident didn't register anything.
     
  20. Longboard

    Longboard Registered Member

    Joined:
    Oct 2, 2004
    Posts:
    3,238
    Location:
    Sydney, Australia
    so: what is this my space and facebook ??
    Something for the young peeples yes

    What is it for ?
    Google search for last month:
    facebook+malware
    http://www.google.com/search?as_q=f...as_dt=i&as_sitesearch=&as_rights=&safe=images
    And my space
    http://www.google.com/search?as_q=m...as_dt=i&as_sitesearch=&as_rights=&safe=images

    Use FireFox ? ABSOLUTELY :ouch:
    http://isc.sans.org/diary.html?storyid=3929

    The posters here will -ahem- 'go in' well armed and aware as for the rest :blech:
    http://www.businessweek.com/magazine/content/05_50/b3963001.htm
    and that was years ago.

    I don't even like mobile phones and I don't have an Ipud.
    ;)
     
  21. tlu

    tlu Guest

    @larry: No offense meant - but if you allow your daughter to log on as admin and to use IE - probably with ActiveX and scripting enabled in the internet zone - I'm not at all surprised about what happened.
     
  22. Carver

    Carver Registered Member

    Joined:
    Feb 5, 2006
    Posts:
    1,910
    Location:
    USA
    When I visted facebook I knew that I might just get something, if worst came to worst I had a backup I could restore other wise I wouldn't have gone.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.