Author Topic: HIDEOUS VIRUS!!!  (Read 13524 times)

0 Members and 1 Guest are viewing this topic.

Offline Industrial Cafe

  • Like a well oiled
  • Really Old Timer ...
  • *******
  • Posts: 6,372
  • [Brian] I've got something to say about that!
    • Undead Asphalt
HIDEOUS VIRUS!!!
« on: January 22, 2010, 05:43:32 PM »
I just received the nastiest virus I've gotten in a long time.

It started by emulating the windows live virus scanner, then it would tell me everything I clicked was infected. and if I clicked check for viruses it would check very quickly and tell me I had key loggers trojans and many other "horrible" things that weren't there.
   I couldn't start up my AVG scanner, start up menu, task manager, or share my C:\ drive (so I could check for viruses from the laptop) because it would tell me it was infected.


I noticed it wouldn't start the fake virus scanner until midway through loading everything in the system tray so I opened the task manager before the "virus" loaded up. IT WORKED!!! I shut down 3 programs before it started up- I don't know what they were called but I knew I didn't recognize them... they were something like "jkqs... something like that.   I'm now running AVG in hopes that it finds it. I'll report back the results.
everything I say is pure speculation and
I have no idea what I'm talking about  ._.


                                    Marla              .:71CB750:.CAFE

Offline mlinder

  • "Kitten Puncher"
  • Really Old Timer ...
  • *******
  • Posts: 5,013
  • Stop Global Tilting now!
    • Moto Northwest
Re: HIDEOUS VIRUS!!!
« Reply #1 on: January 22, 2010, 05:58:39 PM »
Download this:

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

to your desktop.

Restart in safe mode. Run it.
No.


Offline Industrial Cafe

  • Like a well oiled
  • Really Old Timer ...
  • *******
  • Posts: 6,372
  • [Brian] I've got something to say about that!
    • Undead Asphalt
Re: HIDEOUS VIRUS!!!
« Reply #2 on: January 22, 2010, 06:00:05 PM »
will do sir
everything I say is pure speculation and
I have no idea what I'm talking about  ._.


                                    Marla              .:71CB750:.CAFE

Offline mlinder

  • "Kitten Puncher"
  • Really Old Timer ...
  • *******
  • Posts: 5,013
  • Stop Global Tilting now!
    • Moto Northwest
Re: HIDEOUS VIRUS!!!
« Reply #3 on: January 22, 2010, 06:02:32 PM »
AVG won't fix this.
It's a combination of the virtumond rootkit and smitfraud. Very bad stuff. combofix should clean it up mostly, then run malwarebytes or some crap like that after combofix is done. If it's still nto out, I'll walk you through some other things you need to do.
No.


Offline Duke McDukiedook

  • Space Force 6 Star General
  • Really Old Timer ...
  • *******
  • Posts: 12,690
  • Wish? Did somebody say wish?
Re: HIDEOUS VIRUS!!!
« Reply #4 on: January 22, 2010, 06:03:58 PM »
You couldn't reboot in safe mode and run AVG?
"Well, Mr. Carpetbagger. We got somethin' in this territory called the Missouri boat ride."   Josey Wales

"It's Baltimore, gentlemen. The gods will not save you." Ervin Burrell

CB750 K3 crat | (2) 1986 VFR750F

Offline Industrial Cafe

  • Like a well oiled
  • Really Old Timer ...
  • *******
  • Posts: 6,372
  • [Brian] I've got something to say about that!
    • Undead Asphalt
Re: HIDEOUS VIRUS!!!
« Reply #5 on: January 22, 2010, 06:04:11 PM »
I forgot to mention, it won't start in safe mode either, just locks up and after a half hour I tried the method described above.

I'll keep workin on it though, thanks M
everything I say is pure speculation and
I have no idea what I'm talking about  ._.


                                    Marla              .:71CB750:.CAFE

Offline Duke McDukiedook

  • Space Force 6 Star General
  • Really Old Timer ...
  • *******
  • Posts: 12,690
  • Wish? Did somebody say wish?
Re: HIDEOUS VIRUS!!!
« Reply #6 on: January 22, 2010, 06:05:16 PM »
Damn IC, you must be looking at some serious porn, or someone sent you some nasty stuff in those torrents you've been downloading lately.
"Well, Mr. Carpetbagger. We got somethin' in this territory called the Missouri boat ride."   Josey Wales

"It's Baltimore, gentlemen. The gods will not save you." Ervin Burrell

CB750 K3 crat | (2) 1986 VFR750F

Offline Industrial Cafe

  • Like a well oiled
  • Really Old Timer ...
  • *******
  • Posts: 6,372
  • [Brian] I've got something to say about that!
    • Undead Asphalt
Re: HIDEOUS VIRUS!!!
« Reply #7 on: January 22, 2010, 06:07:25 PM »
I guess, I download torrents all the time and never have problems. I make sure they have been verified on torrent forums first.

I was on blogspot.com looking at bicycle blogs when it all started I was looking at linked pictures.

edit: but it could be one of those time delay malware programs.
« Last Edit: January 22, 2010, 06:23:38 PM by Industrial Cafe »
everything I say is pure speculation and
I have no idea what I'm talking about  ._.


                                    Marla              .:71CB750:.CAFE

Offline Duke McDukiedook

  • Space Force 6 Star General
  • Really Old Timer ...
  • *******
  • Posts: 12,690
  • Wish? Did somebody say wish?
Re: HIDEOUS VIRUS!!!
« Reply #8 on: January 22, 2010, 06:12:12 PM »
What browser are you running?
"Well, Mr. Carpetbagger. We got somethin' in this territory called the Missouri boat ride."   Josey Wales

"It's Baltimore, gentlemen. The gods will not save you." Ervin Burrell

CB750 K3 crat | (2) 1986 VFR750F

Offline Industrial Cafe

  • Like a well oiled
  • Really Old Timer ...
  • *******
  • Posts: 6,372
  • [Brian] I've got something to say about that!
    • Undead Asphalt
Re: HIDEOUS VIRUS!!!
« Reply #9 on: January 22, 2010, 06:14:33 PM »
firefox.

also, it kept opening a website called laptopvirusscan.com, adult.com, and porn.com on my E internet explorer. (which I didn't know was still installed)
everything I say is pure speculation and
I have no idea what I'm talking about  ._.


                                    Marla              .:71CB750:.CAFE

Offline Kframe

  • Hot Shot
  • ***
  • Posts: 579
  • Life is good!
Re: HIDEOUS VIRUS!!!
« Reply #10 on: January 22, 2010, 06:18:33 PM »
I've had some good luck with Malwarebytes.
It can find and clean a lot of stuff.

If not, give up and do what I did - switch to Linux.
-K
2007 Triumph Bonneville T100, ARK'd, Pods, TOR's, Napoleon's, Innovate G5 Air/Fuel Gauge, Ignition Relocation by D9, Stebel Nautilus, Avon Roadriders
1984 Honda Shadow VT700c, Stock
1974 Honda CB550K, In rehab
1986 Honda Helix

Offline Industrial Cafe

  • Like a well oiled
  • Really Old Timer ...
  • *******
  • Posts: 6,372
  • [Brian] I've got something to say about that!
    • Undead Asphalt
Re: HIDEOUS VIRUS!!!
« Reply #11 on: January 22, 2010, 06:18:45 PM »
hey, I found the program in my startup menu.
C:\Documents and Settings\Gaming\Local Settings\Application Data\oaxifo\jbtisysguard.exe

everything I say is pure speculation and
I have no idea what I'm talking about  ._.


                                    Marla              .:71CB750:.CAFE

Offline Damfino

  • Sneaky, Evil, Magnificent Bastard of a
  • Really Old Timer ...
  • *******
  • Posts: 5,216
  • Look at the grouse! NYUK,NYUK,NYUK!
Re: HIDEOUS VIRUS!!!
« Reply #12 on: January 22, 2010, 06:37:04 PM »
I had that about two weeks ago. Believe it or not, all I did was a system restore and that got rid of it.
Your Message Here!
You can still call me 'Schmitty'

1976 CB 750
2014 CB 1100DLX
2015 Harley Davidson Freewheeler



You know, a long time ago being crazy meant something. Nowadays everybody's crazy.
Charles Manson

You've got to watch your back in the SSDB, this is where the clever guys get bored with bike talk and make poo jokes.
I like my women a little big. Natural. Now, they shave this and wax that. It's not right. I love natural women. Big women. This trend in women has to go. Bulomia, anorexia. That's just wrong. You know what will cure that? My special sticky buns. One lick of my sticky buns and your appetite will come right back. ~ RIP Mr. Borgnine  01/24/1917 - 07/08/2012  :'(

Offline Industrial Cafe

  • Like a well oiled
  • Really Old Timer ...
  • *******
  • Posts: 6,372
  • [Brian] I've got something to say about that!
    • Undead Asphalt
Re: HIDEOUS VIRUS!!!
« Reply #13 on: January 22, 2010, 07:00:50 PM »
thanks mlinder, combofix found and deleted it fast.
it also found an ass load of other things.


WOOOO!!!!
everything I say is pure speculation and
I have no idea what I'm talking about  ._.


                                    Marla              .:71CB750:.CAFE

Offline MRieck

  • Really Old Timer ...
  • *******
  • Posts: 10,582
  • Big ideas....
Re: HIDEOUS VIRUS!!!
« Reply #14 on: January 22, 2010, 07:47:01 PM »
Stay off of the porn or get a Mac. ;) ;) ;D
Owner of the "Million Dollar CB"

Offline Industrial Cafe

  • Like a well oiled
  • Really Old Timer ...
  • *******
  • Posts: 6,372
  • [Brian] I've got something to say about that!
    • Undead Asphalt
Re: HIDEOUS VIRUS!!!
« Reply #15 on: January 22, 2010, 08:02:35 PM »
but I love porn so much!
everything I say is pure speculation and
I have no idea what I'm talking about  ._.


                                    Marla              .:71CB750:.CAFE

Offline Inigo Montoya

  • Master
  • *****
  • Posts: 1,855
Re: HIDEOUS VIRUS!!!
« Reply #16 on: January 22, 2010, 08:40:01 PM »
Ah skip mac and go to linux!
Anyways, remember that malwarebytes uses its own installer so installs in safe mode, safe mode networking and safe mode command prompt.
Another one called spyware terminator installs in safe mode too.
There is an a/v program called bit defender which you can burn to disk and then boot from said disk. Very good scanner as it does not load windows at all.

If it comes right down to it and you have a second pc, take out the hdd and hook it up through usb and scan it that way.

Offline mkramer1121

  • Expert
  • ****
  • Posts: 1,304
Re: HIDEOUS VIRUS!!!
« Reply #17 on: January 22, 2010, 08:44:00 PM »
Just fixed this on a computer at work today 'cause the IT guy couldn't do it and refused to use google...Worked great, follow this tutorial:  http://www.bleepingcomputer.com/virus-removal/remove-antivirus-live

Sorry didn't read all the posts, glad you got it IC...

Offline Duke McDukiedook

  • Space Force 6 Star General
  • Really Old Timer ...
  • *******
  • Posts: 12,690
  • Wish? Did somebody say wish?
Re: HIDEOUS VIRUS!!!
« Reply #18 on: January 22, 2010, 08:46:51 PM »
What do you guys recommend for spyware and antivirus for a Linux computer?

After I get all the old stuff off the Gateway I plan on installing Linux.

"Well, Mr. Carpetbagger. We got somethin' in this territory called the Missouri boat ride."   Josey Wales

"It's Baltimore, gentlemen. The gods will not save you." Ervin Burrell

CB750 K3 crat | (2) 1986 VFR750F

Offline Industrial Cafe

  • Like a well oiled
  • Really Old Timer ...
  • *******
  • Posts: 6,372
  • [Brian] I've got something to say about that!
    • Undead Asphalt
Re: HIDEOUS VIRUS!!!
« Reply #19 on: January 22, 2010, 08:49:04 PM »
no. ;D
everything I say is pure speculation and
I have no idea what I'm talking about  ._.


                                    Marla              .:71CB750:.CAFE

Offline Duke McDukiedook

  • Space Force 6 Star General
  • Really Old Timer ...
  • *******
  • Posts: 12,690
  • Wish? Did somebody say wish?
Re: HIDEOUS VIRUS!!!
« Reply #20 on: January 22, 2010, 09:04:05 PM »
Hmmmm.... interesting sounding software- No.

Have to check into this...
"Well, Mr. Carpetbagger. We got somethin' in this territory called the Missouri boat ride."   Josey Wales

"It's Baltimore, gentlemen. The gods will not save you." Ervin Burrell

CB750 K3 crat | (2) 1986 VFR750F

Online CBJoe

  • Master
  • *****
  • Posts: 1,976
Re: HIDEOUS VIRUS!!!
« Reply #21 on: January 22, 2010, 09:15:14 PM »
I love Ubuntu ..... I'm not too quick on the uptake and it's still easy for me to use.

Been running it on most of my machines for 3 years and have NEVER had a single issue.  My Suse box (server) has been running since 2006 without any issues whatsoever.

I'm done with windows..... (still cant get my wife to run anything but XP)... Maybe I should go run combofix  ::)
'07 Bonneville Black
'15 Moto Guzzi California 1400
CB750K2 Hot Rod Revival http://forums.sohc4.net/index.php/topic,171693.0.html
'65 CB77
'66 CM91 (C90'ish)

Offline mlinder

  • "Kitten Puncher"
  • Really Old Timer ...
  • *******
  • Posts: 5,013
  • Stop Global Tilting now!
    • Moto Northwest
Re: HIDEOUS VIRUS!!!
« Reply #22 on: January 22, 2010, 09:31:57 PM »
What do you guys recommend for spyware and antivirus for a Linux computer?

After I get all the old stuff off the Gateway I plan on installing Linux.



You don't need any.
No.


Offline Duke McDukiedook

  • Space Force 6 Star General
  • Really Old Timer ...
  • *******
  • Posts: 12,690
  • Wish? Did somebody say wish?
Re: HIDEOUS VIRUS!!!
« Reply #23 on: January 23, 2010, 01:34:52 AM »
C'mon, the haxors have to make up some viruses for the script kiddies to pass around to Linux systems, right?

Maybe they don't want to #$%* where they eat....  :-\
"Well, Mr. Carpetbagger. We got somethin' in this territory called the Missouri boat ride."   Josey Wales

"It's Baltimore, gentlemen. The gods will not save you." Ervin Burrell

CB750 K3 crat | (2) 1986 VFR750F

Offline Bob Wessner

  • "Carbs Suck!"
  • Really Old Timer ...
  • *******
  • Posts: 10,079
Re: HIDEOUS VIRUS!!!
« Reply #24 on: January 23, 2010, 02:55:03 AM »
What do you guys recommend for spyware and antivirus for a Linux computer?

After I get all the old stuff off the Gateway I plan on installing Linux.



You don't need any.

Well, can't agree with that. There may not be as many because it is a relatively small segment (target) of the OS world, but there are Linux viruses. I would install anti-virus software on any OS.
We'll all be someone else's PO some day.