PDA

View Full Version : Yet another virus



PessOptimist
11-19-2010, 08:40 PM
A couple days late but thought I would share.

I came home Wednesday and received news that my sig other had been getting virus attack warnings all afternoon. Ah, jeez, I deal with computer problems a lot at work and don't need this.

I am not an IT type, just have to deal with a lot of "legacy" "proprietary" software used with comm equipment.

There were many windows open, the latest from "vista av" showing hundreds of things attacking. One of the windows appeared to be a windows update. It finally occurred to me this machine is using pccillin av software. My first thought was ms has done it again. All the warnings took me to a "buy the software" page. I closed all the windows and all programs running and soon the "vista av" window popped up again warning of many programs attacking. I looked at the pccillin log and it had found and quarantined a rouge program. Searching on a different computer for "vista av" got lot's of hits about where to buy anti virus or anti spyware programs but if you scroll down far enough you find news about this particular "rogue" program.

My av software apparently found it but did not remove it from memory. A cold restart eliminated the annoyance.

Too wordy, as usual for me, but I thought I would share. Apparently this program shows up mostly outside the US. It had me going for a while. Very clever and well done.

If any one is having this problem, stop and think about what av program you have installed vs what the warning says is finding all the parasites.

nnuut
11-19-2010, 09:34 PM
That sounds like one a caught (Trojan) with Vista? The only difference was that I couldn't get rid of it, it blocked my AV, It blocked MSConfig, Task Manager, My Computer hell it blocked everything! On reboot it was back, I tried everything I know, it was deadly and I ended up formating "C" and reloading. I think I caught it by opening a video on a website, one of those "YOUR COMPUTER IS INFECTED" things, I refused to click on their link, that made it mad?10236

Steel_Magnolia
11-19-2010, 10:23 PM
My Dell running Vista caught the virus that PessOptimist is talking about. I couldn't do anything because a 'buy this software to fix a bug' window kept popping up. The suggested cure was actually the bug. And besides being annoying, if I had 'bought' the software it was trying to sell the crooks would have my money and possibly my credit card number and I wouldn't get anything but frustration.

After researching it I found a freeware program called Malwarebytes that my Norton 360 said was fine. I installed it, it found the bug and killed it.

I don't know why Norton didn't kill it. I thought 360 was decent protection. Silly me. :rolleyes:

burrocrat
11-19-2010, 11:53 PM
My Dell running Vista caught the virus that PessOptimist is talking about. I couldn't do anything because a 'buy this software to fix a bug' window kept popping up. The suggested cure was actually the bug. And besides being annoying, if I had 'bought' the software it was trying to sell the crooks would have my money and possibly my credit card number and I wouldn't get anything but frustration.

After researching it I found a freeware program called Malwarebytes that my Norton 360 said was fine. I installed it, it found the bug and killed it.

I don't know why Norton didn't kill it. I thought 360 was decent protection. Silly me. :rolleyes:

i tole you to quit browsing that porn, girl. just head over to the beltway.

it's every bit as titillating, and at least twice as offensive. 'cept we'll never ask for your credit card number. well, we might, but you shouldn't give it.

besides we use a different currency over there now.

crws
11-20-2010, 12:01 AM
360 isn't that great:
Many of the free scanners are more comprehensive now, like avast! or AVG.
Here is the best review site I've found, been around for ages:
http://anti-virus-software-review.toptenreviews.com/
This one is slithering in because it's new-
Is it:
XP Security 2011 ?
Starts scanning and then pops up the XP Security Center? Says you have infections...

It uses a file named pw.exe
This site was the most helpful in mapping what chages the virus made, including a quick fix-
(attached, rename the extension from .zip to .inf)
http://www.myantispyware.com/2010/11/18/how-to-remove-pw-exe-malware/
Used Ctrl-Alt-Del, then found PW.exe, ended the process, copied the text as noted, saved as .inf,
followed the install instructions to reset registry associations, then searched for pw.exe on my windows drive and deleted all.
There were 2, one in prefetch, and the main executable in my profile/Application Data folder.

I too, used Malwarebytes to clean things up.
(MBAM Link is down this page http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/)

The XP Security 2011 virus seems especially nasty-
Although I didn't find any tools I wanted to use at the site below, the description made me research and fix it ASAP.
http://www.articlesbase.com/security-articles/remove-the-xp-security-2011-how-to-100-remove-the-xp-security-2011-easily-and-effectively-3690512.html
I got mine right after loading a video on a Minyanville page.

Nate
11-20-2010, 07:58 AM
crws seems to have a handle on his pc, but for those that aernt as savy to review their processes, I'd recommend finding a combination of two programs to run simultaneously.
Norton's AV is usually NOT listed within top 10 AV reviews, but remains to be listed within the top 10 sellers. Its a resource hog, and yet, wont stop all viruses from getting on your pc. It will however discover it when running a system scan.
I tried Webroot spysweeper afterwards for a year or two. Doesnt hog resources as bad as nortons, but same thing as Nortons, wont stop a virus before getting on your pc, but will discover it while running system scans.
I've been running AVG for about 4 years now. It stops (most) infections before they are aquired, and is lighter on resources. But....I did acquire my first virus 2 months ago while using it, and managed to lose all my Iraq video and pictures.
I currently use a program called CCleaner (free). Its a system cleaner that clears history, cookies, unused registry entries, etc. I run this before every AV sweep. http://www.piriform.com/
Second, I still use AVG "Internet Security" (paid version) and run their scanner.
Third, I now have Ad-Aware (free version). This regularly seems to find tracking cookies & such left over that were not detected by CCleaner or AVG. This makes me believe there is no perfect all-in-one antivirus/adware/spyware program out there. http://www.lavasoft.com/
Keeping the history clear & deleting cookies help alot also in my opinion.
I have seen this virus you guys/gals are talking about. One version looks like the XP security center, the other looks like vista security center. AVG did not stop this page from popping up, but as long as I didnt click anything, nothing was installed. Just an adware cookie.

nnuut
11-20-2010, 09:26 AM
I now use McAfee, it comes with my cable service and includes a registry cleaner. Haven't had any problems.:D

KevinD
11-20-2010, 03:40 PM
I'm using ESET NOD32...just to be different. :D http://www.eset.com/home/nod32-antivirus

Buster
11-21-2010, 09:34 PM
The last virus I was bit by was the "Antivirus-360...since then I employed AVG-9.0 and not had a bug since..

(knock wood)