Virus / Spyware Attack

Dreamweaver69SS

Junior Member
Dec 27, 2009
5
0
0
Brand newbie here - first post, and it's kinda long... apologies in advance. (go easy :) ) - Also, I'm just a pseudo non-IT kinda guy, so I may be asking / posting low level stuff for your skills.

I went to a site I have frequented in the past, clicked on a news article I wanted to read and, as soon as I did, I started having all kinds of "alert" screens popping up. Since my abilities are just barely above that, say, an "advanced user" of some software programs, it freaked me out. I can't remember exactly what it was, but I do remember:

* There were 4 different screen that would pop up

* The little window at the lower right side of my screen with all the programs that are running (???) had a "new" program. I can't remember what it was but, even if I right clicked on it to try to see the properties, it would automatically launch a website that tried to get me to purchase an anti virus program (I am currently using ESET NOD32)

* A large window that tried its best to look like a "Windows Security" window kept popping up

* A small rectangle, about the size of the "You are now Connected" window that shows up every time I log on --- and in the same location --- popped up.

* A larger square box appeared at the far lower left of the screen

All the pop ups had red title bars, and they all had (basically) a "Yes / No" choice to do things like run a virus scan, "continue to be infected", etc. One said I had 34 threats. ALL would take me to a site --- and, I'm sorry, I didn't record the website's name, but I do remember it started with a "P", if that helps --- and all were links to buy some anti virus, anti spyware. I never went any farther than that.

I couldn't open any website other than the one it was trying to get me to... everything I tried redirected me back to that website. Many of my normal operations were unavailable.. I couldn't right-click on the start menu, I couldn't go to help, etc. etc. - most of the things I tried to do wouldn't load, and I didn't try to load any files or start any other software. It also wouldn't allow me to use the Start/Log Off feature to reboot, so I did it manually.

Each time I rebooted it did the same thing. I ran a manual scan with my antivirus but it would only quarantine the files (it found 4), it wouldn't remove them. I have a Thinkpad R60 so I rebooted and hit the Thinkvantage button. When I went into the menu, I changed the clock date to a day earlier --- I couldn't do it from the clock on the lower right of the screen as usual; that, too, was inaccessible. when I changed the date, it seemed to fix the problem ???? At least, for now, so far so good. So I tried to do a restore but, according to what the screen said, it didn't restore back to an earlier point. So, for now, I am just going to set my clock back every day to the prior day until I figure out what to do. I know --- that probably seems pretty lame but, again, I am pretty much a novice.
 

balloonshark

Diamond Member
Jun 5, 2008
7,160
3,628
136
Sounds like you have the same problem as this guy. Was is called platinumantivir?
http://forums.anandtech.com/showthread.php?t=2035468

At any rate, you have a rogue (fake) antivirus and it needs cleaned up. See if you can find out the name of it if it's not platinumantivir. There are tons of them. Some of the advice in the above thread may help.

P.S. I'm not an expert either. I just happened to see your post so I stopped by.

P.S.S. Welcome to AnandTech :).
 

Dreamweaver69SS

Junior Member
Dec 27, 2009
5
0
0
Sounds like you have the same problem as this guy. Was is called platinumantivir?
http://forums.anandtech.com/showthread.php?t=2035468

At any rate, you have a rogue (fake) antivirus and it needs cleaned up. See if you can find out the name of it if it's not platinumantivir. There are tons of them. Some of the advice in the above thread may help.

P.S. I'm not an expert either. I just happened to see your post so I stopped by.

P.S.S. Welcome to AnandTech :).

YES - That is exactly what it was. Not sure how to approach getting rid of it... may need to bring it somewhere :( --- Thanks for the help, and thanks for the welcome.
 

balloonshark

Diamond Member
Jun 5, 2008
7,160
3,628
136
You could try MalwareBytes and/or SuperAntiSpyware and see if they can remove it. Both have free versions that are good at removing malware.

http://majorgeeks.com/download.php?det=5756

http://www.superantispyware.com/download.html (get the free version).

Also, like I said in the other thread, this looks to be something new so it may take the anti-virus / anti-malware companies time to create a fix.

If you can access your data on that computer, you may want to back it up before doing anything. Just make sure that it is scanned very well before using on your fixed computer or on other machines.
 

SirGeeO

Member
Dec 22, 2009
51
0
0
^I always wondered if mp3's and whatnot can be infected...it's no encryption/decryption method to em', it's really no extension (.dll, etc.), so how would those be infected?...*thinks hard*

Anyway...I would like to know more about this type of new malware that seems to be hitting people. I see you made the novice - or - rookie mistake of even clicking the page. I was taught, any sign of a ad-ware, malware pop-up/program, Ctrl + Shift + ESC, and end your internet browser. It's always better to start from your homepage then from a redirected homepage, let alone a IE service at all.

Check your system logs as well, if you can (but then again, your resetting the date)
 

Modelworks

Lifer
Feb 22, 2007
16,240
7
76
^I always wondered if mp3's and whatnot can be infected...it's no encryption/decryption method to em', it's really no extension (.dll, etc.), so how would those be infected?...*thinks hard*
Mp3 no, there is no way to infect one. It is a stream of bits for a decoder. You can though use the method of providing bad mp3 data to a known version of a decoder to crash it then use a separate program to take advantage of the crash using the mp3 players program credentials to gain access to the OS. Then you could write files, delete files, possibly even download files without the user knowing.


The files that usually are used for virus are exe, com, bat, flv, doc, ppt, pdf, jar,vbs

One easy way to cut back on the threat is to go into your windows system directory and find vbscript.dll then using the security tab remove execute from the options. vbscript is one of the major tools virus writers like to use. With it disabled the scripts cannot run.

That is why I think MS needs to take another look at how they are controlling security on the OS. A user should be able to say that a program can never access but what you limit it to. Like being able to set it so the program has access to no other directory but its own or no access to the registry or the internet. It is doable now but you have to use security controls with different settings and it is very convoluted.

Anyway...I would like to know more about this type of new malware that seems to be hitting people. I see you made the novice - or - rookie mistake of even clicking the page. I was taught, any sign of a ad-ware, malware pop-up/program, Ctrl + Shift + ESC, and end your internet browser. It's always better to start from your homepage then from a redirected homepage, let alone a IE service at all.

The new malware isn't really new it is just better made. In emails with AVG they were talking about how they can release a new AVG today and by tomorrow the malware folks have copied the look, feel, sounds, etc. So if running AV and you see a window appear it looks just like the window that your AV would normally display. People click ok or deny and that does the install. Even if you click cancel they will still install, so ctrl+alt+del and kill the browser process.

I always set my home page to just www.google.com but I even found a virus that changes the hosts file to send people to a look alike google.com page. Best thing you can do is just remain alert, run something like hijackthis once in a while and take a look at what processes are running once a day , don't wait till something starts acting strange.
 
Last edited:

Dreamweaver69SS

Junior Member
Dec 27, 2009
5
0
0
.... I was taught, any sign of a ad-ware, malware pop-up/program, Ctrl + Shift + ESC, and end your internet browser. It's always better to start from your homepage then from a redirected homepage, let alone a IE service at all.

Good info, and now I, too, know to do just that: Thank you

Check your system logs as well, if you can (but then again, your resetting the date)
Sorry - Don't know how to check, and wouldn't know what to look for to ascertain what is and what is not proper.

One easy way to cut back on the threat is to go into your windows system directory and find vbscript.dll then using the security tab remove execute from the options. ..

Found the file: how do I open / review it, eg; how do I get to the security tab?

I really appreciate the help and insight all of you have provided.


What's really strange is that the virus seems to have vanished since I reset the clock. Do you think that means it is really gone, or did I just put a band aid over the wound?