Fraud trojans |
Post Reply
|
Page 12> |
| Author | |
Don Watkins
Admin Group
Admin Joined: 14 Mar 2008 Posts: 22156 |
Quote Reply
Topic: Fraud trojansPosted: 01 Feb 2010 at 6:23am |
|
Got a working CD drive in the box I'm working on and right now it's running the Kaparsky boot disc Randy recommended. Kaparsky has already found "trojan.js.fraud.w" and I don't know if this is the same exact trojan but it's the 4th time I've had people call me on something like this in the last 2 weeks. Other times I've been able to get them to use restore and that's worked, don't know if this is just an especially nasty one or if they just got lucky or what. Anywho it must be a pretty good looking fake Windows warning as they've all punched on the "fix me" window without any hesitation. |
|
![]() |
|
Don Watkins
Admin Group
Admin Joined: 14 Mar 2008 Posts: 22156 |
Quote Reply
Posted: 01 Feb 2010 at 6:26am |
|
Oh, this is what I think the warning looks like. Apparently once they click this and it starts doing it's think it's nasty. |
|
![]() |
|
Don Watkins
Admin Group
Admin Joined: 14 Mar 2008 Posts: 22156 |
Quote Reply
Posted: 01 Feb 2010 at 8:05am |
|
So far multiple instances (some are bogus as they are in cache) of 8 different trojans/viruses. Still 40% to go on the scan but I think most of them have been caught but yeow, don't think they had ever run disk cleanup so there are a zillion files to check. |
|
![]() |
|
Karl_db
Admin Group
Joined: 12 Mar 2008 Posts: 29205 |
Quote Reply
Posted: 01 Feb 2010 at 2:52pm |
|
Were you able to update Kapersky (def files)? I tried...when it first boots off the disk...but wasn't smart enough to figure out networking while running from a boot disk.
|
|
![]() |
|
Don Watkins
Admin Group
Admin Joined: 14 Mar 2008 Posts: 22156 |
Quote Reply
Posted: 01 Feb 2010 at 3:03pm |
|
Yup, it updated them with no problem. It might be because I'm running a DHCP server. It didn't work or at least it still wouldn't boot. I reinstalled Windows (XP-MCE) and it's working now, it appears that it's clean but I'm still having a problem with IE which I'm upgrading to 8 to see if that'll fix it (it might just be broken). |
|
![]() |
|
Karl_db
Admin Group
Joined: 12 Mar 2008 Posts: 29205 |
Quote Reply
Posted: 01 Feb 2010 at 3:09pm |
|
I think I went with default settings on the scan. Gee...I just can't remember the details. Don't remember if it was auto or if I had to OK each one. Regardless...the Kaspersky cleanup cleaned up so many Windows files that it was DOA.
Hm. Which reminds me. I've never gotten around to burning the Eset rescue disk. Shame. Shame. Think I'll do that...right after I study for my license. |
|
![]() |
|
Don Watkins
Admin Group
Admin Joined: 14 Mar 2008 Posts: 22156 |
Quote Reply
Posted: 01 Feb 2010 at 3:30pm |
|
IE 8 fixed the IE problems and I'm now running a pass with SuperAntiSpyware where it's got a bit to go. Sigh, there are just too many doggone files on computers these days. When Kapersky was running I was watching some of it and doggone if it didn't look like QuickTime had installed about six different language versions along with the english version. And don't get me started on Windows. |
|
![]() |
|
Karl_db
Admin Group
Joined: 12 Mar 2008 Posts: 29205 |
Quote Reply
Posted: 01 Feb 2010 at 4:38pm |
|
Yeah...go figure. Some programs ask...some just install additional languages without asking. I always choose "custom install" so just in case they ask.
|
|
![]() |
|
Don Watkins
Admin Group
Admin Joined: 14 Mar 2008 Posts: 22156 |
Quote Reply
Posted: 01 Feb 2010 at 4:42pm |
|
SuperAntiSpyware (thanks Randy!) is still chugging along and it's found a couple of more instances of rougue.internetsecurity2010 which is what I think caused this downward spiral in the first place. Don't think it was active, just some files that remained. Still a ways to go. Good lesson learned; the kids had their own account but it was set up as an administrator account. Kinda defeats the purpose.... |
|
![]() |
|
Bob
Admin Group
Joined: 14 Feb 2008 Location: Piney woods Tex Posts: 11084 |
Quote Reply
Posted: 01 Feb 2010 at 6:24pm |
|
When I picked up this newest to me machine it was set up the same way. Two kids and the adult all had Administrative accounts. The teenage boy was fearless in where he surfed and frequented. Stupid is more like it. It was hijacked, infected, and just lousy with malware.
|
|
![]() |
|
Karl_db
Admin Group
Joined: 12 Mar 2008 Posts: 29205 |
Quote Reply
Posted: 01 Feb 2010 at 9:06pm |
|
Lousy with malware...or hormones? HeeHee
|
|
![]() |
|
Bob
Admin Group
Joined: 14 Feb 2008 Location: Piney woods Tex Posts: 11084 |
Quote Reply
Posted: 01 Feb 2010 at 9:10pm |
|
You got the message. Lousy with malware because of bursting, raging hormones. And a penchant for pirated music sites.
|
|
![]() |
|
Randy
Admin Group
Joined: 22 Mar 2008 Location: USA, Georgia Posts: 15219 |
Quote Reply
Posted: 01 Feb 2010 at 9:41pm |
|
Don - Sounds like you're making some headway. From all my reading and poking about, Malwarebytes seems to still be a good one that checks for the real nasty things that other virus/malware apps miss. The default settings are good and it doesn't take an eternity to run.
At times I think about skipping by info on the latest and greatest bad stuff out there but it just fascinates me as to how sneaky the bad guys get with that stuff. |
|
![]() |
|
Randy
Admin Group
Joined: 22 Mar 2008 Location: USA, Georgia Posts: 15219 |
Quote Reply
Posted: 01 Feb 2010 at 9:43pm |
I don't know of many who would lay off that one. They would just click it thinking it was a Windows notification. |
|
![]() |
|
Don Watkins
Admin Group
Admin Joined: 14 Mar 2008 Posts: 22156 |
Quote Reply
Posted: 02 Feb 2010 at 3:25am |
|
Yup. Good lesson here; know what your AV software looks like when it throws off a warning.
|
|
![]() |
|
Don Watkins
Admin Group
Admin Joined: 14 Mar 2008 Posts: 22156 |
Quote Reply
Posted: 02 Feb 2010 at 5:22am |
|
Okay, I'm pronouncing him clean and fixed. I did have to run SASW on all the different user accounts; I thought running it as admin would take out everything for all accounts but nah but I've run it for all three users then run it again and it's reporting nada. My take on MWB was that it was too aggressive for me. He wanted to make a registry change that would have removed the ability to change the desktop. I can understand that some malware wants to do that to place their stuff on the desktop but that's pretty drastic and I expect some users would have just plugged away and then been confused and unable to restore desktop customization. |
|
![]() |
|
Randy
Admin Group
Joined: 22 Mar 2008 Location: USA, Georgia Posts: 15219 |
Quote Reply
Posted: 02 Feb 2010 at 5:42am |
|
Thanks for the update on that. Won't be using that puppy again until I hear of a change in attitude. That is quite a surprise, having heard the way that outfit was formed and who was invited. I guess it stems from having x-IT support people involved who tend to want to protect the customer from their own mistakes.
Our IT people at work tried to make the desktop unusable but got called on it and they put things back in order when asked. I don't get that. |
|
![]() |
|
Don Watkins
Admin Group
Admin Joined: 14 Mar 2008 Posts: 22156 |
Quote Reply
Posted: 02 Feb 2010 at 5:54am |
|
IT people are only happy when users do it their way. Security people are only happy when no one can log on. |
|
![]() |
|
Don Watkins
Admin Group
Admin Joined: 14 Mar 2008 Posts: 22156 |
Quote Reply
Posted: 02 Feb 2010 at 5:56am |
|
I might add that they have a lot of photos and personal stuff, it's probably going to end up being around four full DVD's worth that they didn't have backed up anywhere else. I'm putting it on DVD's for them. Sigh. Photos of their trips to Europe, Australia, kid and family events, birth of the first grandkid, you name it. People just don't get it. |
|
![]() |
|
Randy
Admin Group
Joined: 22 Mar 2008 Location: USA, Georgia Posts: 15219 |
Quote Reply
Posted: 02 Feb 2010 at 6:02am |
|
ROFLOL! "Security people are only happy when no one can log on."
But of course! It should have occurred to me before now that that was their goal! Glad you at least were able to back up their stuff to DVD before it got gone. Even though they don't get it I sure hate to tell someone their stuff is gone. |
|
![]() |
|
Post Reply
|
Page 12> |
| Forum Jump | Forum Permissions ![]() You cannot post new topics in this forum You cannot reply to topics in this forum You cannot delete your posts in this forum You cannot edit your posts in this forum You cannot create polls in this forum You cannot vote in polls in this forum |