RetouchPRO

Go Back   RetouchPRO > Community > Salon

Notices

Salon Just hanging around...
(Social area, where non-retouching talk is encouraged)

Reply
 
LinkBack Thread Tools
  #1  
Old 01-10-2007, 02:00 AM
Gary Richardson's Avatar
Moderator
 
Join Date: Mar 2004
Location: Yorkshire, England
Posts: 2,687
infection in Action

For those of you who know, I spend a lot of my time removing Malware from other people's computers.

This clip at UTube gives you an idea of why you should browse cautiously and pay attention to your security.

It shows a typical "Spy Sherriff" install, which is one of the "Smitfraud" family of infections, an extremely common infection, usually contracted by downloading an infected codec.

Enjoy!

http://www.youtube.com/watch?v=MaKv_...elated&search=


PS. This is an Add for McAfee Site Advisor, which is a tool for giving indication of which sites contain infected links.

McAfee AV funnily enough (though not surprisingly) does not remove this infection.

Last edited by Gary Richardson; 01-10-2007 at 02:31 AM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
  #2  
Old 01-10-2007, 03:52 AM
chrishoggy's Avatar
Senior Member
Patron
 
Join Date: Dec 2004
Location: Yorkshire
Posts: 562
Blog Entries: 1
Re: infection in Action

Nice clip Gary
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
  #3  
Old 01-10-2007, 07:40 AM
Kraellin's Avatar
Moderator
 
Join Date: Apr 2005
Location: somewhere over there
Posts: 6,509
Blog Entries: 4
Re: infection in Action

hehe, never had one quite that bad, but close
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
  #4  
Old 01-10-2007, 12:52 PM
CJ Swartz's Avatar
Moderator
 
Join Date: Sep 2001
Location: Metro Phoenix area, Arizona
Posts: 2,640
Blog Entries: 10
Re: infection in Action

Gary, thanks for the clip -- if it wasn't so scary I'd say I enjoyed it. The music really adds to the drama. I hope I never let my poor computer get that sick...

I really like McAfee's SiteAdvisor add-on to Firefox -- I like that the free version gives me info about potential threats at a particular website (getting bugged with emails if you sign up on that page, spyware attached to downloads from a site, etc.), and I feel much better when I see that nice green color saying that a site is relatively safe.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
  #5  
Old 01-10-2007, 04:24 PM
Gary Richardson's Avatar
Moderator
 
Join Date: Mar 2004
Location: Yorkshire, England
Posts: 2,687
Re: infection in Action

Yeah, I like Site Advisor too, though it is not always totally reliable.

Some good sites were recently listed as red because some of the tools there had processes which could be used maliciously, they weren't, but Site Advisor relies on a bot system to gather data, and tends to err on the side of caution.

The good thing is that McAfee responded quickly when their error was pointed out to them, and the site listing was revised.

Full marks therefore to McAfee, now if only they could do something about the over bloated pile of junk they sell as an Anti-Virus.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
  #6  
Old 01-15-2007, 11:52 PM
T Paul's Avatar
Moderator
 
Join Date: Aug 2001
Location: USA
Posts: 2,545
Re: infection in Action

My sister's computer now looks like the YouTube clip...her's was spysoldier and ultimately Win32.MatrixHasYou. She gave up in defeat tonight and we are going to try to tackle it tomorrow.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
  #7  
Old 01-16-2007, 09:31 AM
Gary Richardson's Avatar
Moderator
 
Join Date: Mar 2004
Location: Yorkshire, England
Posts: 2,687
Re: infection in Action

Hi T,

Get her to run a HJT (HijackThis) scan and I'll look it over for you, if we know what the infection is, it'll probably save you hours of possibly fruitless endeavour. (Sounds like one of the Smitfraud varients offhand, but I'll be better placed to help her if I can see a HJT log).

Click here to download HJTsetup.exe, and save it to your desktop.
  • Double click on the HJTsetup.exe icon on your desktop.
  • By default it will install to C:\Program Files\Hijack This.
  • Continue to click Next in the setup dialogue boxes until you get to the "Select Addition Tasks" dialogue.
  • Put a check by Create a desktop icon then click Next again.
  • Continue to follow the rest of the prompts from there.
  • At the final dialogue box click Finish and it will launch Hijack This.
  • Click on the "Do a system scan and save a log file" button. It will scan and then ask you to save the log.
  • Copy and paste the log here
DO NOT have HijackThis fix anything yet. Most of what it finds will be harmless or even required.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
  #8  
Old 01-16-2007, 09:53 AM
T Paul's Avatar
Moderator
 
Join Date: Aug 2001
Location: USA
Posts: 2,545
Re: infection in Action

Thanks so much Gary! I haven't heard back from her today, but I will let her know about your extremely kind offer!!!!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
  #9  
Old 01-16-2007, 12:24 PM
Gary Richardson's Avatar
Moderator
 
Join Date: Mar 2004
Location: Yorkshire, England
Posts: 2,687
Re: infection in Action

You're welcome. Just post it in this thread and I'll see it.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
  #10  
Old 01-17-2007, 01:09 PM
T Paul's Avatar
Moderator
 
Join Date: Aug 2001
Location: USA
Posts: 2,545
Re: infection in Action

Well I just talked to my sister. She ended up purchasing SpyDoctor and I think it found over 600 infected files. She is trying to install HiJackThis right now but gets the following error:

Quote:
an error occured while trying to rename a file in the destination directory Movefile failed; code 5 Access denied

Last edited by T Paul; 01-17-2007 at 01:23 PM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
  #11  
Old 01-17-2007, 01:33 PM
Kraellin's Avatar
Moderator
 
Join Date: Apr 2005
Location: somewhere over there
Posts: 6,509
Blog Entries: 4
Re: infection in Action

600! oh my lord. i thought i was in trouble when i found 3 a year ago

you might inform your sister that ANY personal data she had on that computer is now public knowledge, including passwords, bank statements, email addresses, pin numbers, credit card numbers and so on. she shld inform the bank if she had a pin number on the computer, credit card companies if she had any credit card numbers on there and so on down the line. many of these modern viruses and spyware do nothing but search such data out on an infected computer and send that data out for thieves to use.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
  #12  
Old 01-17-2007, 01:38 PM
T Paul's Avatar
Moderator
 
Join Date: Aug 2001
Location: USA
Posts: 2,545
Re: infection in Action

That's not going to make her happy. She still hasn't had any luck installing HJT.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
  #13  
Old 01-17-2007, 01:41 PM
T Paul's Avatar
Moderator
 
Join Date: Aug 2001
Location: USA
Posts: 2,545
Re: infection in Action

It all happened when she was trying to send me some photos. Her computer came with Adobe Photoshop Album Starter 2.0 and she was having some trouble emailing from the problem so she clicked on the link to go to the software web site and wamm her computer was taken over! Sounds like something is nesting in her computer.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
  #14  
Old 01-17-2007, 02:10 PM
Gary Richardson's Avatar
Moderator
 
Join Date: Mar 2004
Location: Yorkshire, England
Posts: 2,687
Re: infection in Action

Hi T,

OK, lets try re-naming HJT and then seeing if we can install it and run a scan.

Won't be able to use the version I linked to, as that auto installs.

Try this.

Create a new folder C:\HJT

Download HijackThis.exe to this folder. (This is a free-standing executable version).

Now rename HijackThis.exe to FredFlintstone.exe then try to run a scan. Post back here if possible, if not let me know, there's other things we can try.


Question: When you say SpyDoctor, do you mean SpywareDoctor by PC Tools?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
  #15  
Old 01-17-2007, 02:15 PM
Kraellin's Avatar
Moderator
 
Join Date: Apr 2005
Location: somewhere over there
Posts: 6,509
Blog Entries: 4
Re: infection in Action

try gary's method first. but, i also recently ran HJT and went to their web site and noticed that they also recommend, in some instances, using earlier versions of HJT due to some viruses attacking the later versions specifically. so, that might be an option also, if gary's method doesnt work.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Sheri's Sketch - HELP NEEDED! tonyt Software 7 06-28-2007 04:22 AM
How Do I Record "Save As" as an Action Without a Filename? steiny Software 1 10-30-2006 10:24 AM
Another Action Question Scribe Software 8 11-02-2005 07:16 AM
Combining Photoshop Actions Into a Set Scribe Software 6 10-24-2005 10:19 AM
Free B&W Toning action set gmitchel Photo Restoration 3 10-20-2005 08:56 AM


All times are GMT -6. The time now is 07:29 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0
Copyright © 2008 Doug Nelson. All Rights Reserved




1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51