Parts Catalog Accessories Catalog How To Articles Tech Forums
Call Pelican Parts at 888-280-7799
Shopping Cart Cart | Project List | Order Status | Help



Go Back   PeachParts Mercedes-Benz Forum > General Discussions > Off-Topic Discussion

Reply
 
LinkBack Thread Tools Display Modes
  #1  
Old 09-07-2008, 09:31 AM
Banned
 
Join Date: May 2002
Location: Blue Point, NY
Posts: 25,396
Trojan horse

I got stuck with the trojan horse "media-codec" last night. It hijacks the explorer browser and continually connects to the internet to feed itself. Every minutes it demands that you purchase some "antispy" software to remove the trojan that it has installed in your computer which it's very pleased to continually inform you.

Very crafty set of code.

FWIW, Ad-Aware didn't see it. Trend-Micro didn't see it. I purchased some new software, "XoftSpySE", which couldn't remove it.

Finally, after six hours of this BS, I got "VIPRE". It found the five cretins and eliminated them after a 2 1/2 hour scan.

Be careful out there.

Reply With Quote
  #2  
Old 09-07-2008, 09:34 AM
Botnst's Avatar
Banned
 
Join Date: Jun 2003
Location: There castle.
Posts: 44,601
Karmic balance has returned to the universe.

It's due to heart-wrenching myocardial infractions.
Reply With Quote
  #3  
Old 09-07-2008, 09:37 AM
Banned
 
Join Date: May 2002
Location: Blue Point, NY
Posts: 25,396
Quote:
Originally Posted by Botnst View Post
Karmic balance has returned to the universe.

It's due to heart-wrenching myocardial infractions.
Hmmm..........now I wonder where that Trojan horse came from............hmmm..........
Reply With Quote
  #4  
Old 09-07-2008, 11:20 AM
Registered User
 
Join Date: Mar 2006
Posts: 1,392
i or should i say the kid.picked up a virus while we were gone on vacation over the labor day weekend.it got into my hotmail and corrupted some files,also i couldn't view any video's as they would start then 2 seconds later restart and restart and restart.it also would not for some reason let me view ebay motors,but everything else worked.then if say i googled mercedesshop,i would get a website with references to travel in china,go back to google and do mercedesshop again and a different site with china would come up.so everytime i tried i got a different website,but they all had mention of china.it even got in and corrupted my system restore to the point it had no previous restore points,even in safe mode.i ended up doing a system recovery.all i ended up losing was my printer.buddy of mine works on computers and told me to dump norton for avg or avast anti-virus.needless to say norton got the "boot".hmm norton wonder if they are related to norton motorcycles.software by lucas by chance!!
Reply With Quote
  #5  
Old 09-07-2008, 11:50 AM
link's Avatar
Registered User
 
Join Date: Jun 2008
Posts: 835
Several years ago there was a strain of virus that employed 5 different programs. If you deleted any one of the programs, the other 4 would reconstitute it in under a second. The only way to defeat it was to run the computer in safe mode and follow a lengthy procedure to remove all the elements. Once removed, it left the computer largely intact.

There is one or more vicious and I do mean vicious new strains moving about the pc world. They both present themselves as ransom-ware, that is they act as a trojan which says you need to go to site x to buy anti-spyware programs. Site X, of course doesn’t exist.

I've seen 2 cases and these were not solvable by typical or even extraordinary means. Once the program gets on to the computer it puts us a charade even including a BSD. The BSD itself is merely a .jpg but it is part of a series of events that take place and the BSD is enough to get most to reboot their computer. Once the reboot happens, it’s pretty much game over for the pc owner. The program over writes several system files, alters the registry, alters the way that both IE and Windows Explorer works, makes the start bar inaccessible, and even re-maps part of the keyboard – the enter key doesn’t work, nor the back slash “\” nor the foreword slash “/”slash. And as the final coup, they delete all existing system restore points. I spent 2 hours with the first one of these I saw, looked through the registry, was able to identify and remove most of the intrusion itself, but not the damage done. Used 6 anti-virus and anti-spyware programs which were not able to identify any part of the intrusion.

If you get a pop up for an anti-virus or anti-spyware program from any web site, go to your Start bar, right click on the program and select close. Or just reboot your computer. Don’t click on any part of the pop up.

Just FYI
Reply With Quote
  #6  
Old 09-07-2008, 11:55 AM
Registered User
 
Join Date: Jul 2007
Location: Columbus OH
Posts: 275
I got one of those. Took CCleaner, Smitfraud, and some registry cleaner I can't remember to get it off.
__________________
1984 300TD
Reply With Quote
  #7  
Old 09-07-2008, 11:58 AM
Banned
 
Join Date: May 2002
Location: Blue Point, NY
Posts: 25,396
Quote:
Originally Posted by link View Post
There is one or more vicious and I do mean vicious new strains moving about the pc world. They both present themselves as ransom-ware, that is they act as a trojan which says you need to go to site x to buy anti-spyware programs. Site X, of course doesn’t exist.

I've seen 2 cases and these were not solvable by typical or even extraordinary means. Once the program gets on to the computer it puts us a charade even including a BSD. The BSD itself is merely a .jpg but it is part of a series of events that take place and the BSD is enough to get most to reboot their computer. Once the reboot happens, it’s pretty much game over for the pc owner. The program over writes several system files, alters the registry, alters the way that both IE and Windows Explorer works, makes the start bar inaccessible, and even re-maps part of the keyboard – the enter key doesn’t work, nor the back slash “\” nor the foreword slash “/”slash. And as the final coup, they delete all existing system restore points. I spent 2 hours with the first one of these I saw, looked through the registry, was able to identify and remove most of the intrusion itself, but not the damage done. Used 6 anti-virus and anti-spyware programs which were not able to identify any part of the intrusion.

If you get a pop up for an anti-virus or anti-spyware program from any web site, go to your Start bar, right click on the program and select close. Or just reboot your computer. Don’t click on any part of the pop up.

Just FYI
This one did exactly as you describe.........desperately wants you to buy some anti-spyware.

Thankfully, it was removable by ordinary means provided that one found suitable software to do so. I was a bit miffed that Trend Micro and Ad-Aware could do nothing with it.

Even now, the Google search bar is not available. It stuffed the bar with "Search" as the engine and I cannot get rid of it.

You're absolutely right about closing some of those pop-ups. If you attempt to close the pop-up with the close key in the upper right corner........you're toast.
Reply With Quote
  #8  
Old 09-07-2008, 12:09 PM
link's Avatar
Registered User
 
Join Date: Jun 2008
Posts: 835
Both trendmicro and ad aware are good programs, but no one program does it all. I use a mix including those plus 4 others.

You might be able to disable the search engine if it set as an add-on. In IE (6) go to tools, internet options, programs and manage add ons.

While there, it is probably a good idea to disable everything that is NOT from Microsoft, Sun, Adobe, Google and or anything else you don’t know you need. If you (or anyone) makes a mistake it is easy to re-enable the add on. Often by removing this unneeded crap the browser will become more responsive.
Reply With Quote
  #9  
Old 09-07-2008, 12:28 PM
Banned
 
Join Date: May 2002
Location: Blue Point, NY
Posts: 25,396
Quote:
Originally Posted by link View Post
You might be able to disable the search engine if it set as an add-on. In IE (6) go to tools, internet options, programs and manage add ons.
I've got Firefox and it doesn't seem to want to allow me to delete "Search" or restore the Browser to the "default" setting.
Reply With Quote
  #10  
Old 09-07-2008, 01:50 PM
Registered User
 
Join Date: Jul 2008
Location: los angeles
Posts: 451
i feel for all of you, and have been there. thankfully, i now have a mac.
__________________
"The law, in its majestic equality, forbids the rich as well as the poor to sleep under bridges, to beg in the streets, and to steal bread."
Reply With Quote
  #11  
Old 09-07-2008, 02:12 PM
Emmerich's Avatar
M-100's in Dallas
 
Join Date: Jul 2003
Location: Dallas
Posts: 683
Run your browser in a virtual machine and problems like these are kaput.
__________________
MB-less
Reply With Quote
  #12  
Old 09-07-2008, 02:27 PM
compress ignite's Avatar
Drone aspiring to Serfdom
 
Join Date: Feb 2004
Location: 32(degrees) North by 81(degrees) West
Posts: 5,554
"virtual machine"

What is it and how do you get Mozilla to run within it?
__________________
'84 300SD sold
124.128
Reply With Quote
  #13  
Old 09-07-2008, 02:36 PM
Banned
 
Join Date: May 2002
Location: Blue Point, NY
Posts: 25,396
Quote:
Originally Posted by compress ignite View Post
what is it and how do you get mozilla to run within it?
x2
Reply With Quote
  #14  
Old 09-07-2008, 03:18 PM
Registered User
 
Join Date: Oct 2005
Posts: 4,263
VMWare ESX is one such virtual host. It's expensive for commercial use, but might be free or cheap for personal use. I'm sure others exist.

A virtual host is a computer program (essentially) which mimics the hardware, creating a virtual machine. More likely, more than one virtual machine. These look like a PC to the OS, but just have a large file on the host which represents its disk image. You can make a copy of this disk image for use in rolling back any changes or restoring a corrupt machine.
Reply With Quote
  #15  
Old 09-07-2008, 03:27 PM
chilcutt's Avatar
Anywhere I Roam
 
Join Date: Mar 2008
Location: Singapore
Posts: 13,161
Quote:
Originally Posted by Brian Carlton View Post
This one did exactly as you describe.........desperately wants you to buy some anti-spyware.

Thankfully, it was removable by ordinary means provided that one found suitable software to do so. I was a bit miffed that Trend Micro and Ad-Aware could do nothing with it.

Even now, the Google search bar is not available. It stuffed the bar with "Search" as the engine and I cannot get rid of it.

You're absolutely right about closing some of those pop-ups. If you attempt to close the pop-up with the close key in the upper right corner........you're toast.
I went thru the same thing and now got it staightened out. The thing that mifs me is that with everything that is going on in the world, and how hard it is to survive there are people out there who enjoy screwing up your world. My computer geek friend, has a line on software that will rederect the incoming "Trojan" and ruin their pc, it is pricey, but I would love to be able to reach out and touch any miscreant who wishes me harm.

Reply With Quote
Reply

Bookmarks


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT -4. The time now is 09:20 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0
Copyright 2024 Pelican Parts, LLC - Posts may be archived for display on the Peach Parts or Pelican Parts Website -    DMCA Registered Agent Contact Page