Page 1 of 1

facebook virus

Posted: Fri Dec 05, 2008 1:40 pm
by Triple6_wild
OK my sister retardedly installed the so called facebook virus

She apparently got an email about a video from a friend on fakebook and when she clicked the link to the video she got redirected to geocitys website with a youtube style window that pretends to load then pops up a missing codec can't play the video kind of error with an option to download the "codec" she accepted download to install this so called codec.

Of course the codec was a virus because I just fully updated her codecs the day before and her computer should play damn near ANYTHING :roflmao2: Why would she fix somthing I already did well I have no idea. This should have been 100% avoidable...

Anyways I now need to try and get rid of the thing and I have stopped it from doing much but I cant get 100% rid of it and am now running out of idea's on what to do :angry:

Ok so ad-aware found some, spy-bot also found some, Leaving spybot on and she keeps being prompted about a registry attempting to be changed tho spy-bot is not allowing this.

Now ive also run nod32 for a virus scanner and it found about 7 infected files and removed them.

Pc pitstop scan comes up as clean and all the processes running are normal aside from garbage my sister put there but safe garbage lol

Every time she turns on the "wireless" she has a fake M$ windows defender style icon balloon in her start bar saying her computer is infected and is instructing her to download a verified by m$ virus scanner (FAKE SCANNER) checked it and it appears to be another virus lol

So im out of ideas. Scans are coming up clean and theres tons of signs its still there.

BRB gotta run out will add when i get back

Edit: Back

Alright so after going to try some stuff and endless hours :pissed off: Ive managed to get rid of it... well i think lol

Some problem files that were picked up by virus scanners and spy-bot
qttasku.exe
qttaskm.exe
hpmun.exe
hpmom.exe
browseru.exe

And these 2 files below slipped by every scan but one scan got them and i hate to give credit to the scan that did but... The real windows defender :cry: NOT THE FAKE ONE Actually have to click the start button and go into control panel and open it yourself!!
(Just in case someone try's to fix there own copy of this virus using this post as a guide so umm ya just making sure)
zlob.ans
zlob.bah

Now after all those had been found by scanners etc the computer was still doing suspicious behavior but only when the internet was turned on and spy-bot kept catching a registry trying to be changed regardless of wireless on or off

Ok starting IE the home page would not load and bring up yet another fake virus scanner pop up after closing the pop up it would load a load a fake windows defender as the page in IE and it looks fairly real lol

Moving on tryed to use housecall & kaspersky for online scanners since the ones i had were not finding anything new yet still getting odd behavior but both scanners failed to load :grade11math: Downloaded the trial version of kaspersky and attempted to run that but it froze at 48% and refused to continue and even after restarting it was still at 48%? No not re-scanned and freeze again... Just still at 48% Very strange indeed.

So no scanners finding anything and any well known scanners not working :unsure:
Appears clean except for the odd behavior mentioned but when the computer is restarted guess what. :biglaugh: Everything is back again LOL

Now strangely i noticed the created date on the folder C:Programfileswebmediaviewer Some of the virus .exe files were found in this folder and the folder was made the same day she got the virus (I thought the folder was supposed to be there because its not my pc) There were lots of files still in this folder. Anyways none of the files or the folder itself could be deleted as they were in use but if the scanners got everything then why would there still be files here?

Well after starting in safe mode i was able to delete the folder webmediaviewer along with all files in it and running the downloaded kaspersky was now possible and came up clean as the computer was clean before it shutdown right ^^

Restarted the pc normally and TADA Nothing... No strange behaviour, No pop ups, No redirect, Spy-bot is not warning about registry change, Scanners finding nothing, It's fixed :angelic:

Now umm I'm no guru at this but the online scans still refuse to run java and it is upto date as I just did that so is it possible that the computer may still be infected at all? Alot of files in that folder slipped through the scans that I deleted manually just on a hunch because of the date. Apparently after doing some looking up on this virus it seems it logs and sends out keystrokes for login passwords and anything els also looks for credit card banking info so umm ya she uses the pc for banking and i wanna make sure its 100% cleaned before letting her use her bank on it.

It appears to be 100% back to normal but I'm just a little paranoid that it may still have something hiding on it because all scanners missed a butt load of files. And due to the whole nature of the virus using tricks as its main tactic, deleting a few files in safe mode seems to easy? Also is there anything els It might of left behind that I need to chase after such as registry entry's? Like after looking online for what registry's the virus should change I checked the paths and came up empty. Theres nothing online about this virus to help remove it so I think I did fairly well lol

Anyways Ive got few screenshots of the fake stuff and will post em later as they are saved on my sisters pc right now and I also have the links to the virus's lol
I will not post em though :lol:

Archived topic from Iceteks, old topic ID:5080, old post ID:39019

facebook virus

Posted: Sun Dec 07, 2008 12:29 pm
by Triple6_wild
Ok some photos

Starting IE the browser is highjacked with this popup

Image


Archived topic from Iceteks, old topic ID:5080, old post ID:39021

facebook virus

Posted: Sun Dec 07, 2008 12:31 pm
by Triple6_wild

Closing the pop up bring up the fake security center :roflmao2:

Image


Archived topic from Iceteks, old topic ID:5080, old post ID:39022

facebook virus

Posted: Sun Dec 07, 2008 12:35 pm
by Triple6_wild
Also in this one you can see the fake windows icon bubble

And one of the first scans that's been run and it didn't even get everything :grade11math:

Pretty bad when it takes like 6 different scanners and a guess on what to delete just to get everything :lol:

I didnt take this screen shot but i just noticed somthing on the left....
Reason virus scanners were turning up nill

Image


Archived topic from Iceteks, old topic ID:5080, old post ID:39023

facebook virus

Posted: Fri Dec 19, 2008 11:00 pm
by rovingcowboy
looks like they are using lots of old 3.1 icons there. mixing in with xp and vista styles.

why do they do that stuff, all that time wasted doing stupid carp stuff

they could do good things that help instead of hurt people, and they could do them lots easier and have less hard times at it.

good is always better then bad.

and a virus creater is a bad egg.

Archived topic from Iceteks, old topic ID:5080, old post ID:39029

facebook virus

Posted: Fri Dec 19, 2008 11:15 pm
by Red Squirrel
The problem is, viruses have been a concept since what, 1990? And yet people are STILL dumb enough to fall for them. In today's day and age not opening a virus is like not stepping on standing nails with your car. It's common sense. But common sense is not so common these days.

Archived topic from Iceteks, old topic ID:5080, old post ID:39030

facebook virus

Posted: Sat Dec 20, 2008 3:47 pm
by Triple6_wild
Ya virus writers probably could do a lot of good stuff in the pc world and I'm sure they do have a productive day job that's helpful to society

People steal for money all the time tho so its no different the the guy busting your front door down to get your tv.

A good mechanic has the knowledge and ability to steal cars. A good coder can made a virus to steal identity's and credit cards. Whats the difference?
There will always be someone out there with the ability and knowledge to steal just about anything but the only difference here is the virus route can be done world wide and from the safety of there home. A cheap used laptop that can be destroyed and an unsecured wireless spot is all it takes to not get caught. Also much easier to find a target worldwide because there will always be a higher % of people who will open the virus worldwide vs the local % of people that will leave the keys in the car. And it takes a ton less guts to push a button then it does to jump into a car.

Being bad pays off faster then being good but do you have the heart to be bad?

Anyways sister also has a pc in her house that's actually a nice computer to boot but guess what? A virus wiped the boot sector or a partition table like a year ago and she still doesn't want to fix it because her pictures are on there but what good is that if you cant access the pics? All it needs is to be reformatted and she has her pc back but no pics are there lol Buy a new laptop let it sit for a few more years maybe?

So ya its not the first virus shes gotten and i don't expect it to be the last because some people never learn :no no no: Like squirrel said if it started in 1990 then why is it still a problem? Get your car stolen once because you didn't lock a door and you WILL lock your next car and set the alarm every time but why would you not learn the same from a virus?

Archived topic from Iceteks, old topic ID:5080, old post ID:39033

facebook virus

Posted: Mon Dec 22, 2008 9:30 am
by rovingcowboy
yep but being bad does not pay at all. they will get you sooner or later then you will be in a peck of trouble.

msn had story on sunday about the worst employees in 2008

one was a clerk in a bank, she took over a million dollars over a decdade long job. she took vactions and bought things like crazy and paid for her kids college all with the stolen money,
the FBI caught her and now she is living in a new house with no bills to worry about. and all the food she wants as long as it is bread and water.

then on tv there is a show called dinner impossible, its on the cable channel food network, they use to have a chef on there called robert irvine, last year they fired him after 2 years of the show. why ? they found out he lied about his former jobs. he said he worked in the white house and in the palace in london for the prince, and several other large
and important jobs. well every thing he said above hotel chef was a lie. so he is back in the hotels or out of work all together,

being bad just does not pay.



Archived topic from Iceteks, old topic ID:5080, old post ID:39037

facebook virus

Posted: Tue Dec 23, 2008 12:01 am
by Triple6_wild
Someone out there is living large because of being bad without getting caught B)

Lets simplify the bad a little to something everyone can see because its easy to steal.

Online pirating perhaps? Millions of people stealing online everyday and getting away with it but who of the millions show up in the news? The hand full that get caught.

Same concept millions of people stealing money and other crimes everyday but only the few will be in the news/jail.

See i cant really say who or what they are doing because you only hear about the ones who get caught or were found out after they were already dead so getting away with it means no one knows also means you only ever see the one side :lol:

Being bad really does pay for the most part lol

Archived topic from Iceteks, old topic ID:5080, old post ID:39038

facebook virus

Posted: Thu Dec 25, 2008 2:00 am
by rovingcowboy
payment for bad is not the type of pay i want. it will be a little too hot to hold on too.

not all things will require being paid for in this life. and the bad being paid for in the after life is never going to stop taking that bit of flesh from you for its pay.

that won't be good to be there.
i prefer on this day of the year to thank god for giving us a way to get out of that hot house in the after life by having his son settle the cost if we just ask and believe in him and get baptized to show our faith.
we humans need a way out of trouble cause we are always getting in trouble of some kind.?

Archived topic from Iceteks, old topic ID:5080, old post ID:39043

facebook virus

Posted: Thu Dec 25, 2008 7:32 pm
by Triple6_wild
Humans are mean and cruel creatures so trouble will always be around.

I stay out of trouble to but you can't stop others from bringing it to you :lol:

Archived topic from Iceteks, old topic ID:5080, old post ID:39046

facebook virus

Posted: Mon Jan 05, 2009 11:58 am
by onykage
my question is,

thats vista. Microsoft's attempt to clone OSX. Why in heavens name is your sis operating the machine as ROOT???????

That is the ONLY thing that is nice about vista. The root/user actually works.

virus's and malware are useless in vista if you are running as a user and not the root.

Just for its sake, when i say "root" I mean "administrator".

Someone out there is living large because of being bad without getting caught cool.gif
getting caught has nothing to do with it, the person(s) behind it have registered a malware prevention software which allows them to legally infect your computer in order to sell their software to you. I was ranting about this in a previous post.

And yes, its 100% legal. Me and Red and any other of you guys that would be interested in the project "could" write a program that when you logged on to your computer your computer would open the default browser and come to iceteks. And then register® a script that would remove the malware for $19.95. Legal, cheap, and such an easy way to pay for grad school.

BTW, my vacation was AWSOME!! and I hope you guys had a great holiday and an equally as nice holiday vacation.

Archived topic from Iceteks, old topic ID:5080, old post ID:39053