reggiep Posted March 1, 2011 Posted March 1, 2011 This malware tells the user “Warning! Your’re in danger! Your computer is infected with spyware!” including the spelling mistake. I know of three computers in the last three days that have had this. The London stock exchange website has been helping to spread it... London Stock Exchange Served Malware | eWEEK Europe UK Now I restored one computer but am having a go at removing it with spybot and malwarebytes but so far no success. Anyone?
localzuk Posted March 1, 2011 Posted March 1, 2011 Yup, seen that twice so far - it seems only to attack the profile, rather than anything more, so creating a new profile sorted it out with both cases I've seen.
maniac Posted March 1, 2011 Posted March 1, 2011 Not seen that one, but had several other ones recently that seem to have installed themselves onto locked down machines somehow, despite having up-to-date spyware/virus scanners on the machines as well. Quite scary how easily this type of software is able to get onto PC's these days.
somabc Posted March 1, 2011 Posted March 1, 2011 Yes it has been all over here. Looks like it is caused by infected adverts on websites. I would make sure your JRE is at the latest version and scan with Kaspersky Removal Tool and Malware Bytes. You can also use Autoruns to remove the .exe in the profile if it is not picked up by the scan (best done in Safe Mode). Kaspersky Lab UK :: Antivirus technical support home Malwarebytes Autoruns for Windows 1
timbo343 Posted March 1, 2011 Posted March 1, 2011 Yeah ive seen that and on my machine too.. the way to get rid is to restart machine in Safe mode with networking... Download and update malware bytes and run malware bytes. It should find 3 files. Once the scan is complete, restart machine.. You should be fine. After that, install AVG... AVG detected it on my main machine and stopped it from running. I have found that if your machine is running mcafee too, mcafee doesnt see the virus as a threat. Hope this helps
Scruff Posted March 1, 2011 Posted March 1, 2011 3 laptops manually disinfected over the last 2 days, slightly boring now
somabc Posted March 1, 2011 Posted March 1, 2011 I find the Kaspersky Removal Tool works well as it is easily downloaded and uninstalled after use and has good detection rates. If you run that before Malwarebytes it works 99% of the time. Kaspersky Virus Removal Tool Download
somabc Posted March 1, 2011 Posted March 1, 2011 You could also try rolling out a sandboxed browser such as Secure Browser - Dell KACE™
localzuk Posted March 1, 2011 Posted March 1, 2011 Yeah ive seen that and on my machine too.. the way to get rid is to restart machine in Safe mode with networking... Download and update malware bytes and run malware bytes. It should find 3 files. Once the scan is complete, restart machine.. You should be fine. After that, install AVG... AVG detected it on my main machine and stopped it from running. I have found that if your machine is running mcafee too, mcafee doesnt see the virus as a threat. Hope this helps I suspect this isn't the case with everyone - AVG had absolutely no luck finding it on one of the machines I fixed for someone the other day. Spybot S&D didn't either.
timbo343 Posted March 1, 2011 Posted March 1, 2011 I suspect this isn't the case with everyone - AVG had absolutely no luck finding it on one of the machines I fixed for someone the other day. Spybot S&D didn't either. This is the one which turns the background blue with red writing isnt it?
AyatollahPies Posted March 1, 2011 Posted March 1, 2011 Sophos is not very good at detecting it. I have the fun task of removing fakeAV from the G/fs laptop this evening. What fun.
localzuk Posted March 1, 2011 Posted March 1, 2011 This is the one which turns the background blue with red writing isnt it? Wasn't blue for me, it was a grey pattern with red writing. Like most malware, there are probably multiple versions.
cromertech Posted March 1, 2011 Posted March 1, 2011 Had one of these this morning. Was easily removed with malwarebytes. The most annoying part was having to kill the {random.exe} process remotely. Always a different file name so no script is able to locate it.
somabc Posted March 1, 2011 Posted March 1, 2011 Can we not have something where when a .exe file is created in a profile it gets deleted or an alert sent!?
mattx Posted March 1, 2011 Posted March 1, 2011 I am finding these tend to pop up whilst users use google for image searches. Once flagged up on my console I just remove the offending cache folder where the offending .js file is located just in case. Example of which: 107aad15ba6b97acb376b51a8c8c6708987d3035111[1].js and 107aad15ba6b97acb376b51a8c8c6708987d3036011[1].js
joe90bass Posted March 1, 2011 Posted March 1, 2011 One of our teachers told me yesterday that over half term she paid £50 for an anti-virus program because she couldn't do anything on her PC unless she paid up......... Wonder if this was the very one?
timbo343 Posted March 1, 2011 Posted March 1, 2011 One of our teachers told me yesterday that over half term she paid £50 for an anti-virus program because she couldn't do anything on her PC unless she paid up......... Wonder if this was the very one? Sounds like the one. Mind you, they all do the same thing.... grab your money but dont do anything
joe90bass Posted March 1, 2011 Posted March 1, 2011 Sounds like the one. Mind you, they all do the same thing.... grab your money but dont do anything Yep! Did tell her to contact her credit card company pronto in case anything else had been taken.
andy_b Posted March 1, 2011 Posted March 1, 2011 I think ebay was also delivering this one (System Tool) disinfected three peoples home computes thus far. Pretty much used the following procedure: Remove System Tool and SystemTool (Uninstall Guide)
timzim Posted March 1, 2011 Posted March 1, 2011 One of our teachers told me yesterday that over half term she paid £50 for an anti-virus program because she couldn't do anything on her PC unless she paid up And I thought teachers were supposed to be clever...
computer_expert Posted March 1, 2011 Posted March 1, 2011 I suspect this isn't the case with everyone - AVG had absolutely no luck finding it on one of the machines I fixed for someone the other day. Spybot S&D didn't either. I managed to disinfect a machine with avast on, but malwarebytes did a great job at removing it along with other nasties. Fortunately the variation that was on the infected computer didn't run in safe mode and didn't change the proxy settings either.
Cache Posted March 1, 2011 Posted March 1, 2011 Had 2 computers today and my laptop picked it up sunday night. rkill managed to kill the processes off (had to use the iExplorer.exe version) and then Malwarebytes sorted it after that.
Chunks_ Posted March 2, 2011 Posted March 2, 2011 Yeah, Seen this on a couple of machines myself. System tool it was called on my occasion... hijacks the desktop - nasty bugger as it stops you running any programs even task manager. Anyway heres a nice easy link to removal instructions . The other link above wasnt as accurate and made you do things that werent nessacery in my situation.
quietriot1983 Posted March 2, 2011 Posted March 2, 2011 And I thought teachers were supposed to be clever... To be fair, if you're not particularly IT-Savvy, you can see how people get roped into paying for these things!
witch Posted March 2, 2011 Posted March 2, 2011 Isn't that the same as this thread? http://www.edugeek.net/forums/general-chat/71778-compromised-websites-anyone-else-affected-yet.html
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now