Jump to content

Recommended Posts

Posted

This malware tells the user “Warning! Your’re in danger! Your computer is infected with spyware!” including the spelling mistake.

 

I know of three computers in the last three days that have had this.

 

The London stock exchange website has been helping to spread it...

London Stock Exchange Served Malware | eWEEK Europe UK

 

Now I restored one computer but am having a go at removing it with spybot and malwarebytes but so far no success.

 

Anyone? ;)

Posted
Yup, seen that twice so far - it seems only to attack the profile, rather than anything more, so creating a new profile sorted it out with both cases I've seen.
Posted
Not seen that one, but had several other ones recently that seem to have installed themselves onto locked down machines somehow, despite having up-to-date spyware/virus scanners on the machines as well. Quite scary how easily this type of software is able to get onto PC's these days.
Posted

Yeah ive seen that and on my machine too.. the way to get rid is to restart machine in Safe mode with networking... Download and update malware bytes and run malware bytes. It should find 3 files. Once the scan is complete, restart machine.. You should be fine. After that, install AVG... AVG detected it on my main machine and stopped it from running.

 

I have found that if your machine is running mcafee too, mcafee doesnt see the virus as a threat.

 

Hope this helps

Posted
Yeah ive seen that and on my machine too.. the way to get rid is to restart machine in Safe mode with networking... Download and update malware bytes and run malware bytes. It should find 3 files. Once the scan is complete, restart machine.. You should be fine. After that, install AVG... AVG detected it on my main machine and stopped it from running.

 

I have found that if your machine is running mcafee too, mcafee doesnt see the virus as a threat.

 

Hope this helps

 

I suspect this isn't the case with everyone - AVG had absolutely no luck finding it on one of the machines I fixed for someone the other day. Spybot S&D didn't either.

Posted
I suspect this isn't the case with everyone - AVG had absolutely no luck finding it on one of the machines I fixed for someone the other day. Spybot S&D didn't either.

 

This is the one which turns the background blue with red writing isnt it?

Posted
This is the one which turns the background blue with red writing isnt it?

 

Wasn't blue for me, it was a grey pattern with red writing. Like most malware, there are probably multiple versions.

Posted
Had one of these this morning. Was easily removed with malwarebytes. The most annoying part was having to kill the {random.exe} process remotely. Always a different file name so no script is able to locate it.
Posted

I am finding these tend to pop up whilst users use google for image searches. Once flagged up on my console I just remove the offending cache folder where the offending .js file is located just in case.

Example of which:

 

107aad15ba6b97acb376b51a8c8c6708987d3035111[1].js and

107aad15ba6b97acb376b51a8c8c6708987d3036011[1].js

Posted
One of our teachers told me yesterday that over half term she paid £50 for an anti-virus program because she couldn't do anything on her PC unless she paid up......... Wonder if this was the very one?
Posted
One of our teachers told me yesterday that over half term she paid £50 for an anti-virus program because she couldn't do anything on her PC unless she paid up......... Wonder if this was the very one?

 

Sounds like the one. Mind you, they all do the same thing.... grab your money but dont do anything

Posted
Sounds like the one. Mind you, they all do the same thing.... grab your money but dont do anything

 

Yep! Did tell her to contact her credit card company pronto in case anything else had been taken.

Posted
One of our teachers told me yesterday that over half term she paid £50 for an anti-virus program because she couldn't do anything on her PC unless she paid up

 

And I thought teachers were supposed to be clever... :doh:

Posted
I suspect this isn't the case with everyone - AVG had absolutely no luck finding it on one of the machines I fixed for someone the other day. Spybot S&D didn't either.

 

I managed to disinfect a machine with avast on, but malwarebytes did a great job at removing it along with other nasties. Fortunately the variation that was on the infected computer didn't run in safe mode and didn't change the proxy settings either.

Posted

Had 2 computers today and my laptop picked it up sunday night.

 

rkill managed to kill the processes off (had to use the iExplorer.exe version) and then Malwarebytes sorted it after that.

Posted
Yeah, Seen this on a couple of machines myself. System tool it was called on my occasion... hijacks the desktop - nasty bugger as it stops you running any programs even task manager. Anyway heres a nice easy link to removal instructions . The other link above wasnt as accurate and made you do things that werent nessacery in my situation.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...