theriver Posted March 2, 2011 Posted March 2, 2011 This happened to me on Sunday. The machine I was working at (and not viewing any particularly objectionable websites, I hasten to add!) suddenly opened Adobe Reader (an old version) and then started showing the warning. Immediately disconnected from the Internet . . . . . As Localzuk says it just hit my profile (Win7, running as standard user), and I fixed it by logging in as a different user and running a bunch of different AV applications.
synaesthesia Posted March 2, 2011 Posted March 2, 2011 Had this come up twice. Malwarebytes on it's own didn't do much, however running it as well as having MSSE alongside it did the trick. One machine had already downloaded something nastier too, which needed a lot of manual work to get rid. The biggest culprits are a randomly named folder containing 2 files in teh Appdata folder for all users and/or current user depending on security of the machine, as well as a bitmap file in the root of C. Safe mode, manual remove, job done > grab note of the filenames, search registry and remove references therein.
Chris_ Posted March 2, 2011 Posted March 2, 2011 Seen this on about 5 computers so far. A couple at school and a few on peoples home computers. Had it on both XP and Vista. Used MalwareBytes to remove it in safe mode.
michael2k6 Posted March 2, 2011 Posted March 2, 2011 Again, seen that on a friends and sorted it with safemode and malware bytes.
AngryTechnician Posted March 2, 2011 Posted March 2, 2011 On the teacher's personal machine I did on Monday, I only had to remove the entry under RunOnce using Autoruns and was then able to boot up and remove the remnants with Microsoft Security Essentials. Didn't stop the damned thing getting on there in the first place though. VIPRE Protect, on the other hand, has been nailing it with the on-access scanner every time. Zero affected school workstations so far as a result.
Mullaney18 Posted March 3, 2011 Posted March 3, 2011 (edited) got rid of this on a few of these too, logged in as local admin and deleted the folder from the users application data\RandomCharacterFolder\RandomCharacter.exe (with icon) I didnt think to look for it on the registry, hopefully it will leave no damage if I only removed the program itself. Disabled the running icons in system tray too, either turned off or hid Sophos EP.. So, whats the best program to run from a domain \ group policy to put on clients, cause its clearly gonna get worse.. Edited March 3, 2011 by Mullaney18
ticker Posted March 3, 2011 Posted March 3, 2011 followed the bleeping computer guide and it worked a treat removed it no problem one happy user.
tech_guy Posted March 3, 2011 Author Posted March 3, 2011 Came across a variant of it last night that had crippled all the file associations. Kaspersky and MalwareBytes cleaned it off but I was left to tidy up afterwards If I could get hold of these people and force them to eat their own brains I would.
morganw Posted March 3, 2011 Posted March 3, 2011 I've done a personal laptop (XP) and a standalone school laptop (W7) using system restore and then two scans with MSSE. How does this stuff actually install, can you acquire it even when running under a non-privileged account?
tech_guy Posted March 3, 2011 Author Posted March 3, 2011 It's a drive by download from a compromised website. The code is embedded in advertisements.
morganw Posted March 3, 2011 Posted March 3, 2011 So do you have to aprove anything to install it or can you pick it up by just visiting certain websites?
JoeBloggs Posted March 3, 2011 Posted March 3, 2011 Got our first machine infected. Just ran the free Kaspersky virus removal tool, founded loads. Not going to bother with Safe Mode & Malaware Bytes, just going to image it! McAfee didn't seem to find anything though, which is worrying.
themightymrp Posted March 3, 2011 Posted March 3, 2011 (edited) Had this on about 8 staff laptops this week!! Sophos up to date and didn't notice a bloody thing! This is how I removed it: 1) Boot into safe mode 2) Browse to c:\documents and settings\all users\application data 3) Search for a randomly named folder (letters and numbers). Open it and note the name of the executable. There may be 2 files in here. 4) Open regedit 5) Browse to HKCU\software\microsoft\windows\currentversion\runonce and delete any reference to the above file. 6) Browse to HKCU\software\microsoft\windows\ShellNoRoam\MUIcache and again delete any references. 7) Still in regedit, select the HKLM folder and go to File Load Hive and browse to c:\documents and settings\staff\NTuser.dat Give the key a relevant name. 8) Within this mounted folder, search the same registry keys as above and delete any references to the file 9) Click on the name of the mounted folder as entered above and go to File Unload Hive 10) Load any other NTuser.dat hives for all accounts that have been logged on since the infection i.e. any domain accounts 11) Repeat searching the registry keys and hives until finished. 12) Make sure all hives are unloaded. 13) Delete the randomly titled folder from c:\documents and settings\all users\application data 14) Reboot the machine and log in as local administrator 15) Allow Sophos to update if not already updated 16) Run a full sweep on the C: drive with settings to automatically remove infections. 17) It is likely to find a FakeAV-??? File in the c:\windows\temp folder. The scan should remove this. 18) For safety, delete temporary internet files, system restore files and anything in the c:\windows\csc folder. 19) Log in as the laptop owner and watch for signs of infection What a swine! Edited March 3, 2011 by themightymrp 1
Dave84 Posted March 3, 2011 Posted March 3, 2011 Haven't seen this in school yet but will deffo keep an eye out for it. NOD32 has been blocking alot of web based nasties recently though.
GREED Posted March 3, 2011 Posted March 3, 2011 I had this at home 3 weeks ago, bugger of a thing to remove. Helpful but contradictory fixes online helped sort it. Pain in the bottom! Rebuilding this weekend.
achedgy Posted March 3, 2011 Posted March 3, 2011 Quickest and easiest way I've found to remove this, is to boot into safe mode, do a system restore to at least last weekend. Run malwarebytes through twice. Sorted
CHR1S Posted March 3, 2011 Posted March 3, 2011 Had 2, see http://www.edugeek.net/forums/security/71669-tdl4-rootkit.html for what the root issue was Ran Anti-rootkit utility TDSSKiller to find and remove the rootkit (tdl4) In safemode deleted the affected users local profile (backup docs, favs etc first) Removed virus and suspicious entries with hijackthis HijackThis - Trend Micro USA Ran an AV scan in safe mode. Fixed both in a reasonably quick time.
Jobos Posted March 3, 2011 Posted March 3, 2011 CA antivirus/threat manager is now detecting this as Win32/FakeAV.RGU
SpuffMonkey Posted March 3, 2011 Posted March 3, 2011 I've done a personal laptop (XP) and a standalone school laptop (W7) using system restore and then two scans with MSSE. How does this stuff actually install, can you acquire it even when running under a non-privileged account? I did notice when I got caught that the Java window opened up - I thought Java could'nt do nasties - but maybe just a coincidence
Pete10141748 Posted March 3, 2011 Posted March 3, 2011 I've almost always got a laptop on my desk from a teacher/TA that has a infection of this kind, though not seen this one exactly so far. Such a PITA but I usually just remove the entire infected profile from the laptop and build them a new one, luckily staff here are (mostly) good at saving work in their mapped drive and not on the desktop so only standard set of icons have to be put back anyway.
difinity Posted March 3, 2011 Posted March 3, 2011 I did notice when I got caught that the Java window opened up - I thought Java could'nt do nasties - but maybe just a coincidence Yes, Java is an avenue of attack, not sure if it's the case with this example, however if you have an older version installed, even with having the latest version you're still vulnerable.
FragglePete Posted March 3, 2011 Posted March 3, 2011 I've dealt with 5 machines regarding this pesky little blighter in the last two weeks, all family and friends' machines. Pete
somabc Posted March 3, 2011 Posted March 3, 2011 I did notice when I got caught that the Java window opened up - I thought Java could'nt do nasties - but maybe just a coincidence Do you have any of the malicious jar files, I would be interested to see exactly what they do?
Shuriken1 Posted March 3, 2011 Posted March 3, 2011 I'm afraid I've not read all the replies but to add my 2p: We've had a couple since half-term. We've found that installing Avast on there, letting that do a scan and then a boot-time scan would find some files but not clear it. We would then enable the wireless, let Sophos update the Endpoint thingy and do a scan with that and it picked it up - can't remember the exact name it gave. We couldn't get Sophos to work without the Avast scan beforehand (although may that was only 'cos it did a boot-time scan) as the virus/malware seemed to block it. Anyway, may be another way to fix it if anyone's still having trouble.
difinity Posted March 3, 2011 Posted March 3, 2011 If people used Firefox with Adblock then that will stop Virii and fake virii coming though compromised ads in the future.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now