Jump to content

Recommended Posts

Posted

This happened to me on Sunday. The machine I was working at (and not viewing any particularly objectionable websites, I hasten to add!) suddenly opened Adobe Reader (an old version) and then started showing the warning. Immediately disconnected from the Internet . . . . .

 

As Localzuk says it just hit my profile (Win7, running as standard user), and I fixed it by logging in as a different user and running a bunch of different AV applications.

Posted

Had this come up twice. Malwarebytes on it's own didn't do much, however running it as well as having MSSE alongside it did the trick.

One machine had already downloaded something nastier too, which needed a lot of manual work to get rid. The biggest culprits are a randomly named folder containing 2 files in teh Appdata folder for all users and/or current user depending on security of the machine, as well as a bitmap file in the root of C. Safe mode, manual remove, job done > grab note of the filenames, search registry and remove references therein.

Posted
Seen this on about 5 computers so far. A couple at school and a few on peoples home computers. Had it on both XP and Vista. Used MalwareBytes to remove it in safe mode.
Posted

On the teacher's personal machine I did on Monday, I only had to remove the entry under RunOnce using Autoruns and was then able to boot up and remove the remnants with Microsoft Security Essentials. Didn't stop the damned thing getting on there in the first place though.

 

VIPRE Protect, on the other hand, has been nailing it with the on-access scanner every time. Zero affected school workstations so far as a result.

Posted (edited)

got rid of this on a few of these too, logged in as local admin and deleted the folder from the users application data\RandomCharacterFolder\RandomCharacter.exe (with icon)

 

I didnt think to look for it on the registry, hopefully it will leave no damage if I only removed the program itself.

 

Disabled the running icons in system tray too, either turned off or hid Sophos EP..

 

So, whats the best program to run from a domain \ group policy to put on clients, cause its clearly gonna get worse..

Edited by Mullaney18
Posted

Came across a variant of it last night that had crippled all the file associations. Kaspersky and MalwareBytes cleaned it off but I was left to tidy up afterwards :(

 

If I could get hold of these people and force them to eat their own brains I would.

Posted

I've done a personal laptop (XP) and a standalone school laptop (W7) using system restore and then two scans with MSSE.

How does this stuff actually install, can you acquire it even when running under a non-privileged account?

Posted

Got our first machine infected. Just ran the free Kaspersky virus removal tool, founded loads.

 

Not going to bother with Safe Mode & Malaware Bytes, just going to image it!

 

McAfee didn't seem to find anything though, which is worrying.

Posted (edited)

Had this on about 8 staff laptops this week!! Sophos up to date and didn't notice a bloody thing! This is how I removed it:

 

1) Boot into safe mode

2) Browse to c:\documents and settings\all users\application data

3) Search for a randomly named folder (letters and numbers). Open it and note the name of the executable. There may be 2 files in here.

4) Open regedit

5) Browse to HKCU\software\microsoft\windows\currentversion\runonce and delete any reference to the above file.

6) Browse to HKCU\software\microsoft\windows\ShellNoRoam\MUIcache and again delete any references.

7) Still in regedit, select the HKLM folder and go to File  Load Hive and browse to c:\documents and settings\staff\NTuser.dat Give the key a relevant name.

8) Within this mounted folder, search the same registry keys as above and delete any references to the file

9) Click on the name of the mounted folder as entered above and go to File  Unload Hive

10) Load any other NTuser.dat hives for all accounts that have been logged on since the infection i.e. any domain accounts

11) Repeat searching the registry keys and hives until finished.

12) Make sure all hives are unloaded.

13) Delete the randomly titled folder from c:\documents and settings\all users\application data

14) Reboot the machine and log in as local administrator

15) Allow Sophos to update if not already updated

16) Run a full sweep on the C: drive with settings to automatically remove infections.

17) It is likely to find a FakeAV-??? File in the c:\windows\temp folder. The scan should remove this.

18) For safety, delete temporary internet files, system restore files and anything in the c:\windows\csc folder.

19) Log in as the laptop owner and watch for signs of infection

 

 

What a swine!

Edited by themightymrp
  • Thanks 1
Posted
Haven't seen this in school yet but will deffo keep an eye out for it. NOD32 has been blocking alot of web based nasties recently though.
Posted

I had this at home 3 weeks ago, bugger of a thing to remove. Helpful but contradictory fixes online helped sort it. Pain in the bottom!

 

Rebuilding this weekend.

Posted
Quickest and easiest way I've found to remove this, is to boot into safe mode, do a system restore to at least last weekend. Run malwarebytes through twice. Sorted :)
Posted
I've done a personal laptop (XP) and a standalone school laptop (W7) using system restore and then two scans with MSSE.

How does this stuff actually install, can you acquire it even when running under a non-privileged account?

 

I did notice when I got caught that the Java window opened up - I thought Java could'nt do nasties - but maybe just a coincidence

Posted
I've almost always got a laptop on my desk from a teacher/TA that has a infection of this kind, though not seen this one exactly so far. Such a PITA but I usually just remove the entire infected profile from the laptop and build them a new one, luckily staff here are (mostly) good at saving work in their mapped drive and not on the desktop so only standard set of icons have to be put back anyway.
Posted
I did notice when I got caught that the Java window opened up - I thought Java could'nt do nasties - but maybe just a coincidence

 

Yes, Java is an avenue of attack, not sure if it's the case with this example, however if you have an older version installed, even with having the latest version you're still vulnerable.

Posted
I did notice when I got caught that the Java window opened up - I thought Java could'nt do nasties - but maybe just a coincidence

 

Do you have any of the malicious jar files, I would be interested to see exactly what they do?

Posted

I'm afraid I've not read all the replies but to add my 2p:

 

We've had a couple since half-term. We've found that installing Avast on there, letting that do a scan and then a boot-time scan would find some files but not clear it. We would then enable the wireless, let Sophos update the Endpoint thingy and do a scan with that and it picked it up - can't remember the exact name it gave. We couldn't get Sophos to work without the Avast scan beforehand (although may that was only 'cos it did a boot-time scan) as the virus/malware seemed to block it.

 

Anyway, may be another way to fix it if anyone's still having trouble. :)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...