Malware Alert...System Tool 2011! RESOLVED

It takes over your entire computer

Tuesday, March 1, 2011 by jazzymjr | Discussion: Personal Computing

Just wanted to alert everyone about a very nasty piece of malware out there! 

My companion was the recipient of this "nice" piece of software.  He is running Windows 7, 32 bit.  He has no idea how he got it.  Anyway, it takes over your whole computer, and you cannot even open any executable on your computer.  It tells you that your computer is infected...it even takes over your desktop.  It disables eveything.  You cannot even get into safe mode to try to run a anti-malware program to try to get rid of it.  It even blocks all your system restore backups!  What a piece of work!  I am hoping that I can get to his documents folder and copy that...I can't remember if I put that on a different partition or not...I sure hope I did!  I am going to have to wipe and re-install everything for him. 

First Previous Page 2 of 3 Next Last
DrJBHL
Reply #21 Tuesday, March 1, 2011 1:46 PM

You can browse in https mode on facebood (highly recommended).

You can also browse in virtual mode using Sandboxie (sandboxie.com) for x32 and x64, or BufferZonePro (free) for x32.

They give you a red line around your browser window and seemed to bother a couple of skins (sandboxie).

Phoon
Reply #22 Tuesday, March 1, 2011 2:40 PM

So I guess the key is to leave a disassociated file on your desktop?

This thing will infect more than just a few files. It will blow itself through the registry and many areas of your system. You got lucky!

I have avoided it before by pulling the plug on the PC... how-ev-errrrrr.... that is NOT advisable.

A few weeks ago I flipped a breaker that turned out to be the computer room. 1 system shut down and the OS was hosed upon attempted reboot.

 

natas2
Reply #23 Tuesday, March 1, 2011 3:11 PM

I have avoided it before by pulling the plug on the PC... how-ev-errrrrr.... that is NOT advisable.

Yeah.  Try the old task manager next time and kill whatever web browser you are using.  It's also a good idea to not have firefox set to reload the last page you were viewing or you might be right back at square 1.

ekimragz
Reply #24 Tuesday, March 1, 2011 3:24 PM

jazzymjr




My companion is not sure how he got it, but he had been looking at a slide show that he got in an email, just before the thing popped up.

 

Them dang slideshows are frought with peril.

Uvah
Reply #25 Tuesday, March 1, 2011 4:23 PM

I guess I'm lucky then.

 

 

*looking over shoulder warrily*

CarGuy1
Reply #26 Tuesday, March 1, 2011 5:11 PM

Be very wary of Imageshack...I've had it try to install 3 times from the http://imageshack.us/ website so far.

I'm savvy enough to keep it from installing...it would be very easy to make the mistake of letting it load, so be careful.

The best way to avoid these type of attacts is to surf via Virtual PC and discard the changes to your session when closing.

jazzilady
Reply #27 Tuesday, March 1, 2011 5:27 PM

I had the very same experiene! I finally did a restore in safe mode to get rid of it! It was really annoying and very malicious! It held me captive until I finally outsmarted it! I have no idea how it got there either, but I never want to experience that again!

CarGuy1
Reply #28 Tuesday, March 1, 2011 5:29 PM

Also, one of the best step by step guides for removing malware can be found here... http://forums.majorgeeks.com/showthread.php?t=35407

Philly0381
Reply #29 Tuesday, March 1, 2011 5:34 PM

DrJBHL
You can browse in https mode on facebood (highly recommended).

You can also browse in virtual mode using Sandboxie (sandboxie.com) for x32 and x64, or BufferZonePro (free) for x32.

They give you a red line around your browser window and seemed to bother a couple of skins (sandboxie).

Okay I downloaded Sandboxie and it is very easy to set up.  It also has a tutorial that walks you through it.  Do the tutorial if you download.  I'm using the Argon Theme and do not have any red line around the browser window, haven't tried it yet with other skins.  The price is right, free. 

happyboy7
Reply #30 Tuesday, March 1, 2011 5:38 PM

Thank you everyone for this good security reminder.  It's crucial to revisit good computer security practices regularly.  I'm the one that keeps our five family computers running in tip-top shape, and these reminders/best practices threads help tremendously.

seldomseen
Reply #31 Wednesday, March 2, 2011 11:33 AM

 

Had this. It's a pesky one. Went to other PC and searched around in some desperation. Went to someplace called My Antispyware(dot)com and their support team contacted me with the following weird note*. I set my system calendar to six days ahead, then rebooted. Then set correct time. Then rebooted. Malware apparently gone...(?). Had to use other PC as this one was terminally borked from the virus. Only got a multiple of popups that disabled almost everything, saying "pay $ to get hip" then "pay more $ to get more hip." IE8 couldn't open. Really horrible. Weird but true: try 6-day date reset. Worked for me but I've no idea why. Also, after all this was said and done, a day or so later, my TrendMicro Pro said I had a trojan that it couldn't delete yet, so the malware was quarantined 'til TrendMicro has the right stuff to nuke it.

 

* Hello Dear friend!
I am really sorry that your computer has been infected. So, these pop-ups and are not the part of our product,
they are a some kind of a virus from the internet and don't belong to our program. It was done by our advertising
partner and he's already banned.
This program will be self-removed in 6 days. There would be no problems after it is deleted.
Also you can just set date and time setting in your windows control panel 6 days later according to current date.

let me know please if you have any other problems.
 Thanks and have a great day!

Good luck to everyone who has gotten this. It's a nasty bugger, all right.

Hey, is it Spring yet anywhere? My window just shows snow and cold and more of the same...aargh.

Peace

Uvah
Reply #32 Wednesday, March 2, 2011 12:37 PM

We're getting a taste of spring here in Pa. Sunshine, temps in the mid 50's, blue skies ... then the sun goes down and it gets cold again. Its on its way. Thank goodness. I've had enough of the cold, snow, ice and stuff.

Dr Guy
Reply #33 Wednesday, March 2, 2011 1:36 PM

seldomseen
Good luck to everyone who has gotten this. It's a nasty bugger, all right.

Hey, is it Spring yet anywhere? My window just shows snow and cold and more of the same...aargh.

Peace

Fascinating!  A self terminating one!  Defintiely worth remembering as that is easy enough to do!  So far these bugs have been defeatable as each one forgets something that allows us to get it.  I guess it is only a matter of time before someone figures out all the angles and closes them all.

Thanks for the tip!

Spring?  Today, Gone tomorrow! (64 today, 45 tomorrow).

G3mpi3
Reply #34 Wednesday, March 2, 2011 1:42 PM

Oh yeah, I had this virus. I downloaded it just so I could fight it off. It was a fun one, but still easy to get rid of in about 5 minutes.

Uvah
Reply #35 Wednesday, March 2, 2011 1:47 PM

Hey G3mpi3 ... let me ask you somethin' ... hehe. If the next one you download just so you can fight it off turns out to be bigger'n your PC what will you do if it says it 'll get rid of you in five minutes? j/k

G3mpi3
Reply #36 Wednesday, March 2, 2011 2:34 PM

Hey G3mpi3 ... let me ask you somethin' ... hehe. If the next one you download just so you can fight it off turns out to be bigger'n your PC what will you do if it says it 'll get rid of you in five minutes? j/k

Meh, I would welcome that. I've turned rebuilding my PC into a hobby. Also, I'm dual booting win7 and Maverick Meerkat, so I'm not worried about that.

Uvah
Reply #37 Wednesday, March 2, 2011 2:37 PM

Wow!

ElanaAhova
Reply #38 Wednesday, March 2, 2011 8:49 PM

happy you get un-infected....

Uvah
Reply #39 Thursday, March 3, 2011 5:45 AM

Now that I think about it there was this advert about 3 maybe 4 months ago asking if I wanted to download and install a new system tool by that name. I chose to ignore it as I have more than enough toys to play with. It came as an email and I regularly delete everything in the spam folder without bothering to check any out.

natas2
Reply #40 Thursday, March 3, 2011 7:06 AM

This is in reply to #31.  That seems fishy.  I'd still want to run some type of Anti-Malware on it.  Very odd that some tool would write up a virus/trojan that will self expire.

 

The important thing to remember is that if you get a pop-up like that, don't click anywhere on your screen.  Ctl+Alt+Delete and bring up task-manager, which will then be the "focus" window.  Kill your browser.  Or do a hard shutdown.  Always try task manager first though.

Please login to comment and/or vote for this skin.

Welcome Guest! Please take the time to register with us.
There are many great features available to you once you register, including:

  • Richer content, access to many features that are disabled for guests like commenting on the forums and downloading skins.
  • Access to a great community, with a massive database of many, many areas of interest.
  • Access to contests & subscription offers like exclusive emails.
  • It's simple, and FREE!



web-wc01