Go Back   Hardware Canucks > SOFTWARE > General
Register Sweepstakes VB Image Host Members List LAN Calendar Search Today's Posts Mark Forums Read

       
Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old August 15, 2008, 10:59 AM
CMetaphor's Avatar
Allstar
Level up: 68% Level up: 68% Level up: 68%
Level: 16 - 234 points to level up
 

Join Date: May 2007
Location: Montreal, Canada
Posts: 890
Default Virus Alert: eCard greetings.

Be on the lookout for an email that seems to be a legitmate eCard greeting. Its a trojan downloader and has affected many systems here where I work. Extremely difficult to remove... been working on them since lunchtime yesterday without success. i'm using CCleaner, Spybot 1.6, Hijackthis, TrendMicro all from safemode - still barely returns full windows functionality. Just letting you all know, be on the lookout.
__________________
Current System: "Gale Force" (09-28-2008)
AMD X2 6000+ w/ TRUE (2x Scythe 120mm) | Asus Crosshair MB | 4Gb OCZ Plat.Rev.2 PC-6400 RAM w/ Corsair Memory Cooler | VisionTek 4870X2 2gig| Coolermaster CM Stacker 832 w/ 7x 120mm Fans (2x Tricool, 5x CM), 1x 80mm CM, and 1x Antec "Big Boy" 200mm Tricool Fan | Silverstone Strider 1Kw PSU | Seagate Barracuda 7200.11 500gig x 4 (Raid 1 & Raid 0)| 3x BenQ FP222w 22' Wide 5ms LCD Monitor & Matrox Triplhead2Go DE

Next system? Who knows...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark to Slashdot!Stumble this Post!Reddit! Bookmark to Newsvine!
Reply With Quote
  #2 (permalink)  
Old August 15, 2008, 11:24 AM
3.0charlie's Avatar
Hall Of Fame
Level up: 20% Level up: 20% Level up: 20%
Level: 23 - 1,199 points to level up
 

Join Date: May 2007
Location: Laval, QC
Posts: 3,640
Default

Same thing for a bogus UPS email that has an attachment showing a tracking number - also same thing from a US Customs email. Both are caught by AVG Email scanner.
__________________
Main: GA-X58-Extreme - i7 920 - TX750W - Raptor - 3Gb DDR3-1333 Triple-Channel - GTX260 SLI'ed - TRUE - P182
HTPC: M3A78-EM - 5000+ X2 - HX520W - 'cuda 1Tb - XP2-5300 2x512Mb - 9800GT - SI-128 - Prelude - Moneual 932B
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark to Slashdot!Stumble this Post!Reddit! Bookmark to Newsvine!
Reply With Quote
  #3 (permalink)  
Old August 15, 2008, 03:57 PM
Nodscene's Avatar
Top Prospect
Level up: 5% Level up: 5% Level up: 5%
Level: 11 - 320 points to level up
 

Join Date: Dec 2007
Location: Toronto
Posts: 154
Default

Yeah, I've been dealing with this quite frequently myself. I usually see it as the xp2008 or 2009 virus that I'm sure everyone has seen or heard about. Of course it always has a bunch more crap with it.

So far the best way I've found to remove it is to start the task manager and stop all the offending services, download and run SuperAntiSpyware, while that's going start HijackThis and clean that out. Turn off System Restore and let SAS finish it's thing. I download combofix (I actually download all programs first) to the desktop and when SAS ask's to reboot I let it. Once it's booted into windows I reboot again into safe mode and run Combofix. After that is done I reboot again and run CCleaner to clean out the temp files. Either the virus or the cleaning process usually kills Symantec Antivirus (all our clients run it) so I have to uninstall that and reinstall it. Combofix turns on System Restore after it's done which is a bonus so I don't have to remember :)

I can usually get a machine cleaned out in anywhere from a half hour to an hour max. I even had one case where the virus was blue screening the computer and managed to clean it out no problems.
__________________
_____________________________________

Create something idiot proof and they will make a better idiot.

_____________________________________

Intel Q6600 - Gigabyte EP35-DS4 - OCZ Reaper 4gig PC2-6400 - XFX 8800GT 512Mb Alpha Dog - AuzenTech X-Fi Prelude - Alesis M1Active MK2 - Corsair HX-620 - Silverstone Temjin TJ05B-X - Scythe Katana 2 - WD Raptor 150Gb - Seagate 7200.11 750Gb x2 - Samsung SH-S203N
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark to Slashdot!Stumble this Post!Reddit! Bookmark to Newsvine!
Reply With Quote
  #4 (permalink)  
Old August 15, 2008, 07:31 PM
Allstar
Level up: 50% Level up: 50% Level up: 50%
Level: 12 - 206 points to level up
 

Join Date: Jul 2008
Location: Canada
Posts: 558
Default

Quote:
Originally Posted by CMetaphor View Post
Be on the lookout for an email that seems to be a legitmate eCard greeting. Its a trojan downloader and has affected many systems here where I work. Extremely difficult to remove... been working on them since lunchtime yesterday without success. i'm using CCleaner, Spybot 1.6, Hijackthis, TrendMicro all from safemode - still barely returns full windows functionality. Just letting you all know, be on the lookout.
Dpybot S&D while it is free, it misses quite a lot - FOr spyware removal I consider SpySweeper and Spyware Doctor (PCtools) to be very good, from tests I've done on a system, found them to be top in their class. For virus/trojans, I use AVIRA Security Suite, also found it removes some of the tougher shit that others miss - I've had some very nasty aviax or something like that trojan and spybot shit, that neither AdAware 2008 nor Spybot S&D could remove, but was easily removed with Spyware Doctor and AVIRA.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark to Slashdot!Stumble this Post!Reddit! Bookmark to Newsvine!
Reply With Quote
  #5 (permalink)  
Old August 15, 2008, 07:44 PM
CTA's Avatar
CTA CTA is offline
MVP
Level up: 35% Level up: 35% Level up: 35%
Level: 13 - 318 points to level up
 

Join Date: Jul 2008
Location: langley (vancouver) bc canada
Posts: 493
Default

that sucks... i prefer gmail because you can preview a few of sentence... and that anti-spam is very powerful...

get sys process explorer for advance and easy to read.
get privacy mantra to clean ALL junks in your computer in one click
get spyblaster for block known spywares only...
get sypware doctor for spyware
get counterspy for keyblock

get norton for anti-virus... of course i am not joking... and i have no final result of comodo... i hope its very good.. avg or nodo32 is good but not as norton's features...

about firewall... not yet... still working on it.
__________________
---
old: no brand silver case, 3g365p-ve, p4 2.6GHz HT, ga-8sq800 ultra, 1024 gb of generic ram (:oops:), MSI ti4200 8x 128mb, 520gb of HDD ( two maxtor and one seagate) and other

NEW: cm 690, hx620, intel q9450, True Black, p5q deluxe, 2gbx2 ram of mushkin xp pc2 8500, evga 9800gx2. wd caviar se 16 640gb, 4x zm-f3 fans.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark to Slashdot!Stumble this Post!Reddit! Bookmark to Newsvine!
Reply With Quote
Reply
Forum Jump
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes