• The move to the new server is done. There are some software and database maintenance updates in process. This has us passing the hat around to help out. We appreciate any donations. Seriously, even a dollar helps. The payment page may be found here - https://www.audiokarma.org/support.html

Virus attack after log in

It got me today at work while checking AK. Pop ups advising Windows XP virus 2012 alert, back door trojan alert, hacking alert, and another I cant remember. Before the pop ups started the broser shut down IE and then they started showing up. Couldnt tell you what protection we have but its on a police department server and you would think that would have a high level of protection. Must be a very insidious little bug to get thru that. I tried malwarebytes in the safe networking mode but it would not let me open anything without the boxes popping up. The IT people are working on it and I will post what they find out. Have had no probems on home computer running MSE.
 
if i run windows i refuse to run i.e better to run chrome or firefox .. in my view they are more secure and easier to operate .. i know for sure no script works on firefox i used to use it

Oh don't let Firefox give you a false sense of security. I found rootkit bits geared for Firefox while deleting the malicious pieces throughout the registry, user folders, and master boot record. I'm almost sure I got all the bad-eys from the machine, but I was unable to repair the damage that was done to bring my machine back to original. Since I was unable to get my bios to recognize my sata cd-drive I was forced to drop the machine off (as much as it kills me) at a local shop for a complete wipe and reload of a newer OS.
 
It got me today at work while checking AK. Pop ups advising Windows XP virus 2012 alert, back door trojan alert, hacking alert, and another I cant remember. Before the pop ups started the broser shut down IE and then they started showing up. Couldnt tell you what protection we have but its on a police department server and you would think that would have a high level of protection. Must be a very insidious little bug to get thru that. I tried malwarebytes in the safe networking mode but it would not let me open anything without the boxes popping up. The IT people are working on it and I will post what they find out. Have had no probems on home computer running MSE.

Did you send them to the cleanup protocol at bleepingcomputer.com that was posted earlier in this thread? Might save them some time.
 
Well, I'm Baaaaaack. I too was attacked by the Security Center. It was pure misery. I had found the bleepingcomputer listing on my own searches and was able to use it to stop the virus from blocking programs. However, 3 times in a row I got a blue screen of death before the virus scans could be completed on Malwarebytes and Avast. When I finally thought I was clear for one final reboot, I get back to Windows and my trackpoint/mouse won't work. I go to safe mode; it does not work. I go to last known good configuration and got my mouse back. I ran both scans again and they found nothing so I setup a boot scan for Avast, just in case. It did not run and after that, no matter what I did, I could not get my laptop mouse, or any other mouse to work. I had to reload Windows.

At this point I am reloaded, and updated on Windows, Avast, Malwarebytes and anything else I could find. This virus finds its way into our computers through Flash Player and Java,neither of which were fully updated on my computer, nor was Windows. I am kicking myself in the ass for this. Complacency will get you screwed.

When this hit I had one browser window on AK and the other was about to do a speed test at speedtest.net. It struck the second that I clicked on "Test Now" on Speedtest. I blame no one for this, but myself.
 
virus

I got bot alert resently and I've mainy visited Ak and Ebay. I upgraded antvirus and scnned and cleaned everything. computer is still running slow.
 
I ran every commercial antivirus program on my PCs and none of them effectively blocked dangerous keyloggers and other viruses. The only one that was more effective was Kaspersky. I finally switched to Macbooks after getting completely fed up. I only run the Mac OS. I went in the Mac direction after Google was hacked, supposedly by Chinese sources. Google replaced all their PCs with Macs. My son still uses a PC because he's a gamer and all the hard core games are written for Windows. Surprisingly, the antivirus that worked best for me was Spybot Search and Destroy, a free program that does, however, ask for donations.
 
ComboFix is great for removing Security Center.. and finding and removing some of the very worst root kits..

It's found and fixed things I've seen no other find, or be able to remove..

BUT... you still have to wonder what could be lurking.... :para:
 
Got attacked again today, Norton blocked it. Looks like the main ad on the page was for Citi Platinum Mastercard. Another Website 9 Malicious Toolkit attack.
 
Actually, no. First of all the ads rotate and target certain people based on their cookies, and I'm sure it's a small percentage of the ads that are malicious. The browser and version of flash or java you're using can be determined by the script and it may not run if it doesn't detect a platform it can't compromise.

this is my downtime, I'm here 2-4 times a day, around 7 am, 6pm and 8-9pm every day, sometimes more. I'm running windows 7 with AVG and using firefox. Never a problem.

Just because you have a problem when your at a website doesn't mean that website is the problem. I run a local music website, my code is 100% html that I type in myself and a few years ago I had several people accusing me of giving them a virus. Turns out the virus was coming from a site they built using "stolen/free code" Yet even today there are people who tell me they won't visit my website because they heard I had viruses.
 
I still cant believe people are saying its not from something on this site. I am positive the 100 or so people complaining here might, maybe, just might, say something.

I have to stop now before I go overboard. I wish the best of luck to the admins working on this.
 
I'm not getting anything, knock on wood! Everyday I been monitoring and scanning but haven't found anything yet.
No problems with anything on my computer either. Other then the threads about this would not be thinking anything was up.
But still checking daily....


Barney
 
update about work computer...

IT folks had a time getting it back running. What he told me was that it was a rootkit virus that did come from something that attached itself to the computer while browsing AK in the form of a java script. He could not pinpoint exactly where and when it happened and the log that he shared with me is something that I cannot share because of PD security issues, but on one of the lines in the log there was a line that said..(if this will help the mods)....rootkit/stealth trojan gmer.net and the rest of it was above my paygrade brain to dechipher or understand. They used combofix to get rid of it and had to run it twice to completely clean the pc.
 
Thanks bighairydude, that's precisely the sort of thing that helps the computer folks ferret out the source of the problem.
 
I got it again yesterday

Even with a fresh download of MSSE....that's about 4 hours of my life wasted so far cleaning this crap out of my computer.....:thumbsdn:
 
Folks when cleaning your machines make sure to run your cleaning software 2 or 3 times and it is usually a good idea to use 2 different pieces of software to make sure you get it all.

If you have been infected, It usually helps to disconnect your machine from your internet connection so the virus can't phone home while you are cleaning.

I just cleaned one from another members machine and Malwarebytes called it Hijack.exe.

It stopped the machine from running any programs. :nono:

BTW this took about 36 hours to fully disinfect and update. So if you want to keep your computer the way it was, it will take quite a long time to do it 100%.
 
update about work computer...

IT folks had a time getting it back running. What he told me was that it was a rootkit virus that did come from something that attached itself to the computer while browsing AK in the form of a java script. He could not pinpoint exactly where and when it happened and the log that he shared with me is something that I cannot share because of PD security issues, but on one of the lines in the log there was a line that said..(if this will help the mods)....rootkit/stealth trojan gmer.net and the rest of it was above my paygrade brain to dechipher or understand. They used combofix to get rid of it and had to run it twice to completely clean the pc.

Aha, that explains why it keeps re-occuring.

The mybleeping computer page has a part that describes using TDSSkiller to remove this rootkit trojan. I downloaded and ran that and even after Malwarebytes was done, this trojan remained (TDSSkiller found and removed it). I'd advise if this keeps re-occuring to try that.
 
Yeah, there's a fair bit of that going around. There is a good cleaning process for this malware on the bleepingcomputer website, if you need it.

Also, there are at least two threads about it with quite a few posts in them, FYI.
 
Make sure that your Windows is up to date along with Java and Flash Player and your virus scanner. The bleepingcomputer fix sort of worked for me, but I still wound up reloading Windows. Get Malwarebytes and keep it up to date also.
 
OK, I've been meaning to post this, so here goes.

Use Google's DNS server. Go to the internet protocol properties and use the following DNS server: 8.8.8.8

Use the following alternate: 8.8.4.4

This is a supplement to other security measures. Google browses the entire internet on a regular basis, and they are in a good position to discover sites that distribute malware. If you attempt to load a site known to be evil, the DNS server will block it.

I have to say that I've been using this DNS for some time, and I have none of the problems being reported here.
 
Back
Top Bottom