A Possible Virus

Moderator: admin

mckenziedt
Gold Member
Posts: 46
Joined: Sat Nov 18, 2006 1:36 am
Location: Manitoba Canada

Post by mckenziedt »

This is copy of my post on another thread, but is just as relevent to this one.

These and a lot more scams are out there trying to separate people from their cash, credit cards, PayPal, bank account, identity, etc, etc. I probably get a couple a month or more depending on the time of year. Even though one doesn't use the internet much, as little as one usage can get you on a scamer's list. This is because many organizations sell their lists of contacts. Even though they sell to legitimate sources, after a few resales the list may find it's way to some less than honorable organization.
Besides learning that there are billions of $ tied up in hidden African accounts that need us to help smuggle them out or that we have a financial account we never remember opening, but is now in danger of being suspended if we don't immediately provide our ID facts to get it reinstated, there is a way to sniff out the phonies.
Look at the sender line in the email. Many times the name is slightly mis-spelled; ebey instead of ebay, Paypol instead of Paypal, Kigiigi instead of Kigigi, Citibank.uk instead of Citibank.com, and on and on. But some crooks are more sophisticated and can have the sending address line show as the real one, but any links are to their own site or are indirectly directed to their own site. So look to see if the link address seems to be the same organization as the purported sender.
Then also check out the email by clicking on the little solid triangle far to the right in the email header section. This expands the email header info. There the true sender and the direct reply to addresses is revealed. So the purported sender might be paypal.com, but the reply to address shows as like we-are-crooks@hotmail.com or whatever. Reporting the fraud site addresses may eventually get them listed on internet security software updates from Norton, McAffee, etc., after a number of complaints are registered. But the crooks will just open a new Hotmail, Yahoo, etc. account and carry on. By using common or offshore providers and frequently changing accounts and providers,they remain virtually untraceable. So the best defence is our own intuition and caution. If it's too good to be true, it probably isn't good. And if it looks suspicious and smells suspicious, it probably is suspicious
By the way there is a nasty virus going around, at least in my neck of the woods now, that pops a sceen up that says the computer is infected with a large number of well known viruses and Trojan horses. The name of this virus scanner program is different from the resident virus scanner installed on the computer, so you can see it is not your own scanning program reporting something. This name changes from one infection to another and it disables your own virus scanner and a lot of other things. It then offers to sell you the full version online so you can clean out your computer, and asks for you credit card info. I don't know if this is to blackmail you to legitimately buy the software or they just really want to get access to your credit card to clean it out. It keeps the computer virtually locked up and useless while waiting for the card info. It requires some fancy work arounds to get it out and even then it leaves a lot of corrupted operating system files, resulting in probably having to re-install Windows. How do I know this? Well I'm sending this with my laptop with my newly installed Windows Vista.

This attack disabled my search functions, task manager, AVG & Defender anti virus, My Computer, Control Panel, right click menu, and more by automatically invoking the upper right X ,delete window, box approx 1/3 second after I would open any of these functions. I have dual O/S boot, so I rebooted into my other operating system that is on hard drive D and searched and deleted on hard drive C from there. The actual virus file was an alpha/numeric gibberage name in :Users/Don(my user name)/AppData/Local . I got it's name by checking the Startup info and did a search to find its location.
D.McKenzie
520,510,mini 500,10ER,10E,Band Saws,Jointers,Scroll Saw,Jig Saws,Belt Sanders,Strip Sander,Speed Reducer & Increaser,Pro-Planer,Mortiser,Grinding wheel,Sharpening guides,Lathe Duplicater,Biscuit Joiner,Tendon Jig,Ring Master,Oneway Chuck, Most Arbors,Bits,Blades,Chucks,Cutters,Fences,Safety Items,Sanding & Sawing Items,Shop Accessories,Spare Parts
User avatar
etc92guy
Gold Member
Posts: 263
Joined: Mon Aug 25, 2008 10:15 pm
Location: Hartland, WI

Post by etc92guy »

No thanks necessary, Dusty. Glad I could help out.:)
Craig
Hartland, WI
-Mark 5 "Greenie" S/N 342238, Manuf. mmm/mmm 1957, Acq. Oct. 2008, Joiner S/N M067266
-10 E/ER(?) S/N Unknown, Joiner 4E S/N 40051
User avatar
dlbristol
Platinum Member
Posts: 874
Joined: Tue Oct 24, 2006 4:57 pm
Location: Collbran, Colorado

Post by dlbristol »

dusty wrote:I hope that you are correct, Michael. I would not wish this ordeal on anyone. :) Not even an Mac/OSX user.:)
Thanks Dusty! I sort of think that the same "contrary spirt" that led me to and keeps me with Mac, led me to SS. I kinda like being contrary.;) But as stated, I don't think OSX is really less vulnerable, it just operates on fewer machines and thus offers a much less lucrative target.

Did you ever wonder how if someone was willing to work hard enough to learn all that is needed to do these attacks, why aren't they willing to do that much work in an honest job?
Saw dust heals many wounds. RLTW
Dave
User avatar
dusty
Platinum Member
Posts: 21530
Joined: Wed Nov 22, 2006 6:52 am
Location: Tucson (Wildcat Country), Arizona

Post by dusty »

[quote="dlbristol"]Thanks Dusty! I sort of think that the same "contrary spirt" that led me to and keeps me with Mac, led me to SS. I kinda like being contrary.]I thought I had this puppy cleared of its virus but this morning I got a security alert from Microsoft telling me that my computer reported signs of having been infected.

I reloaded Silverlight.exe per Microsoft instructions and then reran Microsoft Security Essentials. Big as life, there it was; the same trojan that I thought I had cleared by hand.

I feel safer though now with Microsoft Security Essentials alway running in the background. This is almost as good as running on OSX.:):D:rolleyes:
"Making Sawdust Safely"
Dusty
Sent from my Dell XPS using Firefox.
User avatar
Ed in Tampa
Platinum Member
Posts: 5834
Joined: Fri Jul 21, 2006 12:45 am
Location: North Tampa Bay area Florida

Post by Ed in Tampa »

hadn't heard of silverlight or security essentials but after reading about them here and then doing some searches I think I know what they are.

Before I get this totally off track has any one had any experience with silverlight?

As for the Security Essentials from what I'm reading on the net it that it is probably the antivirus, antispam, anti malware program you want to have. There is a youtube demo of it where the author has known infected web addresses and in each case the Security Essentials caught them and neutralized the malware before they could infect the protected computer.

Interestingly not only does it seek out hacked or infected code but it also has a list of known sites where infections have been caught. Seems to me this is a the way to go about it.

I'm seriously considering dumping my CA security software and swinging completely over to Security Essentials.

I would like to hear feedback on Silverlight
Ed in Tampa
Stay out of trouble!
User avatar
beeg
Platinum Member
Posts: 4790
Joined: Sun Oct 14, 2007 2:33 pm
Location: St. Louis,Mo.

Post by beeg »

Don't think ya need silverlight Ed, unless your into web page development.
SS 500(09/1980), DC3300, jointer, bandsaw, belt sander, Strip Sander, drum sanders,molder, dado, biscuit joiner, universal lathe tool rest, Oneway talon chuck, router bits & chucks and a De Walt 735 planer,a #5,#6, block planes. ALL in a 100 square foot shop.
.
.

Bob
User avatar
beeg
Platinum Member
Posts: 4790
Joined: Sun Oct 14, 2007 2:33 pm
Location: St. Louis,Mo.

Post by beeg »

Don't think ya need silverlight Ed, unless your into web page development.
SS 500(09/1980), DC3300, jointer, bandsaw, belt sander, Strip Sander, drum sanders,molder, dado, biscuit joiner, universal lathe tool rest, Oneway talon chuck, router bits & chucks and a De Walt 735 planer,a #5,#6, block planes. ALL in a 100 square foot shop.
.
.

Bob
User avatar
dusty
Platinum Member
Posts: 21530
Joined: Wed Nov 22, 2006 6:52 am
Location: Tucson (Wildcat Country), Arizona

Post by dusty »

I chose to down load and install Microsoft Security Essentials for reasons that I believe are obvious.

I down loaded and installed Silverlight because when I was attempting to install MSE I received an error message that stated I had the wrong version of Silverlight on my computer. I don't know when Silverlight came on board; I assume it was installed as part of either my Windows XP or Mozilla Firefox.

I don't do web page development and I don't know what else Silverlight does or might do that I would use. I search the web, participate in a number of forums and send a bundle a sizable batch of emails and that is about it.

Microsoft Office, Adobe Reader, Google Earth, Google Sketchup, a photo handler (Olympus Master) and HP Image Zone (for my 4in1 HP Printer/Scanner/Fax/Copier is about all that I have on my computer.

Now I have Microsoft Security Essentials.

Ed in Tampa - if you are not having trouble with your computer I would not advise that you do anything to upset what you already have going.
"Making Sawdust Safely"
Dusty
Sent from my Dell XPS using Firefox.
User avatar
heathicus
Platinum Member
Posts: 2648
Joined: Wed Oct 22, 2008 1:02 am
Location: WhoDat Nation

Post by heathicus »

Silverlight is basically Microsoft's version of Adobe Flash.
Heath
Central Louisiana
-10ER - SN 13927, Born 1949, Acquired October 2008, Restored November, 2008
-10ER - SN 35630, Born 1950, Acquired April 2009, Restored May 2009, A34 Jigsaw
-Mark V - SN 212052, Born 1986, Acquired Sept 2009, Restored March 2010, Bandsaw
-10ER - SN 39722, Born 1950, Acquired March 2011, awaiting restoration
Post Reply