PDA

View Full Version : Warning backup site is infected with a virus!!



lostforawhile
01-23-2010, 01:13 AM
I hope it's not a phishing site, is 3geezbackup.com the real site? if it's not they stole the page from the backup site and posted it up. I got hit with a bunch of trojans when I tried to log on, i was trying to log on because a small orange apparently crashed. took several tries to get it all, it will also intall a rogue antivirus , in your program list. here's my log file from malware bytes anti malware . It will also change your proxy settings to prevent you from reaching the net, and anthing you try to hit such as your anti virus will be blocked, also you can't shut the program down through any normal means
I'm sending this to our director so he knows, i just got back on the net


Malwarebytes' Anti-Malware 1.44
Database version: 3568
Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512

1/23/2010 03:38:10 AM
mbam-log-2010-01-23 (03-38-10).txt

Scan type: Full Scan (A:\|)
Objects scanned: 110098
Time elapsed: 6 minute(s), 33 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
C:\Documents and Settings\Tim\Local Settings\Application Data\kswjxl\lfeosysguard.exe (Trojan.FakeAlert) -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\AvScan (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run\sudtbrhe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\sudtbrhe (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\Tim\Local Settings\Application Data\kswjxl\lfeosysguard.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.

lostforawhile
01-23-2010, 02:24 AM
whatever the hell this was my computer is screwed i can't upload any pictures all my proxy settings are screwed now i have no idea how to fix this bullshit

lostforawhile
01-23-2010, 03:07 AM
Ok I used one zigawattz of power and a flux capacitor and went back to thursday and am back up, i don't know what they put up on the site but it screwed my computer big time

A18A
01-23-2010, 03:51 AM
wat

lostforawhile
01-23-2010, 04:06 AM
wat
I went to the back up site because a small orange was apparently down, tried to log in and got whacked big time. I wonder if those idiots who hacked it before have hacked into it again? it showed up like a fake alert but it did some serious damage, i was finally able to get everything back with a system restore from a couple of days ago. it looks like a fake alert only but normally those don't screw up your computer this badly.

87accordlxi
01-23-2010, 07:26 AM
I just took the site down. We haven't needed it in months. I'll throw something up there if necessary again.

lostforawhile
01-23-2010, 10:16 AM
I just took the site down. We haven't needed it in months. I'll throw something up there if necessary again.i'm just glad no one else got hit, i wonder if they hacked the site then were just waiting for the site to go down and everyone else to try to log in?

2ndGenGuy
01-23-2010, 10:46 AM
You should really quit using Internet Explorer.

lostforawhile
01-23-2010, 10:55 AM
You should really quit using Internet Explorer.

I was in opera not IE, it did take out my IE too though

charliekuney
01-23-2010, 01:33 PM
You shouldn't be using IE, Firefox, Opera, or Safari. You should be using Chrome.

Rendon LX-i
01-23-2010, 04:51 PM
LOL ive been EI for years. i am right now. i think im going to change LOL. i got the trojan but my anti virus progam caught it and took it out. damn Trojan

AccordB20A
01-23-2010, 06:33 PM
its not the browser its how you use it, thats why i dont let people use my computer because they are dumb and click yes to shit that says "this is required to load a page" and i know its shit so i dont click yes.

lostforawhile
01-23-2010, 07:56 PM
its not the browser its how you use it, thats why i dont let people use my computer because they are dumb and click yes to shit that says "this is required to load a page" and i know its shit so i dont click yes.
it didn't give me the option, the backup site came up, and i went to log in as usual, and then it hit me. I think I would have known if a strange message came up. it didn't hit until you logged in then your computer is already full of fake warnings and god knows what else.

Hazwan
01-23-2010, 08:11 PM
its not the browser its how you use it, thats why i dont let people use my computer because they are dumb and click yes to shit that says "this is required to load a page" and i know its shit so i dont click yes.

Word. I've been using IE for years and never had any single ZOMGVIRUS from it. I know people with different browsers get more virusses/junks than me.

Using Firefox now anyway/

lostforawhile
01-23-2010, 08:29 PM
the backup site was taken down quick, good response on that, the only people I know of who would do this, would be one of those trolls that got banned, or those idiot middle eastern guys who hijacked it before. probably someone who knew the main site crashed a lot and set a trap for members heading to the backup site. Probably some jackoff looser

turabaka
01-23-2010, 11:39 PM
If you don't want viruses then just use Linux. I love not having to worry about antivirus software.

A18A
01-24-2010, 09:04 AM
ive had tiny xp for ages with no anti-virus shit, and aside from hardware failure, it ran real mint compared to everyone elses computers i use (Y)

Dr_Snooz
01-24-2010, 08:40 PM
You shouldn't be using IE, Firefox, Opera, or Safari. You should be using Chrome.

You mean Google Keylogger? Puhleeze.


whatever the hell this was my computer is screwed i can't upload any pictures all my proxy settings are screwed now i have no idea how to fix this bullshit

Use Hijack This (http://free.antivirus.com/hijackthis/).

Pirate Bay nearly sent a scorcher up my backside a few weeks ago. I started a download when my system tray popped up a notice that I had been infected with a virus. At the same time, I kept getting pop up notices "Your computer is infected, do you want to start your virus scanner?" Then my virus protection popped up and started scanning. I thought "oh good, Norton will get it." Then I thought, "wait, this isn't Norton..." I killed everything and re-booted, but it stayed with me and knocked out my DNS settings. I reversed all the settings using Hijack This and then did a few hard drive searches to get all the crap files it had stored all over my machine.

The scary thing is that Norton had no clue that this one even existed. Google didn't seem to know much either. It's zamsdyg.exe or something and I had no one to help me with it. Even after a full Norton scan the blasted thing popped up again a few weeks later. McAfee's Free Scan finally got the last little bit of it (I hope).

The really scary thing is that it did all this without me clicking any OK buttons like a sucker. I didn't take any bait, killed every process using Task Manager and it still made a mess.

I don't even want to think what less savvy people are going through right now.

lostforawhile
01-24-2010, 08:43 PM
You mean Google Keylogger? Puhleeze.



Use Hijack This (http://free.antivirus.com/hijackthis/).

Pirate Bay nearly sent a scorcher up my backside a few weeks ago. I started a download when my system tray popped up a notice that I had been infected with a virus. At the same time, I kept getting pop up notices "Your computer is infected, do you want to start your virus scanner?" Then my virus protection popped up and started scanning. I thought "oh good, Norton will get it." Then I thought, "wait, this isn't Norton..." I killed everything and re-booted, but it stayed with me and knocked out my DNS settings. I reversed all the settings using Hijack This and then did a few hard drive searches to get all the crap files it had stored all over my machine.

The scary thing is that Norton had no clue that this one even existed. Google didn't seem to know much either. It's zamsdyg.exe or something and I had no one to help me with it. Even after a full Norton scan the blasted thing popped up again a few weeks later. McAfee's Free Scan finally got the last little bit of it (I hope).

The really scary thing is that it did all this without me clicking any OK buttons like a sucker. I didn't take any bait, killed every process using Task Manager and it still made a mess.

Jeez...
That sounds like a variant of what I had, I run Malwarebytes anti malware all the time in addition to my virus stuff, it's very good, thats what they usually recommended on hijack this, it can recognize a virus without needing a definition,just by what it's doing and how it's acting.

A20A1
04-19-2010, 10:10 AM
Mostly I see viruses from PDF / Adobe Reader, blog sites, and browser redirects to fake myspace, facebook or other sites.

Some of those end up installing whats called "ransom ware" and you get fake virus programs installed and it runs fake virus scans. The virus may set up hidden user accounts while crippling your user account privileges so you can't run programs, boot into safemode, etc. It also changes your internet lan connection preferences to use "Proxy server"

My XP was infected once but I have dual boot so I just used Vista to delete the accounts on XP, edited the XP boot.ini to load safemode by default, and ran Malwarebytes in vista and again in XP from safemode. It tried to infect vista but it couldn't affect my privileges so I could still open antivirus programs.

Then I purchased Malwarebytes because it wasn't subscription based BS like other software. One time fee of $25 and I got some real time protection for both my OS's on the same computer!

I also now run the free version of "Online Armor" as my firewall... just make sure you are infection free before setting up the firewall, and don't set it to automatically trust installed programs just to be safe.

Civic Accord Honda
04-20-2010, 06:05 PM
lol running 7 with no protections and no viruses just run ccleaner every week to keep it running fast :)

Christofur
02-26-2011, 04:19 PM
Then only time i use IE:barf: is to download Firefox :)

lostforawhile
02-26-2011, 04:30 PM
this was fixed a long time ago, that site was taken down, I believe someone hacked it, we now use the facebook three geez page as a backup as far as I know

import racer
02-27-2011, 03:33 PM
Nortons sucks use AVG Pro,Works Alot Better.

HON-DUH
02-27-2011, 08:49 PM
Get a Mac!
:inout:

lostforawhile
02-27-2011, 08:56 PM
uh, the problem has been solved a long time ago, this is an old thread, the site we used as a backup was hacked and malicious software installed, this site was even hacked a few times, why I don't know, but anyway, hardly anyone used that site, and it was just shut down, we use the facebook page if something causes the site to go down now

MessyHonda
02-27-2011, 11:15 PM
Then only time i use IE:barf: is to download Firefox :)

werd

MessyHonda
02-27-2011, 11:56 PM
Get a Mac!
:inout:

i would rather spend my money on my car than apple products....not saying they are bad but just saying that they over price them...

lostforawhile
02-28-2011, 12:45 AM
I think this thread can be closed the issue was solved a long time ago