Go Back   Android Forums > Android Community > The Lounge > Computers & IT
Gamers - Check out our new sister sites!
Nintendo Wii U!    |    OUYA - $99 Android System!

Like Tree4Likes
  • 2 Post By CodeMonkey
  • 1 Post By CodeMonkey
  • 1 Post By 9to5cynic

test: Reply
 
LinkBack Thread Tools
Old September 17th, 2012, 12:57 PM   #1 (permalink)
Senior Member
Thread Author (OP)
 
350X's Avatar
 
Join Date: Jan 2012
Location: NWOhio
Posts: 1,217
 
Device(s): 3X LG Optimus V Rooted - Eken T02A Tablet - KindleFire - Ramos W17PRO Tablet
Carrier: Not Provided

Thanks: 46
Thanked 89 Times in 81 Posts
Default russian porn virus ?

russian porn virus ?

My mothers laptop got infected with a bunch of stuff, it infected FF, Opera, IE, installed bookmarks, shorts cuts, quick launch icons.....

most of it said Mail.Ru on it, a wrong click had 90 porn pages load up, and some very questionable porn at that. I thought it was all gone but it happened again the next night.

not finding anything with Avast

anyone ever run into this?

worst part is, it was tethered to my phone at the time, why it was able to do all it did so fast, as the laptop is usually on slow dialup.

350X is offline  
Reply With Quote
Sponsors
Old September 17th, 2012, 01:15 PM   #2 (permalink)
Junior Member
 
Join Date: Mar 2011
Posts: 29
 
Device(s):
Carrier: Not Provided

Thanks: 0
Thanked 10 Times in 4 Posts
Default

4G LTE BLAZING VIRUS

If I may, I would totally recommend downloading and running Malwarebytes, and be sure to turn off System Restore on the C:\ beforehand. May be able to get rid of it... it's a good little product.
ApparitionXVII is offline  
Reply With Quote
The Following User Says Thank You to ApparitionXVII For This Useful Post:
wellsy37 (September 19th, 2012)
Old September 17th, 2012, 05:25 PM   #3 (permalink)
Junior Member
 
Join Date: Sep 2012
Posts: 28
 
Device(s):
Carrier: Not Provided

Thanks: 0
Thanked 2 Times in 2 Posts
Default

I'd second Malwarebytes. I run Malwarebytes, Avast and McAffee and never have virus problems. Either that or switch to Ubuntu for any "questionable downloads"
Angus19 is offline  
Reply With Quote
Old September 17th, 2012, 09:11 PM   #4 (permalink)
no place like ~
 
9to5cynic's Avatar
 
Join Date: Feb 2011
Location: /home/
Posts: 4,729
 
Device(s): Galaxy S3 (Verizon) Evo 4G - retired/rooted
Carrier: Verizon

Thanks: 3,023
Thanked 1,721 Times in 1,162 Posts
Send a message via AIM to 9to5cynic
Default

Hmm... I'm guessing it might have had local copies of all the larger files (as to why it was able to load so fast)...

But seriously, I'd probably just nuke it start over. Especially if some really questionable content was on the machine. But that's me. And really, you never know for sure exactly what the program is going to do... there could be parts missed by the AV software....

That's the stuff that makes me nervous, and a clean install of most modern OSes take only a half an hour or so. Hopefully important files were backed up. I would scan anything that you need from that computer with some AV just to be sure all the files are clean.
9to5cynic is offline  
Reply With Quote
Old September 17th, 2012, 10:57 PM   #5 (permalink)
Senior Member
Thread Author (OP)
 
350X's Avatar
 
Join Date: Jan 2012
Location: NWOhio
Posts: 1,217
 
Device(s): 3X LG Optimus V Rooted - Eken T02A Tablet - KindleFire - Ramos W17PRO Tablet
Carrier: Not Provided

Thanks: 46
Thanked 89 Times in 81 Posts
Default

but a clean install can't wipe a hard drive clean, ive nuked hard drives, made them smoke and a recovery program still finds more then everything.

only a complete HD change will remove anything loaded onto it and yes, it was either some photo tricks or some illegal as F stuff.
350X is offline  
Reply With Quote
Old September 18th, 2012, 02:07 PM   #6 (permalink)
Senior Member
 
CodeMonkey's Avatar
 
Join Date: Dec 2008
Location: On the sofa
Posts: 544
 
Device(s): Nexus 4 (stock), Nexus Galaxy (retired), Atrix (ret.), N1 (ret.), Magic (ret.), G1 (ret.)
Carrier: Not Provided

Thanks: 11
Thanked 95 Times in 81 Posts
Default

Use the live CD tool DBAN to wipe the drive before a fresh install.
Change passwords on all accounts used on the laptop from another machine asap.
Davdi and Speed Daemon like this.
__________________
Monkey see, monkey do.

CodeMonkey is offline  
Reply With Quote
The Following 3 Users Say Thank You to CodeMonkey For This Useful Post:
mikedt (September 19th, 2012), Speed Daemon (September 22nd, 2012), wellsy37 (September 19th, 2012)
Old September 19th, 2012, 08:38 AM   #7 (permalink)
New Member
 
Join Date: Aug 2012
Location: Nigeria
Posts: 11
 
Device(s):
Carrier: Not Provided

Thanks: 0
Thanked 1 Time in 1 Post
Default

It is obvious that the PC has been infected by virus. The next thing you should focus on is how to remove it.
cursor system is offline  
Reply With Quote
Old September 19th, 2012, 07:39 PM   #8 (permalink)
no place like ~
 
9to5cynic's Avatar
 
Join Date: Feb 2011
Location: /home/
Posts: 4,729
 
Device(s): Galaxy S3 (Verizon) Evo 4G - retired/rooted
Carrier: Verizon

Thanks: 3,023
Thanked 1,721 Times in 1,162 Posts
Send a message via AIM to 9to5cynic
Default

Yeah, hit it with DBAN and reinstall windows.
9to5cynic is offline  
Reply With Quote
The Following User Says Thank You to 9to5cynic For This Useful Post:
mikedt (September 20th, 2012)
Old September 19th, 2012, 08:49 PM   #9 (permalink)
Senior Member
Thread Author (OP)
 
350X's Avatar
 
Join Date: Jan 2012
Location: NWOhio
Posts: 1,217
 
Device(s): 3X LG Optimus V Rooted - Eken T02A Tablet - KindleFire - Ramos W17PRO Tablet
Carrier: Not Provided

Thanks: 46
Thanked 89 Times in 81 Posts
Default

I ran malwarebytes before and even now all it finds is that I have the MS firewall n virus turned off, I use zone alarm n avast instead.
350X is offline  
Reply With Quote
Old September 20th, 2012, 07:08 AM   #10 (permalink)
你好
 
mikedt's Avatar
 
Join Date: Sep 2010
Location: Shenzhen City, China 中国深圳市
Posts: 4,695
 
Device(s): Three Chinese Androids: Kliton I806LS, Lenovo P700i, Ampe A76
Carrier: China Mobile, China Telecom.

Thanks: 1,375
Thanked 1,171 Times in 825 Posts
Send a message via Skype™ to mikedt
Default

Quote:
Originally Posted by 9to5cynic View Post
Yeah, hit it with DBAN and reinstall windows.
Best advice. Once you've hit a HDD with DBAN, there is absolutely nothing left, no lurking nasties or anything.
__________________
The People's Guide to Android in the People's Republic.
Honorary Grand Poobah Shenzhen University English Corner.
http://welcometomychina.tumblr.com/
There are nine million bicycles in Beijing.
There are nine million Androids in Shenzhen.
mikedt is offline  
Reply With Quote
The Following User Says Thank You to mikedt For This Useful Post:
9to5cynic (September 20th, 2012)
Sponsors
Old September 21st, 2012, 01:22 AM   #11 (permalink)
Senior Member
Thread Author (OP)
 
350X's Avatar
 
Join Date: Jan 2012
Location: NWOhio
Posts: 1,217
 
Device(s): 3X LG Optimus V Rooted - Eken T02A Tablet - KindleFire - Ramos W17PRO Tablet
Carrier: Not Provided

Thanks: 46
Thanked 89 Times in 81 Posts
Default

Anyone got a direct link to the DBAN CD/DVD iso I should download and use???

google is flooded with stuff, pick my poison for me
350X is offline  
Reply With Quote
Old September 21st, 2012, 01:48 AM   #12 (permalink)
你好
 
mikedt's Avatar
 
Join Date: Sep 2010
Location: Shenzhen City, China 中国深圳市
Posts: 4,695
 
Device(s): Three Chinese Androids: Kliton I806LS, Lenovo P700i, Ampe A76
Carrier: China Mobile, China Telecom.

Thanks: 1,375
Thanked 1,171 Times in 825 Posts
Send a message via Skype™ to mikedt
Default

Has direct URL to the SourceForge DBAN ISO.
DBAN Download | Darik's Boot And Nuke
Download Darik's Boot and Nuke from SourceForge.net
mikedt is offline  
Reply With Quote
The Following User Says Thank You to mikedt For This Useful Post:
EarlyMon (September 21st, 2012)
Old September 21st, 2012, 04:25 PM   #13 (permalink)
Senior Member
Thread Author (OP)
 
350X's Avatar
 
Join Date: Jan 2012
Location: NWOhio
Posts: 1,217
 
Device(s): 3X LG Optimus V Rooted - Eken T02A Tablet - KindleFire - Ramos W17PRO Tablet
Carrier: Not Provided

Thanks: 46
Thanked 89 Times in 81 Posts
Default

Oh Lord that how out of touch I am, I thought you were talking about some linux distro, why I wasn't finding it.

that thing look dangerous, I don't even want that iso in my machine to bunr it, in fear of setting off the bomb
350X is offline  
Reply With Quote
Old September 21st, 2012, 04:43 PM   #14 (permalink)
Senior Member
 
CodeMonkey's Avatar
 
Join Date: Dec 2008
Location: On the sofa
Posts: 544
 
Device(s): Nexus 4 (stock), Nexus Galaxy (retired), Atrix (ret.), N1 (ret.), Magic (ret.), G1 (ret.)
Carrier: Not Provided

Thanks: 11
Thanked 95 Times in 81 Posts
Default

It's a very handy tool to have - I use it to prep laptops for resale on eBay (military wipe and fresh windows install).
mikedt likes this.
CodeMonkey is offline  
Reply With Quote
Old September 21st, 2012, 07:17 PM   #15 (permalink)
你好
 
mikedt's Avatar
 
Join Date: Sep 2010
Location: Shenzhen City, China 中国深圳市
Posts: 4,695
 
Device(s): Three Chinese Androids: Kliton I806LS, Lenovo P700i, Ampe A76
Carrier: China Mobile, China Telecom.

Thanks: 1,375
Thanked 1,171 Times in 825 Posts
Send a message via Skype™ to mikedt
Default

Quote:
Originally Posted by 350X View Post
Oh Lord that how out of touch I am, I thought you were talking about some linux distro, why I wasn't finding it.

that thing look dangerous, I don't even want that iso in my machine to bunr it, in fear of setting off the bomb
Yeh it's a secure data destroyer, that's all it is. DBAN, Darik's Boot And Nuke. It doesn't know about partitions, formats, boot sectors or anything like that. It totally fills the HDD with random data or zeros, and do it how ever many times you want. Useful if you're selling your old PC on Ebay.
mikedt is offline  
Reply With Quote
Old September 21st, 2012, 11:11 PM   #16 (permalink)
no place like ~
 
9to5cynic's Avatar
 
Join Date: Feb 2011
Location: /home/
Posts: 4,729
 
Device(s): Galaxy S3 (Verizon) Evo 4G - retired/rooted
Carrier: Verizon

Thanks: 3,023
Thanked 1,721 Times in 1,162 Posts
Send a message via AIM to 9to5cynic
Default

If I'm not mistaken, DBAN is also DoD cleared....
9to5cynic is offline  
Reply With Quote
Old September 21st, 2012, 11:15 PM   #17 (permalink)
Member
 
cookiefrog's Avatar
 
Join Date: Aug 2012
Posts: 110
 
Device(s): Samsung Galaxy S3/Samsung Galaxy Tab 2/LG Spectrum 2/Nokia Lumina 822/Hero S (evo design)
Carrier: Not Provided

Thanks: 1
Thanked 26 Times in 20 Posts
Default

Combofix is awesome make sure you download it from bleepingcomputer.com only as it is so good that there is a fake one out there.

Then run malwarebytes. On most cases a single tool does not provide a clear cut solution.
cookiefrog is offline  
Reply With Quote
Old September 22nd, 2012, 04:41 AM   #18 (permalink)
Disabled
 
Join Date: Jul 2012
Posts: 2,033
 
Device(s):
Carrier: Sprint

Thanks: 541
Thanked 552 Times in 439 Posts
Default

Booting from a known-clean, read-only disc with the latest anti-malware tools is by far the best way to go. CodeMonkey's advice about that id #1. I'm not familiar with DBAN, and in the past I've had some great success using a command line Windows PE version of Emisoft's A2 product. So there's one more anti-malware product that has worked well for me in the past, and can be built into a WinPE or ReactOS environment, as well as its own free Emsisoft Emergency Kit image.
Speed Daemon is offline  
Reply With Quote
Old September 22nd, 2012, 11:28 PM   #19 (permalink)
no place like ~
 
9to5cynic's Avatar
 
Join Date: Feb 2011
Location: /home/
Posts: 4,729
 
Device(s): Galaxy S3 (Verizon) Evo 4G - retired/rooted
Carrier: Verizon

Thanks: 3,023
Thanked 1,721 Times in 1,162 Posts
Send a message via AIM to 9to5cynic
Default

DBAN will write to the hard drive all ones or zeros (I believe it does random as well), and it does several passes (if you allow). IIRC it passes DoD clearance. So it completely destroys the data on the disk. That way, there is no lingering 'questionable' content on the disk whatsoever.

mikedt likes this.
9to5cynic is offline  
Reply With Quote
Old October 4th, 2012, 04:20 PM   #20 (permalink)
Senior Member
Thread Author (OP)
 
350X's Avatar
 
Join Date: Jan 2012
Location: NWOhio
Posts: 1,217
 
Device(s): 3X LG Optimus V Rooted - Eken T02A Tablet - KindleFire - Ramos W17PRO Tablet
Carrier: Not Provided

Thanks: 46
Thanked 89 Times in 81 Posts
Default

Looks like I wasn't the only one, and or the word get back to the right people. I haven't nuked it yet as I gotta get my Mother to say what needs backed up [her laptop], but anyways last night I clicked a missed shortcut link, which of course tried to load several pages, but all of them were now dead links to those parked domain or bad DNS pages.
350X is offline  
Reply With Quote
Sponsors
Reply


Go Back   Android Forums > Android Community > The Lounge > Computers & IT
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 03:21 PM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2013, vBulletin Solutions, Inc.