Friday, July 16, 2010
Computer Viruses: html framer & exploit; false positives?
I'm extremely cautious when things like this pop up, based on my previous experience with rouge ware. Resident Shield is a valid part of the AVG package, but it can also be mimicked, and if this was rogue ware, nothing good would happen if you clicked quarantine or fix or anything similar. Although, if it was rogue ware, the very fact that it showed up probably meant that it was too late.
Patti Anne started a Malware-bytes quick scan, then an AVG scan, without replying to the prompt. Malware came back clean, but AVG found two instances of html framer, both lurking in the temporary files somewhere. It removed them.
I also started an Malware-bytes quick scan, just for s&g, and that is when Resident Shield popped up saying I had the "exploit" virus. Exploit creates havoc in excel spreadsheets apparently. I use excel a fair amount, tracking our eBay income & expenses, so that would not be good.
By this time I was fairly certain that this was a valid warning. I also had decided to run a full AVG scan so I clicked the ignore button. The Malware scan came back clean, but the AVG scan found one instance of "exploit", again in a temporary file. It removed it.
The next day Patti Anne got the resident shield warning for html framer again, but this time clicked on the quarantine button. Neither of us has had any problem since.
Turns out, according to an AVG forum, "html framer" was most likely a false positive - and they've already put out a fix. Don't know about "exploit" but it seems to be gone too.
So there we go. More fun in computer land.
Saturday, January 30, 2010
Rogueware and Ransomware
Twice in the last year programs looking very legitimate, in fact imitating windows security systems, popped up on my screen and informed me I had some nasty viruses on my computer. They gave me the option of getting rid of them by pressing the "ok" button, or ignoring it by pressing the "cancel" button.
I handled this incorrectly both times, and both times I got to a place where they wanted me to send them money in order to fix the problem. If you get that far, you've screwed up. The first time I should have known better, the second time I was tired and just wasn't paying attention. The software & message looked very similar to software I was familiar with, but it was anything but.
If a message pops up, look at it very carefully, make sure it's legitimate. Do not respond "ok" or "cancel", until you're positive - those buttons can be programmed to do anything. If you're not positive you're dealing with your normal anti-virus software, hit the red x in the upper right corner to close the program, or just manually turn off your computer and wait a few minutes. When you're back run a complete scan - if you can. Hopefully that will deal with it. If not, try to figure out how to remove it manually.
I reckon.
These programs look very authentic, they hijack your computer to or greater or lesser degree and won't give it back until you send them money (so they say). Anyone who is criminal enough to highjack my computer is probably not to be trusted with my credit card information, and under no circumstances will they get it. I will (and did) reformat my hard drive and re-install the operating system before I send them money.
Ok, so hopefully I'm ready for the next time.
Thursday, January 14, 2010
Trojan, Worm or Virus?
Sunday night I got fooled - as I was preparing to shut everything down and go to bed, I got a message from Windows Defender - it caught a trojan, and wanted to know if I wanted to fix it. But of course, I said, and I clicked a button to fix it, and immediately a service agreement form popped up. That's was odd - because Windows Defender and I were good buddies. I shut everything down and went to bed, figuring I'd run malwarebytes Monday.
Monday morning, everything was screwed up royally. I noticed problems immediately. There were icons on my desktop that I did not put there and had no business being there. There was a big red X next to the clock display. The windows security shield was displayed, odd since I never used windows security, and the windows defender icon was displayed, the Norton icon was nowhere to be seen.
The windows security and windows defender were not real. They took me to some foreign program wanting money.
In a few seconds something that looked like Windows defender popped up and told me I had this terrible virus on my computer. But I noticed now, which I didnt when I was tired the previous night, that it said "Windows Defense", not "Windows Defender". Defender = good, Defense = bad. The graphics were exactly the same, but it was a different program. I'm pretty sure the virus they warned me about was not on my computer.
S0, I attempted to run malwarebytes - it would not run. When I looked at the processes, mbam.exe was displayed, but the software was not running. I attempted to start up Norton, and it would not start. I attempted to download other software that removes malicious software, but everything seemed to be blocked. I could not download anything.
I don't know if it would have done any good to do a system restore, but it didn't matter, because that seemed to be blocked too. I also tried doing this with different browsers, but it made no difference.
So whoever was responsible for this is sophisticated enough to get past all my computer's defenses, disable them all, and keep me from doing anything about it. But they weren't sophisticated enough to do this without my knowledge. It was as plain as day immediately that things were not right. I wonder what happens when they finally figure out how to take over my computer without my knowledge.
"Windows Defense" is known, and there were instructions on how to remove it. Spy-doctor would apparently do it, except I could not download it. There were manual instructions, but in this case they only worked to a point. I certainly like getting down and dirty in the registers, but after awhile the instructions did not correspond to any of the realities I was experiencing.
So Monday afternoon, figuring the computer was hosed up but good, we disconnected it and carted it down to Ron's Computers on main street in Valdese. I'm glad to have the opportunity to contribute to the local economy.
We brought down the old laptop, did a little rewiring, downloaded a printer driver, and we were good to go. Everybody could get online and function at the stuff we need to do. (We have a little home business going). Monday was pretty much a wash, but Tuesday was a normal day.
We got the desktop back from Ron Tuesday afternoon - he formatted the hard drive and reloaded Windows XP. I could have done that, had I known where my disks were. That's not as bad as it may seem - I had everything backed up on an external drive. I did lose paint shop pro 8 - something I downloaded a lifetime ago. And I had a great game of Civ III going - I was doing good and getting ready to attack the French, my first step in conquering planet earth and that's gone now.
I've decided to get along without Norton - this is twice in the past year that something like this has happened. Back in February 2009, we were able to recover, but not this time. So not only did Norton fail to catch these things twice, but both times it was put completely out of commission. Norton isn't free, and I can certainly pay a lot less for something that apparently has major flaws, so now I've gone another route, and we'll see how that works. I no longer have Windows Defender either, and I'm going to let that go. I did download Malwarebytes. I upgraded to IE8, and also have the latest versions of firefox and opera.
So things seem to be working, all the scans come back clean, but I'm still in a wait and see mode.
Saturday, February 28, 2009
Finally - what caused my computer problems
Well, Acutiva sent out a message and finally I know what caused my computer viruses/trojans/malware that kept me busy for a week.
It seems all these nasty things were downloaded whenever you supersized a picture. One of the neat things about Auctiva is not only free image hosting & free scheduling, but it also automatically supersizes images for you, free of charge. All you had to do was click on it, and you got a large picture. For the longest time eBay charged 75 cents for that.
This explains why Patti Anne's computer worked fine, and mine was in a struggle for it's life. Patti Anne did not supersize anything, and I'm sure I did, probably more than once. I'm a visual person, I love pictures. The bigger the better - I love the detail of them and I like to provide the ability to supersize pictures to my customers. I think it gives me an advantage over those that don't.
But this may mean that anybody who supersized any pictures I listed (or that anyone else listed from Auctiva) from Friday afternoon till Saturday afternoon (the 20th & 21st), got a bug. I didnt list anything that Friday, but I did that Saturday & it was later Saturday was when I thought we were going to have to break down and take the computer to a geek. It was pretty bad.
So, that was it. Supposedly it's all fixed now. I haven't used Auctiva since Saturday the 21st, but I'll probably start again on Monday.
In the meantime, I'm learning all about FireFox & Opera.
Friday, February 27, 2009
IE, Firefox & Opera.
So, to try to cut down on malware sneaking past this toothless pit bull of a firewall I have, I downloaded firefox, whatever the latest version was. It's ok - but my fonts changed, it did some weird importation thing with all my favorites in "links", and it seemed to have major issues working with entrecard. But, I was adjusting, it seemed to load faster, and it is quite acceptable.
Ms. O.D. recommended Opera, so I tried that, and that is what I'm typing this little message on right now. It seems to work fine - I especially like the speed dial part of it. And I've been using Opera more than FF the last couple of days. There are things that are different, little adjustments to make, but so far it seems to be working well. One adjustment in Opera is that the spell checker on blogspot doesn't work too well. That's something I need. I once didnt get a job in part because I wasn't sure if it was "en lieu" or "en leiu". I'm pretty sure it's "en lieu". But I digress.
So, today is the first day in a week without some sort of trojan, virus or other malware being discovered by my anti-virus software. I continue to run MBAM and Windows Defender, and I'll do a complete Norton scan this weekend. They're coming up clean so far. That is good.
Wednesday, February 25, 2009
Trojan.Refpron, soxpeca, svchost.exe errors and other nasty stuff
Just for reference, I have an old HP Pavilion desktop, running Windows XP & I use Internet Explorer 7. We have a wireless network set up, used by two desktops and a occasionally a laptop.
My wife and I run a little eBay business. We use a site called "Auctiva" to host our pictures, create & schedule the listings and such. This has saved hundreds of dollars over time, because eBay used to charge for extra pictures, and still charges for scheduling listings. So, the morning of the 20th was a normal morning. I was editing and uploading pictures for the items (postcards and photographs) we were listing, Patti Anne was writing the initial descriptions, then I give them a once over for errors etc, and schedule them to be listed. On my end everything was working fine, but Miss Patti was noticing strange things on Auctiva. Response was slow, she was getting strange messages asking her to open Real Player (there should be no reason to open Real Player in this process), download stuff and other unusual messages. She mentioned that she thought Auctiva was having problems, and suggested we might want to stop using it for the time being. So we did - and we did not list anything on Friday.
Later that afternoon I got out on entrecard and was dropping & had plans to update my blogs when the computer froze up. No response to anything. So I punched the button and reb00ted. I didn't think it was going to come back up. When it finally did, there was no response when I clicked my desktop icons. So I booted again. When it came up this time, things responded, but I started getting some ugly messages. The first was "Generic Host Process for Win32 Services has encountered an error and needs to close. We are sorry for the inconvenience." I thought, WTF? Another message on the heels of this, which I think may be related was, "svchost.exe - the exception breakpoint. A breakpoint has been reached. The instruction 0x66fd6dc8 referenced memory at 0x00000000. The memory could not be written". Another WTF moment. Both of these messages knocked me out of the water, the computer would stop responding. I had never, in my years of using this computer, received either of these messages before.
I run Norton 360, which is a resource hog, but it's what I have, and at this point it had not alerted me to any problems. I looked at my processes, and noted a process called "soxpeca.exe", that I had not seen before. I googled it, and found that it was a nasty thing to have on your computer, and needed to be removed asap. I had no idea how it got there. I ran a "smart" scan, then a "full scan". Norton scanned soxpeca - I saw it. It did not see it as a threat, all it found was a couple of tracking cookies.
Meanwhile, whenever I went online, I was guaranteed to get a svchost breakpoint error or a Win32 error. So I thought I'd reboot in safe mode, and try to get rid of soxpeca once and for all, tho I wasn't quite sure yet how. (I thought they might be related problems - I still don't know if they are or not). Well somehow I screwed that up, but I did have an option to reboot in "the last known good configuration", which I did. That may have been a mistake, I dont know, but things did seem stable for awhile. Later I found that the computer had lost all its system restore points. I dont know if what I did wiped them out or if the malware wiped them out.
Fast forward to Saturday. Saturday I logged on to Auctiva and scheduled all our listings to post to eBay. Shouldnt have. I went out to entrecard again, and that's when Norton started yelling at me. It found in quick succession while running in the background, the following malware, and told me to reboot: Downloader, Trojan.zlob, Bloodhound.Sonar.1 (twice). So I rebooted 3 times in the space of 30 mintues or so. I looked and soxpeca.exe was running again. I ended it, but I knew it would come back. I ran a full Norton scan, Spybot Search & Destroy, Windows Defender (full scan), none found anything worth mentioning. This took hours, by the way. & if I tried to go online, I had to deal with the svchost errors. Sigh.
At some point we received an announcement from Auctiva that their servers were experiencing problems, and they were running on fewer servers than normal. Later, we received another announcement saying that they were experiencing malware attacks, and had taken the effected servers offline. Later we received another announcement saying that they had taken the whole site offline until they could solve the problem. I think I know where my trojans and viruses came from. And forgive me entrecard community, for my evil thoughts.
Fast forward to Sunday: Patti Anne and I both have computer backgrounds, and she's especially good at digging out & fixing problems. She's doing her research and found that soxpeca.exe is associated with Trojan.Refpron, and it is bad, bad, bad. She also found that some free software called Malbytes Anti-Malware (MBAM) was successful at removing it. So she downloaded it and ran the "quick scan", and it caught Trojan.Refpron. We checked the running processes and soxpeca.exe is no longer there. Then we ran the full scan, and it came back clean.
Believe me, I've skipped over a lot here - Patti & I were at this for hours, and getting very close to giving up and taking the computer to a geek.
Well, the viruses and trojans seem to be gone at this point, but I'm still getting svchost or Win32 errors, every 5 to 8 minutes when I'm online.
Monday: We continued to research the svchost problem. Found a site called www.pchell.com, which addressed a very similar problem. It had clear concise directions for updating service settings, re-registering windows update dlls, removing corrupted update files and so on. While Patti Anne went to a doctor's appointment, I wiled away the minutes following their steps. I was amazed that their instructions seemed to be perfect - usually the author manages to leave out a step or you don't get an expected response, or they make an assumption about your level of knowledge and you end up getting lost. But this worked fine - and it had me at the "C" prompt entering dos commands, just like the old days. Felt good. Only problem was, it didnt work. After I was done, I went on line, 8 minutes later, svchost.exe breakpoint error.
Patti Anne returns, and we have a good laugh about the pchell instructions. So she researched some more, and she found this - there is a setting the bowels of the control panel which might stop this problem. So off to the control panel we go.
Go to: Control Panel, Performance & Maintenance, System, Advanced Tab, Performance Settings button, Data Execution Prevention Tab, Select the button for "Turn on DEP for all programs and services except those I select", check the box next to "Generic Host Process for Win32 Services". This seemed to solve the svchost.exe breakpoint, and the Win32 error problems. I don't know what the side effects are tho, maybe none, but I don't know. I don't advise changing the default settings for this unless you have to.
Now, it's not lost on me that Patti Anne's computer is running just fine. We're on a wireless network, and I'm wondering why her's is running fine and mine is in a death struggle. It was very convenient to have her computer running, because a lot of the research we did was done there, since mine didnt function too well..
Tuesday: From Monday around 3 PM till Tuesday around 3 PM the old computer seemed to run fine. Very good response time, no problems. Then for some reason, Patti Anne could not print from her computer. The printer is physically attached to my computer, so I'm thinking, cripes. I booted again. After I came back up, guess what? Patti could print. But I took a Win32 error again, and had to reboot. I checked the setting in the control panel, and it was still checked, so I don't quite understand, and it scares me a little. Then Norton informed me that it had found something called "infostealer.gamepass" and I needed to reboot in order to complete the fix. Sigh. So I did. When it came back up I checked the control panel setting again - still set. I checked for soxpeca - not there. We ran a couple of programs to clean up registries, ran MBAM again, found nothing, ran Windows Defender, nothing again.
Wednesday - today: This morning, Norton found something it simply called "Trojan Horse". I had to reboot to remove it. Ran various quick & smart scans, came back clean. And Patti Anne decided it might be a good move to downloaded & install Mozilla Firefox, and use that instead of IE7, at least for now. So that's what I'm using. It takes a little getting used to. But everything has been stable since this morning.
No svchost.exe or Win32 errors since yesterday. Hopefully tomorrow will be a virus/trojan/malware free day.
So, this is what we've been up to. I've learned stuff. One thing I learned is what a heuristic algorithym is, but I'll leave my thoughts on that for another day.
I hate computers. Almost as much as cars.
