Virus and trojans

Forum for general cruising topics
User avatar
ParaHandy
Old Salt
Posts: 709
Joined: Mon Jun 11, 2007 1:11 am

Virus and trojans

Post by ParaHandy »

Whilst perusing on TOP I clicked on a link and immediately acquired a Russian friend. It was claimed by the unwilling purveyor of this that it was due to IE6 or earlier but I'm using IE7 and ESET as the anti-virus package. This Russian "friend" appears to be called Kryptik and or QHost and is continuously battling with ESET. There's a package from spywarenerds.com which claims to get rid of it. I'm reluctant to jump out of the fat into the fire etc so I'm asking if anyone can recommend this nerd package or is there any other suitable way of getting rid of it ...

If I can't get rid of it, the computer has to go ...
User avatar
Nick
Admiral of the Blue
Posts: 5927
Joined: Sun May 12, 2002 4:11 pm
Boat Type: Albin Vega 27 and Morgan Giles 30
Location: Oban. Scotland
Contact:

Re: Virus and trojans

Post by Nick »

.
Download, update and run Malwarebytes Antimalware - gets rid of most things painlessly, everyone should have a copy.

BTW, if you are using IE7 Windows will have automagically updated you to IE8 unless you specifically said nay. (See my post on other thread re. flaky editor).
- Nick 8)

Image
User avatar
ash
Yellow Admiral
Posts: 1713
Joined: Tue Mar 01, 2005 12:14 pm
Boat Type: Moody 346
Location: Tarbert, East Loch Tarbert, Loch Fyne, Scotland

Re: Virus and trojans

Post by ash »

You might need to start the 'puter in 'Safe Mode with Downloads' to obtain and run Malwarebytes and get rid of the wee beastie.

Ash

PS - I keep ignoring the wee golden shield which keeps telling me that upgrades are available so I'm still on IE7.
"This is a sailing Forum"
Albin Vega "Mistral" is now sold
User avatar
Silkie
Admiral of the Fleet
Posts: 3475
Joined: Sat Mar 05, 2005 12:55 pm
Boat Type: Hurley 22
Location: Bonnie Scotland
Contact:

Re: Virus and trojans

Post by Silkie »

How are you getting on with this Para? Have you got it sorted yet? Another vote from me for Malwarebytes.
different colours made of tears
User avatar
ParaHandy
Old Salt
Posts: 709
Joined: Mon Jun 11, 2007 1:11 am

Re: Virus and trojans

Post by ParaHandy »

Silkie wrote:How are you getting on with this Para? Have you got it sorted yet? Another vote from me for Malwarebytes.
I was going to wait until tomorrow before reporting but as of now, it's got rid of it.

More anon ... will wait until tomorrow afore a dram in ra Balvicar whizzo's name is raised ...
User avatar
Silkie
Admiral of the Fleet
Posts: 3475
Joined: Sat Mar 05, 2005 12:55 pm
Boat Type: Hurley 22
Location: Bonnie Scotland
Contact:

Re: Virus and trojans

Post by Silkie »

Thinking on..

I got a nasty last week from clicking on a link in another place. The site itself seemed the perfectly innocuous nautical content I was expecting and I browsed it happily for a few minutes. It was only when I closed the window that I realised that something was downloading itself onto my machine. Malwarebytes got rid of it at first pass but I was left with a damaged IE8 and eventually had to go back to a restore point.

..I wonder if this is the next phase in the campaign against YBW that prompted the recent software upgrade? Should I send Dan a link to this thread?
different colours made of tears
User avatar
Nick
Admiral of the Blue
Posts: 5927
Joined: Sun May 12, 2002 4:11 pm
Boat Type: Albin Vega 27 and Morgan Giles 30
Location: Oban. Scotland
Contact:

Re: Virus and trojans

Post by Nick »

Should I send Dan a link to this thread?
Personally I'd rather keep a low profile - I think it would be better if you just PM-ed him telling him what happened, and if Para did the same.

Do you really think someone has it in for YBW to that extent, and if so who?
- Nick 8)

Image
User avatar
ParaHandy
Old Salt
Posts: 709
Joined: Mon Jun 11, 2007 1:11 am

Re: Virus and trojans

Post by ParaHandy »

Silkie wrote:Thinking on..
ESET is a decent anti-virus package - I thought Norton & McAfee just look good but do sweet feck all. However, the virus was still trying to access the Russian websites - 2 of them - but ESET blocked them even though it said it had quarantined and deleted them. Only after webbies prog was installed did the access stop. Eset has just requested a copy of the quarantined files so presumably this virus is a new one to them. If it is, then all who accessed the link on TOP and who say their anti-virus never saw it might have a problem. I'm not happy that ESET couldn't stop it altogether and not before it had corrupted the internet properties (it changed the proxy server settings and corrupted some disc space) whereas what webbers recommended did. It wouldn't do any harm to let Dan know.
User avatar
ash
Yellow Admiral
Posts: 1713
Joined: Tue Mar 01, 2005 12:14 pm
Boat Type: Moody 346
Location: Tarbert, East Loch Tarbert, Loch Fyne, Scotland

Re: Virus and trojans

Post by ash »

I haven't been to TOP for a couple of days - can P/H or Silkie give us a clue about which link to avoid.

One of my sons got infected with the virus which diverts you - sometimes known as 'Google Divert'. This seems to be a pretty smart beastie - stops you downloading antivirus progs. Even if you think that you're clear, it restores back to a date when you were infected and away you go again. Not sure if he's clear of it yet - don't know where he got it.

Ash
"This is a sailing Forum"
Albin Vega "Mistral" is now sold
User avatar
ParaHandy
Old Salt
Posts: 709
Joined: Mon Jun 11, 2007 1:11 am

Re: Virus and trojans

Post by ParaHandy »

ash wrote:I haven't been to TOP for a couple of days - can P/H or Silkie give us a clue about which link to avoid.
it was Bilbo's link to a video clip of an aeroplane. the virus was inside the ActiveX (?) thing that you had to click to see the video.
User avatar
Aja
Yellow Admiral
Posts: 1136
Joined: Fri Jun 09, 2006 12:08 pm
Boat Type: Moody 346
Location: Tighnabruaich
Contact:

Re: Virus and trojans

Post by Aja »

Oh Bummer. The one about the spyplane? I had a look at that too. :(
Donald

Edit: Hold on. I didn't have to click on ActiveX - the one I looked at wasn't video - it was Flash. I've downloaded Malwarebyte and will give it a run.

Donald
User avatar
ParaHandy
Old Salt
Posts: 709
Joined: Mon Jun 11, 2007 1:11 am

Re: Virus and trojans

Post by ParaHandy »

Aja wrote:... the one I looked at wasn't video - it was Flash.
yes, same one .. i think it was flash (dinnae know the difference but am up tae speed verra quickly recently) .. had to click on the menu bar to get it to play
User avatar
Rowana
Old Salt
Posts: 773
Joined: Fri Feb 08, 2008 4:58 pm
Boat Type: Macwester Rowan 8 meter
Location: Aberdeenshire

Re: Virus and trojans

Post by Rowana »

As soon as I clicked on the link, McAfee threw up it's hands in horror, and wouldn't let me go any further.
BLESSED ARE THOSE WHO ARE CRACKED,
FOR THEY ARE THE ONES WHO LET IN THE LIGHT
User avatar
Nick
Admiral of the Blue
Posts: 5927
Joined: Sun May 12, 2002 4:11 pm
Boat Type: Albin Vega 27 and Morgan Giles 30
Location: Oban. Scotland
Contact:

Re: Virus and trojans

Post by Nick »

.
Naughty Bilbo.

I think the fact that is was the hobbit rules out Silkie's theory that this was phase 2 of the War on Scuttlebutt though.
- Nick 8)

Image
User avatar
claymore
Admiral of the Green
Posts: 4762
Joined: Sun Oct 19, 2003 2:55 pm
Boat Type: Claymore
Location: Ardfern or Lancashire

Re: Virus and trojans

Post by claymore »

Just listen to you lot - you sound like the products of cousins who have married.
Regards
Claymore
:goatd
Post Reply