Windows 7 Forums


Reply
Thread Tools

[SOLVED] Malware destroyed my 7 Pro install (notebook)

 
 
catilley1092 catilley1092 is offline
Win 7/Linux Mint Lover
catilley1092's Avatar
Join Date: Nov 2009
Location: North Carolina, USA
Posts: 3,510
Thanked: 510
 
      06-24-2010
I was on my notebook a couple of nights ago, and I decided to take Safari for a spin, since they claim they are better now. The site(s) that I were on may have been questionable (porn sites). I figured MSE had my back covered, after viewing 20 or so pages, I started closing them, and suddenly, my notebook acted weird, there was shown a virus scanner to click onto, but I couldn't click onto MSE or Malwarebytes. I tried to go to Windows Live Safety Scanner in IE, no go. All that I had was Firefox. I shut it down and went to XP Pro.

As soon as I got started up good, I did a MSE scan, and it was in cleaning mode for nearly an hour. Malwarebytes found nothing. Windows Live Safety Scanner found multiple infections, including this one: Trojan:JS/Fake SpyPro, the most severe. I could no longer boot into 7, and was afraid that my whole notebook would be infected, so I nuked the whole notebook with DBAN. It took a while, but after 7 hours, the job got done.

I had a good backup of Win 2K, so I first installed that with Macrium. The rest I reinstalled from scratch (XP Pro, Vista SP2 & 7 Pro), all 32 bit. But this time, instead of backing up with Macrium, I used the WD edition of Acronis. After fully updating and activating each partition, I backed up each separately, afterwards, I done a full backup.

If you have a WD or Seagate backup drive, you can get Acronis for free, Ian posted the links in Kalario's thread (Backup Failed) in Crashes, BSOD's & Debugging. It's not the same as the paid for version, but it's a damn good backup program, it allows you to clone your drive, do a drive sweep, backup, restore, create bootable media to help you recover. Many backups are useless without a CD.

Anyway, in the future, would the use of a VM (such as Mint) prevent another problem like this from happening? Getting rid of the entire VM is about three clicks away. This was bad, the worst that has ever happened to me since owning a computer.

Cat
 
Reply With Quote
 
 
 
 
yodap yodap is offline
No longer shovelling
yodap's Avatar
Join Date: Mar 2009
Location: NY, USA
Posts: 1,287
Thanked: 243
 
      06-24-2010
Maybe just use the Linux Live CD to do that kind of surfing. But your idea is probably ok too.
 
Reply With Quote
 
Core Core is offline
throwing darts
Core's Avatar
Join Date: Feb 2009
Location: Akaa, Finland
Posts: 815
Thanked: 172
Send a message via MSN to Core Send a message via Yahoo to Core Send a message via Skype™ to Core Core's Twitter Pag
 
      06-24-2010
Did you have UAC enabled? I am just asking because I wonder if it makes any difference.
 
Reply With Quote
 
Nibiru2012 Nibiru2012 is offline
Quick Scotty, beam me up!
Nibiru2012's Avatar
Join Date: Oct 2009
Location: Planet X
Posts: 4,739
Thanked: 1055
 
      06-24-2010
Did you try that RKill I posted about a few days ago?

This would have been an excellent test for it.
 
Reply With Quote
 
catilley1092 catilley1092 is offline
Win 7/Linux Mint Lover
catilley1092's Avatar
Join Date: Nov 2009
Location: North Carolina, USA
Posts: 3,510
Thanked: 510
 
      06-24-2010
You could go either way, I guess, but it performs better after updating. And I've never broke a Linux OS.

But where was MSE when this was going on? I update it on a daily basis. For the first time, I'm having second thoughts about the product, it's supposed to protect me at all times. At least give me a chance to "get me outta here" would be acceptable to me. However, I may have had too many pages open at the time to receive a timely warning.
 
Reply With Quote
 
catilley1092 catilley1092 is offline
Win 7/Linux Mint Lover
catilley1092's Avatar
Join Date: Nov 2009
Location: North Carolina, USA
Posts: 3,510
Thanked: 510
 
      06-24-2010
Quote:
Originally Posted by Core View Post
Did you have UAC enabled? I am just asking because I wonder if it makes any difference.
Yes, it's enabled, I don't disable anything to do with security. It just hit like lightning, is all that I know.

Nibiru, I did think of RKill, in fact I went to the web page. But from what I gathered, and I could have misunderstood, it only allows you to find the root cause of the problem, then you can get rid of it. But as I've said, I may have misunderstood.

At any rate, I wanted to nuke the target of infection, and DBAN does a damn good job of getting that done.
 
Reply With Quote
 
TrainableMan TrainableMan is offline
^ The World's First ^
TrainableMan's Avatar
Join Date: May 2010
Location: PA, USA
Posts: 4,338
Thanked: 836
 
      06-24-2010
I don't use MSE but if it has any malicious script detection it likely only has those hooks into common browsers like IE (of course) and maybe Firefox. I use Norton, which I don't recommend and will look to replace once my paid subscription ends, and it provides scanning in IE 32-bit browsers and Firefox, it does nothing in 64bit browsers because NIS is only a 32bit application, but at least I can see it as a toolbar of the browsers it supports. Safari isn't a huge market-share and I wouldn't expect it to be supported by Norton nor MSE.

If the code tried to run a bad exe it had copied to your HD then you would expect the virus scanner to catch it but if it is executing scripts etc in a browser that is not detected the same way. Also if it's a new type virus it may not be detected either. Or if it has taken over, hiding the file before it runs it or by disabling your virus protection first well then it's too late. Like the one that was posted about a few weeks ago that passes a good exe to the virus scanner then exploits a weakness and substitutes evil exe as it is passed to the cpu for execution.

That is why browser embedded protection is so important - to catch malicious scripts as they are being downloaded, not after it has run it's scripting to dig into your system.

I have installed something called sandboxie which is supposed to run the browser in a separate area that disappears when you close it, essentially a Virtual mode just for the browser. It is supposed to help protect you from that sort of thing but the truth is I haven't done anything with it beyond the install. I think it may be trial software that you pay for after a while but I never saw a "you have 30 days left" or whatever so I don't know. If it has an expiration I haven't hit it yet. Perhaps you might try this product or something similar when testing new browsers (or even questionable programs as it works for other exes too I believe).

It's also a good idea to maintain a hosts file of blocked sites as often times it's not the sites themselves but the advertisers that slip in the evil scripting. Spybot S&D updates your hosts file and also WinHelp2002 puts out quarterly updates which you can download & copy into your hosts file. Esentially links to any of these sites listed in your hosts file are ignored - prevents tons of ads and nasty script sites, unfortunately it often blocks advertising for MSN etc and they won't show you their news vids until you watch their commercial - usually I say its not worth it but what you can do is maintain an empty and a blocking hosts file and just copy over when you want to go from protected to unprotected. You could even write 2 simple bat files and create shortcuts to do it for you.

Last edited by TrainableMan; 06-24-2010 at 09:41 AM..
 
Reply With Quote
 
Veedaz Veedaz is offline
~
Veedaz's Avatar
Join Date: Sep 2009
Location: England
Posts: 1,988
Thanked: 329
 
      06-24-2010
Quote:
Originally Posted by Nibiru2012 View Post
Did you try that RKill I posted about a few days ago?

This would have been an excellent test for it.
Tested RKill a few days ago and its dam good ! .... it would be an idea to keep RKill at hand Cat.
 
Reply With Quote
 
Kalario Kalario is offline
Aquarius
Kalario's Avatar
Join Date: Dec 2009
Location: Planet Gong
Posts: 586
Thanked: 64
 
      06-24-2010
Maybe not going on these questionable sites in the first place
 
Reply With Quote
 
yodap yodap is offline
No longer shovelling
yodap's Avatar
Join Date: Mar 2009
Location: NY, USA
Posts: 1,287
Thanked: 243
 
      06-24-2010
Quote:
Originally Posted by Kalario View Post
Maybe not going on these questionable sites in the first place
Well.......there is that option.
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
How to Install Windows 7 davehc Software 0 08-16-2010 03:50 PM
Tips- Using Grub4Dos install Windows 7 from USB Storage mjb Installation, Setup and Updates 0 06-24-2010 05:48 PM
Clean Install Windows 7 with Upgrade Media Nibiru2012 Installation, Setup and Updates 0 12-22-2009 08:03 PM
Clean Install Windows 7 with Upgrade Media Nibiru2012 Installation, Setup and Updates 2 12-04-2009 07:30 PM
Repair Install Ian System Administration 0 07-16-2009 04:04 PM


All times are GMT +1. The time now is 05:34 AM.
W7Forums is an independent website and is not affiliated with Microsoft Corporation.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33