Notices
Site Feedback / Suggestions If you have any suggestions or want to see something voice your opinion in here.

Just got a mess of Trojan's and Malware from here.

Thread Tools
 
Search this Thread
 
Old Apr 20, 2011 | 05:02 AM
  #1  
ReCoil's Avatar
Thread Starter
Newbie
 
Joined: Oct 2009
Posts: 5
Likes: 0
From: Lenexa, KS
Just got a mess of Trojan's and Malware from here.

Just FYI guys, I just got about 20 articles of various Trojans, Viruses, Tracker Cookies and Malware from a little window on Evolutionm.net that said "Evolutionm.net requires a plugin to operate." And had a little button to download the plug-in, when clicked it downloads all that crap on your computer and shuts down all your programs and won't let you start any new programs or services. Just giving the heads up!

Last edited by ReCoil; Apr 20, 2011 at 05:06 AM.
Reply
Old Apr 20, 2011 | 06:19 PM
  #2  
Speedlimit's Avatar
Admin Emeritus
 
Joined: Jan 2003
Posts: 2,239
Likes: 101
From: NR Reading PA
Hi,

We have had no other reports of such a problem. We'll keep this thread open should others see a similar problem. Thanks.

Bob..
Reply
Old Apr 20, 2011 | 06:30 PM
  #3  
dacib's Avatar
Evolving Member
iTrader: (1)
 
Joined: Dec 2010
Posts: 310
Likes: 1
From: Miami
Use combofix and malwarebytes to clean your computer. I'm an IT guy and these 2 tools do miracles.

Combofix - run it first in Safe Mode(when it asks you if you want to download Microsoft Recovery or something like this click NO, you don't need it). After it's done it will ask you to reboot, do so and let it go in normal mode. Once you log in normally run it again. When finished reboot again.
You can download it from here, it's free: http://www.bleepingcomputer.com/down...virus/combofix

Malwarebytes - After you're done with Combofix download and install the free version from Malwarebytes.org. After install click on update tab and do the update, when finished run Full Scan. When the scan it's finished it will take to a windows that shows you everything it found. If it finds select everything it finds and click remove. It might ask you to reboot so it can remove some that are still running.


Good Luck!!!
Reply
Old Apr 20, 2011 | 06:41 PM
  #4  
Get Rad's Avatar
Evolved Member
iTrader: (5)
 
Joined: Nov 2009
Posts: 589
Likes: 1
From: Central New Jersey
Originally Posted by dacib
Use combofix and malwarebytes to clean your computer. I'm an IT guy and these 2 tools do miracles.

Combofix - run it first in Safe Mode(when it asks you if you want to download Microsoft Recovery or something like this click NO, you don't need it). After it's done it will ask you to reboot, do so and let it go in normal mode. Once you log in normally run it again. When finished reboot again.
You can download it from here, it's free: http://www.bleepingcomputer.com/down...virus/combofix

Malwarebytes - After you're done with Combofix download and install the free version from Malwarebytes.org. After install click on update tab and do the update, when finished run Full Scan. When the scan it's finished it will take to a windows that shows you everything it found. If it finds select everything it finds and click remove. It might ask you to reboot so it can remove some that are still running.


Good Luck!!!
What if this is a link to the malware? Someone else click this link and let us know
Reply
Old Apr 20, 2011 | 07:26 PM
  #5  
user 629782012's Avatar
Account Disabled
 
Joined: Apr 2011
Posts: 251
Likes: 0
I had the same thing earlier today.. honestly i can't remember which page i was on however the section i was viewing was the wheels suspension secton. once it poped up windows security essentials said not to open it so i clicked alt f4 closed it all down. i haven't had anything else pop up.. this was about 2pm in the afternoon
Reply
Old Apr 20, 2011 | 08:31 PM
  #6  
beetle_orange's Avatar
Evolved Member
iTrader: (58)
 
Joined: May 2008
Posts: 1,900
Likes: 5
From: Illinois
I tried combo fix but as soon as I tried running it my avg thought it was a virus.
Reply
Old Apr 21, 2011 | 08:18 AM
  #7  
dacib's Avatar
Evolving Member
iTrader: (1)
 
Joined: Dec 2010
Posts: 310
Likes: 1
From: Miami
You have to run it in Safe Mode.

Or get rid of Windows and go with Linux(Ubuntu), no viruses at all!!!
Reply
Old Apr 21, 2011 | 10:29 AM
  #8  
Mad_SB's Avatar
Evolved Member
iTrader: (8)
 
Joined: Apr 2003
Posts: 2,138
Likes: 0
From: Georgia
Originally Posted by Speedlimit
Hi,

We have had no other reports of such a problem. We'll keep this thread open should others see a similar problem. Thanks.

Bob..
I got the same popup the other night but knowing the page was displaying just fine I did not bother clicking... I'm sure it was a malware add served up through doubleclick or whomever the add service is.
Reply
Old Apr 21, 2011 | 10:31 AM
  #9  
Mad_SB's Avatar
Evolved Member
iTrader: (8)
 
Joined: Apr 2003
Posts: 2,138
Likes: 0
From: Georgia
Originally Posted by dacib
You have to run it in Safe Mode.

Or get rid of Windows and go with Linux(Ubuntu), no viruses at all!!!
no, your box just gets rooted instead

At the end of the day personal computer security is all about internetz common sense... never click something if you don't know what it is or why you are seeing it.

Last edited by Mad_SB; Apr 21, 2011 at 10:33 AM.
Reply
Old Apr 21, 2011 | 10:41 AM
  #10  
bluepeartype-s's Avatar
Registered User
iTrader: (17)
 
Joined: May 2004
Posts: 486
Likes: 3
From: Arizona...Hot!
Originally Posted by Mad_SB
no, your box just gets rooted instead

At the end of the day personal computer security is all about internetz common sense... never click something if you don't know what it is or why you are seeing it.
Agreed... if you don't know it don't click it..or open it.

I also work in IT...when the pop-ups shows up go into the task manager (CNTL + ATL +DEL) and kill allthe..

iexplore.exe running underneither processes tab. This way you don't click anything on the pop-up.

Last edited by bluepeartype-s; Apr 21, 2011 at 10:44 AM.
Reply
Old Apr 21, 2011 | 12:18 PM
  #11  
ReCoil's Avatar
Thread Starter
Newbie
 
Joined: Oct 2009
Posts: 5
Likes: 0
From: Lenexa, KS
This was no run of the mill pop-up ad or something. It came up like plug-ins usually do in Mozilla and said I needed a plug-in to run something on EvoM and so I clicked to install plug-in like I've done many times for other plug-ins and it jacked my stuff up. I've already got everything fixed again, it's no problem anymore, just very annoying to have to start in safe mode and all.

Last edited by ReCoil; Apr 21, 2011 at 12:23 PM.
Reply
Old Apr 21, 2011 | 12:44 PM
  #12  
Speedlimit's Avatar
Admin Emeritus
 
Joined: Jan 2003
Posts: 2,239
Likes: 101
From: NR Reading PA
Originally Posted by ReCoil
This was no run of the mill pop-up ad or something. It came up like plug-ins usually do in Mozilla and said I needed a plug-in to run something on EvoM and so I clicked to install plug-in like I've done many times for other plug-ins and it jacked my stuff up. I've already got everything fixed again, it's no problem anymore, just very annoying to have to start in safe mode and all.
If anyone sees that pop up, please get a screen capture. Thanks.

Bob..
Reply
Old Apr 21, 2011 | 12:53 PM
  #13  
dacib's Avatar
Evolving Member
iTrader: (1)
 
Joined: Dec 2010
Posts: 310
Likes: 1
From: Miami
Originally Posted by Mad_SB
no, your box just gets rooted instead

At the end of the day personal computer security is all about internetz common sense... never click something if you don't know what it is or why you are seeing it.
Never heard of any Linux user getting their system rooted... But true about common sense.
Reply
Old Apr 21, 2011 | 05:25 PM
  #14  
Speedlimit's Avatar
Admin Emeritus
 
Joined: Jan 2003
Posts: 2,239
Likes: 101
From: NR Reading PA
Originally Posted by ReCoil
This was no run of the mill pop-up ad or something. It came up like plug-ins usually do in Mozilla and said I needed a plug-in to run something on EvoM and so I clicked to install plug-in like I've done many times for other plug-ins and it jacked my stuff up. I've already got everything fixed again, it's no problem anymore, just very annoying to have to start in safe mode and all.
Does this look like the pop up? Thanks.



http://support.mozilla.com/media/upl...6525-385-1.png
Reply
Old Apr 22, 2011 | 04:16 AM
  #15  
ReCoil's Avatar
Thread Starter
Newbie
 
Joined: Oct 2009
Posts: 5
Likes: 0
From: Lenexa, KS
Originally Posted by Speedlimit
Does this look like the pop up? Thanks.



http://support.mozilla.com/media/upl...6525-385-1.png

Yes, that looks exactly like the pop-up I got.
Reply



All times are GMT -7. The time now is 03:48 PM.