Jump to content


I'm Infected!!


  • Please log in to reply
13 replies to this topic

#1 Guest_scaramonga_*

Guest_scaramonga_*
  • Guests

Posted 31 December 2006 - 08:22 AM

Well........I'm infected :bluerip: :dribble:

I dunno how the hell it happened but I am!

Posted Image

firefox.exe always running 24/7 even after reboot! We can see the 'real' version as I have Firefox open and its using correct memory resources.

If I delete the file from Task Manager it returns instantly. This is effecting NET applications like online gaming/MSN/Skype etc where they have slowed to a crawl.

NOD refuses to recognise it as does Spysweeper, Spywareblaster and Adaware. Tried a couple of online virus checkers and they don't recognise either!!

Done a search on Google and this may be the 'Poison Ivy' virus?? :cheers: :cheers: I see no way of removing it as I really don't know what this 'firefox.exe's' real properties are??

Reinstall is looming guyz!! :dribble: :drunk:


Quote

Since June of 2006, numerous users have reported experiencing similar issues with their browser which were later found attributable to a malicious trojan - specifically one based on Poison Ivy, an advanced "reverse connection", firewall-bypassing remote administration tool. The trojan creates a 'server' file on the affected system which alerts the trojan-maker when an affected system is online and which then gives access to, monitoring of, and even complete control of an infected user's system - giving him (among other things) the possibility to steal usernames & passwords, banking or credit card info, or any other private information that may have been stored, typed or viewed on-screen while the computer is infected. The default settings is for the malicious 'server' file to inject itself into the target system's Default Browser memory space and then run as a phony 'duplicate' browser process, which enables it to bypass detection by firewalls and routers. So while many Firefox users naturally assumed the problems they were experiencing were a 'Firefox problem', they would in fact have happened whichever browser was set as their system Default.

While there are other similar Remote-Admin apps used by trojan-makers, Poison Ivy quickly became popular for a number of reasons - it was new, it could be deployed without arousing much suspicion, it injected itself into the Default Browser process, and it had an attractive range of monitoring & set-up features. One such feature was the apparently unique 'Persistence' option - if enabled, the server file located on the infected system will restart itself even when the process is manually killed by the user - which means more 'up time' for the hacker - no waiting for the infected user to reboot their system or manually restart an affected application. Another handy feature is the 'Melt' function - which deletes the original infected file upon first run, so that a user cannot inspect it or uploaded to an anti-virus company's database.

This may explain why most of the popular spyware & antivirus utilities - and even the usual rootkit detectors - fail to detect anything malicious on affected systems.

Edited by scaramonga, 31 December 2006 - 08:27 AM.


#2 Sphere

Sphere

    The moth next to my brain is Bart, say hi to him if you like

  • Sponsor
  • PipPipPipPipPip
  • 2,355 posts
  • Location:*tap* Behind ya!
  • Interests:I'm a Dutchy, that means I'm not a German (which doesn't sound/look the same to me!) also, being a Dutchy means I'm an idiot... sort off!

    And I def. need to get a real life again... I'm bored with my current life, ideas can be pm'd to me!
  • Country:Dutchyland

Posted 31 December 2006 - 02:00 PM

You could try to remove it.... there's some software, I'll check when I'm home, which can kill and exclude programs from starting at boot.

It can also even delete the program... if the program allows it and it's killed first

#3 m.oreilly

m.oreilly

    rog'er wilco

  • Admin
  • PipPipPipPipPipPip
  • 8,847 posts
  • Country:lower uncton

Posted 31 December 2006 - 05:16 PM

geez scara!!! oh man, wtf??? please post back the minute you find a fix :bluerip: . patty was complaining about FF being loaded on her rig even after she exited...

#4 Nvyseal

Nvyseal

    Chairman of the Board

  • Administrator
  • PipPipPipPipPipPip
  • 9,821 posts
  • Location:From the whatever it is, Pluto
  • Country:USA

Posted 31 December 2006 - 06:18 PM

Wow! thats too bad! :dribble: Now see, if you were running that bloated "Vista" software, it would have notified you of something trying to access and install on your system via the UAC. It would have said :bluerip: Did you want to install me?? :crazy:


You may want to try: Trojan Remover if it is a trojan

#5 m.oreilly

m.oreilly

    rog'er wilco

  • Admin
  • PipPipPipPipPipPip
  • 8,847 posts
  • Country:lower uncton

Posted 31 December 2006 - 10:20 PM

:dribble: :dribble:






hey rik... :bluerip:

#6 Guest_scaramonga_*

Guest_scaramonga_*
  • Guests

Posted 31 December 2006 - 11:32 PM

Quote

Now see, if you were running that bloated "Vista" software, it would have notified you of something trying to access and install on your system via the UAC

:bluerip: :dribble: :dribble:

OK......after trying various methods to get rid of this I gave in :cheers:

Wiped the drives and done a fresh reinstall......back to XP64 and all seems well so far :cheers: apart from Firefox taking an age to initially start for some reason??

This is one bad virus so be on the lookout in that task manager!

#7 nitram

nitram

    NITRISCO

  • Members
  • PipPipPip
  • 233 posts
  • Location:Nottingham England
  • Country:England

Posted 31 December 2006 - 11:43 PM

View PostNvyseal, on Dec 31 2006, 06:18 PM, said:

Wow! thats too bad! :drunk: Now see, if you were running that bloated "Vista" software, it would have notified you of something trying to access and install on your system via the UAC. It would have said :cheers: Did you want to install me?? :crazy:
You may want to try: Trojan Remover if it is a trojan


View Postm.oreilly, on Dec 31 2006, 10:20 PM, said:

:dribble: :dribble:
hey rik... :bluerip:

Why is it that you 2 are allways sooooo helpful. :cheers:

#8 Guest_scaramonga_*

Guest_scaramonga_*
  • Guests

Posted 31 December 2006 - 11:56 PM

View Postnitram, on Dec 31 2006, 11:43 PM, said:

Why is it that you 2 are allways sooooo helpful. :dribble:

LOL!

It's OK buddy.......they are just getting me back for all the leg pulling I give em about Vista :dribble: :bluerip:

#9 Camaro

Camaro

    Established Member

  • Members
  • PipPipPipPipPip
  • 907 posts
  • Country:USA

Posted 01 January 2007 - 12:12 AM

true but it's quite possible that vista would not have been a help, read what it says it insinuates itself as your browser. even IE im assuming, if that is your default browser, an you know vista already lets IE do as it wants......... lol

#10 LoneWolfMage

LoneWolfMage

    Member

  • Members
  • PipPipPip
  • 33 posts
  • Country:USA

Posted 01 January 2007 - 03:25 AM

Greetings~

I would have suggested .. if i had remebered at the time and didnt get sidetracked.. a good program that you can also get analyized on line called Hijack This ..most ofd you here may know of it or may have even used it .. as far as im concerned .. its a really good program .. and free .. i have used it on MANY puters without a problem .. with removing MANY diffrent things that may not be able to removed other wise ,,,

For future Refrence Hope it will help :bluerip:
LoneWolf
HijackThis Download

On Line Analysis

#11 WFO

WFO

    Super Adv. Member

  • Members
  • PipPipPipPip
  • 569 posts
  • Country:USA

Posted 01 January 2007 - 03:51 AM

Too little too late... Trojan Hunter still offers a free 30 day trial... http://www.misec.net/ and there is always ewido... http://www.ewido.net/en/

My favorite AT is BOClean. It is pay only. Lifetime upgrades and updates It is the best. Works in Vista X64, XP...etc...etc. :dribble: Those that use BOClean never have to post HJT logs. :dribble: http://www.ewido.net/en/

Sorry if I sound like a commercial but it's soooo true. :bluerip:

#12 Tweak

Tweak

    Established Member

  • Members
  • PipPipPipPipPip
  • 674 posts
  • Country:US

Posted 01 January 2007 - 06:42 PM

HiJack This, LSP Fix may have been useful also, and instead of ewido use the AVG version as it is the same basic program but more uptodate and works well. moosoft also offers The Cleaner which may have been useful and Process Viewer may have been helpful in some aspects. Maybe using Opera would have helped, maybe not, but I'll stick with it.

#13 BlueScreenOfDeath

BlueScreenOfDeath

    ~* Hardware & Beta Guru *~

  • Members
  • PipPipPipPip
  • 479 posts
  • Location:Little Rock, AR
  • Country:USA

Posted 02 January 2007 - 01:39 AM

View Postnitram, on Dec 31 2006, 05:43 PM, said:

Why is it that you 2 are allways sooooo helpful. :dribble:

it gives them a warm fuzzy feelin inside :bluerip:

#14 m.oreilly

m.oreilly

    rog'er wilco

  • Admin
  • PipPipPipPipPipPip
  • 8,847 posts
  • Country:lower uncton

Posted 02 January 2007 - 05:19 AM

View PostBlueScreenOfDeath, on Jan 1 2007, 05:39 PM, said:

it gives them a warm fuzzy feelin inside :bluerip:
:dribble:




1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users