What the hell? Computer suddenly infected like crazy

Adlad I so relate my friend. I've been working on my Dads PC on and off for about 3 days...got at least 10 hours into and still not 100% in the clear from this crap.

Regardless of HOW it happened or exactly what caused it I think it's a good idea to just know SHIT is going to happen so be prepared to deal with it. It helps to know what but it could have come from so many sources.

Here's the bitch I've been dealing with from...

System Security 4.52...it's same as System Security 4.51...anyway... LOTS of searched on this Bad ass. I"ve been online for over 10 years and never had a PC locked down so tight.

Forget using any programs to fix it but I could not even visit some of the well known sites from the PC even in Safe Mode to correct the issue.

Even tried doing a search on google for Malwarebytes, what we use, and when I clicked a link to open the url from google got an error and would not display their site!

If anyone else is having issues this may help. It's the first thing that gave me back access to Dads PC so I could move forward and execute programs to clear things up.

Basic Info To TERMINATE OR KILL the System Security 4.51/ 4.52 crap....

Code:
Download the following file and save to your desktop.

http://live.sysinternals.com/procexp.exe

Rename the file to winlogon.exe and the run it.

Inorder to get MBAM installed you will need to identify and terminate/kill the SystemSecurity process.
As you see from the screenshot it very easily identified by its shield icon and use of random numbers for its executable. eg 1234567.exe 638476435.exe 453732.exe and the list goes on.

Highlight the shield icon/random.exe line and rightclick and select kill process.

SystemSecurity will no longer be active in memory but is still installed so best let MBAM rip it good and proper smile.gif

More info on the System Security issue which sounds very similar to your issue is here...

Code:
http://www.malwarebytes.org/forums/index.php?showtopic=17583

What a pain in the ass this has been. I'm working as much as I can trying to make money and I need to use my Dads PC from his house as I'm taking care of my mother with health issues.

Hope you get everything taken care of and cleaned also.
 
Adlad,

You actually got off light. 31/2 weeks ago the Business section of USA Today had a story of a variation of your situation when a national wave of such attacks occurred. The most successful was a Norton Anti Virus warning which hijacks the browser and basically holds it for ransom by saying there's a zillion Trojan Horses and worse and if you don't buy their remedy you'll lose your computer. You pay and lose anyway.

With respect I'm not sure how I got off light. This thing totally ruined my PC and had I not had all my crucial data backed up already I would have been in deep shit.

I literally went from a clean, fast, updated system, to a useless piece of junk in under 5 minutes. 25+ confirmed trojans, messed up GUI, network connections and various files deleted... This thing ruined my computer.

In fact, short of taking a pistol to the hard drive, I'm not sure how it could have been much worse
 
Adlad I so relate my friend. I've been working on my Dads PC on and off for about 3 days...got at least 10 hours into and still not 100% in the clear from this crap.

Sorry to hear that. It seems this is a new wave of viruses that is actually based on a pretty smart (albeit annoying) concept. To trick people into thinking it's legit anti-virus software and that you have a ton of trojans installed on your system. Then when the person goes to buy the software they probably screw them over again.

What really surprised me though is how this thing made it onto my system. I'm no newbie with computers and I know when somethings not right.

I reckon this was also a modded version. Something that does actually install real trojans that kill your PC. Probably some guy just having fun with his genetically modified e-virus.

Malwarebytes definitely seem to be the leading authority on this stuff though. I've installed their latest version of Anti-Malware and intend to use it from now on. Although again, I'm not sure this would have prevented the attack in the first place
 
There is a Type of "Trojan" that will change your internet connection to go through there DNS. So Everytime you get rid of it, It will reinfect you. It even goes so attempt to guess your router user name and password and change the dns in their. in order to get rid of it you have to be offline check your hosts file, internet properties, and wireless router make everything is correct. Then Use malewarebytes / Spybot to remove and recheck everything again make sure your connection is right. Then i'd recommend Updateing and scanning again. to make sure everything is fine. Figured this would be usefull if anyone else runs into the problem.
 
dude you got a keylogger.. that's bad!! you better reformat it
 
I am dealing with this AS I TYPE.
This morning all of a sudden POOF. that anti-virus messages comes up.

I stopped it temporarilly it seems by going into safe mode and deleting the 'new' files
(well not "new", but new) that were created when this happens. I also went into my registry and stopped a weird 123456.exe file. There's still something in there though because my spybot keeps alerting me that changes are trying to be made to my registry.

I beat it once before....hopefully i can again. (my spybot scanner won't even run!)

So now i'm running adware. Trying out that adware program/scanner someone suggested above and reading that page that somone suggested. Trying to avoid a format.

edit* Anyone suggest a good anti-virus program like NOD?
 
Once clean, i would fully recommend that you change a lot of passwords of the sites you recently have visited.
And stop downloading shares that dont have a virustotal scan report.
Even at that all shares could still possibly be infected so always run new things in a virtual atmosphere until you know its safe.
 
Norton Ghost is the way to go. Build your machine the way you like it and ghost it. If you get a virus/trojan that can't be cleaned off, just re-image. It takes ten minutes to re-image your PC and it's like nothing ever happened. You will also need a separate partition to store the image files, but if you need to rebuild your PC, then you can create one during the setup.
 
Thanks guys. My adware found 80 threats so far. Hopefully it nips it in the ass since my spybot won't scan.

And I downloaded that malware program Malware Bites, and now it won't even run setup.
 
Thats very true.

I would NOT recommend a second partition however.

I would suggest:

(a) Clone the computer to a second hard disc.
Put that disc somewhere safe

When the time comes to replace it, just stick in the other hard drive, boot from it (and recover any files etc), then reghost it, and put it on the "old" disc.

Very handy way to do it.

Or if you got RAID, even better, choose mirroring for RAID etc..


But then again not many people have RAID (unlike me).


Norton Ghost is the way to go. Build your machine the way you like it and ghost it. If you get a virus/trojan that can't be cleaned off, just re-image. It takes ten minutes to re-image your PC and it's like nothing ever happened. You will also need a separate partition to store the image files, but if you need to rebuild your PC, then you can create one during the setup.
 
Well I do have a 2nd hard drive on this machine. I may be forced to just revert to that.
 
*hugs his linux machine* :-)

linux has no exemption from viruses, in actuality the linux viruses that are out, are worst than windows viruses,though there is not as many as windows viruses they are rapidly being made, cause once they gain root access your screwed. :yield:

go download Avira Antivir
Commodo Firewall
Ad-aware
those are some of the best you can get for free, they are better than most commercial programs
and if you are still paranoid just go grab Deep Freeze, if you dont want to pay for it there are
unethical ways to get it;)
 
Last edited:
AVG kinda sucks. I use it when I'm too poor or don't feel like cracking a trial av. :P Use to have zone alarm suite.. with the firewall and all with over 100k trial days.

But are you sure it wasn't a picture on a site that said that? Also, stop downloading porn.. It gives you lots of adware and spyware and all.

Stop accepting files from people you dont really know. Who knows, they might be tryign to find your secrets to $$$$ a day/month. "supposedly" you are able to make .exe files into .jpg/other image files... dunno really tho
 
I actually do use a second HDD for my ghosting.. I just thought that for most people it is easier for them to partition rather than install disk #2. But yes, in the case that the HDD with the 2nd partition gets fried all together, you will have a totally independant disk to ghost from.

I am not sure how raid would save you from virii and trojii and such, considering that you would have a mirror of a virus.


Thats very true.

I would NOT recommend a second partition however.

I would suggest:

(a) Clone the computer to a second hard disc.
Put that disc somewhere safe

When the time comes to replace it, just stick in the other hard drive, boot from it (and recover any files etc), then reghost it, and put it on the "old" disc.

Very handy way to do it.

Or if you got RAID, even better, choose mirroring for RAID etc..


But then again not many people have RAID (unlike me).
 
I use to use AVG cause it was lite on system resources..

But truth is, AVG just gives you a false sense of security.. I got infected even thought I was always up to date with the definitions..

AVG is Terrible!!
 
Adlad,

No disrespect intended. I see your point. An absolute disaster. It sucks sour eggs!! I been there more than once! :(

This thread is helpful. Lots of valuable info. I should of listened to my buddy years ago. He said computer security would be the topic on everyone's lips. Major front page cyberattacks last week in the U.S. and S. Korea. The U.S. National Security Agency and Homeland Security Agency got hit hard. They couldn't even gag the story! :eek:

silentthunder
 
What do you mean by running new things in a virtual atmosphere? I have never heard of doing this. How do you test a download?


Once clean, i would fully recommend that you change a lot of passwords of the sites you recently have visited.
And stop downloading shares that dont have a virustotal scan report.
Even at that all shares could still possibly be infected so always run new things in a virtual atmosphere until you know its safe.
 
Back
Top