1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

A Word of Warning to All Scrapebox Users !

Discussion in 'Black Hat SEO' started by deltrum, Aug 14, 2010.

  1. deltrum

    deltrum Junior Member

    Joined:
    Aug 1, 2010
    Messages:
    102
    Likes Received:
    68
    I set my laptop up yesterday to embark on its usual harvest/post session. I harvested approx. 40k urls and start to run slow commenter. Went to bed as usual.

    Came down this morning to find that the explorer.exe service had been terminated and bitdefender was advising of a virus that it had blocked....I thought fine.

    Restarted the system and blue screen. Restarted again and quite possibly, saw the most resistant form of malware had installed itself....I had been rooted.

    Booted into safe mode, tried all the usual AV scan, malware scan etc...but nothing.

    Apparently, this is the start of a new breed of malware that roots itself in tdss.exe and services.exe.

    I managed to get rid of it by removing all registry entries, ccleaner, hijackthis, malwarebytes, trendmicro online.

    Nothing would budge this when booted normally....no exe could be started all AV protection had been disabled...

    So, lesson learnt....all future scrapebox work shall be undertaken in vmware.

    Just thought I would let you all know....beware ;)
     
    • Thanks Thanks x 7
  2. abdaar007

    abdaar007 Junior Member

    Joined:
    Jul 15, 2010
    Messages:
    136
    Likes Received:
    55
    Occupation:
    ChemE BS Student
    Location:
    TeHas
    Whoa thanks for the heads up bro...I will get vmware immediately now
     
  3. deltrum

    deltrum Junior Member

    Joined:
    Aug 1, 2010
    Messages:
    102
    Likes Received:
    68
    Trust me mate....I am used to picking up and fixing viruses but this piece of malware really had me stumped....thought a reformat was going to be required.
     
  4. Vaolla

    Vaolla Registered Member

    Joined:
    Aug 7, 2010
    Messages:
    88
    Likes Received:
    12
    nice lesson for everyone , I must get cmware too now I guess.
     
  5. LyNHS

    LyNHS Regular Member

    Joined:
    Jul 20, 2010
    Messages:
    282
    Likes Received:
    98
    Occupation:
    Google AdSense
    Home Page:
    That exact same thing happened to me - and I'm not actually Joking. I contacted ScrapeBox for a new download URL and reset it this morning - only, I'm not even attempting to fix my Laptop... it's over 5 years old and only works in Safemode ...

    I'm not sure I completely understand the reason when you say explorer.exe, but all I know is the blue screen and that is exactly what I experienced soon after ScrapeBox crashed ... I just thought it was an update thing.

    Hmmm ... thanks for the info though, I thought it was just me !
     
  6. mariosocieto

    mariosocieto Regular Member

    Joined:
    Mar 23, 2010
    Messages:
    274
    Likes Received:
    100
    Location:
    sin.CITY
    thnkas for sharing sir, hope your programs is okay
     
  7. gregstereo

    gregstereo Elite Member

    Joined:
    Oct 5, 2009
    Messages:
    1,833
    Likes Received:
    1,027
    Occupation:
    I'm known to locate certain things from time to ti
    Location:
    Moose Factory, ON
    As with any BH software, running solid security software and regular scans/monitoring is essential.
     
  8. deltrum

    deltrum Junior Member

    Joined:
    Aug 1, 2010
    Messages:
    102
    Likes Received:
    68
    I think the malware came through when SB was parsing urls. Anyway, load a virtual environment....safest way ;)
     
  9. bobwhite44

    bobwhite44 Newbie

    Joined:
    Jan 13, 2010
    Messages:
    17
    Likes Received:
    6
    wow - thanks!
     
  10. aznxmtg

    aznxmtg Regular Member

    Joined:
    Jul 9, 2010
    Messages:
    327
    Likes Received:
    48
    I have malwarebtyes installed along with comodo firewall and another av. No shit is getting pass me :D And I run it on my laptop where it has no connections to my other computers.
     
    Last edited: Aug 14, 2010
  11. bbrez1

    bbrez1 Power Member

    Joined:
    Feb 21, 2009
    Messages:
    675
    Likes Received:
    2,360
    U should always run BH software on a virtual computer
     
  12. theindiaphile

    theindiaphile Senior Member

    Joined:
    Jul 26, 2010
    Messages:
    830
    Likes Received:
    245
    Can someone recommend a good article about setting up a virtual computer - this is not something I know about..?
     
  13. bilbo

    bilbo Power Member

    Joined:
    Jan 26, 2009
    Messages:
    644
    Likes Received:
    1,134
    Occupation:
    an actor on wizard of oz - the 3rd munchkin
    Location:
    middle earth
    dont you wear protection while your in bed :) ............like kapasky and blockers etc.
     
  14. deltrum

    deltrum Junior Member

    Joined:
    Aug 1, 2010
    Messages:
    102
    Likes Received:
    68
    For virtual environment, check out vmware

    Bilbo, this malware managed to pass and disable all blockers.
     
  15. kez1000

    kez1000 Supreme Member

    Joined:
    Jul 24, 2009
    Messages:
    1,403
    Likes Received:
    1,340
    Location:
    UK
    dam so that what it is..i have this crazy peiece of adware on my pc that i cannot get rid of...when ever i shut down my pc i get the blue screen of death. Avg,malware and hitman cannot get rid of this adware
    Posted via Mobile Device
     
  16. deltrum

    deltrum Junior Member

    Joined:
    Aug 1, 2010
    Messages:
    102
    Likes Received:
    68
    Sounds like it mate....this new type of malware has only started circulating this month....Norman and Kaspersky has issued a TDSSRootkit removal tool however, I had to search through multiple dir paths and registry to remove.
     
  17. sqhunter

    sqhunter Regular Member

    Joined:
    Jul 8, 2009
    Messages:
    385
    Likes Received:
    267
    Thanks for the info. I took a fast look at vmware and did not understand anything, looks like server software and also not free.. alternatively could sandboxie run sbox and we be safe that way????
     
  18. kez1000

    kez1000 Supreme Member

    Joined:
    Jul 24, 2009
    Messages:
    1,403
    Likes Received:
    1,340
    Location:
    UK
    dam so that what it is..i have this crazy peiece of adware on my pc that i cannot get rid of...when ever i shut down my pc i get the blue screen of death. Avg,malware and hitman cannot get rid of this adware
    Posted via Mobile Device
     
  19. xxf8xx

    xxf8xx Supreme Member

    Joined:
    Nov 30, 2009
    Messages:
    1,321
    Likes Received:
    596
    Occupation:
    IM
    Guys vmware is simple. Get vmware player if you want a free version. Then just download a vm. I'm sure you can find one.
     
  20. mirrorer

    mirrorer Jr. VIP Jr. VIP

    Joined:
    Jan 30, 2009
    Messages:
    1,164
    Likes Received:
    1,030