News:

SMF - Just Installed!

Main Menu

may be gone..

Started by indigowulf, January 14, 2010, 02:41:16 PM

Previous topic - Next topic

indigowulf

so, 3 days ago, I ran a system scan. It came back squeaky clean. Since then, the only risky thing Ive done was to download an art file for my birds of prey adoptables, from the artist. Im thinking her computer must be infeceted, and the virus piggy backed to my system.

My scanner keeps telling me it found, quarinteened, and deleted the infected files, but every few minutes it pops itself back up. Clearly the scanner doesnt see the file that its reinstalling itself from. Tried multiple toys and tools to find it. All say it doesn exist. When I can get my browser to work, google and other sites have no info on this. my best cleaner updated thier website 4 days ago, and this isnt on it. so, its new, and its nasty.

Im writing this in notepad, because my browser keeps crashing every few seconds. its also trying to *constantly* refresh to a page called myclock.info/fp/index.html Now I wouldnt recomend trying to GO to that adress, im sure its very very unsafe. However, if anyone has any info on it, or can actually search it, Id appreciate it!

So, if you dont see me for a bit, thats why. I have a gidget auction thats sposed to be ending in a few hours. ill do that when i get back, dont worry!


YourLoveOnly

Good luck with that! I'm afraid I can't be of much help, but I hope it gets fixed soon. :)

indigowulf

it would appear I had some sort of add-on running (ie addon) that for some reason just crashed itself. I got an error saying addon crashed, ie closed, and now that i re-open ie, its smooth. well, for the moment at least. still running my *third* virus-scan. first 2, from different companies, both said I was good. 3rd one has already identified 4 infected trojan files. waiting for it to finish scan to go delete all the icky.

man, i hope if this did piggyback in the art file zip, the bird psd itself isnt corrupt.

oh, that addon was called bzhcwcio2.dll  time to google!

if anyone wonders, i crashed it by refreshing a page it was refusing to show faster then it could block it lol


JBGarrison72

#3
My latest infection included a trojan: awexe.exe which I found running in my processes.  It had d/l'd other stuff, which disabled my AV software at such a deep level that I couldn't uninstall and reinstall any AV software.  I had to reformat.  This was the other day (as you know).  There was also another process running which was an ad malware... redirecting my browser to a spam site; don't remember the process off hand.
- Jeffrey Boyd Garrison

indigowulf

whatever that addon is, google has no knowledge of it lol. ive only downloaded 2 things in like .. 2 months. after last one, virus scan came up clean. after this bird file, its dirty. so im 99% sure i got it that way. which means no amount of anti-vi software would have saved me, i would have dl'd the file intentionally :(

ive already PM'd the artist i got it from and alerted her to possible problem. which kinda sucks, cuz she has 3 more birds to template and send me files on


JBGarrison72

Possible that she d/l'd a dirty brush tool which infected the PSD files?  If I were a hacker virus coder, that's how i'd do it.
- Jeffrey Boyd Garrison

JBGarrison72

Actually, not to beat a dead horse, but I'm not familiar with PSD files and how the'yre opened by graphics programs, but I'm guessing it's probably not even possible to infect PSD files unless there were a way to exploit a vulnerability in the way graphics program opens them... again, I'm not an expert, but on second thought it seems doubtful that PSD files could carry a useable execution payload.
- Jeffrey Boyd Garrison

springacres

Ooh, this reminded me to check my anti-virus software.

Also, unless there were hidden files in the .zip, I have no idea how the PSD would have given you the virus, Indigo.  I know Gimp seems to have a way to use plugins somehow, but I haven't explored that at all so I don't know if maybe that was the culprit somehow?

I use Symantec, and it's set up to scan certain types of files immediately (every time I insert a memory stick, for instance, Symantec pops up and starts scanning it for viruses).  Does your anti-virus program have a setting like that, or can you set it up to scan every so often?


indigowulf

ya, the first .psd was emailed over (for the chick) normally, with no issues. the 2nd was too large and had to be zipped. One hand, when I informed her, just to be helpfull.. she tells me her virus software is up to date and hasnt caught anything. On the other hand, she tells me, in the next sentence, she thinks her (a certain file we both have) has a trojan. lol. Its possible I got it a while ago and it just didnt set activate until today.

You see, I have this mechanical curse. If someone else touches a computer I use, it has a problem. There's never an exception. So, even tho the comp Im using belongs to my roommate, it was reformatted and I took it over. His comp has a power supply issue, and he used mine to try to look at a certain comic.

Now, I had been on browsing moments before with no problem. I also read this comic he tried to read. However, the moment he tried to open a browser and type in the comic adress, an error popped up, and that was the first sign of the virus.

I hate my curse!

hopefully Im clean now, did online virus scanner thing since the 2 I have installed caught nothing, then manually removed the files it caught. No appearant issues since then.


springacres

Sounds complicated.  But I'm glad everything seems to be working for you now.  *knocks on wood*


indigowulf

I have the worst luck. I was switching rooms around with coolduff, and my computer desk support leg broke. so, my comp is sitting on the floor, all the parts seperated (keyboard, ect). Im logging in from coolduff's comp, to say I cant access my adoptable files until I get my baby put back together in a functional capacity.