Previous in Forum: csrss.exe   Next in Forum: Access Database
Close
Close
Close
20 comments
Rate Comments: Nested
Power-User

Join Date: Oct 2008
Location: Meherrin Virginia
Posts: 319
Good Answers: 6

Virus Pro Copy Cat

08/01/2010 1:08 PM

Has anyone ran up on this latest scam, it appears to be an offshoot of virus pro only this one can actually disable your virus program, disable task manager and any other selection you try to make.

It also has icons resembling AVG and states that it originates in windows. It also says it is from virus pro.

Right now I intend to disable the ISP modem and boot up in safe mode and see if I can find any recently added files that don't make sense. I intend to evaluate the situation at that point.

I think it got entrance when the computer was on face-book.

Any other ideas?

__________________
If you fail to follow through, you will fail.
Register to Reply
Interested in this topic? By joining CR4 you can "subscribe" to
this discussion and receive notification when new comments are added.

Good Answers:

These comments received enough positive votes to make them "good answers".

"Almost" Good Answers:

Check out these comments that don't yet have enough votes to be "official" good answers and, if you agree with them, vote them!
2
Guru

Join Date: Oct 2008
Location: Deepest Darkest Rutherford Oz
Posts: 951
Good Answers: 145
#1

Re: Virus Pro Copy Cat

08/01/2010 8:41 PM

Just copped this one on my work computer, it snuck through the defenses.

You need to shut down everything straight away, dont click on any of the "buttons" on the pop ups

Shut down your computer and reboot in safe mode.

Download a antivirus program from another source onto the affected computer, and run the program. Then delete the virus "locker" or vault. Then go through your directories and remove any folder (not just the files within) that has a weird name.

Refer to the antivirus report log.

This virus is a version of one that has been around for a while, it is insidious in that it will replicate itself somewhere else on your computer if you try and remove it "live".

It disables the Task Manager and any existing antivirus/adware program you have running. Which is why you need to load a new one on with your computer running in safe mode.

__________________
There are two reasons for a man to do a thing, One that sounds good, and the real one...
Register to Reply Good Answer (Score 2)
Power-User

Join Date: Jul 2008
Location: Adelaide, Australia
Posts: 403
Good Answers: 14
#2
In reply to #1

Re: Virus Pro Copy Cat

08/02/2010 12:23 AM

Hi

I rated that a good answer, well done.

I did a System Restore in safe mode, then ran Malwarebytes in full scan to find the offending files. I trust we are talking the same virus.

Tony

__________________
The nice thing about Standards is there are so many to choose from.
Register to Reply Score 1 for Good Answer
Power-User

Join Date: Oct 2008
Location: Meherrin Virginia
Posts: 319
Good Answers: 6
#7
In reply to #2

Re: Virus Pro Copy Cat

08/02/2010 9:09 AM

I tried the system restore path in safe mode and this thing must turn that off as well and with xp that clears out the history. As smart as this thing seems it must also rename/create files and directories with random names. I think this hard drive might be trash from a confidence stand point.

__________________
If you fail to follow through, you will fail.
Register to Reply
Guru

Join Date: Dec 2006
Location: Germany 49° 26' N, 7° 46' O
Posts: 1950
Good Answers: 109
#3
In reply to #1

Re: Virus Pro Copy Cat

08/02/2010 3:06 AM

Great Advice, thank you. GA

RHABE

Register to Reply
Guru

Join Date: Dec 2009
Posts: 581
Good Answers: 15
#8
In reply to #1

Re: Virus Pro Copy Cat

08/02/2010 10:37 AM

You need to shut down everything straight away, dont click on any of the "buttons" on the pop ups

Assuming the virus is trying to infect your computer via a browser pop-up, apparently the most popular method these days, a shutdown is not necessary. Ctrl-alt-delete to bring up Task Manager, then kill the "browser".exe application. Then don't go back to that address when you resume browsing.

Depending on the way you shut down, you can create as much damage as a virus. Shutting down through the start menu is generally ok, but removing power is sometimes not. As Tob says, do not click anything in the browser window, not even the pop-up's X button. Do not hit the Escape key to dismiss the pop-up. (If I were a virus writer, I would definitely hook my code into those functions.)

Much of this advice is older than dirt (very young dirt, of course), but new computer users are being created every day.

__________________
Ignorance is no sin. Willful ignorance is unforgiveable.
Register to Reply
Guru

Join Date: Oct 2008
Location: Deepest Darkest Rutherford Oz
Posts: 951
Good Answers: 145
#12
In reply to #8

Re: Virus Pro Copy Cat

08/02/2010 4:06 PM

My experience with this particular beastie is that it doesn't allow Task Manager to run at all.

Yes the "pro bug" popped up again later and I had to go through the process again.

Frustrating thing for me is that all of our Antivirus/malware protection is done at the servers, so once it's past that its almost a free for all. Our IT policy doesn't afford me god status on my computer so I'm not allowed to "individually" fortify my work machine.

Unlike my home machines which hide behind a router firewall, as well as Anti virus/mal/botware.

Now I was running both IE8 and Firefox 3.6 so I'm not sure which one let it in. It has just been a TPA! Which is what the oxygen thievin sh*ts want, oh and money for nothing.

__________________
There are two reasons for a man to do a thing, One that sounds good, and the real one...
Register to Reply
Guru
Popular Science - Weaponology - New Member Safety - ESD - New Member Hobbies - Fishing - New Member

Join Date: Sep 2006
Location: Near Frankfurt am Main, Germany. 50.390866N, 8.884827E
Posts: 17996
Good Answers: 200
#4

Re: Virus Pro Copy Cat

08/02/2010 5:35 AM

Already good advice here, but here is a further method that requires even less knowledge.

Many Antivirus companies have a free downloadable bootable Linux CD. You just have to download the .ISO image, make the CD and have a PC where you can change the BIOS to boot first from CD....

Load CD, boot from it and run the antivirus software scan.

The good point is that Windoze is absolutely "DEAD" at this point, the whole hard disk contains just "Data" and no active programs at this point.

Furthermore, I would just like to say that if you observe the security rules (don't visit questionable websites, which INCLUDES Facebook and Twitter by the way...warnings have been made about them for at least a year in Germany for example) AND you have a hardware firewall, software firewall and good antivirus software - all at the latest versions, this should never happen.....

Scan your computer FULLY at LEAST once a week.....update the relevant softwares DAILY at least!!! Automatically is best!!!

Anyone who even thinks differently is just lying to themselves and just asking for trouble.....

Company networks are often a hive of bad bees, looking at porn, questionable sites etc.......

__________________
"What others say about you reveals more about them, than it does you." Anon.
Register to Reply
Power-User

Join Date: Mar 2010
Posts: 101
Good Answers: 11
#5

Re: Virus Pro Copy Cat

08/02/2010 8:00 AM

One of my kid's laptops just picked up a nasty bug running Internet Explorer that was a phony anti-virus program. It slipped by the AVG security and corrupted it so AVG could not counter-attack and it also hijacked the browser and took control of the networking by changing the LAN settings...something I rarely check.

Startup in safe mode with networking. First, get back into your internet options, connections, LAN settings, and make sure that the box that says "use a proxy server for your LAN" is not checked. Then download and update Malwarebytes and run a full system scan, clean, reboot and run scan again. It took three times to completely get rid. I also ran Super AntiSpyware twice just to be sure and it picked up a few kernels left behind. FYI, Firefox, Chrome are safer programs than IE and I rarely get issues with these guys. Good luck.

Register to Reply Score 1 for Good Answer
Power-User

Join Date: Oct 2008
Location: Meherrin Virginia
Posts: 319
Good Answers: 6
#13
In reply to #5

Re: Virus Pro Copy Cat

08/02/2010 5:55 PM

You are correct the LAN was set to proxy, I tried downloading ms defender and it blocked it. looks pretty sophisticated.

I would personally contribute to have one of our guys figure a way to blow this guys server and hardware.

__________________
If you fail to follow through, you will fail.
Register to Reply
Power-User

Join Date: Mar 2010
Posts: 101
Good Answers: 11
#16
In reply to #13

Re: Virus Pro Copy Cat

08/03/2010 1:12 AM

Otha, follow my instructions and you should get out of the woods on this nasty virus.

Get your LAN set properly first, and that will stop the hijacking whilst you get the malware software from malwarebytes.com installed AND updated in SAFE mode. This is a new virus, and you need to get the latest. Run the program several times until it is clear...this takes at least two or three. Clear your cache, close all programs at startup that are not necessary (which is only about three), restart and boot to your normal programs...then decide to go with something like Firefox or Chrome which are far less susceptible to these critters than IE.

Register to Reply
Power-User

Join Date: Apr 2008
Posts: 138
Good Answers: 2
#6

Re: Virus Pro Copy Cat

08/02/2010 8:31 AM

I think I must have picked up this virus also because Windows will not even start on my computer. I turned my computer on yesterday and found this problem. I was in Facebook the night before but I did not see anything suspicios before I turned the computer off. I am getting a message that says that the BOOTMGR is missing. anyone have an idea what this mean? I tried to do a restore but I get a message that says that I need the driver for the CD,DVD or Floopy Drive??????

Register to Reply
Guru
Hobbies - DIY Welding - Wannabeabettawelda

Join Date: May 2007
Location: Annapolis, Maryland
Posts: 7940
Good Answers: 458
#9

Re: Virus Pro Copy Cat

08/02/2010 12:26 PM

The best way I have found to deal with these insidious fake anti-virus software (also known as RANSOMWARE) is to immediately shut down the computer (save your current files that are open if desired), remove the affected hard-drive from the machine and install it in one of these USB based external hard-drive cases. Then connect the external hard-drive case to a running computer with known, good AV software installed and run a scan on the USB-based drive.

You will not be able to run your normal AV on the boot drive with ransomware installed. They have figured out how to disable most AV programs at start up. Safe mode doesn't help either.

Register to Reply
Power-User

Join Date: Apr 2008
Posts: 138
Good Answers: 2
#10
In reply to #9

Re: Virus Pro Copy Cat

08/02/2010 3:26 PM

Thanks I will try that. I have no other choice. I cannot access any of my files. I think I have lost them. If this does not work then I will format the drive. Is there an antivus for this?

Register to Reply
Guru
Popular Science - Weaponology - New Member Safety - ESD - New Member Hobbies - Fishing - New Member

Join Date: Sep 2006
Location: Near Frankfurt am Main, Germany. 50.390866N, 8.884827E
Posts: 17996
Good Answers: 200
#11
In reply to #10

Re: Virus Pro Copy Cat

08/02/2010 4:02 PM

Try the free software "Recuva" first.....

__________________
"What others say about you reveals more about them, than it does you." Anon.
Register to Reply
2
Guru

Join Date: Aug 2007
Location: Indiana, USA
Posts: 579
Good Answers: 61
#14

Re: Virus Pro Copy Cat

08/02/2010 6:23 PM

Tonymech hit it. MalwareBytes Anti-Malware program has removed every one of these phony AV programs I've come across as SysAdmin of 7 networks with 100+ users.

More information & step by step instructions are available at http://www.bleepingcomputer.com/virus-removal/remove-antivirus-pro-2010.

__________________
Experience: The knowledge you gain just AFTER you needed it.
Register to Reply Good Answer (Score 2)
Power-User

Join Date: Oct 2008
Location: Meherrin Virginia
Posts: 319
Good Answers: 6
#17
In reply to #14

Re: Virus Pro Copy Cat

08/03/2010 12:23 PM

Thanks for all the input guys.

Here is how it all washed out. I was beginning to get paranoid with these virus programs, I realized that anyone of them could indeed be as bad as the one that had invited itself to my wifes computer. In fact I was half way through installing one and had second thoughts about the whole thing and aborted it.

Tomymech and yourself gave me enough assurance that I was willing to try Malwarebytes. This new variant of this virus would lock out the application as soon as I tried to load it. I went to JustAnswer.com and they suggested that I down load a file named rkill and install it prior to installing Malwarebytes. This worked out just fine and seems to have killed the intruder. I am still a bit nervous about passwords and such.

The rkill file can be googled and is a free download.

__________________
If you fail to follow through, you will fail.
Register to Reply Score 1 for Good Answer
Guru

Join Date: Aug 2007
Location: Indiana, USA
Posts: 579
Good Answers: 61
#18
In reply to #17

Re: Virus Pro Copy Cat

08/03/2010 12:51 PM

GA, Otha. I had not heard of rkill, but a little searching provided good info. It kills processes that disable certain other processes like regedit & legitimate antivirus programs, allowing you to remove the offending malware.

If you have not done so, you still need to run Malwarebytes to actually remove the nasty. rkill only turns it off, it doesn't delete it.

__________________
Experience: The knowledge you gain just AFTER you needed it.
Register to Reply
Power-User

Join Date: Oct 2008
Location: Meherrin Virginia
Posts: 319
Good Answers: 6
#20
In reply to #18

Re: Virus Pro Copy Cat

08/04/2010 3:12 PM

Thanks, I did go to the site that you supplied the link to. I think the discussion section of it was more enlightening than the body of the description.

Up till this point I had not realized that there were 4 different extensions in case this virus was set up to wholesale shut down .exe extensions or .com or whatever.

I was lucky mine went right through with the .exe extension. As stated in the discussion it does now give you a report as to what it did.

__________________
If you fail to follow through, you will fail.
Register to Reply
Guru

Join Date: Oct 2008
Location: Deepest Darkest Rutherford Oz
Posts: 951
Good Answers: 145
#15

Re: Virus Pro Copy Cat

08/02/2010 7:12 PM

You might all like to have a look at this site.

Some informative stuff;

http://www.us-cert.gov/reading_room/

I put our IT dude onto it he has found it most helpful.

__________________
There are two reasons for a man to do a thing, One that sounds good, and the real one...
Register to Reply
Anonymous Poster
#19

Re: Virus Pro Copy Cat

08/04/2010 2:39 PM

Never download any avg programs from the net, the only way to get full protection for this on your computer is to go out to agros or tesco and by a copy on cd, this way if you do develop a virus you can at least take it up with the company you purchased the cd from, the web has thousands of virus on it, and it only takes 1 crack in your system young or old to be able to enter and cost you a new system, trust me, ive tried it. and cost me....! beware the web.

Register to Reply
Register to Reply 20 comments

Good Answers:

These comments received enough positive votes to make them "good answers".

"Almost" Good Answers:

Check out these comments that don't yet have enough votes to be "official" good answers and, if you agree with them, vote them!
Copy to Clipboard

Users who posted comments:

Andy Germany (2); Anonymous Poster (1); Brave Sir Robin (1); hernaju1 (2); Lynn.Wallace (1); Oregoon (2); otha (4); pwr2thepeople (2); RHABE (1); Tobugrynbak (3); Tonymech (1)

Previous in Forum: csrss.exe   Next in Forum: Access Database

Advertisement