Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Youtube Virus downloaded 1-19 via Facebook: Blocks entrance to spyware removal software and dummy www.onlineantispyguide.com "scan" adds filthy popup


  • This topic is locked This topic is locked
4 replies to this topic

#1 kandredesign

kandredesign

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:06:31 PM

Posted 19 January 2010 - 10:26 PM

Today, I was sent a message on FB from a "friend". This was sent to 10 people and linked to a "spongebob squarepants" youtube video. When I clicked on the video, I saw that is was from yuotube.com. I immediately closed the application, but I was too late - already infected.

Since this afternoon, I have had a host of different problems:

1) A message, masked as a Windows security warning, saying that I was infected and running a "scan" (looking like a Windows Control Panel window) that says I have hundreds of trojans and viruses in my file locations. It takes me to a location with a http address of www.onlineantispyguide.com/index.php?affid=41100.

2) Popups immediately following that are truly X rated.

3) When I try to add additional free spyware, IE says that Internet Explorer cannot access them. I was able to run a HiJack This log, and the 2 files your website requested. The RootRepeal program was not allowed to run. I can run the spyware I have, but the updating


In a very-windows looking atmosphere, you get 3 tiled windows. The first is a small one that says:
MESSAGE FROM WEBPAGE

Your computer remains infected by viruses! They can cause data loss and full damages and need to be cured as soon as possible. Return to Systems Security and download it secure to your PC. (You then have a OK and Cancel button). The Cancel button is inactive.

"OK" takes you to the 2nd tiled window. This says

SCAN RESULTS

18 Win32 Dangerous
23 SoapHoax Dangerous
36 Win32/Bogle HexWorm Dangerous

REMOVE ALL THREATS IMMEDIATELY

Windows highly recommends you remove all the threats. Staying unprotected leads to unprecedented consequences including complete computer crash of your PC and operating system.

(The http at the top says www.//lkrjsoft.in/?affid=02992)

HELP! These keep coming up and adding filthy content and popups. I have 3 small children under the age of 12 on the computer!!! Eek!


Attached Files



BC AdBot (Login to Remove)

 


#2 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:31 PM

Posted 25 January 2010 - 12:59 PM

Hi,

My name is Extremeboy (or EB for short), and I will be helping you with your log.

We apologize for the delay of response.

If you still require assistance we would like to see the current condition of your system so please post a new set of DDS Logs as well as a RootRepeal log and a description of any remaining problems or symptoms you may still have please.

If for any reason you did not post a DDS log or RootRepeal log please refer to this page and in step #6 and Step #7 for further instructions on downloading and running DDS & RootRepeal. If you have any problems when running the tools or unable to produce a report for any reason, just let me know in your next reply.


For your next reply I would like to see:
-The DDS logs
---DDS.txt and Attach logs
-RootRepeal logs
-Description of any remaining problems you may still have.


Thanks again and we apologize for the delay.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#3 kandredesign

kandredesign
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:06:31 PM

Posted 25 January 2010 - 02:33 PM

Thank you for your assistance. I was able, thru running some system antiviral scans, to eliminate my problem. I want to thank you, though, for the donation of your time and efforts to help us. I know it is a volunteer effort, and I appreciate people such as you who donate your energies and expertise.

Blessings,
Diana clapping.gif



#4 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:31 PM

Posted 25 January 2010 - 02:44 PM

No problem, and thanks for your kind words. I'm glad you got it resolved.

Happy surfing again.

Some prevention tips...

Preventing Infections in the Future


Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

Some of the main things you should consider to perform/read are:
  • Disabling Autorun/Play on Flash-Drive/Removable Drives
  • Avoid gaming sites, underground web pages, pirated software sites, and Peer to Peer Programs
  • Keep Windows Updated through going to Windows Updates
  • Updating Non-Microsoft Programs
  • Keeping Security softwares updated

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#5 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:31 PM

Posted 25 January 2010 - 02:46 PM

Hello.

Since the problem appears to be resolved, this topic is now Closed.
If you need this topic reopened, please Send Me a Message. In your message please include the address of this thread in your request.

This applies only to the original topic starter

Everyone else please start a new topic.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users