Large Scale Central

A rootkit.... NOT amused. OT

For the past 3 darn days I have been trying to get rid of this thing.

Avast can’t find it.
Spybot can’t find it.
Sophos can’t find it.
Combofix sees it is there, and tries, but can’t get rid of it.
Malwarebytes tries, but it keeps coming back.

WHERE did it come from? We’ve narrowed that down to two suspects. The Home Model Engine Machinist website was hacked. and/or Kim opened something purportedly from facebook… I could almost live with the false ‘malicious url’ pop-ups, and Ask.com being redirected… but what info is it stealing while it is busy being annoying?

if you haven’t googled it to find out what it is I’d suggest you do so. It carries more than one virus/worm/malware I think. Facebook is the answer

I vote Facebook. The other day I was on it and 10 minutes later I got a strange message.

Mik,

Go to Microsoft.com and download “Malicious Software Removal Tool”. This thing is very strong-should take care of it for you. I use it all the the for stubborn malware AND viruses.

I’m told by computer experts, that Facebook is full of things you don’t want!! I’m seriously thinking of shutting mine down! I just spent 5 days getting rid of a firewall that was interfering with everything, like you say wasn’t showing anywhere in my computer, people I consider to be at a high level of computer expertise had never heard of it. I won’t even mention it as it is vicious, and will not show up in add or remove programs. I finally found something on Google, did it twice, and the co. that bought out this firewall thingy called me on monday and confirmed it was gone. Then it was on to Malicious Softwear removal tool, Malwearbytes.org. tweak register cleaner, Spybot, and on my paid for spywear and antivirus had to use their removal tool to get rid of all their junk. The co. I pay for spywear and antivirus protection since 2002 just left me hanging and told me they couldn’t remove this particular firewall, and everywhere on the net you read about everyone having it and not being able to get rid of it. So now I have a different spywear and antivirus program (free I might ad) when this runs out its bye bye for them. Oh and the greatest thing was that when they couldn’t and wouldn’t help me any farther, found out later it was due to the guy that bought out the co. they are big distributors for alot of spywear and such co’s, and mine in particular! They or a supervisor said we are GIVING you an additional 3 mos. of service even though I couldn’t use anything they had till I removed this thingy!!! Oh boy did I tell them geeeeeeeeeeeeeeeeez yer sure generous! What the Hell am I going to do with that now that nothing works??? oh and by the way the guy on Monday told me he thought there must be a glitch or a defect in the softwear they were trying to download to me which was an old version i might add, and even after I got rid of this termite, it still wouldn’t work, would not download updates, so I had an old version and no updates so really wasn’t worth the effort to continue so everything is gone now. Now I am on a regular program of running various programs daily, weekly, and monthly now, thanks to a close computer savy friend of mine. Compuker running splendidly, better than it has in months! Regal

(http://freightsheds.largescalecentral.com/users/blueregal/_forumfiles/chimp_laughing.gif)

On Facebook I don’t play any games or join anything that requires access to my account or information.
As for clicking links, there is always a measure of danger involved no matter where you are.
Ralph

Fingers crossed. Hitman Pro 3.5.7 identified it as an Alureon variant. TDSSKiller claims to have removed it. No obvious symptoms for the last hour… We shall see if it re-appears again…

Have a friend on FB am going to pass this info to. They have been struggling with some kind of malware for a month.

And here I am, browsing the internet WAYYYYY too much, taking tons of chances with things, have no firewall and no antivirus, and yet I don’t have issues.

How?

Yet!!!

My spam has dropped to zero, since I bought a new computer, and NEVER, NEVER, NEVER went on Facebook with the new unit.
Doesn’t take a rocket scientist to realize that Facebook was the root of all the problems on the old puter.
(knock on wood).

Here’s a story on the problems at Facebook. As I stated before, it’s the aps and games causing the security problems.
Ralph

http://technolog.msnbc.msn.com/_news/2010/10/18/5310412-just-how-bad-is-facebook-app-privacy-problem-

Facebook is dirty period! I went through my battle with it about a year ago. Wife was doing nothing wrong other than looking at friends pictures. Easy answer to Facebook is browse it on a phone. They can’t attack them YET>

Ralph Berg said:
Here's a story on the problems at Facebook. As I stated before, it's the aps and games causing the security problems. Ralph

http://technolog.msnbc.msn.com/_news/2010/10/18/5310412-just-how-bad-is-facebook-app-privacy-problem-


and as one of my fav radio voices would say…“the rest of the story…”

http://www.youtube.com/watch?v=KpLNlSKugHw

Glad I never signed up, never understood all the hype in the 1st place…all those technogeeks gushing about how great Facetube was are now too busy disassembling their computers bug hunting to gush much anymore. :wink:

Robbie Hanson said:
And here I am, browsing the internet WAYYYYY too much, taking tons of chances with things, have no firewall and no antivirus, and yet I don't have issues.

How?


Watch it, might be tempting fate there. Famous last words, “Look Ma, no firewall!”

http://news.yahoo.com/s/ap/20101018/ap_on_hi_te/us_facebook_apps_breached;_ylt=AoB74ATec1YZSBsgYfmYoBGs0NUE;_ylu=X3oDMTFoNjA1OTN2BHBvcwMxMzUEc2VjA2FjY29yZGlvbl90ZWNobm9sb2d5BHNsawNmYWNlYm9va3NheXM-

Quote:
. . .. The Wall Street Journal reported Monday that several popular Facebook applications have been transmitting users' personal identifying information to dozens of advertising and Internet tracking companies. Facebook said it is working to fix the problem, and was quick to point out that the leaks were not intentional, but a consequence of basic Web mechanisms. . . . .

Probably the next thing we’ll learn is that Faceook, not the apps, was transmitting the information for a price. But it was just a "mistake.:

Doug Arnold said:
Probably the next thing we'll learn is that Faceook, not the apps, was transmitting the information for a price. But it was just a "mistake.:
Somebody pays for the bandwidth. And with Facebook, I'm sure the tab is HUGE. Most of the ads, are advertising the "free" games. I'm sure Bob could explain the business model. Ralph

The business model is the same as the first ‘law’ of themodynamics… There’s no such thing as a free lunch … but sometimes the how and who of paying the tab isn’t quite obvious. So I just gotta wonder if they get a kickback from the folks selling anti-whatever software, and the crooks as well? Might help explain how a young kid gets to be a billionaire by starting a ‘free’ service?