Wikiposts
Search
Computer/Internet Issues & Troubleshooting Anyone with questions about the terribly complex world of computers or the internet should try here. NOT FOR REPORTING ISSUES WITH PPRuNe FORUMS! Please use the subforum "PPRuNe Problems or Queries."

Nasty, nasty people.

Thread Tools
 
Search this Thread
 
Old 11th Jul 2012, 04:05
  #1 (permalink)  
Psychophysiological entity
Thread Starter
 
Join Date: Jun 2001
Location: Tweet Rob_Benham Famous author. Well, slightly famous.
Age: 84
Posts: 3,270
Received 37 Likes on 18 Posts
Nasty, nasty people.

Do not attempt to run these links.


http://molholm-sla(break)gter.dk/rumyn.html?pr=iivuuf

And

http://nav(break)itrolla.ee/golrua.html?pt=fycwpi


Got these from an old (non-technical) friend tonight. There was no personal text which is unlike her. G-mail put up a huge red warning.

It had several listed friends CP'd who are very vulnerable due to age and non-tekkiness.

Anything known?




.

Last edited by Loose rivets; 12th Jul 2012 at 16:02.
Loose rivets is offline  
Old 11th Jul 2012, 07:54
  #2 (permalink)  
 
Join Date: Jan 2012
Location: .
Posts: 2,173
Likes: 0
Received 0 Likes on 0 Posts
well, either his e-mail account has been hacked or his PC has been zombied. Impossible to know without more details of the kind of e-mail account and how he accesses it.
Either way, he needs to get help to clean things up.

Last edited by Milo Minderbinder; 11th Jul 2012 at 07:55.
Milo Minderbinder is offline  
Old 11th Jul 2012, 14:05
  #3 (permalink)  
Spoon PPRuNerist & Mad Inistrator
 
Join Date: Sep 2003
Location: Twickenham, home of rugby
Posts: 7,410
Received 276 Likes on 176 Posts
A reminder to all to be EXTREMELY careful about clicking on links - even here on PPRuNe!

SD
Saab Dastard is offline  
Old 11th Jul 2012, 15:39
  #4 (permalink)  
 
Join Date: Jul 2010
Location: East sussex
Posts: 624
Likes: 0
Received 0 Likes on 0 Posts
Saab, I've noticed more and more on sites of late, "Be aware of clicking on links" is this the new 'Not our fault pall ?

Daz

Last edited by dazdaz1; 11th Jul 2012 at 15:42.
dazdaz1 is offline  
Old 11th Jul 2012, 16:29
  #5 (permalink)  
Psychophysiological entity
Thread Starter
 
Join Date: Jun 2001
Location: Tweet Rob_Benham Famous author. Well, slightly famous.
Age: 84
Posts: 3,270
Received 37 Likes on 18 Posts
I've just read a genuine e from her, and fortunately her son is visiting, and set about cleaning her machine. It was a quick message, but implied there was something there.


I hope G-mail's big red flag thing saved me this end. Off to run an update and scan.
Loose rivets is offline  
Old 12th Jul 2012, 06:30
  #6 (permalink)  
 
Join Date: Aug 2002
Location: Earth
Posts: 3,663
Likes: 0
Received 0 Likes on 0 Posts
A bit questionable to put up such links if I may say so Loose Rivets.

Even if you have doctored the text, you don't want to encourage people to visit them.

Last edited by mixture; 12th Jul 2012 at 06:31.
mixture is offline  
Old 12th Jul 2012, 16:03
  #7 (permalink)  
Psychophysiological entity
Thread Starter
 
Join Date: Jun 2001
Location: Tweet Rob_Benham Famous author. Well, slightly famous.
Age: 84
Posts: 3,270
Received 37 Likes on 18 Posts
Mmmm, okay, OP amended with warning. But isn't this supposed to be the professional computer section.

"I'll think I'll take that (break) out and see what happens."

Shirly not.


Without the full link - protected as it is - you experts would not have all the data you may need at hand. Having said this, I suppose they're generated randomly, so won't give much away.
Loose rivets is offline  
Old 12th Jul 2012, 17:38
  #8 (permalink)  
 
Join Date: Jan 2012
Location: .
Posts: 2,173
Likes: 0
Received 0 Likes on 0 Posts
OK, I'm a sucker. I'll bite

Using Firefox heavily locked down the first one gets blocked by Googles DNS server - I get a red warning screen warning of malware

The second link isn't blocked that way, but Avast tells me the web page is trying to install a trojan which it calls HTML:Refresher-A[Trj]





Interesting
I just looked that up on Virustotal
Someone submitted a sample of that a couple of weeks ago and only four virus engines picked it up

https://www.virustotal.com/file/bb76...a39c/analysis/

What does that prove? That most AV programs may not have stopped it. You need secondary software as well, but the mot important thing ? DON'T CICK ON LINKS!!!!

Last edited by Milo Minderbinder; 12th Jul 2012 at 17:44.
Milo Minderbinder is offline  
Old 15th Jul 2012, 08:30
  #9 (permalink)  
 
Join Date: Jul 2000
Location: Wiltshire
Posts: 798
Received 1 Like on 1 Post
Without clicking on any links or visiting 'dodgy'sites, I suddenly noticed MSE had turned off. Wouldn't turn on, and nor would the Windows firewall. Turned out it was infected with Zero Access. Got rid using MBAM followed by a check with TM Housecall, but wonder how it got there (I'm the only one to use the computer).
oldbeefer is offline  
Old 15th Jul 2012, 08:51
  #10 (permalink)  
 
Join Date: Jan 2012
Location: .
Posts: 2,173
Likes: 0
Received 0 Likes on 0 Posts
Major shift in strategy for ZeroAccess rootkit malware, as it shifts to user-mode | Naked Security

"This new version of ZeroAccess is being aggressively distributed through the normal mechanisms - drive by downloads, fake keygens, fake game downloads....."
Milo Minderbinder is offline  
Old 15th Jul 2012, 11:06
  #11 (permalink)  
More bang for your buck
 
Join Date: Nov 2005
Location: land of the clanger
Age: 82
Posts: 3,512
Likes: 0
Received 0 Likes on 0 Posts
So much for MSE being the only AV/firewall program needed then.
green granite is offline  
Old 15th Jul 2012, 12:41
  #12 (permalink)  
 
Join Date: Jul 2000
Location: Wiltshire
Posts: 798
Received 1 Like on 1 Post
No, I know people who have had expensive, paid for software who still get caught.
oldbeefer is offline  
Old 15th Jul 2012, 15:09
  #13 (permalink)  
 
Join Date: Jan 2012
Location: .
Posts: 2,173
Likes: 0
Received 0 Likes on 0 Posts
Security essentials isn't really enough on its own
It needs padding out with something else
e.g. Threatfire or Panda Cloud - these two seem to have the least system resources overhead
I've tried using ClamWin and its forks as a secondary program, but the performance hit is too high

However, of the free ones my first choice is still Avast, with browserprotect.org blocking hijacks
However, the bet thing is to block the infection from happening: so (as others have said elsewhere) run in "stadnard user" mode, use Firefox as the browser and use the No-Script and AdBlock plus plugins to stop any malware running in the browser. If the infected script on the webpage can't run in the browser, it can't infect you. (To that end also disable javascript in Adobe Reader as well)
Milo Minderbinder is offline  
Old 15th Jul 2012, 16:11
  #14 (permalink)  
More bang for your buck
 
Join Date: Nov 2005
Location: land of the clanger
Age: 82
Posts: 3,512
Likes: 0
Received 0 Likes on 0 Posts
My comment was meant very tongue in cheek Milo.
green granite is offline  
Old 15th Jul 2012, 16:16
  #15 (permalink)  
 
Join Date: Jan 2012
Location: .
Posts: 2,173
Likes: 0
Received 0 Likes on 0 Posts
sorry....not with it this afternoon ....to much post prandial alcohol methinks
Milo Minderbinder is offline  

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service

Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Use of this site indicates your consent to the Terms of Use.