icarus: Snape by mysterious artist (Default)
icarusancalion ([personal profile] icarus) wrote2008-11-20 10:55 pm
Entry tags:

Oh, what a lovely infestation I have.

Oh, wonderful. I tried downloading the latest SPN episode from mininova.org and got a virus infected file instead.

Threat name: Trojan.Downloader.NUS and, worse yet, Adware.Maxifiles
Threat level: somewhere between Kristallnacht and nuclear holocaust

Bonus? Looks like it blocks me from going to the mininova.org web page. I can't warn anyone. Except you, of course.

Currently cleaning it out with Spywaredoctor. Next I run AVG.



ETA: Spywaredoctor caught it, cleaned it. Malwarebytes Anti-Malware found more. I still can't access mininova, however.

Annihow has more info for all of us. This particular problem disabled AVG, so she has masterful ways and tools to scan and disinfect your computer.

[identity profile] anniehow.livejournal.com 2008-11-21 10:12 am (UTC)(link)
Well, I went to eztv and got my dose there ;)

A friend of mine had this and he managed to get rid of it by finding a removal procedure on an antivirus forum. I know it was eight steps and it involved Malwarebyte and getting a different free antivirus than AVG (which recently has fallen behind in quality). He's at work right now and I can't call him there, but once he's off I'll get him to give me the instructions immediately (which he was going to give me this weekend anyway) and I'll pass them along.

Thanks very, very much for the warnings!

[identity profile] sherryillk.livejournal.com 2008-11-21 10:20 am (UTC)(link)
Do you have a Demonoid account? A private tracker might be the way to go if only for the community that warns of this stuff...

I hardly ever use Mininova... It's always looked a bit sketchy to me.

[identity profile] icarusancalion.livejournal.com 2008-11-21 10:20 am (UTC)(link)
Oh, that would be great, thank you!

[identity profile] daneffew.livejournal.com 2008-11-21 12:01 pm (UTC)(link)
Have you tried a couple of LJ communities that have downloads instead of torrents.

Dramatic_Eps and TVShare. They have downloads from everything on the different sites such as Megaupload sendspace etc. I think easier and quicker that torrents.
ext_9136: (Default)

[identity profile] birggitt.livejournal.com 2008-11-21 03:02 pm (UTC)(link)
Mininova had been down for a while, now. I only hunt at isohunt, and avoid mininova as hell.
Also, they are trying to go legal, allowing legal downloading. You could use torrents to download them, using a new tech: Hyper MP (http://hypermpgroup.blogspot.com/). This thing is an exe file! which contains a player with the movie or episode and adds.
I, myself, wouldn't download an .exe file even if my mother send i to me, so...
Anyhow, I'm really sorry about nasty bugs

[identity profile] skipmcgee.livejournal.com 2008-11-21 05:15 pm (UTC)(link)
Yep, that did it - got it under control enough that I could get Spyware Doctor up and running. Thank you so much, you have no idea how aggravated I was getting. Were you able to get yours cleaned out?

[identity profile] icarusancalion.livejournal.com 2008-11-21 05:31 pm (UTC)(link)
That sounds like what I was hit with. If I'm right -- I know I don't need to tell you -- don't download it. The worst problem I encountered was Adware.Maxifiles which is very dangerous.

Maxifiles adds a toolbar onto your task manager and creates pop-up advertisements.

Threat High: these infections may override user control of your system or pose high security risks such as capturing high-risk data for example, bank account details or passwords for unsolicited third-party use. Typical characteristics could include:

* Involuntary installation with no user interaction or control
* Hijacking browser home pages
* Returning sensitive data to other servers
* Automatically reinstalling itself following an uninstall
* Examples of these infections include keyloggers and dialers

Could it be possible that this is how their HyperMP.tv works? Or maybe a hacker knew that people would be expecting it so took advantage.

[identity profile] anniehow.livejournal.com 2008-11-21 05:32 pm (UTC)(link)
Ok, I've got something that might help if you're still at it (hope you're not, though!)

here: http://anniehow.livejournal.com/59665.html

[identity profile] icarusancalion.livejournal.com 2008-11-21 05:39 pm (UTC)(link)
It looks like. But I'm not able to go to the mininova.org web site. The message I get is:

The connection to the server was reset while the page was loading.

The network link was interrupted while negotiating a connection. Please try again.


So something is still wrong. Are you able to go to mininova?

[identity profile] icarusancalion.livejournal.com 2008-11-21 05:41 pm (UTC)(link)
I have. I was just impatient because I wanted WG to watch with me and he has to go to bed early. And I thought I'd be a nice guy and upload for people.

Yeah, I don't think I'm going to upload this one.



ext_26836: BEES! (Default)

[identity profile] mellifluous-ink.livejournal.com 2008-11-21 05:43 pm (UTC)(link)
Trendmicro.com is also lovely for cleaning out everything, not just malware. Viruses, worms, trojan viruses...everything.

[identity profile] skipmcgee.livejournal.com 2008-11-21 05:43 pm (UTC)(link)
Hmm, nope, I can't get their either. I hadn't even thought to check because I'm still irrationally angry at the whole site in general. The Spyware Doc is still running though, so maybe it'll find whatever this is? I'm going to go searching around and see what other sites I'm not connecting to.

[identity profile] icarusancalion.livejournal.com 2008-11-21 05:56 pm (UTC)(link)
Yes, it's done something.

[livejournal.com profile] anniehow has more helpful tools here: http://anniehow.livejournal.com/59665.html

They found other viruses but nothing has solved the fact that we can't get to mininova.

[identity profile] icarusancalion.livejournal.com 2008-11-21 06:01 pm (UTC)(link)
Thank you. Malwarebytes Anti-Malware allowed [livejournal.com profile] skipmagee to download the latest virus databases and get her virus protection working again. It also found other viruses on my computer. My AVG is still out of commission, but I was able to install a free 30-day trial of TrendMicro in the interim.

DrWeb found another trojan, gtdownlr_134.ocx, that I've probably had for a while.

ext_9136: (Default)

[identity profile] birggitt.livejournal.com 2008-11-21 06:18 pm (UTC)(link)
No, I don't think so, but I do believe crackers are gonna make a fest with the .exe files. And, as people are aware they are putting some of this new tech to be tested, is easy to got something nasty instead you were looking for.
I stop using AVG after the last week fiasco, when an update deleted Window System files. I'm using a free Avira (http://www.free-av.de/), which is acting really cool so far.
ext_2356: Water Ribbon (Default)

[identity profile] dunv-i.livejournal.com 2008-11-21 06:31 pm (UTC)(link)
You could try grabbing the databases on a different computer and manually installing them - I dunno how AVG does this kind of thing, unfortunately. I use avast. I also don't know if that will work. Um. Techsupportforum.com is my current redirect when I'm offering tech help.

[identity profile] icarusancalion.livejournal.com 2008-11-21 06:46 pm (UTC)(link)
I'm definitely in the market for new virus protection.

AVG's been fixed, but I still have Trend Micro running from last night. That's probably bad, isn't it? To have two anti-virus programs running at the same time?

Interestingly, I'm still not able to access the mininova site.
ext_9136: (Default)

[identity profile] birggitt.livejournal.com 2008-11-21 06:53 pm (UTC)(link)
Yeah, two anti-virus are most likely to collide...
Weird thing you cant access to Mininova, though. Maybe the site is down? Maybe they are trying to get rid from malware?

[identity profile] icarusancalion.livejournal.com 2008-11-21 07:06 pm (UTC)(link)
Are you able to access mininova? I think other people can. I suspect this is a feature of the virus I got, to make it so you can't access the site and warn. (How did they do this?)

[identity profile] icarusancalion.livejournal.com 2008-11-21 07:12 pm (UTC)(link)
Yeah, two anti-virus are most likely to collide...

Ha. My brother once had these tropical fish called "betas." They were beautiful, but you could only have one because they'd instantly go after a rival fish.

Yep. That's how two anti-virus programs act. They try to remove each other.

I'm getting rid of the 30-day trial of Trend Micro for now, and then I'm going to research virus protection software.
ext_9136: (Default)

[identity profile] birggitt.livejournal.com 2008-11-21 07:50 pm (UTC)(link)
Yup, I just did it, so, yes, it is you.
And I bet you are right, they are trying to avoid you alert them. There are quite a lot of virus which can do that, but usually, they block your access to places where you can run an AV software on-line.
But it is not really difficult, only a pair of lines of extra coding.
ext_9136: (Default)

[identity profile] birggitt.livejournal.com 2008-11-21 07:52 pm (UTC)(link)
Yes, my dad had them, too =D
Damn territorial, but, oh, so pretty =D
Mmm... I'm using a very good AV at work, I can't remember now which one, but I'll let you know as soon as my mushy brain is back on business

[identity profile] lherelenfeline.livejournal.com 2008-11-21 08:09 pm (UTC)(link)
I use ISOHunt, and it's generally kept the compy safe.
ext_9136: (Default)

[identity profile] birggitt.livejournal.com 2008-11-21 08:27 pm (UTC)(link)
Ha! That's why adore LogMeIn!
The AV is Clam (http://www.clamav.net/)!

[identity profile] icarusancalion.livejournal.com 2008-11-21 08:46 pm (UTC)(link)
Ooo! Will it work on XP?

Page 2 of 3