icarus: Snape by mysterious artist (Default)
icarusancalion ([personal profile] icarus) wrote2008-11-20 10:55 pm
Entry tags:

Oh, what a lovely infestation I have.

Oh, wonderful. I tried downloading the latest SPN episode from mininova.org and got a virus infected file instead.

Threat name: Trojan.Downloader.NUS and, worse yet, Adware.Maxifiles
Threat level: somewhere between Kristallnacht and nuclear holocaust

Bonus? Looks like it blocks me from going to the mininova.org web page. I can't warn anyone. Except you, of course.

Currently cleaning it out with Spywaredoctor. Next I run AVG.



ETA: Spywaredoctor caught it, cleaned it. Malwarebytes Anti-Malware found more. I still can't access mininova, however.

Annihow has more info for all of us. This particular problem disabled AVG, so she has masterful ways and tools to scan and disinfect your computer.

[identity profile] skipmcgee.livejournal.com 2008-11-21 06:55 am (UTC)(link)
Yeah same thing just happened to me. You say spywaredoctor is the way to go? I've tried Adaware and it's just not cutting it

[identity profile] icarusancalion.livejournal.com 2008-11-21 06:59 am (UTC)(link)
Yep. The sites say that Spywaredoctor will remove it.

[identity profile] skipmcgee.livejournal.com 2008-11-21 07:06 am (UTC)(link)
And of course the damn thing won't let me download the malware removal db from the site. I'm withholding so many curse words right now it can't be healthy.

[identity profile] icarusancalion.livejournal.com 2008-11-21 07:07 am (UTC)(link)
Do you already have Spywaredoctor downloaded?

[identity profile] skipmcgee.livejournal.com 2008-11-21 07:10 am (UTC)(link)
Yeah I have the program but not the specific databases - the smart update keeps getting shut out when it tries to download.
ext_2068: (Default)

[identity profile] seticat.livejournal.com 2008-11-21 07:25 am (UTC)(link)
I've totally ditched Mininove at all. I hunt with Isohunt and avoid anything pointing to Mininova. When I got hit a bit back, I found a combo of Anti-Malware and Spyware Doctor [from PC Tools] were the only things that totally cleared stuff. AVG wouldn't touch it. neither would Spybot or Ad-Aware.

[identity profile] icarusancalion.livejournal.com 2008-11-21 07:27 am (UTC)(link)
Yeah, even having cleaned it with Spyware Doctor, I still can't contact the mininova site, and AVG is turned off.

[identity profile] icarusancalion.livejournal.com 2008-11-21 07:29 am (UTC)(link)
This nasty virus has completely shut off AVG. I have no virus protection right now.

[identity profile] icarusancalion.livejournal.com 2008-11-21 07:32 am (UTC)(link)
What about running Malwarebytes Anti-Malware?

http://www.malwarebytes.org/mbam.php
ext_2068: (Default)

[identity profile] seticat.livejournal.com 2008-11-21 07:41 am (UTC)(link)
Spyware Doctor was the *only* thing that would touch it. It's been well worth what I paid for it, which wasn't all that much as I remember. Spyware Doctor (http://www.pctools.com/spyware-doctor/?ref=google_sd&gclid=CPuG3MHihZcCFQykagodAWS7-g)

[identity profile] starrylizard.livejournal.com 2008-11-21 08:00 am (UTC)(link)
Thanks. I don't use torrents, but I'm spreading the word as best I can. Ugh, so annoying! I hope it hasn't done any damage to your computer.

[identity profile] starrylizard.livejournal.com 2008-11-21 08:01 am (UTC)(link)
can you reinstall AVG? I had a virus a while back shut it down, but when I reinstalled it, it found the thing and killed it okay.

[identity profile] ifyouweremine.livejournal.com 2008-11-21 08:04 am (UTC)(link)
Aw crap, I'm sorry that happened to you, hon! #huggles#

Is a streaming video version of the episode alright? (http://www.surfthechannel.com/episode/343/143077.html)

If not I know there are some reliable downloads already up at SPN comms, I could grab a link to one for you if you needed.
amalthia: (Default)

[personal profile] amalthia 2008-11-21 08:22 am (UTC)(link)
did I ever share the link to EZTV?
amalthia: (Default)

p.s.

[personal profile] amalthia 2008-11-21 08:24 am (UTC)(link)
Sorry about the virus. :( and yeah I think our projector computer got something very similar but what I think happened was some new kind of trick they use to trick people into downloading the virus when you visit a website. It basically overlays an invisible link? At least that's what happened to EZTV and they had to get strong security because no one could see the link to the virus download? I'm not explaining so well but that's how I understood it. :(

[identity profile] icarusancalion.livejournal.com 2008-11-21 08:40 am (UTC)(link)
I just finished the attempt. This virus has a feature where it kills the connection so I can't upload the latest database update (the same thing it's doing with mininova.org). In fact, the newly downloaded version says that the database is two months out of date.

I'm downloading alternate virus protection software, to see if that helps.

Re: p.s.

[identity profile] icarusancalion.livejournal.com 2008-11-21 08:44 am (UTC)(link)
This one tricked me with a "codec." Shit. Spydoctor removed the virus (I think) and Malwarebytes Anti-Malware found something else. But I'm still unable to connect to mininova.org or update the database on AVG.

I'm hoping an alternate free trial version of Trend Micro's virus protection will help me in the interim. But I think this is going to mean a trip to the computer guy.

I have No Script to prevent those invisible links. It's a pain in the neck, but well worth it.

[identity profile] icarusancalion.livejournal.com 2008-11-21 08:46 am (UTC)(link)
Thank you. I just wish I could go to mininova and warn people there, but the Malware has somehow blocked that connection (along with my virus protection database updates).

[identity profile] icarusancalion.livejournal.com 2008-11-21 08:47 am (UTC)(link)
I got an alternate version from the SPN coms and those seem to be just fine. But thank you, I appreciate it.

amalthia: (Default)

Re: p.s.

[personal profile] amalthia 2008-11-21 08:49 am (UTC)(link)
I really should have had no script on the firefox browser of the projector computer...after that last reformat we decided no more downloading to that computer because we could never tell where the viruses were coming from where with our own computers we have the most up-to-date protection and it's quite easy to tell when you've installed a nasty virus. :(

But really the people who create those...the death penalty is too good for them. Spammers and virus makers I can't think of people I hate worse. They really do ruin good things.

[identity profile] ifyouweremine.livejournal.com 2008-11-21 08:53 am (UTC)(link)
No problem, and I hope you can get that virus off your computer! <3

[identity profile] icarusancalion.livejournal.com 2008-11-21 08:56 am (UTC)(link)
I found EZTV to be frustrating and difficult to use.

amalthia: (Default)

[personal profile] amalthia 2008-11-21 08:57 am (UTC)(link)
I kind of use the combination of mini and eztv...

[identity profile] anniehow.livejournal.com 2008-11-21 09:38 am (UTC)(link)
Sorry to intrude, I saw the warning up at Starrylizard's (and just in time too!) since there's more than one torrent listed at Mininova for the episode, could you be more specific as to which one infected you? And it happened when you finished the download and it asked you to get an "extra" codec?

[identity profile] icarusancalion.livejournal.com 2008-11-21 09:46 am (UTC)(link)
Unfortunately in my (probably understandable) flurry to get rid of it, I didn't mark which file it was. I'd just avoid the mininova files altogether unless you have a friend who can verify it's clean.

It was a zip file, that when opened, required an extra "codec" (named HDTV secure or something, which should have roused my suspicions). I got warnings from Spyware Doctor that something was up, and it popped open a page with various butt hole shots.

My virus protection appeared to still be operative, but I ran Spy Doctor ASAP. It found the infections (there were five in all) and quarantined them. I tried to access mininova and found that I couldn't.

Then I went to run AVG, and that's when I discovered that I couldn't update AVG's virus database.

I'm sorry I'm not able to do more. Stay away from mininova's SPN torrent unless you know for sure it's good. Everyone who downloaded this virus is likely unable to inform mininova that there's a problem.

Page 1 of 3