Become a Site Supporter and Never see Ads again!

Author Topic: Facebook virus  (Read 5764 times)

0 Members and 1 Guest are viewing this topic.

Offline Myco

  • Trade Count: (11)
  • Needs to get out more...
  • *****
  • Posts: 7572
  • Gender: Male
Facebook virus
« on: February 09, 2010, 11:22:02 PM »
anybody else get this virus? Something on facebook just installed a rootkit virus on my pc. avast warned me of it, but now my pc is frozen on a white screen just after windows starts up, Anyone have any suggestions to get rid of this? Thanks
Microtech Gefell M200: M20/M21/M27 caps> Bumblebee MiAGi-II/Darktrain silver cable's/"Chuck" Belden cables> Aerco MP-2 or Busman modded DR-680 pre-amps> Darktrain cables & interconnects> Tascam DR-680 (Busman mod)
AT853's(card's/hyper's)>AT8533x>Aerco MP-2>Sony M10

Offline Fatah Ruark (aka MIKE B)

  • Trade Count: (11)
  • Needs to get out more...
  • *****
  • Posts: 9945
  • Gender: Male
  • I dream in beige.
    • sloppy.art.ink
Re: Facebook virus
« Reply #1 on: February 09, 2010, 11:43:59 PM »
How are you sure it was Facebook?

Try booting into Safe Mode (hit F8 while booting) to see if you can get the OS to start.

If you can get into Windows Safe Mode then you should run the MS Malicious Software Removal Tool (you should get this every month in your updates. I think there was an update today...so hopefully you updated before this happened).

To run the MSRT click your start button and then run..., and type MRT into that box (this is for XP). If you have Vista or Windows 7 then you can just type MRT in the Search Programs box after you click the start button.

And yes it is MRT and not MSRT. Crazy MS folks can't do things that make sense...that would be very un-MS like.

||| MICS:  Beyer CK930 | DPA 4022 | DPA 4080 | Nevaton MCE400 | Sennheiser Ambeo Headset |||
||| PREAMPS: DPA d:vice | Naiant Tinybox | Naiant IPA |||
||| DECKS: Sound Devices MixPre6 | iPod Touch 32GB |||
|||Concert History || LMA Recordings || Live YouTube |||

Offline Lil Kim Jong-Il

  • Trade Count: (6)
  • Needs to get out more...
  • *****
  • Posts: 6498
  • large Marge sent me
Re: Facebook virus
« Reply #2 on: February 10, 2010, 12:16:34 AM »
where you looking at a photo gallery when it happened?

saw that here
The first rule of amateur neurosurgery club is .... I forget.

Offline Myco

  • Trade Count: (11)
  • Needs to get out more...
  • *****
  • Posts: 7572
  • Gender: Male
Re: Facebook virus
« Reply #3 on: February 10, 2010, 08:34:07 AM »
I am back up now, but it's still on there I believe.

It's really weird. When it all first happened I had just posted an update on the stupid new page on Facebook and all of a sudden the avast! antivirus sirens start going off and prompt me to start moving a bunch of files to the quarantine chest. Some program called PC Security Tools starts to install and then attempt a "security scan". I refuse the "scan" when it prompts me to. The avast! booted most of the files into it's quarantine chest, and I can now run an Avast! antivirus scan and it says that all is clean and uninfected, but this "Security Tools" program is still on my pc. Avast! warned me this was a rootkit virus, and seems like it's in there deep in the system32 files. I don't know it's it's still working or not, but there is still evidence of it around. It's not listed on the list for add/remove programs, so I can't remove it that way either.
Microtech Gefell M200: M20/M21/M27 caps> Bumblebee MiAGi-II/Darktrain silver cable's/"Chuck" Belden cables> Aerco MP-2 or Busman modded DR-680 pre-amps> Darktrain cables & interconnects> Tascam DR-680 (Busman mod)
AT853's(card's/hyper's)>AT8533x>Aerco MP-2>Sony M10

Offline mattmiller

  • Trade Count: (20)
  • Taperssection All-Star
  • ****
  • Posts: 1454
  • Gender: Male
Re: Facebook virus
« Reply #4 on: February 10, 2010, 08:46:36 AM »
Run Malwarebytes Anti-Malware to see if it takes care of it.

If not, run Superantispyware.

If you still suspect something's there, run HijackThis, and then copy-and-paste the results into www.hijackthis.de.  It'll tell you what needs deleted.
Mics: Neumann KM100 (x4), AK40 (x2), AK50 (x2)
Pre: Lunatec V3
Recorders: Tascam DR-680, Tascam HD-P2 (x2), Sony PCM-M10

Offline Lil Kim Jong-Il

  • Trade Count: (6)
  • Needs to get out more...
  • *****
  • Posts: 6498
  • large Marge sent me
Re: Facebook virus
« Reply #5 on: February 10, 2010, 08:50:28 AM »
Thats similar to what happened to my roommate.  She was looking at someone's photos and when she followed a facebook link to more pictures she got the same notification to download the security tools however we were able to keep it from downloading into vista.  I am still curious about how she invoked it through the facebook pages.
The first rule of amateur neurosurgery club is .... I forget.

Offline Myco

  • Trade Count: (11)
  • Needs to get out more...
  • *****
  • Posts: 7572
  • Gender: Male
Re: Facebook virus
« Reply #6 on: February 10, 2010, 09:33:53 AM »
Thats similar to what happened to my roommate.  She was looking at someone's photos and when she followed a facebook link to more pictures she got the same notification to download the security tools however we were able to keep it from downloading into vista.  I am still curious about how she invoked it through the facebook pages.

I never clicked on any specific links or anything asking to install it. The only sequence that I followed was I noticed that Andy Murray had this poll on his board that asked if you (HATE!! or Like) the new Facebook changes and I clicked on HATE!!. I then went and posted something on my board, and then the problems all started right after I posted to my board. It happened to one other person I know so far. Fargin' Facebook.  :angry3:
Microtech Gefell M200: M20/M21/M27 caps> Bumblebee MiAGi-II/Darktrain silver cable's/"Chuck" Belden cables> Aerco MP-2 or Busman modded DR-680 pre-amps> Darktrain cables & interconnects> Tascam DR-680 (Busman mod)
AT853's(card's/hyper's)>AT8533x>Aerco MP-2>Sony M10

Offline vanark

  • TDS
  • Site Supporter
  • Trade Count: (29)
  • Needs to get out more...
  • *
  • Posts: 8540
  • If you ain't right, you better get right!
    • The Mudboy Grotto - North Mississippi Allstar fan site
Re: Facebook virus
« Reply #7 on: February 10, 2010, 09:39:01 AM »
Thats similar to what happened to my roommate.  She was looking at someone's photos and when she followed a facebook link to more pictures she got the same notification to download the security tools however we were able to keep it from downloading into vista.  I am still curious about how she invoked it through the facebook pages.

I never clicked on any specific links or anything asking to install it. The only sequence that I followed was I noticed that Andy Murray had this poll on his board that asked if you (HATE!! or Like) the new Facebook changes and I clicked on HATE!!. I then went and posted something on my board, and then the problems all started right after I posted to my board. It happened to one other person I know so far. Fargin' Facebook.  :angry3:

Funny, I saw that poll on Andy's page and went to it and decided it looked sketchy to me and didn't vote.
If you have a problem relating to the Live Music Archive (http://www.archive.org/details/etree) please send an e-mail to us admins at LMA(AT)archive(DOT)org or post in the LMA thread here and we'll get on it.

Link to LMA Recordings

Link to Team Dirty South Recordings on the LMA

Mics: Microtech Gefell M21 (with Nbob actives) | Church Audio CA-11 (cards) (with CA UBB)
Pres: babynbox
Recorders: Tascam DR-60D | Tascam DR-40 | Sony PCM-A10 | Edirol R-4

Offline Myco

  • Trade Count: (11)
  • Needs to get out more...
  • *****
  • Posts: 7572
  • Gender: Male
Re: Facebook virus
« Reply #8 on: February 10, 2010, 10:18:09 PM »
MRT doesn't work unfortunately, and the virus is fighting my antivirus by shutting down the system when it trys to remove it. The virus won't let me update or run any protections, and I can't install anything new. Thanks for trying to help though. Looks like I gotta call in the Geek Squad tomorrow. grrrr. Serves me right for letting my guard down. I never expected to get anything from anyone here that I know. Let this be a lesson to everyone here. Don't participate in these f*ckin polls and Facebook add-ons.
Microtech Gefell M200: M20/M21/M27 caps> Bumblebee MiAGi-II/Darktrain silver cable's/"Chuck" Belden cables> Aerco MP-2 or Busman modded DR-680 pre-amps> Darktrain cables & interconnects> Tascam DR-680 (Busman mod)
AT853's(card's/hyper's)>AT8533x>Aerco MP-2>Sony M10

Offline vanark

  • TDS
  • Site Supporter
  • Trade Count: (29)
  • Needs to get out more...
  • *
  • Posts: 8540
  • If you ain't right, you better get right!
    • The Mudboy Grotto - North Mississippi Allstar fan site
Re: Facebook virus
« Reply #9 on: February 10, 2010, 10:30:07 PM »
MRT doesn't work unfortunately, and the virus is fighting my antivirus by shutting down the system when it trys to remove it. The virus won't let me update or run any protections, and I can't install anything new. Thanks for trying to help though. Looks like I gotta call in the Geek Squad tomorrow. grrrr. Serves me right for letting my guard down. I never expected to get anything from anyone here that I know. Let this be a lesson to everyone here. Don't participate in these f*ckin polls and Facebook add-ons.

Did you try rolling your computer back to a restore point before the infection?  In XP, boot into safe mode (press F5 when it just starts to boot) and select safe mode.  Hopefully a restore point helps.  If you have changed any files, back them up first so you don't lose them in the restore.
If you have a problem relating to the Live Music Archive (http://www.archive.org/details/etree) please send an e-mail to us admins at LMA(AT)archive(DOT)org or post in the LMA thread here and we'll get on it.

Link to LMA Recordings

Link to Team Dirty South Recordings on the LMA

Mics: Microtech Gefell M21 (with Nbob actives) | Church Audio CA-11 (cards) (with CA UBB)
Pres: babynbox
Recorders: Tascam DR-60D | Tascam DR-40 | Sony PCM-A10 | Edirol R-4

Offline it-goes-to-eleven

  • Trade Count: (58)
  • Needs to get out more...
  • *****
  • Posts: 6696
Re: Facebook virus
« Reply #10 on: February 10, 2010, 10:31:13 PM »
Let this be a lesson to everyone here. Don't participate in these f*ckin polls and Facebook add-ons.

Don't Do Facebook.
Don't Do Windows.. especially for basic stuff like browsing the web.
Block third party ad servers.. a lot of badness comes that way.
By default do not allow sites to run javascript, java, flash, etc.

If I had to run windows, all my browsing and internet stuff would be done from within a disposable virtual machine.

Offline vanark

  • TDS
  • Site Supporter
  • Trade Count: (29)
  • Needs to get out more...
  • *
  • Posts: 8540
  • If you ain't right, you better get right!
    • The Mudboy Grotto - North Mississippi Allstar fan site
Re: Facebook virus
« Reply #11 on: February 10, 2010, 10:49:46 PM »
Let this be a lesson to everyone here. Don't participate in these f*ckin polls and Facebook add-ons.

Don't Do Facebook.
Don't Do Windows.. especially for basic stuff like browsing the web.
Block third party ad servers.. a lot of badness comes that way.
By default do not allow sites to run javascript, java, flash, etc.

If I had to run windows, all my browsing and internet stuff would be done from within a disposable virtual machine.

Sorry for the semi-threadjack, but has anyone tried using a Sandbox software like Sandboxie?  I might give it a try soon.
If you have a problem relating to the Live Music Archive (http://www.archive.org/details/etree) please send an e-mail to us admins at LMA(AT)archive(DOT)org or post in the LMA thread here and we'll get on it.

Link to LMA Recordings

Link to Team Dirty South Recordings on the LMA

Mics: Microtech Gefell M21 (with Nbob actives) | Church Audio CA-11 (cards) (with CA UBB)
Pres: babynbox
Recorders: Tascam DR-60D | Tascam DR-40 | Sony PCM-A10 | Edirol R-4

Offline Myco

  • Trade Count: (11)
  • Needs to get out more...
  • *****
  • Posts: 7572
  • Gender: Male
Re: Facebook virus
« Reply #12 on: February 10, 2010, 10:51:01 PM »
MRT doesn't work unfortunately, and the virus is fighting my antivirus by shutting down the system when it trys to remove it. The virus won't let me update or run any protections, and I can't install anything new. Thanks for trying to help though. Looks like I gotta call in the Geek Squad tomorrow. grrrr. Serves me right for letting my guard down. I never expected to get anything from anyone here that I know. Let this be a lesson to everyone here. Don't participate in these f*ckin polls and Facebook add-ons.

Did you try rolling your computer back to a restore point before the infection?  In XP, boot into safe mode (press F5 when it just starts to boot) and select safe mode.  Hopefully a restore point helps.  If you have changed any files, back them up first so you don't lose them in the restore.

I'll try that tomorrow, thanks Rory.
Microtech Gefell M200: M20/M21/M27 caps> Bumblebee MiAGi-II/Darktrain silver cable's/"Chuck" Belden cables> Aerco MP-2 or Busman modded DR-680 pre-amps> Darktrain cables & interconnects> Tascam DR-680 (Busman mod)
AT853's(card's/hyper's)>AT8533x>Aerco MP-2>Sony M10

Offline Fatah Ruark (aka MIKE B)

  • Trade Count: (11)
  • Needs to get out more...
  • *****
  • Posts: 9945
  • Gender: Male
  • I dream in beige.
    • sloppy.art.ink
Re: Facebook virus
« Reply #13 on: February 10, 2010, 11:46:23 PM »
Worse comes to worse I would just re-install Windows before going to the Geek Squad. No need to waste your money on them.

It's not a bad idea to "start fresh" every once in a while. It may even help your computer run better.

And I would also suggest installing Microsoft Security Essentials as your anti-virus. I'm not sure it would have caught that virus, but it is FREE and doesn't eat up a lot of CPU cycles.

||| MICS:  Beyer CK930 | DPA 4022 | DPA 4080 | Nevaton MCE400 | Sennheiser Ambeo Headset |||
||| PREAMPS: DPA d:vice | Naiant Tinybox | Naiant IPA |||
||| DECKS: Sound Devices MixPre6 | iPod Touch 32GB |||
|||Concert History || LMA Recordings || Live YouTube |||

Offline Myco

  • Trade Count: (11)
  • Needs to get out more...
  • *****
  • Posts: 7572
  • Gender: Male
Re: Facebook virus
« Reply #14 on: February 11, 2010, 08:25:24 AM »
Thanks for your suggestions guys. I do have back-up discs of my drives that I made right around Christmas time with Nero Back-up, but I don't know what to do with them. Any suggestions there?
Microtech Gefell M200: M20/M21/M27 caps> Bumblebee MiAGi-II/Darktrain silver cable's/"Chuck" Belden cables> Aerco MP-2 or Busman modded DR-680 pre-amps> Darktrain cables & interconnects> Tascam DR-680 (Busman mod)
AT853's(card's/hyper's)>AT8533x>Aerco MP-2>Sony M10

 

RSS | Mobile
Page created in 0.11 seconds with 40 queries.
© 2002-2024 Taperssection.com
Powered by SMF