Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Virus hit me on Facebook - help!
Vanity | 11 June 2009 | Mene Mene Tekel Upharsin

Posted on 06/11/2009 8:49:43 PM PDT by MeneMeneTekelUpharsin

Was downloading a video from the internet (Kung Fu movie) when my Avast anti-virus software first warned me of a trojan (from the find site) and then a worm. I deleted both. Both Avast and Trend Micro House Call show no infection. However, on my Facebook account, something sent an ugly message with an even uglier link (which also warned on a virus) to everyone on my Facebook. I do not automatically log in to Facebook, I put in my password every time. How did it do that?


TOPICS: Miscellaneous
KEYWORDS: trojan; virus; worm
Navigation: use the links below to view more comments.
first 1-2021-25 next last

1 posted on 06/11/2009 8:49:43 PM PDT by MeneMeneTekelUpharsin
[ Post Reply | Private Reply | View Replies]

To: MeneMeneTekelUpharsin

Sure it was a Kung Fu movie?


2 posted on 06/11/2009 8:51:42 PM PDT by exist
[ Post Reply | Private Reply | To 1 | View Replies]

To: exist

ROFL I was just going to ask that!


3 posted on 06/11/2009 8:52:05 PM PDT by Extremely Extreme Extremist ("President Obama, your agenda is not new, it's not change, and it's not hope" - Rush Limbaugh 02/28)
[ Post Reply | Private Reply | To 2 | View Replies]

To: MeneMeneTekelUpharsin

Do you remember the name of the worm or virus ?


4 posted on 06/11/2009 8:54:33 PM PDT by TheCipher (Obama In the Lions' Den)
[ Post Reply | Private Reply | To 1 | View Replies]

To: MeneMeneTekelUpharsin

Sorry can’t help, I have a mac.


5 posted on 06/11/2009 8:57:26 PM PDT by svcw
[ Post Reply | Private Reply | To 1 | View Replies]

To: MeneMeneTekelUpharsin
If no signs of infection through multiple scans try ‘rootkit revealer’ and ‘hijackthis’. The hijackthis info is way to long to post in this forum but there is plenty of help out there.
6 posted on 06/11/2009 8:58:31 PM PDT by allmost
[ Post Reply | Private Reply | To 1 | View Replies]

To: MeneMeneTekelUpharsin

First thing to try: system restore

(start/progs/access/system tools/system restore). You attempt to restore your computer to a previous date. You won’t lose data files, but might need to reinstall anything that you may have installed since the date of restore.

Many viruses immediately delete restore points.

Try www.malwarebytes.org. My kids just did something similar tonight looking up song lyrics. Malwarebytes worked and only required a reboot.

However, I was working on a computer for a client who got a virus off of some sort of facebook video last week and it was the worst I’d ever seen. Any geek squad would have slicked the hard drive. Hopefully you won’t be in that boat. I spent over 12 hours saving her computer from a necessary format.

The symptoms for the “nasty” virus: malwarebytes will detect the virus and then crash when trying to clean.

My resolution: note each and every occurrence on paper. Clean all registry keys and delete all infected files that you can manually. Then, use an XP disk and boot to recovery mode. Delete any infected files in the windows directories that you were unable (because they were in use) in normal mode. Boot to safe mode and scan again. Repeat the process until you get a clean scan.


7 posted on 06/11/2009 9:00:23 PM PDT by mmichaels1970
[ Post Reply | Private Reply | To 1 | View Replies]

To: mmichaels1970

If it’s that deep, system restore is probably infected as well.


8 posted on 06/11/2009 9:02:19 PM PDT by allmost
[ Post Reply | Private Reply | To 7 | View Replies]

To: svcw
Sorry can’t help, I have a mac.

Writing a virus for the mac is like deploying a bioweapon in Antarctica. No bang for the buck.
9 posted on 06/11/2009 9:02:26 PM PDT by mmichaels1970
[ Post Reply | Private Reply | To 5 | View Replies]

To: MeneMeneTekelUpharsin
http://www.malwarebytes.org

Free program at malwarebytes.org has saved my machine a couple times now. Make sure the URL at the site is malwarebytes.org and not something else. Some viruses won't let you go to the real site.
10 posted on 06/11/2009 9:03:14 PM PDT by mysterio
[ Post Reply | Private Reply | To 1 | View Replies]

To: svcw
Hello fellow Mac head..

Nothing but Mac since 1986. I know zero about PC.

11 posted on 06/11/2009 9:03:49 PM PDT by LimaLimaMikeFoxtrot ("If you don't have my army supplied, and keep it supplied, we'll eat your mules up, sir"-Gen.Sherman)
[ Post Reply | Private Reply | To 5 | View Replies]

To: allmost
If it’s that deep, system restore is probably infected as well.

I concur. Normally the virus won't bother to do much other than delete every restore point so that your calendar comes up blank. Then you're on to anti-virus scanning and cleaning. In my experience if there is still a date that can be restored in the calendar, it will work.
12 posted on 06/11/2009 9:04:25 PM PDT by mmichaels1970
[ Post Reply | Private Reply | To 8 | View Replies]

To: mmichaels1970

I had terrible trouble when koobface got to my computer via Facebook. None of my usual fixes worked. What finally solved things for me was the Kaspersky antivirus program:

http://usa.kaspersky.com/downloads/

Might work for you. I’d give the 30 day home version a try.


13 posted on 06/11/2009 9:04:32 PM PDT by ancientart (Dems: The party who booed the Boy Scouts off the stage at the 2004 convention)
[ Post Reply | Private Reply | To 7 | View Replies]

To: MeneMeneTekelUpharsin

I’m guessing it attacked once you logged onto Facebook, not before that. Unless you have some evidence that says otherwise...


14 posted on 06/11/2009 9:10:39 PM PDT by Kirkwood
[ Post Reply | Private Reply | To 1 | View Replies]

To: ancientart
What finally solved things for me was the Kaspersky antivirus program

Thanks for the tip. I've used Kaspersky before but it's been shelved for a while due to the recent effectiveness of malwarebytes. I'll keep it in mind for the next one that rears its head.
15 posted on 06/11/2009 9:12:35 PM PDT by mmichaels1970
[ Post Reply | Private Reply | To 13 | View Replies]

To: MeneMeneTekelUpharsin

There are a couple of possibilities that I can think of (but I am by no means a Windows Virus/Worm/Trojan expert, as I am an Apple user):

First - are you 100% certain it was your installed Anti-virus that was “alerting you” with a pop-up? One of the biggest and most successful ploys to get folks to install trojans is to use a pop-up that masquerades as a message from some anti-virus and installs, with your permission, when you click it.

Another possibility, as someone else pointed out, is - are you sure you downloaded what you think/say you did?

And finally, from within facebook itself, some people put up nefarious links claiming to be something else of interest - you may have clicked one of those - thus opening yourself to a trojan or worm that used your facebook account info, generating those horrible messages for all your friends to be spammed with (and some will likely fall for it and get hit themselves).

About once per month, someone on my friend list gets something like that.

I am so glad those bugs don’t affect Apple’s OS X operating system. IT would upset me pretty seriously if something like that were to be posted under my name.


16 posted on 06/11/2009 9:24:02 PM PDT by TheBattman (Pray for our country...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: mmichaels1970
Writing a virus for the mac is like deploying a bioweapon in Antarctica. No bang for the buck.

Wrong - the security by obscurity myth doesn't fly - there have been operational worms and viruses written for FAR more obscure operating systems than Apple's OS X.

A better analogy would be deploying a bioweapon in an area where the inhabitants all have incredible immune systems where no-one has been sick from a virus or other infection in 15+ years. Not going to say you CAN'T make them sick, but the effort to come up with a bug that will actually make one sick and be contagious too is more trouble than it is worth.

Oh - and there have been several attempted viruses/trojans for OSX - but none have successfully made it to the "wild" in a form that poses any risk or danger to users.

17 posted on 06/11/2009 9:28:08 PM PDT by TheBattman (Pray for our country...)
[ Post Reply | Private Reply | To 9 | View Replies]

To: MeneMeneTekelUpharsin

I recently was hacked by a website I found chasing the news.

Got a message from my virus program that I had a trojan, but it would not remove it.

Used every tool I had in my tool box, and I have been chasing this stuff for many years for others, nothing worked.

Every time I removed the Trojan and rebooted it would come back. Then I rebooted without the network cable attached and the trojan did not return. It was being downloaded from the web at each reboot. When I reattached the network cable it immediately downloaded the Trojan again.

Called my company’s IT tech and he suggested a small fast free utility. It is a command line tool that is used in Safe Mode, but it did the trick.

Called SmitFraudFix

Download at:

http://siri.urz.free.fr/Fix/SmitfraudFix_En.php

Cannot predict the results, but it fixed the problem and nothing else I used did.

I think it was either attached to the WinSoc or in the Start-up boot sequence.


18 posted on 06/11/2009 9:39:25 PM PDT by Texas Fossil (Once a Republic, Now a State, Still Texas)
[ Post Reply | Private Reply | To 1 | View Replies]

To: MeneMeneTekelUpharsin

The people who invent these viruses are twisted individuals who need to get a life.


19 posted on 06/12/2009 12:53:40 AM PDT by screaming eagle2
[ Post Reply | Private Reply | To 1 | View Replies]

To: TheCipher

Trend Micro said it was Trojan_bredolab.bn, Trojan_download.xt and Worm__Koobface.id. Avast just said trojan and worm and gave option to delete them, which I did. However, worm warning came up again last night.


20 posted on 06/12/2009 3:06:41 AM PDT by MeneMeneTekelUpharsin (Freedom is the freedom to discipline yourself so others don't have to do it for you.)
[ Post Reply | Private Reply | To 4 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-25 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson