Avast WEBforum

Other => Viruses and worms => Topic started by: chabbo on May 15, 2010, 08:55:37 PM

Title: New Facebook virus ?
Post by: chabbo on May 15, 2010, 08:55:37 PM
hello, i tink i got a new Facebook virus

its link to atitta på denna bild :D hxxp://yuarel.com/facebook-album-10-05-15-JPG

and its a file who i have on desktop look like Facebook app

but no idea how to send it to avast, avast dont see it as virus,
Title: Re: New Facebook virus ?
Post by: chabbo on May 15, 2010, 08:59:59 PM
hello, i tink i got a new Facebook virus

its link to atitta på denna bild :D hxxp://yuarel.com/facebook-album-10-05-15-JPG

and its a file who i have on desktop look like Facebook app

but no idea how to send it to avast, avast dont see it as virus,


http://www.virustotal.com/sv/analisis/370e2de98ca15a168e8110fc20bd4d674a919ed92fe934cd9f2742b5fff9a1e9-1273949310
Title: Re: New Facebook virus ?
Post by: Hermite15 on May 15, 2010, 09:01:56 PM
I tried to have a look at it through Firefox virtualized but it's not a pic, it's a screen saver, and I don't want to download it for testing ;)
Title: Re: New Facebook virus ?
Post by: chabbo on May 15, 2010, 09:02:35 PM
that shit did froze my pc and spam over my msn :'(
Title: Re: New Facebook virus ?
Post by: YoKenny on May 15, 2010, 09:08:01 PM
Please go to PROFILE then Modify Profile then Forum Profile Information then  Signature: and put information about your system just like my signature about your system just like my signature so that the helpers can offer pertinent advice.

In Account Related Settings select Hide email address from public to prevent scammers and spammers harvesting your chli_peppar hotmail.com email address.

hxxp://yuarel.com/facebook-album-10-05-15-JPG is .scr malware!
Title: Re: New Facebook virus ?
Post by: Hermite15 on May 15, 2010, 09:08:16 PM
that s**t did froze my pc and spam over my msn :'(

ok use this:
http://www.malwarebytes.org/mbam.php (although I swore I would never recommend it again, not very friendly guys over there)

run a quick scan with it, post the log here; if anything found follow the instructions and reboot.
Title: Re: New Facebook virus ?
Post by: YoKenny on May 15, 2010, 09:14:07 PM
Malwarebytes is very friendly to people that have malware and have a malware problem.

It i
Title: Re: New Facebook virus ?
Post by: chabbo on May 15, 2010, 09:40:20 PM
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4104

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

2010-05-15 21:39:53
mbam-log-2010-05-15 (21-39-53).txt

Scan type: Full scan (C:\|)
Objects scanned: 158779
Time elapsed: 25 minute(s), 9 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\winsvncs.txt (Malware.Trace) -> Quarantined and deleted successfully.
Title: Re: New Facebook virus ?
Post by: chabbo on May 15, 2010, 09:50:56 PM
its still not deleted :O
Title: Re: New Facebook virus ?
Post by: Hermite15 on May 15, 2010, 09:55:49 PM
its still not deleted :O

I suppose you were prompted for action and reboot no? did you do that?

edit: or is it something else now, your system's still infected I presume...
Title: Re: New Facebook virus ?
Post by: essexboy on May 15, 2010, 10:00:56 PM
Hi lets have a look see - you will need to attach the logs as they are large

Download OTL (http://oldtimer.geekstogo.com/OTL.exe)  to your Desktop

netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
nvrd32.sys
symmpi.sys
adp3132.sys
mv61xx.sys
nvraid.sys
/md5stop
%systemroot%\*. /mp /s
CREATERESTOREPOINT
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\drivers\*.sys /90


Title: Re: New Facebook virus ?
Post by: polonus on May 15, 2010, 10:02:39 PM
Hi forum users,

Be cautious with this website link: http://safeweb.norton.com/reviews/41176
http://www.unmaskparasites.com/security-report/?page=http%3A//yuarel.com/facebook
Suspicious inline script:
Code: [Select]
var gaJsHost=(("https:"==document.location.protocol)?"https://ssl.":"http://www.");
document.write(...    
about what this malicious adcode does:
http://www.google.com/support/forum/p/Webmasters/thread?tid=524385eed6a23eb9&hl=en
and
Code: [Select]
 var pageTracker=_gat._getTracker("UA-3938091-1");
pageTracker._initData();
pageTracker._trackPagevi...
 code outside HTML which is suspicious....
Malware description here: http://forum.malekal.com/http-yuarel-com-facebook-jpg-20100511n-t25590.html
and can be found here: http://support.clean-mx.de/clean-mx/viruses.php?sort=satzart%20asc
seems all profiles are being tracked for dubious purposes...
A way that credential theft is being performed: http://evilcodecave.wordpress.com/2009/01/24/msn-credential-theft-httpzopblobcom/
Malware description: http://www.sophos.com/security/analyses/viruses-and-spyware/malvbinjectt.html
http://www.threatexpert.com/report.aspx?md5=ee04ef11df3b09a8235790af3521f520
and this somewhat earlier variant:
http://www.threatexpert.com/report.aspx?md5=39aa7adf2cb4d7b3d9b1cf319b983f5c
For succesful removal one needs:
1. Temporarily Disable System Restore;
2. Update the virus definitions or definitions of MBAM and/or SAS. Reboot computer in SafeMode;
3. Delete the IE temp files,some Mal/VBInject-T temp file exist there,
but better you follow essexboys' instructions to the dot, he will lead you through the necessary cleansing steps

polonus

Title: Re: New Facebook virus ?
Post by: chabbo on May 15, 2010, 10:33:03 PM
Your file is too large. The maximum attachment size allowed is 200 KB.
Title: Re: New Facebook virus ?
Post by: essexboy on May 15, 2010, 10:41:19 PM
Could you upload the main txt file  to Mediafire (http://www.mediafire.com/) and post the sharing link.
Title: Re: New Facebook virus ?
Post by: Pondus on May 15, 2010, 10:58:55 PM
Have sendt sample to avast and malwarebytes......
Title: Re: New Facebook virus ?
Post by: polonus on May 15, 2010, 11:04:14 PM
Hi Pondus,

Thank you for forwarding this where this should go,

pol
Title: Re: New Facebook virus ?
Post by: chabbo on May 15, 2010, 11:13:33 PM
arent pondus and polonodus same ppl?

I'm getting wierd now :O


http://www.mediafire.com/?zkrivmmedlq
Title: Re: New Facebook virus ?
Post by: polonus on May 15, 2010, 11:24:44 PM
Hi chabbo,

Pondus and Polonus are both interested in analyzing online malicious website malcoded scripts and help protecting against these. Pondus is a Norwegian and Polonus is Dutch, they are two different persons. But when malicious websites are being reported you may see their nicks here. Essexboy is a trained malware eliminator and to my experience he is one of the best around and whit malware removal you are lucky if he comes to the rescue,

polonus
Title: Re: New Facebook virus ?
Post by: Pondus on May 15, 2010, 11:29:23 PM
Quote
arent pondus and polonodus same ppl?
tjena grabben......hur mår ni.... ;)
no i am me, and he is he.......polonus...... ;D
Title: Re: New Facebook virus ?
Post by: chabbo on May 16, 2010, 12:24:33 AM
problem solve with Formate pc  :'(

but are both polonius working at Avast house there they build and work with avast or are they just sitting home and work for avast?
Title: Re: New Facebook virus ?
Post by: essexboy on May 16, 2010, 12:33:00 AM
OK your log was large because you have either just re-installed or updated to SP3

Run OTL
Code: [Select]
:OTL
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
[2010-05-15 20:47:50 | 000,274,432 | RHS- | C] (Ogbh4L2MOks73vCqx) -- C:\Documents and Settings\elmou\Application Data\msng.exe

:Commands
[resethosts]
[purity]
[emptytemp]
[EMPTYFLASH]
[Reboot]
Title: Re: New Facebook virus ?
Post by: Pondus on May 16, 2010, 12:39:25 AM
Quote
but are both polonius working at Avast house there they build and work with avast or are they just sitting home and work for avast?
we do not work for avast,just normal avast user like you
Title: Re: New Facebook virus ?
Post by: chabbo on May 16, 2010, 01:39:24 PM
my mother got the virus how should i help she remove it on a easy and fast way without Reinstall xp
Title: Re: New Facebook virus ?
Post by: essexboy on May 16, 2010, 01:53:40 PM
Run OTL as directed to you previously - I will remove the elements and then all should be OK.  There was no requirement for you to have reformated
Title: Re: New Facebook virus ?
Post by: Pondus on May 16, 2010, 08:03:23 PM
Now detected by Malwarebytes as " Worm.Palevo "