PDA

View Full Version : Meet a victim of the super lame Conficke worm...



Steve1968LS2
04-24-2009, 08:27 PM
Yep.. it's me..

A couple days ago my computer was totally trashed by the worm and virus combination they've been talking about on the news. It turned off my firewalls, disabled my NOD32 virus software and rewrote a bunch of my system code.

For example I couldn't delete ANY files. I couldn't re-engage my firewall and the "software screen" in the middle always stayed on top.

Luckily my files are store on a 1.5TB external drive. The computer is a hopeless mess so while we are on vacation a friend is going to throw away the small internal drive and install all new stuff. Since I game he will also upgrade a few other things.

Beware this virus/worm.. it's freakin' nasty.. here's a screen shot - I had to take a photo since it killed the ability to screen capture. If you see this virus software offer then it's too late. The talk about it in the news deal below.



The Waledac virus recruits the PCs (http://www.foxnews.com/story/0,2933,517817,00.html#) into a second botnet that has existed for several years and specializes in distributing e-mail spam.
Conficker also carries a third virus that warns users their PCs are infected and offers them a fake anti-virus program, Spyware Protect 2009 for $49.95, according to Russian-based security researcher Kaspersky Lab.

If they buy it, their credit card information is stolen and the virus downloads even more malicious software.

"This is probably one of the most sophisticated botnets on the planet. The guys behind this are very professional. They absolutely know what they are doing," said Paul Ferguson, a senior researcher with Trend Micro Inc, the world's third-largest security software maker.

He said Conficker's authors likely installed a spam engine and another malicious software program on tens of thousands of computers since April 7.

http://www.foxnews.com/story/0,2933,517817,00.html


Just a friendly warning to others.. beware....

James OLC
04-24-2009, 08:48 PM
That sucks Steve - good timing for a vacation.

Steve1968LS2
04-24-2009, 09:32 PM
Here's a screenshot of the carnage... hope you never see this on your PC

Notice how I couldn't activate my firewall?

https://static1.pt-content.com/images/pt/2009/04/10pbur5-1.jpg

class67
04-24-2009, 09:52 PM
What were you doing or what applications were you using at the time this happened? does it or can it just randomly pop up at any time?

This is scary!!!

JJSmitches
04-24-2009, 11:17 PM
OH SHOOOT! Counter-Strike!

Steve1968LS2
04-25-2009, 05:52 AM
What were you doing or what applications were you using at the time this happened? does it or can it just randomly pop up at any time?

This is scary!!!


No idea.. and with this deal (according to the news story) you don't know when you got it since it lays dormant. I have the Windows firewall, the router firewall and NOD32 protector/filter software. Plus I like to think I'm pretty safe.

I just hope I didn't loose my Fallout 3 saved game.. I wonder if they are stored on STEAM?

Paddington
04-25-2009, 11:53 AM
To Keep the viruses away keep your PC updated as much as you can. Both with Windows update but also other programs is a threat to your PC.

Ever noticed Java updating on your pc ? Did you know that it leaves the old version on your pc? Those bad guys writing the viruses know so they write their viruses to check your pc for older non secure versions and BOOM their in control of your pc.


I will list a few cool software that we recommend at my job.
http://secunia.com/vulnerability_scanning/personal/ (great program that checks if your applications are secure and updated to latest version)

http://research.pandasecurity.com/archive/Panda-USB-and-AutoRun-Vaccine.aspx You might need a vaccine and so does your Pc.

Any idea on how you got it? Did someone bring a USB stick to your PC?

Another great resource for PC programs is www.filehippo.com (http://www.filehippo.com)

Now someone find me a 1971 RS with a nice body and broken engine im going for the new LS engines :)

Tom E
IT PRO
from Norway Scandinavia

Steve1968LS2
04-25-2009, 01:28 PM
I move a lot of files around so who knows. I've read up and this worm is pretty high up the food chain.

System is getting rebuilt right now.. should be uber fast when done and more secure.

Damn hackers need to die in a fire..

Paddington
04-25-2009, 02:37 PM
I move a lot of files around so who knows. I've read up and this worm is pretty high up the food chain.

System is getting rebuilt right now.. should be uber fast when done and more secure.

Damn hackers need to die in a fire..
Yes and im not pointing any fingers but Conficker was stopped buy Microsoft in october 08....
So if your PC had been security patched it would not have gotten that worm.
http://www.brisbanetimes.com.au/technology/how-to-avoid-a-conficker-infection-20090401-9j34.html

derekf
04-25-2009, 04:49 PM
Check this out:

http://www.joestewart.org/cfeyechart.html

Basically, since Conficker blocks a variety of sites, this page tries to load an image from each of them -- if they don't appear, you may be infected (and if they do all appear, you are not).

As for your FO3 saves - not sure about Steam saving them (it's not a halflife based game so I doubt it), pretty sure they're in your user profile.

Steve1968LS2
04-25-2009, 04:59 PM
Check this out:

http://www.joestewart.org/cfeyechart.html

Basically, since Conficker blocks a variety of sites, this page tries to load an image from each of them -- if they don't appear, you may be infected (and if they do all appear, you are not).

As for your FO3 saves - not sure about Steam saving them (it's not a halflife based game so I doubt it), pretty sure they're in your user profile.

Yea, I did that test and it worked fine.. maybe the worm was "dormant"...

My windows was up to date, so I don't know it got through.. oh well, good excuse to upgrade the gaming unit.

I just wish they would keep saved games under a "saved games" folder.. nothing on the PC side looked like saved games. Would HATE HATE HATE to have to start over..

derekf
04-25-2009, 05:19 PM
Looks like it's up under Users\<username>\AppData\Local\Fallout3, I think. I don't have the saves there anymore - I zip them up and save them off - but the folder is still there.

Steve1968LS2
04-25-2009, 05:28 PM
Thanks!

-The Stig-
04-25-2009, 05:33 PM
Steve... you game?

What do you play? My computer at home is about 5 years old now, it's like an old car. You have to let it warm up and sit for a few minutes before attempting to do anything.

New PC is not in the budget.. save all my lunch money for the Car(s).

Steve1968LS2
04-25-2009, 06:11 PM
Computer hardware is dirt cheap right now. Just bought a 1.5TB harddrive for $100.. lol

When I have free time I like to blow stuff up in games. Mostly FPS and strategy stuff.

JustinB
04-25-2009, 08:57 PM
My old man got it on his desktop today. Google search malwarebytes download the free trial, update and run it. Took care of the the problem in about 15 minutes.

69stang
04-27-2009, 06:13 PM
Just cleaned mine as I got a trojan last wednesday. I first thought it was the conficker as it disabled norton AV, my system restore and numerous other exe files. Found it to be a version of Vundo. The people over at Aumha forums walked me through cleaning my system and getting rid of it. Found 71 infected files. I can tell you I felt like beating the crap out of the person responsible with a ballpeen hammer. Was back up and running again last night.

MonzaRacer
04-27-2009, 06:42 PM
Big problem most people have is that the updater baloon pops up and it gets clicked and turns it off.
Use a good antivirus (i personally run AVG and AVAST and have them run 12 hours apart, keep all updates on and use windows defender) I have 3 different computers, and have been very vigilant and most issues have been minor. Now you also need to have your computer do restore points regularly and when issues come up simply keep going back till things work right again.
I had minor issues with my lap top but a restore point fixed issue. But that was a bad program that was downloaded.
I wish you luck.