Follow us on Twitter!
Follow us on Facebook!
 

Go Back   Pixtus - Photography Forum, Photographers, Photo Tips > General Information > Open Talk


Virus alert!

This is a discussion on Virus alert! within the Open Talk forums, part of the General Information category; I was looking at a local newspaper website, when a a popup appeared, and indicated is was .... "MS Removal ...

Reply
 
LinkBack Thread Tools Display Modes
  (#1) Old
Forum Regular
 
BenE's Avatar
 
Posts: 527
Join Date: Apr 2006
Location: Midway twix East and West, Texas
Real First Name: BE
Camera: SX70 Polaroid & Holga :)
Can Others Edit My Photos: No
iTrader Rating: 0

Likes Received LIKES Received: 22
Likes Given LIKES Given: 2
Virus alert! - 04-13-2011, 05:12 PM


I was looking at a local newspaper website, when a a popup appeared, and indicated is was .... "MS Removal Tool".

A scan started , so I immediately unplugged. Then I logged back on, and
Googleed MS removal tool. There are a lot of sites that state it is a fake virus removal software tool.

I could not even stay online long enough to bookmark a link, and would not want to post one anyway, in case it is one for the fake virus protection.

So far this is what I did. Shut down, rebooted, did a system restore point to Monday. After the system had fully loaded and before the fake tool could stop my virus program, I started that.

Not sure if this will solve the problem. I wanted to post about the fake software. Since it pops up as "MS Removal Tool", the intent is to fool you in to believing it is a Microsoft Product, which is is not.

I am online now from another computer, so I will not know the results for a while.
Reply With Quote
Sponsored Links

Premium Members do not see Google advertisements. SIGN UP today and help support our community.
  (#2) Old
Uber Poster
 
texkam's Avatar
 
Posts: 3,355
Join Date: Feb 2009
Location: Plano, Texas
Real First Name: Mark
Camera: Canon
Can Others Edit My Photos: No
iTrader Rating: 3

Likes Received LIKES Received: 137
Likes Given LIKES Given: 197
04-13-2011, 05:16 PM


What browser were you using?
Reply With Quote
  (#3) Old
Forum Regular
 
BenE's Avatar
 
Posts: 527
Join Date: Apr 2006
Location: Midway twix East and West, Texas
Real First Name: BE
Camera: SX70 Polaroid & Holga :)
Can Others Edit My Photos: No
iTrader Rating: 0

Likes Received LIKES Received: 22
Likes Given LIKES Given: 2
04-13-2011, 05:17 PM


Firefox
Reply With Quote
  (#4) Old
Uber Poster
 
texkam's Avatar
 
Posts: 3,355
Join Date: Feb 2009
Location: Plano, Texas
Real First Name: Mark
Camera: Canon
Can Others Edit My Photos: No
iTrader Rating: 3

Likes Received LIKES Received: 137
Likes Given LIKES Given: 197
04-13-2011, 05:19 PM


Yikes!
Using Ad Block Plus?
Reply With Quote
  (#5) Old
Forum Regular
 
BenE's Avatar
 
Posts: 527
Join Date: Apr 2006
Location: Midway twix East and West, Texas
Real First Name: BE
Camera: SX70 Polaroid & Holga :)
Can Others Edit My Photos: No
iTrader Rating: 0

Likes Received LIKES Received: 22
Likes Given LIKES Given: 2
04-13-2011, 05:22 PM


Quote:
Originally Posted by texkam View Post
Yikes!
Using Ad Block Plus?
From the little I could learn not much stops this. I am still researching some sites, but want to be sure I don't go to the fake virus site.
Reply With Quote
  (#6) Old
Uber Poster
 
texkam's Avatar
 
Posts: 3,355
Join Date: Feb 2009
Location: Plano, Texas
Real First Name: Mark
Camera: Canon
Can Others Edit My Photos: No
iTrader Rating: 3

Likes Received LIKES Received: 137
Likes Given LIKES Given: 197
04-13-2011, 05:26 PM


Wonder if researching this on my Linux box would be helpful?
Reply With Quote
  (#7) Old
Forum Regular
 
BenE's Avatar
 
Posts: 527
Join Date: Apr 2006
Location: Midway twix East and West, Texas
Real First Name: BE
Camera: SX70 Polaroid & Holga :)
Can Others Edit My Photos: No
iTrader Rating: 0

Likes Received LIKES Received: 22
Likes Given LIKES Given: 2
04-13-2011, 05:32 PM


I found this on Yahoo answers (that should be a safe url) ... I believe the restore is the way to go, but they recommend the process be done in safe mode.

How to remove fake MS Removal Tool.? - Yahoo! Answers
Reply With Quote
  (#8) Old
Only visiting this planet
 
SJHester's Avatar
 
Posts: 344
Join Date: Nov 2008
Location: McKinney, Texas
Real First Name: Steve
Camera: Olympus stuff
Can Others Edit My Photos: Yes
iTrader Rating: 1

Likes Received LIKES Received: 11
Likes Given LIKES Given: 47
04-13-2011, 06:47 PM


get a copy of malwarebytes (the free version). install it, update it and then run a complete scan. if you have the name of the "virus" (I call this ransom ware, they give you the virus and charge you to remove it) the malwarebytes page will have instructions on a free tool to remove it from memory as well.

The guys at malwarebytes seem to be the only ones fighting this ransomware, i have licensed a copy as i seem to be the local resident on removing these. My wife works at a homeless shelter and many of the residents seem to get this type of virus, i cant/wont charge them to remove it (they are homeless, spending money on virus removal before feeding their kids does not seem right). so this is my donation.

Good luck, and PM me if you need help
Reply With Quote
  (#9) Old
Only visiting this planet
 
SJHester's Avatar
 
Posts: 344
Join Date: Nov 2008
Location: McKinney, Texas
Real First Name: Steve
Camera: Olympus stuff
Can Others Edit My Photos: Yes
iTrader Rating: 1

Likes Received LIKES Received: 11
Likes Given LIKES Given: 47
04-13-2011, 06:49 PM


oh, you should download the malwarebytes from the computer you are on, use a flash drive to move it to your machine, and probably need to run your machine is safe mode (F8 at start up) to actually do much.
Reply With Quote
  (#10) Old
Uber Poster
 
Rson's Avatar
 
Posts: 2,742
Join Date: May 2006
Location: Keller, Texas
Real First Name: Rich
Camera: A disposable from CVS
Can Others Edit My Photos: Yes
iTrader Rating: 0

Likes Received LIKES Received: 84
Likes Given LIKES Given: 14
04-13-2011, 10:26 PM


That is not a virus, it is a Malware. Traditionally the are injected into your computer from a compromised website. If you get it you might have a chance to roll back to a previous known good point. Otherwise you have to remove it manually using Hijackthis, MalwareBytes, and turning off your system restore.
Reply With Quote
  (#11) Old
Junior Member
 
LinuxRacr's Avatar
 
Posts: 48
Join Date: Feb 2011
Location: Dallas, Texas
Real First Name: Patrick
Camera: Nikon D300s
Can Others Edit My Photos: Yes
iTrader Rating: 1

Likes Received LIKES Received: 0
Likes Given LIKES Given: 0
04-13-2011, 10:36 PM


Also if using Firefox I highly recommend getting a plugin called, "No Script". Look it up.


Sent from my iPhone using Tapatalk
Reply With Quote
  (#12) Old
Senior Member
 
daveb's Avatar
 
Posts: 492
Join Date: Jul 2006
Location: Arlington, Texas
Real First Name: dave
Camera: Nikon D700, D2X, D200, D70,F6
Can Others Edit My Photos: No
iTrader Rating: 1

Likes Received LIKES Received: 7
Likes Given LIKES Given: 3
04-13-2011, 11:16 PM


Quote:
Originally Posted by texkam View Post
Wonder if researching this on my Linux box would be helpful?
funny thing is that I see the "scans" on my Ubuntu box - i watch it hitting c:\windows and doing it's thing It is a html5 animation it is not actually doing anything.

Like was said before get a copy of malware bytes and scan the machine.
If that does not work PM me and I will give you a tech solution ...

But malwarebytes works well for these things.

---------------------------
Dave
Image Fusion Studio
http://www.imagefusionstudio.com
Studio Alegria
http://www.studioalegria.net
Reply With Quote
  (#13) Old
I do my own stunts
 
revjvegas's Avatar
 
Posts: 1,247
Join Date: Jan 2010
Location: Houston, Texas
Real First Name: John
Camera: D90
Can Others Edit My Photos: Yes
iTrader Rating: 3

Likes Received LIKES Received: 29
Likes Given LIKES Given: 9
04-14-2011, 06:34 AM


Quote:
Originally Posted by LinuxRacr View Post
Also if using Firefox I highly recommend getting a plugin called, "No Script". Look it up.


Sent from my iPhone using Tapatalk
Very cool add-on. Thanks for that pointer.

---------------------------
www.JohnVegas.com
www.f650gs.net
Check out the NEW Pixtus Photography Cheat Sheet!
Reply With Quote
  (#14) Old
Supa Dupa Poster
 
Murph's Avatar
 
Posts: 4,379
Join Date: Apr 2005
Location: San Antonio, Texas
Real First Name: Murph
Camera: Nikon and Yashica TLR
Can Others Edit My Photos: Yes
iTrader Rating: 3

Likes Received LIKES Received: 43
Likes Given LIKES Given: 11
04-14-2011, 06:39 AM


Added No Script to Firefox. Thanks, lets see if it works.

---------------------------
Texas can exist without the United States, but the United States, cannot, except at great peril, exist without Texas. Sam Houston.
Reply With Quote
  (#15) Old
Premium Member
 
Redneck's Avatar
 
Posts: 1,348
Join Date: Sep 2008
Location: Concan, Texas
Real First Name: André
Camera: Nikon
Can Others Edit My Photos: No
iTrader Rating: 1

Likes Received LIKES Received: 64
Likes Given LIKES Given: 44
04-14-2011, 07:04 AM


The same happened to my son. We got rid of it by starting the computer in safe mode with networking and we then had the BitDefender online scan/removal running.
Free Online Virus Scan - BitDefender Online Scanner

---------------------------
Frio Canyon Photography
Reply With Quote
Reply

Tags
alert, virus

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Visit Our Sponsors
 

Google Sponsors

Premium Members do not see Google advertisements. SIGN UP today and help support our community.

Copyright ©2004 - 2011, Abel Longoria - www.Pixtus.com
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.