**** EVERYONE READ **** DSF malware

Off Topic (Everything besides dubstep)
Forum rules
Please read and follow this sub-forum's specific rules listed HERE, as well as our sitewide rules listed HERE.

Link to the Secret Ninja Sessions community ustream channel - info in this thread
User avatar
dj seizure
Posts: 1616
Joined: Mon May 04, 2009 11:39 am
Location: Buckinghamshire Massive
Contact:

Re: **** EVERYONE READ **** DSF malware

Post by dj seizure » Fri Sep 03, 2010 3:07 am

Phigure is definitely not getting enough big upness he deserves for this!

But I'm a computer noob and I'm not sure about a few things. I logged on here when it all started and got the "do you want to continue anyway" bull, saying it was a scary website etc. I tried my luck and did.

I do scan once a week and it picked 400 "infections" this week. Everyweek for the last year I'd be lucky to get one.
I use Chrome, but sometimes use Mozilla, now my mozilla won't work at all. My java won't work either and says I need an update but when I go to do so, I download the plugin to update it and a bunch of error screens appear and say I can't which means no more Java.

I have no idea what to do, shall I just run through the whole Rar you put together and see if that cleans up stuff?

Phigure
Posts: 14134
Joined: Fri May 28, 2010 5:55 am
Contact:

Re: **** EVERYONE READ **** DSF malware

Post by Phigure » Fri Sep 03, 2010 4:27 am

dj seizure wrote:I have no idea what to do, shall I just run through the whole Rar you put together and see if that cleans up stuff?

good place to start

if you want, you could try downloading and installing hijackthis, and sending me the log. it might help me find a solution more specific to your infection(s)
j_j wrote:^lol
Soundcloud | Twitter

User avatar
prism
Posts: 450
Joined: Thu Jun 25, 2009 12:56 am

Re: **** EVERYONE READ **** DSF malware

Post by prism » Fri Sep 03, 2010 5:20 am

i have these symptoms on my main system , am following the guide you provided ,via laptop but the thing wont even boot up safe mode now.

pretty skrewed up yo

Phigure
Posts: 14134
Joined: Fri May 28, 2010 5:55 am
Contact:

Re: **** EVERYONE READ **** DSF malware

Post by Phigure » Fri Sep 03, 2010 5:25 am

prism wrote:i have these symptoms on my main system , am following the guide you provided ,via laptop but the thing wont even boot up safe mode now.

pretty skrewed up yo
OUCH

burn yourself a linux recovery disk or do a repair installation of windows
j_j wrote:^lol
Soundcloud | Twitter

User avatar
prism
Posts: 450
Joined: Thu Jun 25, 2009 12:56 am

Re: **** EVERYONE READ **** DSF malware

Post by prism » Fri Sep 03, 2010 6:07 am

thanks for the tips man . i manage to get in 1/10 reboot attempts and virus pack content isn't working , so hope install will fix this shit :|

User avatar
badger
Posts: 13776
Joined: Mon Nov 13, 2006 10:24 pm
Location: Bristol

Re: **** EVERYONE READ **** DSF malware

Post by badger » Fri Sep 03, 2010 8:00 am

ugh sorry to hear that prism. can't be any more help but hope you get it sorted :|
dj seizure wrote:I logged on here when it all started and got the "do you want to continue anyway" bull, saying it was a scary website etc. I tried my luck and did.
don't want to come across as a dick but that wasn't very clever. half the battle in keeping your computer safe from viruses etc is common sense rather than having the latest anti virus software or firewalls etc. i agree with xarcane that it's the responsibility of the forum to do it's best to keep you all safe where possible but users need to be vigilant here and everywhere else on the internet to try and avoid problems because ultimately it's you that's going to have to go through all the ballache of fixing problems and not us

Phigure
Posts: 14134
Joined: Fri May 28, 2010 5:55 am
Contact:

Re: **** EVERYONE READ **** DSF malware

Post by Phigure » Fri Sep 03, 2010 8:11 am

There's an idea in computer security called "dancing pigs". It basically says that if a user is given the choice between security, and dancing pigs, nearly all users will choose the dancing pigs. In this case, DSF happened to be dancing pigs...
If a random websurfer clicks on a button that promises dancing pigs on his computer monitor, and instead gets a hortatory message describing the potential dangers of the applet — he's going to choose dancing pigs over computer security any day. If the computer prompts him with a warning screen like: "The applet DANCING PIGS could contain malicious code that might do permanent damage to your computer, steal your life's savings, and impair your ability to have children," he'll click OK without even reading it. Thirty seconds later he won't even remember that the warning screen even existed.[2]
Last edited by Phigure on Fri Sep 03, 2010 8:48 am, edited 1 time in total.
j_j wrote:^lol
Soundcloud | Twitter

User avatar
badger
Posts: 13776
Joined: Mon Nov 13, 2006 10:24 pm
Location: Bristol

Re: **** EVERYONE READ **** DSF malware

Post by badger » Fri Sep 03, 2010 8:24 am

lol so true

no one can resist the lure of ham. even potentially malware ridden ham

Image

go on, you know you want to touch it

User avatar
parson
Posts: 11311
Joined: Mon Jul 31, 2006 6:26 am
Location: ATX
Contact:

Re: **** EVERYONE READ **** DSF malware

Post by parson » Fri Sep 03, 2010 8:30 am

dancing pigs i fuckin love that

faust.dtc
Posts: 5162
Joined: Mon Sep 01, 2008 11:17 am

Re: **** EVERYONE READ **** DSF malware

Post by faust.dtc » Fri Sep 03, 2010 8:44 am

Ive used a shit load of different things to scan my machine and cant find any virus' anymore but if i use Google it still redirects the results to other search engines such as Ask. Strange...

Phigure
Posts: 14134
Joined: Fri May 28, 2010 5:55 am
Contact:

Re: **** EVERYONE READ **** DSF malware

Post by Phigure » Fri Sep 03, 2010 8:47 am

faust.dtc wrote:Ive used a shit load of different things to scan my machine and cant find any virus' anymore but if i use Google it still redirects the results to other search engines such as Ask. Strange...
check your hosts file in C:/Windows/System32/drivers/etc and open it in notepad. check for any redirects at the bottom
j_j wrote:^lol
Soundcloud | Twitter

faust.dtc
Posts: 5162
Joined: Mon Sep 01, 2008 11:17 am

Re: **** EVERYONE READ **** DSF malware

Post by faust.dtc » Fri Sep 03, 2010 8:57 am

Phigure wrote:
faust.dtc wrote:Ive used a shit load of different things to scan my machine and cant find any virus' anymore but if i use Google it still redirects the results to other search engines such as Ask. Strange...
check your hosts file in C:/Windows/System32/drivers/etc and open it in notepad. check for any redirects at the bottom
How do I identify the hosts file in this location? Ive just had a look on my work pc and it wasnt obvious. And if I do find redirects can they just be deleted by editing the text in notepad or something?

A few add-ons for firefox were mentioned for extra protection but I cant remember what they were. Ive installed adblock, any idea what the other 2 were?

Thanks again for your support, im sure everybody has found it just as valuable as I have. Respect...

Phigure
Posts: 14134
Joined: Fri May 28, 2010 5:55 am
Contact:

Re: **** EVERYONE READ **** DSF malware

Post by Phigure » Fri Sep 03, 2010 9:04 am

faust.dtc wrote:
Phigure wrote:
faust.dtc wrote:Ive used a shit load of different things to scan my machine and cant find any virus' anymore but if i use Google it still redirects the results to other search engines such as Ask. Strange...
check your hosts file in C:/Windows/System32/drivers/etc and open it in notepad. check for any redirects at the bottom
How do I identify the hosts file in this location? Ive just had a look on my work pc and it wasnt obvious. And if I do find redirects can they just be deleted by editing the text in notepad or something?

A few add-ons for firefox were mentioned for extra protection but I cant remember what they were. Ive installed adblock, any idea what the other 2 were?

Thanks again for your support, im sure everybody has found it just as valuable as I have. Respect...
happy to be of help! the first ip or domain will be the one you're trying to access (google, for example), and the second will be the redirect (ask.com). that is, if the redirect is being done through the hosts file. if it is, all you've got to do is delete it. If you know you've never used the hosts file before and don't have anything in there you care about, just go ahead and get the default hosts file:

http://support.microsoft.com/kb/972034

and paste it in.

Also, the other FireFox addon would be noscript. there might be more that would potentially help, but i think adblock and noscript should do it
j_j wrote:^lol
Soundcloud | Twitter

faust.dtc
Posts: 5162
Joined: Mon Sep 01, 2008 11:17 am

Re: **** EVERYONE READ **** DSF malware

Post by faust.dtc » Fri Sep 03, 2010 9:13 am

:n: :n: :n: :n: :n: :n:

It all makes sense now. Ill give it a go when I get home and hope it resolves the problem.

Much appreciated...

Phigure
Posts: 14134
Joined: Fri May 28, 2010 5:55 am
Contact:

Re: **** EVERYONE READ **** DSF malware

Post by Phigure » Fri Sep 03, 2010 9:17 am

faust.dtc wrote::n: :n: :n: :n: :n: :n:

It all makes sense now. Ill give it a go when I get home and hope it resolves the problem.

Much appreciated...

once again, I'm happy to help. malware is a bitch.
j_j wrote:^lol
Soundcloud | Twitter

User avatar
Basstronomer
Posts: 1113
Joined: Mon Oct 08, 2007 10:26 am

Re: **** EVERYONE READ **** DSF malware

Post by Basstronomer » Fri Sep 03, 2010 10:22 am

Phigure wrote:once again, I'm happy to help. malware is a bitch.
Hey Phigure, do you usually follow these steps for all infections or do you have a different approach for each one ?
I'm asking because the only protections I've got on my PC are Spybot and AVG (I'm switching to Avast after everything I read on AVG here). So my question is : Which software (apart from the one in your RAR) should I install on my laptop ?

Phigure
Posts: 14134
Joined: Fri May 28, 2010 5:55 am
Contact:

Re: **** EVERYONE READ **** DSF malware

Post by Phigure » Fri Sep 03, 2010 11:19 am

djekos wrote:
Phigure wrote:once again, I'm happy to help. malware is a bitch.
Hey Phigure, do you usually follow these steps for all infections or do you have a different approach for each one ?
I'm asking because the only protections I've got on my PC are Spybot and AVG (I'm switching to Avast after everything I read on AVG here). So my question is : Which software (apart from the one in your RAR) should I install on my laptop ?
Most of it depends on the infection. I've put together this kit since most infections will be relatively similar. Aside from Combofix, SuperAntiSpyware, and Malware Bytes, the tools were all specifically aimed at Alureon and Security Tool infections.

Personally, I hate using antivirus that runs around the clock, but it's a good idea for the large majority of users. I've had Avast for the past two months or so, and even though all the security features were enabled, it did nothing to stop the stuff from DSF. It wouldn't even detect it when I scanned for it, so I can't personally recommend it. Uninstalled it yesterday.

I'm not a big fan of antimalware software with active protection anyways, for the most part they just cover foolish mistakes like opening obviously malicious executable files...

However, I do highly recommend ESET Nod32. Very high detection rates, not too bad of a memory hog, and IMO the best "active" antivirus out there.

For me though, active antivirus really just acts as somewhat of an early warning tool (they can give hints of virus activity before they even really start showing the obvious symptoms). For the actual removal, I use Malware Bytes, SUPERAntiSpyware, and Combofix, as well as any tools out there tailored specifically for the virus. I'll check the infection names that come up in scans (like TDSS or Alureon) and google around for removal tools.
j_j wrote:^lol
Soundcloud | Twitter

User avatar
Basstronomer
Posts: 1113
Joined: Mon Oct 08, 2007 10:26 am

Re: **** EVERYONE READ **** DSF malware

Post by Basstronomer » Fri Sep 03, 2010 11:34 am

Thanks for the tips :D

User avatar
aspect-dubz
Posts: 1763
Joined: Sun Aug 02, 2009 4:14 pm
Location: BRISTOL,UK
Contact:

Re: **** EVERYONE READ **** DSF malware

Post by aspect-dubz » Fri Sep 03, 2010 3:55 pm

hey phigure, im basically having the opposite problem from the original virus you posted about and cannot get onto the internet from my original user account. i also tried dragging the task.mgr file to the desktop but got a pop-up stating i don't have authorisation. i tried on both the guest and main account. Do you have any idea of what to do?

User avatar
DRTY
Posts: 7900
Joined: Mon Apr 21, 2008 6:08 pm
Location: Bournemouth

Re: **** EVERYONE READ **** DSF malware

Post by DRTY » Fri Sep 03, 2010 5:09 pm

aspect-dubz wrote:hey phigure, im basically having the opposite problem from the original virus you posted about and cannot get onto the internet from my original user account. i also tried dragging the task.mgr file to the desktop but got a pop-up stating i don't have authorisation. i tried on both the guest and main account. Do you have any idea of what to do?
Does your connection appear at all? Try wired.... also, open internet explorer, go to tools, internet options, connections, lan settings, and make sure it hasnt put a proxy on. (boxes should all be unchecked).

No idea if that's the advice you need.... but it could be worth a go.

Locked

Who is online

Users browsing this forum: No registered users and 0 guests