PDA

View Full Version : Virus


Pages : [1] 2

daystar57
August 28th, 2008, 11:50 AM
I was just wondering if anyone has been hit with the virus that is going around 'Trojan Blusod"? I discovered last night that I had the virus. It caused my wallpaper to disapear and downloaded a file / program "AntivirusXP 2008" that tried to get me to deleate over 370 files. I was on the phone 3+ hours with a computer geek who was able to fix the virus and clean up my files. I was told this is a high risk virus and a lot of people are getting it.

icebear
August 28th, 2008, 11:51 AM
:hide


not yet.

how is it being spread?

daystar57
August 28th, 2008, 12:04 PM
:hide


not yet.

how is it being spread?


I bought my computer at Best Buys so I called the Geek Squad to fix it. The guy who fixed my computer seemed very knowable about computers. I was told this virus has been out a couple of months now and they have not yet been able to figure out how it is being spread. The guy who fixed my computer told he personally had fixed around 30 computers in two days. Best Buys had told me they have been receiving a lot of calls in connection to this virus. My wife found out this morning that two peoples she know has gotten this virus and one of the computers crashed. I think I was lucky because I believe my Norton firewall blocked other programs from loading on my computer.

I too would like to know how this being spred.

fracturedInfinity
August 28th, 2008, 01:24 PM
Computer Associates classifies it as spyware:
http://www.ca.com/hk/securityadvisor/pest/pest.aspx?id=453139165

Symantec has a page here about it with removal instructions:
http://www.symantec.com/en/ca/security_response/writeup.jsp?docid=2008-062711-5534-99&tabid=2

It looks like it requires it to be executed locally, so probably it's spread via popups on compromised websites that people unwittingly click on. I didn't seen any indication in the above articles that it emails itself or anything. Although, it could be contained in a file that someone may send you, so remember to always scan all files that come over the internet before opening them.

In His Service
August 28th, 2008, 03:35 PM
I had the same version and the only program to remove it is called Malwarebytes' Anti-Malware. It's free and was really the only thing that would remove it with ease.

daystar57
August 28th, 2008, 04:18 PM
I had the same version and the only program to remove it is called Malwarebytes' Anti-Malware. It's free and was really the only thing that would remove it with ease.



That is exactly what the guy from Best Buys used to get rid of it. He ran a couple of other programs but it was the Malwarebytes that found my infected files and got rid of them.

In His Service
August 28th, 2008, 05:19 PM
It's being spread when you port your e-mail from your ISP. as soon as you download your messages, your infected. YOU DONT HAVE TO OPEN YOUR MESSAGES TO GET INFECTED!. It contains a macro which starts up upon downloading your messages. You need to set your spam settings with your ISP to make sure it doesn't get to your computer.

Agape!

daystar57
August 28th, 2008, 05:52 PM
It's being spread when you port your e-mail from your ISP. as soon as you download your messages, your infected. YOU DONT HAVE TO OPEN YOUR MESSAGES TO GET INFECTED!. It contains a macro which starts up upon downloading your messages. You need to set your spam settings with your ISP to make sure it doesn't get to your computer.

Agape!


My ISP is SBC - Yahoo and I'm using Thunderbird for my email. How do I set my spam settings to catch this so it doesn't happen again?

Thanks!

In His Service
August 28th, 2008, 10:40 PM
Here's the deal. It is unfortunate that the McAfee Anti Virus that Yahoo uses doesn't find it. In fact right now, only one is the Malware Bytes one. You may want to occasionally look into your e-mail through the web first and make sure there are no spam messages that got by. Yahoo has a limit of 500 that you can block. So, you may have to actually talk to them about it as it got by there servers.

Sorry I can't be of more help for ya.

Pacman
August 30th, 2008, 01:07 PM
This virus seems to be around a lot at the moment. Infected machines seem to download a LOT of malware, and at least one that i've seen has been infected with a rootkit.

If your security software says you do have a rootkit, don't repair the system. Reinstall it from scratch. You can't trust any system that's been compromised to that degree. If you don't have reinstall disks for your OS, get hold of your computer's manufacturer and harass them until they give you the disks. They'll try everything they can to avoid giving them to you, but if you keep at it they should give in.