Thursday, September 9, 2010

Any other TPM users get a malware infection recently?


I got a malware infection on June 20 which activated shortly after using this site.
Now I just noticed member Emma Zahn saying in the following comment that she recently got one too:
Thanks. I would expand on my remarks except for two things:
1) Just after submitting my last post my computer got hit with Antivirus7. I admit calling them jerks was a bit harsh but really....was a malware attack really called for? :)
2) I am out of Ritalin.
Maybe later. You're welcome to take the point and run with it if you like.
Posted by Emma Zahn in reply to a comment from David Seaton
June 24, 2010 4:01 PM | Reply | Permalink
They were not the same, mine was "AV Security Suite," hers was "AntiVirus 7."
BUT it's curious that they are both what is known as "scareware," and very similar.  Mine has been described as originated from the same root as Antivirus Soft.
These scareware thingies are really nasty, they don't just appear like fake anti-virus programs with tons of pop ups per minute, eventually redirecting your browser to porn or other junk sites, but they take over and block your real anti-virus and other protection programs (I have fully updated AVG, the paid version, and it didn't detect a known malware named to imitate it, go figure! I also have Windows Vista Business which has other protections.) They are very difficult to remove from your computer, going into the registry with files that can replicate if partially removed.
I got lucky. First I knew the warning pop ups were fishy and I didn't do what any of them directed me to do, just continued to try to close them (the latter is hopeless, they keep coming like rain.) I used Windows Restore to go two days back on my computer and then I immediately purchased and installed Malwarebytes Anti-malware software, and crossing fingers, it hasn't come back.
But I noticed that Malwarebytes just popped up when I opened TPM on Internet Explorer for the first time in a long time (instead of on Firefox where I usually view the site and where I think I caught the malware.)
Emma and I could have got it from other travels on the web but I thought the concidence was worth posting about and asking if anyone else got a malware infection soon after using this site, especially of the "scareware" type. Also, the day I got infected, I really hadn't done that many things on the internet except here.
Unfortunately, if other TPM users recently got malware infections they might still be trying to fix their computer, and not be able to see this post or comment on it.

  after the jump

45 Comments

| Leave a comment
user-pic
In the last week I received two of these on site, quickly clicked off and ran own scan with my anti virus program.
I sent e mail to TPM - no response.
I do believe it is within one (or more) of the ads as I went back to same page (most have ever rotating ads) and no problem.
Again, communication from TPM on this would be appreciated.
Thanks for posting on this issue.
user-pic
Well if enough people comment and/or recommend this post, they'll have to communicate or suffer loss of audience, as being known as a malware spreader is not good for the ratings.
If you read the link in my post for "Anti-Virus 7"--it's a WaPo article--the reporter tracked it to China. Makes me wonder if this has something to do with the spam infection.
Also what I can't get out of my mind but might be wrong about is I think a bit before it happened, I put this guy who seemed like a real blogger on my following list:
sinosunnysun
http://tpmcafe.talkingpointsmemo.com/talk/blogs/sinosunnysun/
His last two posts, which seemed like nice innocent little missives about life in China, may be sort of trojan horses to get one infected? I am wondering if those who commented on his last post were also infected?
I didn't recommend the post or comment, I just put him on following to see what else he might be posting in the future.
user-pic
I commented on sinosam's post. I have had trouble, but don't remember if it came before or after sinosam. I bet he is a trojan, though. I have Norton Internet and ran it, but it didn't find anything.
user-pic
Maybe we are being paranoid, but the more I thought on it, there's just something fishy about those posts, they've got a grifter/scam artist edge to them remindful of the more famous Nigerian emails (or some of the more famous grifters of Manhattan who come up to pedestrians with a long tale of woe.) The innocence would be part of it, to prey on Americans' interests in an "authentic" diary from a young person from China. Really there isn't a very logical reason for a Chinese citizen to be posting something like that here. Not something so personal; something a bit more complex or more political I wouldn't suspect, I would just think they are trying to reach the American political market.
user-pic
Oh and I forgot to say thanks so much for piping up; I feel less nuts. :-)
I would also like to remind everyone that the Asian spam infection (more like an epidemic) that TPM got was, according to them, not your usual spam but very sophisticated and they had a devil of a time blocking it. So we could have "the latest and greatest" in ingenious ways to give people malware infections too. After all, this kind of malware, as the WaPo article I linked to above under "AntiVirus 7," is not just kids doing it for devilish fun, it's for profit. It's to scare people into signing up and paying for the fake antivirus software. Just like with some spam (or in olden days, direct mail,) if you get one response per 1,000 hits, you make money...
user-pic
I never responded to his posts. Don't think that's it.
user-pic
I had the same problem a couple weeks ago, and couldn't get rif=d of the pop-ups, couldn't access any of my anti-spyware programs, and the computer crashed. Couldn't run windows; I was freaking out. Eventually the computer shut down wouldn't boot.'
For some reason, by morning, I could boot a DOS screen, and could get to a Restore point; but the whole thing left me wit the willies.
I posted about it then, but no one else said they'd had the same problem, so it must not be TPM-related problem. It happened after being only on this site.
Flowerchild pointed me to the free SUPER-Antivirus program. I have that now, and SpySweeper.
user-pic
I had the name wrong; here's the link.
http://superantispyware.com/
user-pic
I posted about it then, but no one else said they'd had the same problem
Well, thanks for saying it again, so they know more than one person suspects this site.
BTW, I fixed it the way you did, I went to Windows Restore, forgot to say through "safe mode," and then got some Anti-Malware protection pronto.
You know, I had a geek do some set up work when I bought this laptop a couple of years ago, and he said not to use Windows Restore, it's bad, and shut it off...and that AVG is wonderful, not like Norton or McAfee, you should get the paid edition.....blah blah blah. Well, AVG used to be wonderful, but in the last couple years it's become evil like the rest of them, mho, and fully updated it didn't protect me from this malware which is named to look like it! (I did a search on AVG site for "AV Security Suite" and it turned up zero!)
And I am sooooo glad I went and found out where to turn Windows Restore back on after he shut it off; turns out I set it to make copies every day. If I hadn't, I'd be one of those people on the "help I got a malware infection and can't get rid of it on matter what I do" forums.
user-pic
I was also frustrated because I have forgotten all the DOS commands I used to know from my first 286 PC days; i tried to google DOS commands for 'stop loading', and found nothing! I felt helpless; always the computer and email glitches happen on fridays, so no tech help, and I live in this area where computer help takes days or even weeks. I couldn't think of being computerless for that long (not much of another life, but....there it is.
May I offer a hearty 'piss-whizzle' to the tech world and the numerous ways we are unprotected from perfidous scallewags who wish us harm, or really don't give a rat's ass?
user-pic
Offer your piss-whizzles all you want, Wendy :-)
In the meantime, try this for shutting down your browser in times of crisis:
I've found the only way to successfully close your browser is through the Task Manager. To bring up Task Manager in Windows - hit the Ctl-Alt-Del series of keys. Depending on your version of Windows, Task Manager will then start or a screen will appear that gives you the option of shutting down, restarting or opening Task Manager. Once Task Manager is up, Click on the Applications tab, then your Browser, then the End Task tab towards the bottom right of the box. I should probably copy and paste this part in reply to Wendy Davis.
user-pic
Nice puppy.
user-pic
Thanks, seashell. When it was crashing, windows wouldn't respond at all, neither would the anti-spyware programs.
Next time i'll try not to panic as strongly; but this was the third time that malware had kicked my ass, and it seemed almost final. ;-)
I still can't figure out how resting overnight helped enough that it could even boot up a DOS screen; it was like little DOS elves came in during the night. (grin)

user-pic
Do you know if Macs are also prey to this sort of invasion? Or is it equal opportunity, whether PC or Mac, so long as one is using Windows Office Suite?
I had an inexplicable, yellow triangle/ exclamation point pop-up a week or so ago. Was that malware? I couldn't esc or go back a page or even close the page so I force quit (bad to do that, right?) and rebooted.
And, yes, I was on TPM at the time.
user-pic
I have not gotten any on my Mac Mini or Linux systems. I do not browse with windozzzz....
C
user-pic
If your computer basically went back to what you are used to seeing after a reboot, you didn't get the malware we are talking about getting. It's possible you have some kind of program that protected you which also caused the freeze up? But that's just speculation from someone who doesn't know much about these things....
user-pic
Me too. Twice.
user-pic
I don't think I noticed anything, but thanks for the alert.
user-pic
AV Security Suite scareware is making the rounds. I did not get it but my son got it on his computer (and he never visits TPM. I had read that it actually exploits a vulnerability in Adobe (reader?)PDF files.
The best way I know to get rid of this pest, and annoying junk like it, is to follow the removal instructions from bleeping computer (dot) com. Here is the link:
http://www.bleepingcomputer.com/virus-removal/remove-av-security-suite
This is a great computer geeky site and have used it many times to help people in exactly this situation.
And just for general info, Malware Bytes is a great removal product and you can download the free version from CNET (one of my favorite places for clean reviewed downloads)
http://download.cnet.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html?tag=mncol#editorsreview
I am positive that it is not a TPM specific thing. This kind of crap infiltrates in waves.
Hope this helps anyone who is experiencing this problem.
user-pic
Thanks for the comment and the links. I am going to bookmark bleeping computer and I already use CNET.

user-pic
Thanks for contributing tips.
Still, I'm not convinced I didn't catch it from something on TPM. I am certain I haven't opened any PDF's within weeks of it happening. Nor did I download any attachments from email with the time frame.
Also, if people get the AV malware that I did, unless they are really savvy with Windows, I don't recommend trying the removal instructions for AV Security Suite from mybleepingcomputer. My link in my post for AV Security Suite is to bleepingcomputer.com's page on it. I learned a lot reading their post and the comments, also the post and comments at removalblog.com. It's where I learned about Malwarebytes' software.
It's not easy to remove, there are no tools anyone has made, just instructions for removing it manually that requires a lot of expertise. There's a lot of people in comments on both sites that tried it and it didn't work and they may have screwed up their computers further. I did print out the instructions, and started to try to do it, then I think I may have mistakenly deleted a registry item that wasn't part of the malware, because the names of the files are intentionally like important program files. Also many infected said the files are scattered in places where many can't find them without special permissions.
Like I said upthread, I am glad I had Windows Restore in this situation. By going back a couple days after I fucked up trying to remove it, I got rid of any mistakes I made to the registry. If people who are infected have Windows Restore, I recommend they use it in safe mode, and then get one of the protectors for this malware.
There were commenters on both help sites that said they got rid of it using Windows Restore, but several of those said they caught it again a few days later. None of those that said they caught it again said they downloaded special protection program after using Windows Restore. This suggests to me that it comes via a website that the people visit frequently. AND two people on this thread said they such malware twice. And when I used TPM on the browser I don't usually use for it, Malwarebytes gave an alert that they had blocked something.
So to me, TPM is still quite suspect.
user-pic
You're safe from any kind of virus except microsoft macro virus (MS office) pretty much if you have a Mac (and that doesn't effect your computer, only your microsoft files). You can control the pop up junk very well with Firefox browser.
user-pic
Your statement is completely false.
In case you haven't noticed the writers of this type of attack and others have finally caused a response from Apple. Apple recently has started to include malware protection as part of their operating system.
FYI. Security researchers world wide at DEFCON and Black Hat Security Conferences have repeatedly demonstrated the Apple OS and the Safari browser in particular are more vulnerable than the Google Browser and Windows Vista or Windows 7. This is not an arguable fact. Anyone can read the analytical reports of the conferees and see the results of their testing. Security researchers are in wide agreement the primary reason Apple hasn't had more problems is because attackers have focused on Windows.
user-pic
Come on koala, you're just mad cause I showed you up so bad on another blog. And probably because you don't have an iPod. If you get one & listen to it, it calms down all that anger and bad language. Pretty soon you'll be out throwing a bone at a dog or taking your Mom to Whataburger & just enjoin' the good ol USA!
user-pic
You are such an idiot. You are simply clueless about everything. You've proven this over and over. I gotta give you high marks for consistency though. You couldn't show up a rock.
user-pic
I'm curious...
Just what is malware?
BTW: I also have a Mac...
user-pic
aa - Spend enough time on the web and it's inevitable that you'll run into this one. Just ask the New York Times.
Here is fairly easy to understand explanation of the exploit. Link goes to Sophos.
FWIW - I checked sinosunnysun's blog and found only a couple of links. I didn't click, but my status bar said that both were to Wikipedia (English).
In my experience, and the New York Times exploit is included, the sh!t hits the fan immediately once you click the link. I'm pretty sure that if you weren't in TPM at the time, you probably didn't get it here.
user-pic
Oops, reply placed below as a comment, @ 10:12 PM.
user-pic
Thanks, seashell.
But you know, your link is just convincing me more that it was probably TPM.
The article you link to is about an infiltration through ads at the New York Times in Sept. 2009, where you had to click on the pop-up in order to get infected. Though I might have gone from New York Times to here and back, I would think they would have figured out how to protect their site by now.
I'm pretty sure it happened starting up after the laptop whent to sleep after I had been on this site and left the window open. I'm not 100% sure though, so I didn't make a straight out accusation but started this post.
Also I never click on ads except to close them if they are pop-ups. Never. They don't bother me, they just don't interest me, I've trained myself not to be distracted by them just like with a print publication. (When I shop online I do so by searching.) So it may not be through the advertising here.
Also, Emma Zahn's comment which I quote says she got it right after commenting here.
And the article also says:
Fake anti-virus alerts have become one of the biggest revenue-generators for cybercriminals, and as a result we're seeing more attacks all the time either planting malicious scareware on compromised websites
I will mention again that the tech management here said in one of the posts on the topic of getting rid of the spam problem that it was a particularly virulent and unusual breach of their site. They had a lot of trouble stopping them, for example, they had to shut off registration many times. If that happened, seems to me that what the article calls "cybercriminals" would find this website a very likely one to compromise.
Those that aren't getting infecteed either have another system that isn't infected, haven't been to where on the site it happens, or have protection that works.
It seems like a perfect site to compromise to me, they don't have a large savvy tech staff but they have a large interactive audience (not to mention recently partnering up with Facebook in a problematic manuever,) and have all kinds of clearly jerry-built ways to log in and out between the Movable Type blogging and other software.
The point:
After seeing the evidence on this thread, I really do think everyone who uses TPM with Windows should download and install either the Superantispyware that wendy used or the Malwarebytes Anti-Malware. I think it might be dangerous to use this site without that. I didn't click on any pop-ups, but I still got infected. Right now, I wouldn't recommend any friends or family use this site without getting anti-malware protection that keeps up with the newest scareware.
user-pic
aa- I didn't click on an ad in the New York Times. It was a link within a politics article that did me in.
It was after clicking on the link that the pop-up box appeared, one that looked like this. (Link to Sophos jpg)
This box popped-up within seconds of clicking on the link contained within the article I was reading. It is this box that they were warning users not to click - not the original, supposedly safe link that I clicked.
Having been hit more than once by this irritating sh!t, I've found the only way to successfully close your browser is through the task manager. To bring up Task Manager in Windows - hit the Ctl-Alt-Del series of keys. Depending on your version of Windows, Task Manager will then start or a screen will appear that gives you the option of shutting down, restarting or opening Task Manager. Once Task Manager is up, Click on the Applications tab, then your Browser, then the End Task tab towards the bottom right of the box. I should probably copy and paste this part in reply to Wendy Davis.
So again, it seems likely that you were not in TPM at the time of the infection. I've clicked on links in Google with the same result, as well as other, usually considered safe, web sites. And I'm not saying it couldn't happen in TPM, just that you would probably know it.
BTW - I believe that only the paid version of Malware Bytes offers the preventive measures you speak of. The free version merely cleans them up after infection :-). There are other apps that offer preventive measures, but none of them are guaranteed because who can keep up with the turkeys that send the malware out in the first place?


user-pic
Just re-read Aunt Sam's comment at the top. She says she was in TPM, so it's likely you are right about where you got it.
user-pic
I think you're over-reacting...and that's exactly what they want you to do. That's how spyware authors gets their kicks. They do something that stir up fears and everyone panics, goes out and buy new software to protect themselves. Once the dust settles, they strike again and the panic starts all over again. You gotta learn to live with it. Make sure you keep all valuable info off the internal hard-drive...either memory/thumb drives or external/network hard-drives.
user-pic
You can also partition your hard-drive too. That way if you have to rebuild the C:\ drive, your data is safe on the D:\ drive.
user-pic
I don't get what is wrong with alerting people that it is happening? Do you also think TPM shouldn't have done anything about their spam problem?
As to your suggestion about dividing drives, to me that is overreacting, getting all geek when not necessary (This is personal taste, I think. Reminds me of the people who say "no problem, just uninstall and reinstall Windows." To some like me that is my worst nightmare, to others it is a fun exercise.) like I said, I am quite happy with Microsoft Restore, it does enough for me in that regard. Losing a day is no big deal to me. If I am working on something big and important, of course, I backup backup backup, like every hour. As to the whole system, Restore is enough for me.
user-pic
Unfortunately it is the ad aggregators who sell the advertising who are the culprits in this.
Many major sites face this all the time. Because of the numbers of users high traffic sites generate they are targets of how this all works.
You can blame TPM for this if you want but TPM hasn't got a whole lot to do with it. The single recourse for sites like TPM and others is take their business elsewhere. There are some problems with that because the major ad aggregators are few in number and control the lions share of this. They have a rotten track record in this regard. The 'scareware' stuff going around is a major pain. It is currently the most common infestation of malware. A couple of variants of this which have surfaced in the last week or two have become increasingly difficult to remove. These are largely independent of the browser you use.
A simple way to protect yourself if you have Windows XP is to create a user account on your computer that has standard permissions only and browse with that. Don't use an account with admin permissions. With Windows Vista and Windows 7 there are underlying mechanisms in those operating systems which more or less take care of this for you, making them significantly less vulnerable.
user-pic
There is method of passing on infections called drive-by downloading.
Ever notice an article you want to read has you going thru a couple of pages to get to the article? While surfing thru the pages you can accidentally pick up something really nasty....tracking cookies, malware, viruses and so forth. Sorry, but that's the way the internet works.
Your anti-virus software, if it's up-to-date, should pickup any known infections that are in its' data dictionary. It's the one's that aren't in there that kills you. If both AV Security Suite and AntiVirus 7 are known, your anti-virus manufacture should be able to work with you to tweak your application to make sure it gets captures them before any damage occurs.
As for the infections, I suspect the blogger has figured out how to infect users who reads an infected blog. This may be a new twist that exploits a loophole in the security scheme used by anti-virus manufactures.
I make it a point to run my anti-virus, spybot (shareware) and spywareblaster (shareware) every other day - that includes data dictionary updates too.
The real problem is users are at the mercy of the attackers. Anti-virus software is only good for known attacks that follow a pattern. Anything that doesn't conform to known method of attack can be overlooked and not caught before it does its' damage. The anti-virus community can't second guess every step an attack will take.
user-pic
I got a migraine recently after reading TPM. Does that count?
user-pic
Only if it were a *viral* migraine. ;-)
user-pic
Wow! So I was not just experiencing a paranoid delusion? That's a relief. Now if I can just stop Antivirus7 from continuing to haunt me.
I was sure I got the infection from TPM because it was the only window/tab I had open at the time. I also know I made it worse than it might have been because my reflexes are not what they once were. I was not able to stop a click intended to return me to the TPM thread after commenting and instead clicked on the first Antivirus popup. It was emulating a WindowsXP security screen. It took me longer than it should have to realize that screen should not be showing up as an IE8 tab.
It is a very, very annoying program. It still shows up as an add-on in my IE8 even though I disabled it there and deleted the file from my system. Like seashell, I deleted the program I found in my Task Manager processes called antivirus7.exe and also removed it from my system tray. Then I searched for and deleted any file I could find that had been added to my computer that day.
Even after all that it still launches on restart. I haven't been in my registry yet and won't until I get a Ritalin refill. :)
I noticed on initially researching that the files on my computer were similar but did not exactly match those in the 'fixes' I found. Looks like there are various versions out there.
And, I got infected despite having two firewalls and two anti-virus programs running. Like I said, a really, really nasty bug.
user-pic
Thanks so much for chiming in with details Emma, and you sum it up all so well here:
And, I got infected despite having two firewalls and two anti-virus programs running. Like I said, a really, really nasty bug.
That's I've been trying to make clear to those who are turning it around to a blaming the victim story, i.e., "you must have done something wrong." I still don't get why fully updated subscription to AVG didn't protect me, especially as I got a version. It's not like these were just invented yesterday unless there is something unusual about the way they are attacking?
I'm sorry to hear you ended up with the mess that is described by many other victims on those help sites, with the bits and pieces of files scattered all over and it still popping up.
That's why I recommended that if it happens to anyone else, seems like the best way to react is the way me and wendy stumbled into, to use Windows Restore and zap it from behind with protection.
Like I said, so far, fingers crossed, I got lucky and it only cost me an hour or so. I only thought it right when I saw your comment to warn others and possibly TPM if the thing was rampant, because if eventually programs like AVG mark their site as "unsafe" I'm sure they would want to do something about that.
I've been online since the early days of ebay and have never ever caught anything (if I did it was so benign I didn't know about it, and since I've been so lucky I guess it was finally my turn.) And I spent some time as a moderator on another site communicating with a white hat hacker that threatened to go black hat when he was unhappy with management, so I am not unwise about the thinking in that world and how they can attack a site.
Also, from some comments, I suspect some people commenting are confusing what we got with something more benign that they've encountered in the past. But in a way, that's good that they haven't had to deal with the mess that these things cause and how intensive and complex the fix is if you get infected, and can lecture about the wrong thing.
I'd hate to see someone like my father, for example, have to deal with it.
A tip for you from what I did wrong before I scrapped trying to fix it and went to do the Windows Restore thing: when you go to look for the files be very careful to make sure you are not removing original registry files. I don't know about Anti-Virus 7, but with AV Security Suite, their files were almost identical to some original files, with only a few characters changed.
user-pic
Emma, here's a comment I saved on Notepad from one commenter on the help sites which you might check into to help you clean up. Cavaet that it was regarding AV Security Suite and not Anti-Virus 7, and of course who knows if he knows what he's talking about. But any little bit helps:
flyboy says June 16, 2010 at 6:14 am: My system got this nasty little bug yesterday through a legitimate site and have (I think) now got it off.
Neither AVG9 nor Superanti spyware would get rid of it.
Microsofts Security essentials will, it will automatically check for updates and run a quick scan.
It found it and has removed it.
No need to buy anything and no need to reboot in safe mode.
Only will work if you can validate your copy of windows though.
user-pic
I use Norton protection and (knock wood) no problems up till now. Recently I did suddenly have something purporting to be McAfee suddenly running a scan, but it had all its certificates in order and I had no trouble dis-installing it. If you have a good anti-virus program, and I would advise not skimping on this item, you shouldn't have any problems
user-pic
Reply below @ 2:29 as a comment. Also I will add to it that Emma Zahn, commenting just above you, had two anti-virus programs running and was still infected, directly following commenting on this site.
user-pic
If you have a good anti-virus program, and I would advise not skimping on this item, you shouldn't have any problems
That's simply not true in this case, David. You've just been lucky. The links in my original post have long threads of comments by people who have gotten infected with this kind of malware while they were being protected by the top anti-virus programs. They all learned that you have to have a good specialized anti-malware program as well if you are a prolific internet user (many suspect getting it from a "legitimate" site.) I read all the comments on the AV Security Suite infection on both bleepingcomputer.com and removalblog.com and some infected included those with full Norton protection. Even some of the more popular antispyware programs were cited as not protecting the victims, it has to be one that keeps up with malware.
user-pic
An example of how sick the world is these days, anyone notice that Spyware Doctor keeps sponsoring this thread?
Posted by bluebell
June 29, 2010 6:46 PM | Reply | Permalink

No comments:

Post a Comment