Malware infected AGAIN!

Submitted by 1464 on

Yes, I know this is a double post, kinda.  I just wanted to let the powers that be know that I actually was infected by a virus that I speculate may have been from MGoBlog, as it popped up as soon as I visited the site and locked down my PC.  I've seen posts on this topic, and my antivirus has picked up threats in the past.

Today, somehow, it got past my McAfee.  It popped up a fake antimalware program.  I'm in IT, so I've seen similar things.  Luckily, I was able to establish it as 'conhost.exe'.  It was a file located in the App Data folder in my Docs and Settings user folder.  I was able to log in as another technician in safe mode and delete my user folder.  I'm logged in as myself now and everything seems fine.  I'm running MBAM right now to see if anything is left over.  Just a heads up.  I'm sure you guys are looking into it.

Update:

So I came back to check this thread, and wouldn't you know it, the damn thing hits me again.  Stupid me for thinking it was an isolated incident.  I guess I'm the clinical definition of crazy.  I'm posting this in Safe Mode with Networking.  I'm not going to revisit this site from my PC again for a few weeks, to give you guys a chance to fix this stuff.  We don't have access to Internet Options on my work PC, as they think we will bypass the proxy, so I cannot ratchet up my security settings to adjust for this.

So MGoBlog, goodbye for now.  If fate is on our side, I will be back some day.  Probably around when fall practice starts...

Dark Blue

July 14th, 2011 at 9:29 AM ^

LOOK if you never listen to me about anything, listen to me right now. I use the paid version of malwarebytes which costs around $20. At the same time I also run AVG anti-virus which I think I picked up a 2 year licesnse for about $70. 

I surf tons of questionable content on the net. I download shit all day, I come to MGo whenever I want and I've never had a problem with malware. So for $90 you can do anything you want online. Pretty good deal imhe

Dark Blue

July 14th, 2011 at 9:58 AM ^

I didn't take it as a criticism. M-Wolve Imma give you an explanation for why I sometimes act like I do on MGo. 

You have all of these "die-hard" MICH fans but at the first sign of adversity ~75% of em act like the world is ending. I spent a lot of time around these parts, and never once have I ever said a bad word about a MICH player or corch, or hell any college kids for that matter. The same cannot be said for a lot of the posters on this site.

So about shortly after the 2010 football season, I got fed up with it and decided I was just gonna be a HUGE ass on this site. I don't come here very often other than to read what Brain or Tim writes. I pop in on the board every once in a while. 

BOOM EXPLAIN'D

M-Wolverine

July 14th, 2011 at 10:04 AM ^

I take it for what it's worth. Sometimes you cross the line from wacky to rude (but then, who hasn't?), but that's the danger when walking the cutting edge. For the most part, "I" don't mind. I just thought that last paragraph was helpful, yet completely in character.

mgokev

July 14th, 2011 at 8:43 AM ^

My work computer detected a black hole attack the second I opened IE7.  mgoblog is set to my homepage and I haven't gone to any other sites.

mgokev

July 14th, 2011 at 8:59 AM ^

I think all will be well if Samuel L Jackson comes in and hacks into the computer system to fix the mgoblog virus that the Newman guy put on there before he ran off with the super secret shaving cream vial holder...

phork

July 14th, 2011 at 9:44 AM ^

Corporations really need to start looking at alternative software.  IE (this machine still has IE6 on it) is a joke and a wide open door.  I speak to the IT guys at my place all the time and they are frustrated with all the idiots that get stuff, simply because they are forced to use IE and McAfee.

ottomatic

July 14th, 2011 at 10:52 PM ^

If your corporate IT is still on IE6 I'm guessing you are on XP, and have down versions of Adobe Reader, Flash, Shockwave, and JRE. That combination leaves you open to about 200 different exploits. Microsoft technically supports IE6 because it's within the ten year window but they have publicly advised against using it.

That's why criminal syndicates have zombie armys tha number in the millions.

 

Job Security for me, thank you lazy sysadmins.

M-Wolverine

July 14th, 2011 at 9:52 AM ^

My apologies to anyone who responds/asks a question that I don't reply on. It's kind of hard to track what's new in the App. We were promised some App upgrades this summer....I wonder if we can get "new post" in a new version.

elaydin

July 14th, 2011 at 10:08 AM ^

Busy with the ipad version... but I'll look into some sort of "new" indication before the season starts.  It won't match the web site's indicator, but it could be useful (assuming I can get it to work with decent performance).

MGoKereton

July 14th, 2011 at 10:18 AM ^

Hey guys.  I was attacked by this trojan last night as well.  It started installing some "Security Shield" anti-malware thing without my consent.  AVG Free quarantined it, but it didn't do any good.  Every fifteen seconds some notice about "How my computer is infected with malware" (except in very, very poor English) and I should click the balloon to fix it.  Now, every thing I do comes up as this "Security Shield" identifying it as a trojan and it won't open--meaning internet browsers, Word documents, anything.  It also seems to have destroyed AVG.  It doesn't even exist on my computer anymore.

Would running the computer in safe mode (with networking) and trying to install MalwareBytes or something similar save the computer?

maizenbluedevil

July 14th, 2011 at 10:41 AM ^

Safe mode + malwarebytes is exactly what you need to do.

I got infected by something here last year (sounds like the exact same thing you have) while at work and that's what the IT guy did to fix my computer.

After you fix it, if you run IE as your browser, ditch it ASAP and download FireFox + AdBlock and NoScript, or Chrome + AdBlock.

I'm running Chrome + AdBlock.  In one of the other threads someone noted that of all the reported problems, no one has reported the problems while running Chrome.  I don't think you can run NoScript on Chrome (someone correct me if I'm wrong), but, since there's been no reported issues with Chrome users yet, I'm taking my chances with Chrome even though I only have AdBlock and not NoScript.

Griff88

July 14th, 2011 at 10:44 AM ^

will take care of the issue MgoKereton.

- Turn off system restore

- Install Malwarebytes, boot into safe mode if able (If for some reason the infection prevents you from installing malwarebytes... try renaming the .exe to something else.)

- Run a scan... once it's finished it should clean the system.

- Reboot and run the scan again. You should be good to go.

Install Avast, or Avira free... or Microsoft Security Essentials. Or look into buying NOD 32 antivirus. Personally I use Avast Free and Malwarebytes Free. I have never had an issue with infections.