PHOTOBUCKET VIRUS ALERT

Welcome to the Leverguns.Com Forum. This is a high-class place so act respectable. We discuss most anything here ... politely.

Moderators: AmBraCol, Hobie

Forum rules
Welcome to the Leverguns.Com General Discussions Forum. This is a high-class place so act respectable. We discuss most anything here other than politics... politely.

Please post political post in the new Politics forum.
Post Reply
Pete44ru
Advanced Levergunner
Posts: 11242
Joined: Sun Sep 02, 2007 7:26 am

PHOTOBUCKET VIRUS ALERT

Post by Pete44ru »

Please be aware that Photobucket.com has an imbedded virus, as of last night.

If you have pics there, like I do, and try to copy a link for posting a pic, a "Photobucket Support" window will pop-up to alert you to the possibility of a virus, and advise you to click on it to download the cure.

DO NOT DO IT !

SHUT DOWN IMMEDIATELY, AND GET OUT OF DODGE !

AND DO NOT INSTALL THE MALWAREBYTES "CURE", OFFERED.


The cure is the virus, and it's trying to extort $$$ for the mal(bad)ware download.

I would also immediately run a virus scan on my box ASAP I rebooted.

Read about it further here, where I did, on the Ruger Forum:

http://www.rugerforum.com/phpBB/viewtopic.php?t=45851

If your computer gets infected, (edit) DO NOT USE THIS LINK FOR REMOVAL INSTRUCTIONS:

http://www.removal-instructions.com/rem ... s2009.html
.
Last edited by Pete44ru on Mon Jan 26, 2009 9:17 am, edited 1 time in total.
User avatar
Hobie
Moderator
Posts: 13902
Joined: Sat Mar 31, 2007 1:54 pm
Location: Staunton, VA, USA
Contact:

Re: PHOTOBUCKET VIRUS ALERT

Post by Hobie »

Using Firefox, this didn't happen. Have they fixed it?
Sincerely,

Hobie

"We are all travelers in the wilderness of this world, and the best that we find in our travels is an honest friend." Robert Louis Stevenson
w30wcf
Senior Levergunner
Posts: 1358
Joined: Mon Apr 23, 2007 11:23 pm
Location: Erie, PA

Re: PHOTOBUCKET VIRUS ALERT

Post by w30wcf »

Pete,
THank you for posting. That happened to me yesterday and, fortunately, Norton stopped it.

w30wcf
aka John Kort
aka Jack Christian SASS 11993 "I can do all things through Christ who strengthens me." Philippians 4:13
aka w44wcf (black powder)
NRA Life member
.22 WCF, .30 WCF, .44 WCF Cartridge Historian
User avatar
J Miller
Member Emeritus
Posts: 14885
Joined: Sat Mar 31, 2007 7:46 pm
Location: Not in IL no more ... :)

Re: PHOTOBUCKET VIRUS ALERT

Post by J Miller »

I was just on Photobucket yesterday afternoon and it didn't hit me. I'm running Firefox too. However I did get hit by that virus the day before it became public knowledge early last year and it just about totaled this computer. It took us days of working on it to get rid of that stinking virus.

Joe
***Be sneaky, get closer, bust the cap on him when you can put the ball where it counts ;) .***
User avatar
SteveR
Senior Levergunner
Posts: 1436
Joined: Sat Sep 08, 2007 8:14 am
Location: New York

Re: PHOTOBUCKET VIRUS ALERT

Post by SteveR »

Virus 2009, antispyware 2008, 2009 and all of the different variants are one of the worst to get rid from your computer, it exploits windows internet explorer, and can do the same with firefox if already infected. It tries to trick you into buying there software, which of course allows them to steal your credit card and other personal information. Once you click on the close or any part of the window it self installs. The only effective way of not getting infected when it pops up, hit control,alt,del. Then click on application tab, then click on the program name and end from there.

This is a very, very bad one. I only succeeded in removing it from 1 computer, the others had to be reformatted and the os had to be reinstalled.

Firefox seems to help, but do use the add-on WOT, web of trust for Mozilla Firefox browsers, which will show you that the link Pete44ru used to remove the spyware is itself spyware!!

DONT USE THE LINK PETE HAS PROVIDED!!!!

AVG 8.0, Norton, Advanced System Protector, Spybot Seach and Destroy, and Adaware2008 will find most of this Trojan, but if you are already infected you will not be allowed to download any of these, so you will have to do with a different computer, install on the infected machine in safe mode. It takes a while to run scans when infected so expect a few days to get back up and running without formatting and reinstalling the OS.

Steve
User avatar
Old Ironsights
Posting leader...
Posts: 15084
Joined: Mon Apr 02, 2007 9:27 am
Location: Waiting for the Collapse
Contact:

Re: PHOTOBUCKET VIRUS ALERT

Post by Old Ironsights »

Another problem with this class of Malware is that it makes it almost impossible to close your browser.

Once you get the PopUp the ONLY thing you can do without installing the Malware is to kill the Browser process in the process tree.

Do this with the 3-finger-salute to get into Task Manager, or, keep a nice little utility running i the background called Process Explorer - a freebie from the M$ tech geeks that takes the place of Task Manager and lets you have much more controll over which processes you want to kill.
C2N14... because life is not energetic enough.
מנא, מנא, תקל, ופרסין Daniel 5:25-28... Got 7.62?
Not Depressed enough yet? Go read National Geographic, July 1976
Gott und Gewehr mit uns!
User avatar
Old Time Hunter
Advanced Levergunner
Posts: 2388
Joined: Sun Apr 01, 2007 11:18 am
Location: Wisconsin

Re: PHOTOBUCKET VIRUS ALERT

Post by Old Time Hunter »

Spybot search & destroy nailed mine before it got in, just denied it.
User avatar
Borregos
Advanced Levergunner
Posts: 4756
Joined: Thu Sep 13, 2007 7:40 am
Location: Ontario, Canada

Re: PHOTOBUCKET VIRUS ALERT

Post by Borregos »

Thanks for the heads up :D
Pete
Sometimes I wonder if it is worthwhile gnawing through the leather straps to get up in the morning..................
User avatar
AJMD429
Posting leader...
Posts: 32179
Joined: Sun Sep 09, 2007 10:03 am
Location: Hoosierland
Contact:

Re: PHOTOBUCKET VIRUS ALERT

Post by AJMD429 »

SteveR wrote: This is a very, very bad one. I only succeeded in removing it from 1 computer, the others had to be reformatted and the os had to be reinstalled.
I assume the "built-in" Restore function in Windows also gets corrupted by this malware, right...?

I miss the pre-Windows days where you could EASILY have your ENTIRE system backed up on a hard drive, un-plug it, and go back to your normal drive, then if your normal one got infected, simply replace it with the backup one. I'm guessing it is all the anti-copying stuff Windows has that thwarts such easy backup and restore.
Doctors for Sensible Gun Laws
"first do no harm" - gun control LAWS lead to far more deaths than 'easy access' ever could.


Want REAL change? . . . . . "Boortz/Nugent in 2012 . . . ! "
User avatar
SteveR
Senior Levergunner
Posts: 1436
Joined: Sat Sep 08, 2007 8:14 am
Location: New York

Re: PHOTOBUCKET VIRUS ALERT

Post by SteveR »

AJMD429,

Yes, it does reside in the Win Restore feature, when removing you have to turn off system restore, because on reboot the trojan will just reinstall itself.

Also a small program called HijackThis will help to get your browser back under your control, and as OI said, process explorer will show what is supposed to be running and what is not, at which time you can shut down the bad processes and use whatever antispyware-antivirus you are using to clean.

Steve
User avatar
gamekeeper
Spambot Zapper
Posts: 17446
Joined: Thu Sep 06, 2007 3:32 pm
Location: Over the pond unfortunately.

Re: PHOTOBUCKET VIRUS ALERT

Post by gamekeeper »

BTT
Whatever you do always give 100%........... unless you are donating blood.
Leverdude
Senior Levergunner
Posts: 1518
Joined: Tue Apr 03, 2007 6:25 pm
Location: Norwalk CT

Re: PHOTOBUCKET VIRUS ALERT

Post by Leverdude »

I'm running Firefox on a Mac & had no issues.
I dont understand these things but my wife says Macs dont get viruses.
User avatar
Old Ironsights
Posting leader...
Posts: 15084
Joined: Mon Apr 02, 2007 9:27 am
Location: Waiting for the Collapse
Contact:

Re: PHOTOBUCKET VIRUS ALERT

Post by Old Ironsights »

Leverdude wrote:I'm running Firefox on a Mac & had no issues.
I dont understand these things but my wife says Macs dont get viruses.
Not exactly true... it's just that most of the virus-writers are Macaddicts trying to screw with Windoze users... ;)

It's all about economies of scale. There are more PCs than Macs or Linux boxes, so more people can be affected by the viruses/bots... most of which have some sort of financial hook now.

Always target your biggest market. ;)
C2N14... because life is not energetic enough.
מנא, מנא, תקל, ופרסין Daniel 5:25-28... Got 7.62?
Not Depressed enough yet? Go read National Geographic, July 1976
Gott und Gewehr mit uns!
User avatar
marlinman93
Advanced Levergunner
Posts: 6479
Joined: Sun Apr 01, 2007 3:40 pm
Location: Oregon

Re: PHOTOBUCKET VIRUS ALERT

Post by marlinman93 »

I was there last night and my Norton notified me of an attempt that it had stopped.
Pre WWI Marlins and Singleshot rifles!
http://members.tripod.com/~OregonArmsCollectors/
User avatar
Old Ironsights
Posting leader...
Posts: 15084
Joined: Mon Apr 02, 2007 9:27 am
Location: Waiting for the Collapse
Contact:

Re: PHOTOBUCKET VIRUS ALERT

Post by Old Ironsights »

Was just there about 2 hrs ago. Aparantly it's been handled...

I run VERY minimal "active" protection, preferring to accepot or deny every core action manually... but there was no issue today...
C2N14... because life is not energetic enough.
מנא, מנא, תקל, ופרסין Daniel 5:25-28... Got 7.62?
Not Depressed enough yet? Go read National Geographic, July 1976
Gott und Gewehr mit uns!
JohndeFresno
Advanced Levergunner
Posts: 4559
Joined: Fri Sep 07, 2007 1:52 pm

Re: PHOTOBUCKET VIRUS ALERT

Post by JohndeFresno »

Thanks for warnings and for cures!!!
Pete44ru
Advanced Levergunner
Posts: 11242
Joined: Sun Sep 02, 2007 7:26 am

Re: PHOTOBUCKET VIRUS ALERT

Post by Pete44ru »

I think I'm gonna give photobucket at last another day - just to be on the safe side.

I can do w/o posting pics from there for awhile, since I also have a villagephotos account.

.
Post Reply