 |
Welcome to Windows 7 Forums. Our forum is dedicated to helping you find solutions with any problems, errors or issues you are experiencing with Windows 7. The Windows 7 forum also covers news and updates and has an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.
Windows 7 - Possible infection through a job ad - advice welcome |
01-25-2012
|
#1 | | |
Possible infection through a job ad - advice welcome Hi all,
Firstly - I don't quite believe I've just done what I have so a dunce cap is being placed upon my head as I type.
I got back from a run last night to see a reply to a job I'd applied for on gumtree. Really I should have sussed something but a combination of fatigue, dunce-ness and desperation meant the email which asked me to download an application form via winzip was obliged.
What was unzipped wasn't even a MSWord document or icon, but a programme icon. The extraction process never seemed to happen as the pop-up with the % bar never started up (just appeared for a bit and then disappeared).
Anyway - sense soon returned and alongside it a howling panic. I googled the scam and it's a common one. I also re-started in safe mode and ran Malware Malbytes full scan and the same with Avast. Avast only picked up "Java:Agent-AIB[Expl]".
Now - two questions. Firstly do you think the virus downloaded properly? The pop-up icon never indicated a full unzip. Secondly, if so could this be it? I'm paranoid that it's on my PC and undetectable.
Advice and help welcome as ever.
| My System Specs | | System Manufacturer/Model Number Advent Centurion CPQ9104 OS windows 7 CPU AMD Phenom x3 8600 Motherboard Foxconn A7VMX-K Memory 4gb Graphics Card HD Radeon 5770 Sound Card Realtek ALC662 Monitor(s) Displays AOC 936swa PSU Corsair 700W Cooling Cooler Master CM12V Hard Drives 640 GB
SATA, 7200 RPM |
01-25-2012
|
#2 | | Windows 7 Ultimate x64 SP1, LinuxMint 9 LTS x64, Debian 6, Ubuntu 10.04 LTS x64 |
Hi,
Is the download still on your PC? If so, I recommend uploading here for an online scan if the file is smaller than 20MB in size: Jotti's malware scan
If not, then please run an online scan using ESET ONLINE SCANNER and post back the results: ESET Online Scanner
Regards,
Golden | My System Specs | | System Manufacturer/Model Number Golden Mk. I.3 OS Windows 7 Ultimate x64 SP1, LinuxMint 9 LTS x64, Debian 6, Ubuntu 10.04 LTS x64 CPU Intel i7 860 @ 2.80 GHz Motherboard Gigabyte P55A-UD3R Rev.1. Award BIOS F13 Memory 16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24) Graphics Card EVGA NVidia GTX 560 1024MB Sound Card Realtek Integrated Monitor(s) Displays Dual Samsung SyncMaster 2494HS Screen Resolution 1920*1080 and 1920*1080 Keyboard Logitech G110 Mouse Logitech MX518 PSU Thermaltake ToughPower QFan 750W Case Thermaltake Element S VK60001W2Z Cooling Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans Hard Drives 1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
2*Samsung F1 SpinPoint 1TB in RAID1;
1*Western Digital WD10EARS 1TB
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0 Internet Speed Not fast enough!!! |
01-25-2012
|
#3 | | |
Do a system restore to a point before you opened the attachment... | My System Specs | | System Manufacturer/Model Number HP Pavillion 601 OS Windows 7 Ultimate CPU Intel P4 3.4Ghz Dual Processor Motherboard Austek Memory 2GB Graphics Card Integrated 82915G Chipset 128MB Sound Card Intel HD integtrated Monitor(s) Displays HP2009m 20' HD Wide Screen Screen Resolution 1600x900 Hard Drives WD 250GB WD 500GB External Internet Speed 30mb |
01-25-2012
|
#4 | | |
Golden,
thanks for that - I'm running the scan at the moment. I also have the email - it contains hyperlinks through which you download a winzip file.
Being an amateur I'm unsure how I can upload this to you? Should I download, save (but not extract) and email it? Or how esle can I upload it to you?
thanks again | My System Specs | | System Manufacturer/Model Number Advent Centurion CPQ9104 OS windows 7 CPU AMD Phenom x3 8600 Motherboard Foxconn A7VMX-K Memory 4gb Graphics Card HD Radeon 5770 Sound Card Realtek ALC662 Monitor(s) Displays AOC 936swa PSU Corsair 700W Cooling Cooler Master CM12V Hard Drives 640 GB
SATA, 7200 RPM |
01-25-2012
|
#5 | | |
kills that last order - ran it through Jotti and it reported varying trojan 'bankers'......unfortunately I think I opened it and uploaded it again (a dunce cap for a dunce cap?) something has been picked up on the scan you advised so I'm hoping it's this. | My System Specs | | System Manufacturer/Model Number Advent Centurion CPQ9104 OS windows 7 CPU AMD Phenom x3 8600 Motherboard Foxconn A7VMX-K Memory 4gb Graphics Card HD Radeon 5770 Sound Card Realtek ALC662 Monitor(s) Displays AOC 936swa PSU Corsair 700W Cooling Cooler Master CM12V Hard Drives 640 GB
SATA, 7200 RPM |
01-25-2012
|
#6 | | Windows 7 Ultimate x64 SP1, LinuxMint 9 LTS x64, Debian 6, Ubuntu 10.04 LTS x64 |
Hi,
OK. Complete the ESET scan, and then post the exact name of the threats it identifies here. Depending on what they are, you may need to do a System Restore as Tews suggested, or in the worse case a format and reinstallation of your system - it all depends on the severity of the malware.
We can help you through the restore or install if neccessary - this forum has many experts more than capable of getting you back up and running in a short time.
Regards,
Golden | My System Specs | | System Manufacturer/Model Number Golden Mk. I.3 OS Windows 7 Ultimate x64 SP1, LinuxMint 9 LTS x64, Debian 6, Ubuntu 10.04 LTS x64 CPU Intel i7 860 @ 2.80 GHz Motherboard Gigabyte P55A-UD3R Rev.1. Award BIOS F13 Memory 16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24) Graphics Card EVGA NVidia GTX 560 1024MB Sound Card Realtek Integrated Monitor(s) Displays Dual Samsung SyncMaster 2494HS Screen Resolution 1920*1080 and 1920*1080 Keyboard Logitech G110 Mouse Logitech MX518 PSU Thermaltake ToughPower QFan 750W Case Thermaltake Element S VK60001W2Z Cooling Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans Hard Drives 1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
2*Samsung F1 SpinPoint 1TB in RAID1;
1*Western Digital WD10EARS 1TB
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0 Internet Speed Not fast enough!!! |
01-25-2012
|
#7 | | |
Throwing my 2 cents in (or is it 2 pence?) there's another free product from Comodo called Cleaning Essentials that's getting some pretty good reviews as a malware detecting/removing program. I run full Malwarebytes scans regularly and always get clean results. First time I ran CCE it detected 5 suspicious files not flagged by any other scanner I use. Might be worth a try. Latest version is 2.3 just in case an earlier version is downloaded. Comodo Cleaning Essentials | My System Specs | | System Manufacturer/Model Number Sony Vaio VPCEB47GM Laptop OS Win 7 Pro 64-bit CPU Intel i5 2.4 Ghz Memory 8GB DDR3 Graphics Card Intel HD 3000 Sound Card IDT High Definition Monitor(s) Displays 15.6 WGXA Anti-Glare LED Screen Resolution 1280x800 Hard Drives 640Gb 7200rpm |
01-25-2012
|
#8 | | |
cheers Golden - I didn't note the name, as I remember it was something along the lines of win32/installCore and win32/registrybooster. It said they were variations of.
Going to run it again, also will run the Comodo (cheers Marsimar). Assuming that nothing comes up on either (and that the safemode Avast and Malwarebytes scans were clean). I should be ok? | My System Specs | | System Manufacturer/Model Number Advent Centurion CPQ9104 OS windows 7 CPU AMD Phenom x3 8600 Motherboard Foxconn A7VMX-K Memory 4gb Graphics Card HD Radeon 5770 Sound Card Realtek ALC662 Monitor(s) Displays AOC 936swa PSU Corsair 700W Cooling Cooler Master CM12V Hard Drives 640 GB
SATA, 7200 RPM |
01-25-2012
|
#9 | | |
just ran the comodo cleaning essentials and nothing came up. Just got the second ESET scan to do later.
thanks again. | My System Specs | | System Manufacturer/Model Number Advent Centurion CPQ9104 OS windows 7 CPU AMD Phenom x3 8600 Motherboard Foxconn A7VMX-K Memory 4gb Graphics Card HD Radeon 5770 Sound Card Realtek ALC662 Monitor(s) Displays AOC 936swa PSU Corsair 700W Cooling Cooler Master CM12V Hard Drives 640 GB
SATA, 7200 RPM |
01-25-2012
|
#10 | | Windows 7 Ultimate x64 SP1, LinuxMint 9 LTS x64, Debian 6, Ubuntu 10.04 LTS x64 |
Hi,
According to Wilders, InstallCore appears to be relatively innocous. RegistryBooster seems to be a PUA (potentially unwanted application)....think spam. I would still run the ESET scan to completion, and to be extra vigilent, I will ask our trained MVP malware fighters Corinne or Jacee to look at this thread.
Regards,
Golden
EDIT : I have asked Jacee or Corinne to look at this for you when they can. | My System Specs | | System Manufacturer/Model Number Golden Mk. I.3 OS Windows 7 Ultimate x64 SP1, LinuxMint 9 LTS x64, Debian 6, Ubuntu 10.04 LTS x64 CPU Intel i7 860 @ 2.80 GHz Motherboard Gigabyte P55A-UD3R Rev.1. Award BIOS F13 Memory 16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24) Graphics Card EVGA NVidia GTX 560 1024MB Sound Card Realtek Integrated Monitor(s) Displays Dual Samsung SyncMaster 2494HS Screen Resolution 1920*1080 and 1920*1080 Keyboard Logitech G110 Mouse Logitech MX518 PSU Thermaltake ToughPower QFan 750W Case Thermaltake Element S VK60001W2Z Cooling Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans Hard Drives 1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
2*Samsung F1 SpinPoint 1TB in RAID1;
1*Western Digital WD10EARS 1TB
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0 Internet Speed Not fast enough!!! Possible infection through a job ad - advice welcome problems? All times are GMT -5. The time now is 01:20 AM. |  |