Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

XP Defender Pro is new clone of XP Internet Security 2010, which is a rogue antispyware program.

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Archives » General Discussion (1/22-2007 thru 12/14/2010) Donate to DU
 
BrklynLiberal Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Apr-27-10 08:12 PM
Original message
XP Defender Pro is new clone of XP Internet Security 2010, which is a rogue antispyware program.
Edited on Tue Apr-27-10 08:12 PM by BrklynLiberal
Printer Friendly | Permalink |  | Top
CRF450 Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Apr-27-10 08:23 PM
Response to Original message
1. The shit's getting rediculous.
I know so many people that put a fake anti-virus program on their computers not knowing that the program itself is a virus. Most of the time it's youngins that download stuff from limewire all the time.

And I love malwarebytes BTW, I use that for scanning the computer more than Avast!
Printer Friendly | Permalink |  | Top
 
BrklynLiberal Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Apr-27-10 08:25 PM
Response to Reply #1
2. I was just lucky. I almost bought this crap..and then something told me to Google it first.
Edited on Tue Apr-27-10 08:25 PM by BrklynLiberal
Thank goodness...
Printer Friendly | Permalink |  | Top
 
CRF450 Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Apr-27-10 08:33 PM
Response to Reply #2
3. 1 very important rule I go by when it comes to computer upkeep...
Is to use one or two reputable anti-virus programs, and never toutch anything else! But yeah in your case, the name of that program nearly fooled you for a moment.
Printer Friendly | Permalink |  | Top
 
csaclint Donating Member (4 posts) Send PM | Profile | Ignore Tue Apr-27-10 08:34 PM
Response to Original message
4. this bug is a pain in the rear!
If this is written the same as the previous versions, people should be aware that any action, including clicking the cancel button, or closing the pop-up window, will start the download process for this bug. If you happen to have this window pop-up while you are browsing, the safest thing to do is just a hard shutdown of the computer. For most new pc's just hold down the power button until the computer turns completely off.
Printer Friendly | Permalink |  | Top
 
BrklynLiberal Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Apr-27-10 09:27 PM
Response to Reply #4
8. I have absolutely no idea where it came from!!
I had my PC on..stepped away for a mintue and there were allt hese screaming warnings and alerts and lists of Trojans and viruses and crap.

I had no idea where it all came from. Still do not know how it got on my machine. I NEVER download anything unless I know where it came from....but obviously that is not enough
Printer Friendly | Permalink |  | Top
 
renate Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Apr-28-10 10:51 AM
Response to Reply #8
10. that happened to me too
My husband didn't believe that I didn't click on SOMETHING but I didn't even close a pop-up, not by hitting the X in the corner, not by hitting "close," nothing; I turned off my computer right away, which has usually done the trick in the past. (Even the NY Times got hacked a few months ago so visitors got a virus pop-up; a similar thing had popped up occasionally over the previous year and turning off the computer had always worked before.) This time, even though I didn't click on anything, I still got a virus, and when he looked it up, he found that I was without sin :) and that you don't need to click on anything to get this one.
Printer Friendly | Permalink |  | Top
 
Xithras Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Apr-28-10 11:06 AM
Response to Reply #8
12. It's a web based attack.
In a nutshell, a browser based Java applet generates a popup window that appears almost indistinguishable from a regular application window. It doesn't look like a browser popup, but it is. The application then precaches several applications, including a trojan exe file, into your cache folder. When you click any buttons on the window, the exe is activated and a stealth installer inserts itself into your system.

All of those screaming warnings are actually a part of the virus itself, designed to freak you out so you'll click on it.

The brilliant thing about this particular attack is that it actually doesn't exploit a security hole, but instead relies on user gullability. This particular attack works on all Windows browsers, but would also work on Mac or even Linux if the writers wanted to target those platforms. The application "plays by the rules" in the sense that it limits itself to acting as a safe browser process until the user activates the program locally on their system. It's a social engineering hack more than a computer hack.
Printer Friendly | Permalink |  | Top
 
BrklynLiberal Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Apr-28-10 11:12 AM
Response to Reply #12
13. So now that I have gotten rid of it, how do I prevent it from ever happening again?
Printer Friendly | Permalink |  | Top
 
Xithras Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Apr-28-10 10:58 AM
Response to Reply #4
11. Actually, there's a much easier (and safer) way to kill it than that.
The virus is capable of popping up without actually installing itself on the system, and can't initiate that installation until you click on it. If you are running IE8 with Protected Mode on (and ALL IE users should be running IE8 with Protected Mode at this point), the virus CANNOT install itself until you interact with it.

So...

When the virus window pops up, right click on your Task Bar and choose Start Task Manager. Highlight every instance of iexplore.exe and click End Process. Now reopen IE, click Safety, and Delete Browsing History (to clear the cached version of the installer from your temp folder). Because the virus is initially running as an Internet Explorer web application, killing IE will kill the virus. It's incredibly important that this be done before clicking ANYTHING else though. Once you click on the window and the virus installs itself, you will need to go through the full removal procedure.

The procedure is much the same for Firefox users (and no, Firefox isn't immune to this particular attack).

Powering down the computer accomplishes the same thing, but performing a hard shutdown is never recommended if there are other options.
Printer Friendly | Permalink |  | Top
 
BrklynLiberal Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Apr-28-10 11:14 AM
Response to Reply #11
14. Thanks The answer to my question was here and I didn't know it. I have Firefox, so i know it is
susceptible as well.
Printer Friendly | Permalink |  | Top
 
DainBramaged Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Apr-27-10 08:39 PM
Response to Original message
5. I have found a very easy way to stop it before it locks your system down
Edited on Tue Apr-27-10 08:45 PM by DainBramaged
Restart in safe mode without networking. If you have previously installed either CCleaner or Hijack this (here are their websites, both free by the way http://www.piriform.com/ccleaner/download
http://free.antivirus.com/hijackthis/ )

when the system starts in safe mode, fire up either one of these puppies. What you will find will be in the start up menu tool listed in the c:\user (you)\application data tree is a file with random numbers with a .exe multiple times waiting to be loaded when you start the computer. By deleting those start commands you will prevent them from reloading the next time you restart. Then you can delete the folders and restart, running malwarebytes or A-Squared or Super Anti-Spyware to get rid of registry entries.


Done it on a half a dozen computers at work over the past month or so.


ALSO, IF IT STARTS, KEEP HITTING CTRL AND F4 AT THE SAME TIME TO STOP IT THEN YOU CAN DELETE THE FILES YOU FIND VIA CCLEANER OR HIJACKTHIS
Printer Friendly | Permalink |  | Top
 
BrklynLiberal Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Apr-27-10 09:25 PM
Response to Reply #5
7. Thanks for this information!!!!
Printer Friendly | Permalink |  | Top
 
Hawkeye-X Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Apr-27-10 08:40 PM
Response to Original message
6. I don't trust any of the crap.
I use my IT knowledge to download trusted and proven software.

Many of them I know I can get for free if a little time of research is done.

Printer Friendly | Permalink |  | Top
 
DainBramaged Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Apr-28-10 10:43 AM
Response to Original message
9. K&R for Wednesday
Printer Friendly | Permalink |  | Top
 
BrklynLiberal Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Apr-28-10 11:15 AM
Response to Reply #9
15. ...
:thumbsup: :hi:
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Thu Jan 02nd 2025, 09:51 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Archives » General Discussion (1/22-2007 thru 12/14/2010) Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC