Forums » Air Combat & Civil Aviation » European Air War » RootKit virus


Topic Options
Rate This Topic
Hop to:
#3485624 - 01/01/12 03:01 PM RootKit virus
AngleOff Offline
Member

Registered: 08/14/07
Posts: 829
Loc: PA., USA
Guys,
this is the second time in as many weeks that I have gotten a virus
at this site. The first was when replying to a thread in the screenshot
and videos forum, and a little while ago trying to reply to Jel's thread
with the download link.
It seems to get in my computer thru a Java script. My Cleaner calls it RootKit.
It turns off your browser security settings, then your firewall, then prevents you
from launching any exe's that could fix your problem. I have to re-boot in safe-mode,
then do a system-restore to a previous day, then run a cleaner I have called ComboFix.
I have had to turn my Java off just to be safe. Most antivirus check any files you try
to download, but most do not stop applets, cookies, Java, or scripts run by your browsers.
(Although I use InternetExplorer as my browser, which may very well be the problem itself.
IE is just as problematic as Windows, WinXP, etc.)
I hope this is just me and no one else is getting this problem......but if you have XP,
maybe this will help.
Thanks,
AO

Top
#3485686 - 01/01/12 04:19 PM Re: RootKit virus [Re: AngleOff]
Col. Gibbon Offline
3DZ Model Builder
Veteran

Registered: 06/04/01
Posts: 11116
Loc: Fleet, Hampshire, England.
Thanks for the heads up AO.

I will check this out. wink
_________________________
Ah that's much better!

Wings Over Bytom

At home, with my great kids, Thomas, Jessica & little Nicola. smile

Top
#3485984 - 01/02/12 09:17 AM Re: RootKit virus [Re: Col. Gibbon]
Shadow9216 Offline
Junior Member

Registered: 09/06/10
Posts: 27
Loc: Pacific Northwest
Got an alert after browsing some of the threads- last one I viewed was the 3dz tutorial, don't know if that's a coincidence or not.
FYI, I use Avast- it's freeware and has been very effective.
Here's the details on the virus:
Infection Details
URL: http://www.ticheria.com/spotrjoin/875698...
Process: file://C:\Program Files (x86)\Mozilla Firefox
Infection: js:Downloader-gen@bhv [Expl]
(realized the link shows up as active- needless to say, don't click on it)


Edited by Shadow9216 (01/02/12 09:18 AM)

Top
#3486209 - 01/02/12 03:49 PM Re: RootKit virus [Re: Shadow9216]
wheelsup_cavu Offline
Veteran

Registered: 12/03/08
Posts: 17658
Loc: Corona, California
Originally Posted By: Shadow9216
Got an alert after browsing some of the threads- last one I viewed was the 3dz tutorial, don't know if that's a coincidence or not.
FYI, I use Avast- it's freeware and has been very effective.
Here's the details on the virus:
Infection Details
Code:
URL:	http://www.ticheria.com/spotrjoin/875698...

Process: file://C:\Program Files (x86)\Mozilla Firefox
Infection: js:Downloader-gen@bhv [Expl]
(realized the link shows up as active- needless to say, don't click on it)

Put it between code tags and it won't be an active link.


Wheels
_________________________
Cheers wave
Wheelsup_cavu

Mission4Today | Get RoF Templates @ Combat-Asylum
Planes of Fame Air Museum | March Field Air Museum | Palm Springs Air Museum

Top
#3486211 - 01/02/12 03:53 PM Re: RootKit virus [Re: AngleOff]
Col. Gibbon Offline
3DZ Model Builder
Veteran

Registered: 06/04/01
Posts: 11116
Loc: Fleet, Hampshire, England.
Pleased to report. No problems here. RootKit is on the Avast hit list, so it gets Nuked before it has a chance to do anything.

Nasty thing though, if your infected, a re-install is required. frown
_________________________
Ah that's much better!

Wings Over Bytom

At home, with my great kids, Thomas, Jessica & little Nicola. smile

Top
#3486328 - 01/02/12 08:26 PM Re: RootKit virus [Re: AngleOff]
Eugene Offline
Senior Member

Registered: 09/15/04
Posts: 4337
Loc: Oregon
About two months ago or so I got a root kit browsing here, after forgetting to restart AV program after a private MP online session wound up. It was as AngleOff described. I was able to cure it after a number of sessions over at My Bleeping Computer - very helpful site and volunteers. Combo Fix can make a variety of changes on one's machine, so probably wise to use carefully. But it along with a couple of other programs were necessary in order to restore internet connectivity, and fully root out the root kit. So to speak.

Not criticizing SimHQ, as many legit sites are or can be unknowingly infected or reinfected.
_________________________
Eugene

CoreDuo E6850
MSI P6N 680i Diamond
BFG N460 GTX Cyclone 1GD5 OC
Forceware 301.42
X-Fi Xtreme Gamer
WinXP Pro
2 gig RAM
Saitek X52 PRO.

Top
Topic Options
Rate This Topic
Hop to:

Moderator:  Avimimus, sandbagger 

Forum Use Agreement | Privacy Statement | SimHQ Staff
Copyright 1997-2012, SimHQ Inc. All Rights Reserved.