ShareThis

Showing posts with label Virus. Show all posts
Showing posts with label Virus. Show all posts

Wednesday, January 25, 2012

Is www.007guard.com a virus? Spybot S & D, Hosts file info

I just found out in doing a localhost TCP client server that my hostname was "www.007guard.com" for 127.0.0.1. Thinking this was a virus, I headed off to the hosts file to see what was up, and to my surprise, there was a huge list of virus/scam/phish type websites listed:

Example:

# Start of entries inserted by Spybot - Search & Destroy
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.1001-search.info
127.0.0.1 1001-search.info
127.0.0.1 www.100888290cs.com
127.0.0.1 100888290cs.com

None of these sites are actually viruses. This is part of Spybot's immunization process against these malicious urls.

Some software products (like spybot) place entries into the hosts file to disable access from your computer to known malware or advertising servers. 127.0.0.1 is a loopback address to your own computer, so by associating a web address with 127.0.0.1 in the hosts file will cause any attempts to visit that web address to fail because it's trying to load the website from your own computer and not the real location of the website - this results in less advertising in the webpages you view amongst other things.

SO! If you run into this... you are not infected or hacked. It is Spybot trying to protect your computer from that.

Monday, December 19, 2011

[W7 FIX] "The remote procedure call failed and did not execute."

Fix 1: Reboot

Fix 2:

go to Start menu and choose run then type in services.msc

When services comes up look for remote procedure call service and restart it.

But I'd also recommend scanning for virus and spyware because those tend to screw up RPC services.

Wednesday, December 14, 2011

Yet another spam email "Notification about the rejected Direct Deposit payment"

This is a spam email. DO NOT click the link they give you. Delete the email.


Benny Keller shivprint@punkassgear.com


Attn: Accounting Department

We are sorry to inform you, that your latest Direct Deposit via ACH transaction (No. 45098742114) was rejected, because your current Direct Deposit software version was out of date. Please visit the secure section of our web site to see the details:

(link removed)

Please apply to your financial institution to get the updated version of the software.

Best regards,
Benny Keller
ACH Network Rules Department
NACHA - The Electronic Payments Association

13450 Sunrise Valley Drive, Suite 100
Herndon, VA 20171
Phone: 703-561-1100 Fax: 703-787-0996

"Direct Deposit payment was declined " Spam email

This is a spam email. DO NOT click the link they give you. Delete the email.

Benedict Warren kurtp@illumsys.com
Attn: Accounting Department

We are sorry to inform you, that your most recent Direct Deposit transaction (# 429301356463) was rejected, because of your current Direct Deposit software being out of date. The detailed information about this matter is available in the secure section of our web site:

(link removed)

Please contact your financial institution to obtain your updated version of the software needed.

Yours truly,
Benedict Warren
ACH Network Rules Department
NACHA - The Electronic Payments Association

13450 Sunrise Valley Drive, Suite 100
Herndon, VA 20171
Phone: 703-561-1100 Fax: 703-787-0996

"Urgent notice about your electronic payments" Spam email

Spam email from Linda Arias ntsujimagee@museumstoomtram.nl


This report is related to the ACH transaction (ID: 22815950031) that was recently sent from your account.

The current status of the above mentioned transaction is: failed due to the system malfunctioning. Please view the report below for the details:

(link removed)

Kind regards,

Linda Arias
2011 NACHA - The Electronic Payments Association
13450 Sunrise Valley Drive, Suite 100
Herndon, VA 20171

Friday, December 9, 2011

How to choose the right Anti-Virus (for Windows)


Having repaired several thousand PCs over the last ten years, I've learned a few things about the subject:


1) When someone says he/she "likes" a particular AV, I never take that person seriously on the subject. An AV choice simply isn't like choosing a graphics program or word processor. The average PC user simply doesn't enough info to know how their choice fares against anything else, even if they've tried others. You must be guided FIRST by sources like AV-Comparatives, who have the resources to objectively and rigorously test the various offerings. AV-C also permits you see how different programs fare over time.


Sadly, PC Mag and ZDNet no longer do this kind of in-depth, comparative analysis, so I have to get off my butt and find other sources [besides AV-C], but you get my drift.


2) When someone mentions that the program is free, I always reply: "free AV is generally too expensive." I realize that it's a tough economy and everyone can't a full price program (BTW, I'm the senior PC tech for a branch of a Fortune 500 retailer), but there are LEGAL ways around the high price of software. You can buy up-to-date, discount security software from 
 Amazon. 
Amazon has several deals, so at their everyday prices you can protect multiple PCs without breaking the bank. (Like Kaspersky IS 2011 3-user for approx $30, incl shipping.)


3) Finally, stick with Firefox, Chrome, and/or Opera to minimize potential exposure to malware in the first place. These browsers (as opposed to IE) are far less likely to blindly download and execute [embedded] malware and thereby cause a problem that must be fixed.


For the record, in the last ten years, I've used Spybot, MalwareBytes, Avira Free, CA eTrust AV, Norton IS/Norton 360, and have settled on Kaspersky IS. KIS runs well even on most small memory (512MB) PCs, so that's what I use for default protection on PCs that I've redone/cleaned. KIS is very flexible (and inconspicuous) for power users and is feature-rich, so a novice need only install it to get excellent protection (ie. one doesn't have to tweak it to achieve adequate protection.)


Kaspersky has recently made major improvements to its stable of products. The latest Kaspersky Pure (equivalent to Norton 360) offers a centralized management interface (haven't tried it yet !), so one can tweak/update/etc any licensed PC, from a single PC. Kaspersky One offers an Internet Security package for any combination of up to five different devices (haven't tried it yet either !), ie. PC, Mac, and smartphone !

Monday, July 25, 2011

How to Remove Jucheck.exe Trojan


Remove Jucheck.exe Trojan (Uninstall Guide)

Jucheck.exe is the Java update verification process which notifies users about new updates available for the Java software installed on your computer. Unfortunately, it's not uncommon for malicious software authors to use well known and legit file names to confuse users and in some cases to avoid detection. We previously wrote about a Trojan horse masquerading as msiexec.exe. There's also an IRC backdoor Trojan which uses another legitimate file name jusched.exe to trick users into running malicious code on their computers. So, how do you determine whether it's a virus or a legitimate application? 

First of all, you should verify that the file is digitally signed and verified by the distributor of software. Jucheck.exe should be digitally signed by Sun Microsystems, Inc., but if the publisher is Unknown then it's probably some kind of malware. 

Secondly, you should verify the file location. Legitimate Java software updater runs from C:\Program Files\Java\jre1.6.0_01\bin\jucheck.exe. This part \jre1.6.0_01\ may vary depending on the version of the Java software installed on your computer. Malicious software usually runs from Windows temporary folder (%Temp%) or Windows system folder (%Windir%). If the jucheck.exe runs from C:\Users\AppData\Local\Temp\jucheck.exe folder or fromC:\Windows\jucheck.exe then you shouldn't allow it to run. 

Finally, you can upload the suspicious file to VirusTotal, Jotti or VirScan to determine whether it's malicious or not. If the file is infected, you should get similar results: http://file.virscan.org/report/f1c42499897ee70aaa40cc4f1619571c.html

If you got the User Account Control (UAC) message about jucheck.exe from Unknown publisher asking you to make changes to your computer, please click No and scan your computer with legitimate anti-malware software. 



Download free anti-malware software from the list below and run a full system scan.
NOTE: With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

If you need help removing the jucheck.exe malware, please a comment below. Good luck and be safe online!

Tuesday, July 19, 2011

Removing virus TRAPI32.exe / TRAPI.exe (AIDEX RunTime)

Not sure how this got onto my system, but if you find yourself with a TRAPI32.exe running in the background under the SYSTEM classification, you may be at rough ends trying to use antivirus to clean it up.

I highly recommend that if you don't already have ZoneAlarm (free version) that you get it. I had ZoneAlarm running during the incubation of this virus. Trapi32.exe will make repeated calls to a Ukranian IP address, so if you don't have some sort of network firewall, you might be at a higher risk to suffer damages from this.

The fix is simpler than you think; no antivirus needed. Ending the task won't kill it because it will just come back. Same with "api-ms-win-core-io-l1-1-032.exe" which seems to have come with the virus.

 Heres how you get rid of it:
  1. Navigate to the folder it is in (Mine was C:\Windows\SysWOW64\trapi.exe
  2. Right click on the exe file. Select "Properties"
  3. Navigate to the Security tab. Now, under "Group or usernames:" select "SYSTEM"
  4. Select the "Edit..." button, and click a "Deny" permission. It should mark all under Deny. Accept, and close out (return to the file in windows explorer.)
  5. Select trapi32.exe in Task Manager and kill it. It shouldn't come back.
  6. Delete the exe file trapi.exe. 
  7. Done!
  8. Do the same for the api-ms-win-core-io-l1-1-032.exe file as well. I think it was under C:\ProgramData\ 
Keywords:
dll runtime files exe libraries how to fix a virus online virus free online what is runtime jucheck.exe
aidex runtime virus msiexec.exe GhostObjGAFix aidex.exe malwarebytes Vista service package 2 Windows 7