Antivirus Protection
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationAntivirus Protection

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #61  
Old March 20th, 2009, 09:04 PM
aschap aschap is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Mar 2009
Posts: 1 aschap User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 5 m 45 sec
Reputation Power: 0
windows update restore

so i've removed the filefix infection from the computer with Grinler's help, but before i worry about the corrupted files i'd love to turn windows update back on but all attempts still fail -


any advice?

Reply With Quote
  #62  
Old March 21st, 2009, 12:00 AM
Pop45398 Pop45398 is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Mar 2009
Posts: 2 Pop45398 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 42 m 56 sec
Reputation Power: 0
Quote:
Originally Posted by aschap
so i've removed the filefix infection from the computer with Grinler's help, but before i worry about the corrupted files i'd love to turn windows update back on but all attempts still fail -


any advice?


Try: http:_SlashSlash_support.microsoft.com/?kbid=326686

Replace "_SlashSlash_" with "//" . . .forum rules won't allow me to post URL's . . I guess that begs the question as to why I'd even bother helping someone here??????

Reply With Quote
  #63  
Old March 21st, 2009, 12:57 AM
midwesternwire midwesternwire is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Mar 2009
Posts: 2 midwesternwire User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 21 m 17 sec
Reputation Power: 0
It took two days to remove this virus

I saw this windows file protection pop up that said my ms office and media files were corrupt. I clicked on the message bubble and it took me to the file fix professional 2009 web site. It looked fishy and cost money so I closed the browser and went on with my business thinking i'd deal with it later. I tried to open a ms word document but it said the software was corrupt and it closed then opened a box containing a very long list of files that it thought were corrupt. Moments later the original pop-up appeared again. I opened the browser to start a google search for the problem and it immediately went to a random financial website (firefox was hijacked) windows defender popped up and said I had a virus. I started to scan my system for the virus but after a few moment a pop up appeared and said my computer was going to shut down in 60 seconds. Every subsequent attempt to remove the virus started the shut down process again. I started doing start->run->shutdown -a. that worked for a while. I'd have to do it every 30 seconds because the virus scan couldn't complete. Plus the virus kept mutating and would stop telling me when the computer was going to shut down. The system would just top responding and restart automatically. Eventually, the virus started to remove the explorer bar when it was going to shut down so I couldn't do anything but watch the system restart. After extensive research, I discovered what files were causing the trouble but the virus locked them so I couldn't delete them manually. I tried to use fileAssassin. That allowed me to remove a few files but they would be reinstalled. Things deteriated to the point that I couldn't even use safe boot. I had to use the xp cd's recovery program and reinstall the infected os files. When my computer was back up and usable i still had the viruses and windows file protection popup. i updated my virus software malwarebytes' anti-malware and super antispyware. I needed both because they detected different viruses. After going back and forth between scanning with the anti-virus programs in normal os mode then scanning in safe-boot i finally removed the viruses. I had several. The virus also changed my internet setting so nothing could connect to the internet. Everything was set to use a proxy and a few different ports and ip addresses. I reinstalled sp3 and checked the the files that were affected. Everything seems fine now. I have never had such an aggressive virus. I think the key is DO NOT CLICK ON THE 'WINDOWS FILE PROTECTION' MESSAGE. If that message comes up close all your programs. update your virus protection software and 'DISCONNECT FROM THE INTERNET'. Run your virus protection program. This virus moves fast and infects everything.

Reply With Quote
  #64  
Old March 21st, 2009, 04:07 PM
Grinler Grinler is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Feb 2004
Posts: 181 Grinler User rank is Private First Class (20 - 50 Reputation Level)Grinler User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 5 h 27 m 54 sec
Reputation Power: 6
The guide at BC was updated to include a tool that will scan a folder or drive, find encrypted files, and clean them automatically using the technique that Julia graciously supplied.

The guide can be found here:

http://www.bleepingcomputer.com/forums/topic212357.html
__________________
Grinler
BleepingComputer.com Virus removal Guides

Reply With Quote
  #65  
Old March 21st, 2009, 07:06 PM
0negative 0negative is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Mar 2009
Posts: 4 0negative User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 2 h 25 m 39 sec
Reputation Power: 0
Thanks so much for your efforts. I can't believe I got my files back!

Reply With Quote
  #66  
Old March 23rd, 2009, 05:37 PM
Grinler Grinler is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Feb 2004
Posts: 181 Grinler User rank is Private First Class (20 - 50 Reputation Level)Grinler User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 5 h 27 m 54 sec
Reputation Power: 6
Looking for feedback to make sure the file decryptor is working properly. Anyone run into any issues or does it appear to be working for you?

Reply With Quote
  #67  
Old March 24th, 2009, 12:55 AM
roo42 roo42 is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Mar 2009
Posts: 8 roo42 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 50 m 38 sec
Reputation Power: 0
Quote:
Originally Posted by Grinler
Looking for feedback to make sure the file decryptor is working properly. Anyone run into any issues or does it appear to be working for you?


First, I'd like to express my deepest gratitude to Julia Wolf, Grinler, and everyone else who worked to defeat this most destructive malware attack, and to develop a tool to enable us to restore our corrupted data files.

I am in the process of using the tool to repair my damaged files, and have been successful with all affected formats (.doc, .jpeg, .pdf and .mp3). As to the operation of the tool, I have observed that while in use it commands 100% of CPU resources, thus one can't really do anything else on the computer at the same time; also, whereas both the encrypting operation of the virus and the decrypting operation of the Filefix Pro "cure" seemed to do their work almost instantaneously, the "anti-filefix" tool takes substantially more time to work, with the time increasing along with file size. For example, decryption of a .jpg of about 5 MB takes 30 seconds to a minute to complete. (I have quite a few photos to process, so I have been running the tool overnight.)

Reply With Quote
  #68  
Old March 24th, 2009, 08:40 AM
Grinler Grinler is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Feb 2004
Posts: 181 Grinler User rank is Private First Class (20 - 50 Reputation Level)Grinler User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 5 h 27 m 54 sec
Reputation Power: 6
I will see what I can do about speeding up, but no promises there.

Reply With Quote
  #69  
Old March 24th, 2009, 03:22 PM
Julia Wolf Julia Wolf is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Mar 2009
Posts: 4 Julia Wolf User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 h 10 m 5 sec
Reputation Power: 0
Quote:
Originally Posted by Grinler
I will see what I can do about speeding up, but no promises there.


Filefix itself reads a 0x10000 byte chunk of the file at a time, decrypts it in memory, and writes it back out... Just FYI

Here are my notes about the decryption algorithm implementation in Filefix Pro:

http:/ /blog.fireeye.com/research/2009/03/filefix-professional-2009-cryptanalysis.html

Reply With Quote
  #70  
Old March 24th, 2009, 04:45 PM
Grinler Grinler is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Feb 2004
Posts: 181 Grinler User rank is Private First Class (20 - 50 Reputation Level)Grinler User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 5 h 27 m 54 sec
Reputation Power: 6
Thanks Julia. Will pass the info along to Bobby.

Reply With Quote
  #71  
Old March 25th, 2009, 12:35 AM
midwesternwire midwesternwire is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Mar 2009
Posts: 2 midwesternwire User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 21 m 17 sec
Reputation Power: 0
This is great. Thank you!!!

I ran Anti-FileFix and it de-encrypted the rest of my files.

Thank you so much for this.

[QUOTE=Grinler]The guide at BC was updated to include a tool that will scan a folder or drive, find encrypted files, and clean them automatically using the technique that Julia graciously supplied.

Reply With Quote
  #72  
Old March 27th, 2009, 09:23 AM
Grinler Grinler is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Feb 2004
Posts: 181 Grinler User rank is Private First Class (20 - 50 Reputation Level)Grinler User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 5 h 27 m 54 sec
Reputation Power: 6
Quote:
Originally Posted by roo42
For example, decryption of a .jpg of about 5 MB takes 30 seconds to a minute to complete. (I have quite a few photos to process, so I have been running the tool overnight.)


The tool has been optimized and should run much faster now. If you are still decrypting files, please redownload it and use the newer version.

Reply With Quote
  #73  
Old October 30th, 2009, 11:53 PM
Lordeluna_2dark Lordeluna_2dark is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Oct 2009
Posts: 1 Lordeluna_2dark User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 13 m 27 sec
Reputation Power: 0
I am using the Anti-Filefix and its not working I am not sure whats going on, I selected folder than scan and fix. Though nothing is being decoded.

Reply With Quote
  #74  
Old November 15th, 2009, 09:33 PM
MrBorsa MrBorsa is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2009
Posts: 1 MrBorsa User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 35 m 49 sec
Reputation Power: 0
Quote:
Originally Posted by Lordeluna_2dark
I am using the Anti-Filefix and its not working I am not sure whats going on, I selected folder than scan and fix. Though nothing is being decoded.


me too

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationAntivirus Protection > Filefix Professional 2009


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump




 Free IT White Papers!
 
How to Present Effectively Online
This white paper offers practical and actionable advice on the key steps that any presenter should consider as they plan and execute a Webinar or online meeting.

 
Open Source Security Myths
Open Source Software (OSS) is computer software whose source code is available to the general public with relaxed or non-existent intellectual property restrictions (or arrangement such as the public domain), and is usually developed with the input of many contributors.

 
Power and Cooling Capacity Management for Data Centers
This paper describes the principles for achieving power and cooling capacity management.

 
Scalable, Fault-Tolerant NAS for Oracle - The Next Generation
For several years NAS has been evolving as a storage alternative for Oracle databases, and for good reason: NAS is quite often the simplest, most cost-effective storage approach for Oracle. Learn about the benefits that HP's approach to scalable NAS brings to Oracle environments in this comprehensive white paper.

 
Understanding Web Application Security Challenges
This white paper discusses many common threats and preventive measures for Web application security, and explains what you can do to help protect your organization.

 

Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 




© 2003-2009 by Developer Shed. All rights reserved. DS Cluster 3 Hosted by Hostway
For more Enterprise Application Development news, visit eWeek