1. Attachments are working again! Check out this thread for more details and to report any other bugs.

Just got a bad Virus from priuschat.com

Discussion in 'PriusChat Website Questions' started by GotInfectedHere, Jun 8, 2011.

  1. GotInfectedHere

    GotInfectedHere New Member

    Joined:
    Jun 8, 2011
    2
    0
    0
    Location:
    CA
    Vehicle:
    2002 Prius
    Model:
    I
    I was reading this thread priuschat.com/forums/gen-ii-prius-main-forum/26601-steering-wheel-comfort.html and my browser (firefox) and all running apps suddenly closed. I virus scanning window popped up and appeared to be scanning files. There was a new virus "shield" icon in the system tray and a shortcut for it on the desktop. I was unable to open task manager or any other executable on my system. I restarted in safe mode and took a break to post this. I'm using my iPod touch now since my laptop is completely infected.
     
  2. GotInfectedHere

    GotInfectedHere New Member

    Joined:
    Jun 8, 2011
    2
    0
    0
    Location:
    CA
    Vehicle:
    2002 Prius
    Model:
    I
    Found this c:\Documents and Settings\All Users\Application Data\defender.exe
     
  3. itonarely

    itonarely Junior Member

    Joined:
    May 3, 2011
    36
    12
    0
    Location:
    Miami
    Vehicle:
    2016 Prius
    Model:
    Two
    If you can boot up in safe mode, try to then perform a system restore to a previous date. I got hit the same way a few months ago (on a different site) and this took care of it for me (after paying someone to do it for me as I did not think to boot in safe mode and the virus would not allow me to access the internet, the system restore function, the task manager, etc.).

    Also, after fixing the problem, I downloaded avast! antivirus protection software for free and it has keot me safe (several times on this site, at least).

    Good luck.
     
  4. bisco

    bisco cookie crumbler

    Joined:
    May 11, 2005
    107,991
    49,089
    0
    Location:
    boston
    Vehicle:
    2012 Prius Plug-in
    Model:
    Plug-in Base
    from p/c? no way harry!
     
    1 person likes this.
  5. xpcman

    xpcman Senior Member

    Joined:
    Jun 11, 2009
    1,302
    295
    0
    Location:
    California - SF Bay area
    Vehicle:
    2008 Prius
    You can't get a virus without downloading. You didn't get it from PriusChat.
     
    1 person likes this.
  6. flareak

    flareak Fleet Captain

    Joined:
    Mar 9, 2004
    1,016
    20
    0
    Location:
    St Louis, MO
    Vehicle:
    2005 Prius
    Model:
    N/A
    How do you know it's because of that same page? It could be from something else. Usually viruses don't get on our computers without some sort of user involvement. That is, you can't really get a virus if the user isn't actively downloading and opening some weird file.

    I just opened that link you posted and I'm completely fine. You sure you didn't open some attachment in an email recently? downloaded a file recently? installed some sort of program recently? etc?

    If not. Then the only other possible explanation would be a direct attack on your computer by a hacker.
     
  7. flareak

    flareak Fleet Captain

    Joined:
    Mar 9, 2004
    1,016
    20
    0
    Location:
    St Louis, MO
    Vehicle:
    2005 Prius
    Model:
    N/A
    Another possibility is that you had a scheduled virus scan, or you were downloading a windows update and the computer decided to restart on its own (which is consistent with closing all your windows and running apps)
     
  8. hampdenwireless

    hampdenwireless Active Member

    Joined:
    Aug 21, 2005
    1,104
    86
    0
    Location:
    Baltimore MD
    Vehicle:
    Other Non-Hybrid
    Of course you can. It happens due to flaws in windows and the web browsers. While macs have been problem free for a long time, there is now malware that can even download on a mac though it does not install automatically.

    The virus probably did not come from PriusChat though.
     
  9. flareak

    flareak Fleet Captain

    Joined:
    Mar 9, 2004
    1,016
    20
    0
    Location:
    St Louis, MO
    Vehicle:
    2005 Prius
    Model:
    N/A
    that's because it's a mac. they don't require user involvement with their OS's security flaws. windows has been attacked so much that it rarely happens
     
  10. cwerdna

    cwerdna Senior Member

    Joined:
    Sep 4, 2005
    12,544
    2,123
    1
    Location:
    SF Bay Area, CA
    Vehicle:
    2006 Prius
    Not necessarily, some require no user intervention.

    See W32.Blaster.Worm Technical Details | Symantec or [ame="http://en.wikipedia.org/wiki/Code_Red_worm"]Code Red (computer worm) - Wikipedia, the free encyclopedia[/ame], for example.

    For Code Red, on those versions of Windows, IIS was enabled by default and if memory serves, so was the vulnerable service. I remember some of my legitimate web servers at work seeing HTTP requests in the IIS logs from infected machines elsewhere on the network of the form:
    Another example where just visiting a page is enough (on an unpatched machine): Unpatched Java hole exploited at lyrics site | InSecurity Complex - CNET News.
     
  11. fuzzy1

    fuzzy1 Senior Member

    Joined:
    Feb 26, 2009
    17,170
    10,081
    90
    Location:
    Western Washington
    Vehicle:
    Other Hybrid
    Model:
    N/A
    Then, before going back on line, go to Windows Update, Change Settings, and turn off Automatic Updates. Otherwise, that 'virus' is likely to reappear again very quickly, regardless of what websites you visit.;)

    Microsoft did push out another Windows Defender definition update yesterday. This posting reminded me to fix my autoupdate setting, which somehow got corrupted recently.
     
  12. flareak

    flareak Fleet Captain

    Joined:
    Mar 9, 2004
    1,016
    20
    0
    Location:
    St Louis, MO
    Vehicle:
    2005 Prius
    Model:
    N/A
    yes... key word is usually. i can't imagine priuschat would be suspect without some sort of user intervention. it doesn't use java
     
  13. cwerdna

    cwerdna Senior Member

    Joined:
    Sep 4, 2005
    12,544
    2,123
    1
    Location:
    SF Bay Area, CA
    Vehicle:
    2006 Prius
    I wouldn't be so confident in the word usually for that anymore. A lot of the virus, worms, malware, etc. exploits vulnerabilities in browsers and Flash. The only user interaction might be to visit a page. Priuschat is pulling in 3rd party content for the ads.

    Glance thru all the critical vulnerabilities at Security Advisories for Firefox 3.6. I'm sure a good percentage could be exploited by specially crafting a page or the proper content and not have any sort of file download dialog come up.

    Here's one that shouldn't require any user intervention other than visiting a malicious page: Microsoft warns IE flaw is being exploited | IT PRO.
     
  14. twittel

    twittel Senior Member

    Joined:
    Jul 7, 2010
    1,605
    148
    0
    Location:
    Mt. Pleasant, SC
    Vehicle:
    2010 Prius
    Model:
    III
    Whenever I do a Google PriiusChat search I get a Win32Trojan virus that my Microsoft Security Essentials catches. It just happened to me again yesterday as I forgot to NOT USE Google search on PriusChat. I suspect the virus may lurk deep within my subdirectories and only manifest itself during this Google search. Also, a "Java Script" run wants to activate. Crazy, but it happens consistently.
     
  15. billnchristy

    billnchristy Active Member

    Joined:
    Jul 18, 2009
    924
    123
    11
    Location:
    GA
    Vehicle:
    2016 Chevy Volt
    Model:
    N/A
    I have had my software go haywire here several times, there can be a script in an ad that will jack you up.

    I use adblock now.
     
  16. cyclopathic

    cyclopathic Senior Member

    Joined:
    Apr 15, 2011
    3,292
    547
    0
    Location:
    2014 Prius c
    Vehicle:
    2010 Prius
    Model:
    II
    don't browse web from account with admin privileges, if you don't create non-admin account
    use NoScript plugin.
     
  17. qbee42

    qbee42 My other car is a boat

    Joined:
    Mar 2, 2006
    18,058
    3,073
    7
    Location:
    Northern Michigan
    Vehicle:
    2006 Prius
    There are many ways to infect a computer without requiring explicit downloading. Some of these involve code inserted into images, others are scripts. The general term for this sort of method is called "drive by", since the infection occurs as the user drives by a page, or views it.

    Many of these nasties work through buffer overflows. Think of a data structure in a program as a table. Most of them have a fixed length, so they can only store so many digits. A cleverly crafted image or other object can be made to overflow the table and spill into the next data structure, thereby inserting executable malware into a program. This is prevented by checking for data overflows, but much code is written without safeguards.

    Tom
     
  18. Danny

    Danny Admin/Founder
    Staff Member

    Joined:
    Nov 24, 2003
    7,093
    2,102
    1,174
    Location:
    Charlotte, NC
    Vehicle:
    2013 Prius Plug-in
    Model:
    Plug-in Base
    I'm looking everywhere in the code, but I'm not seeing any malicious code like I did last time when the header template was hacked. Not sure what to tell you...
     
    3 people like this.
  19. Stev0

    Stev0 Honorary Hong Kong Cavalier

    Joined:
    Sep 23, 2006
    7,201
    1,073
    0
    Location:
    Northampton, MA
    Vehicle:
    2022 Prius Prime
    Model:
    Plug-in Base
    Firefox, Chrome, Opera, and just about every other browser has protection against drive-by viruses. There's only one that openly embraces them (Internet Explorer). If you're running a good Virus Protection package (if it came with your computer, and/or if it's McAfee or Norton, it's not good) and you're running a good browser (not IE), you should be safe.
     
  20. hyo silver

    hyo silver Awaaaaay

    Joined:
    Mar 2, 2005
    15,232
    1,562
    0
    Location:
    off into the sunset
    Vehicle:
    2004 Prius
    Model:
    N/A
    What's your opinion of Kaspersky?