New virus Spreading in pdf form!! heads up

by l23bc
0 replies
  • OFF TOPIC
  • |
Just wanted to give a warning there is a new virus that effects ebooks and pdf in adolbe reader, here is what i found out so far on another forum,

MyOther PC got nailed by a trojan/virus whatever yesterday (Tues lunchtime).

Searching the net for details and fixes revealed the same or a very similar intrusion appears to be affecting a lot of people and have reported

It didn't trash any data but was rather alarming at the time.
It PRETENDS TO BE an ANTI VIRUS program that is finding all sorts of trojans & viruses & worms all over the place when in fact they don't exist.

The "AntiVirus" pop-up report etc. is in fact the VIRUS itself and it keeps trying to get you to PURCHASE the program that is "finding all these infections".

Once "installed and active" this VIRUS WILL STOP YOU OPENING and/or RUNNING ANYTHING AND EVERYTHING.
Constantly reports that whatever you are trying to do is "INFECTED"

This was by far the best I found on the net that helped
http://deletemalware.blogspot.com/20...soft-fake.html

and this specific reply from Admin (renaming a file in safe mode - mine was "tpmhsftav.exe" in a folder called USUMBO) at least got me back into my PC -
http://deletemalware.blogspot.com/20...15925490093491
and I eventually decided to roll-back my PC to a restore-point on Sunday before the "infestation" occurred.

It appears that this virus has still penetrated and infected PCs considered to be very secure with up-to-date virus scanners checkers and robust firewalls etc.
And I'd have considered mine well protected.

Anyway - and the real point of this post.
Until a little while ago I couldn't remember anything out of the ordinary about yesterday - my PC was OK - THEN IT WASN'T !

Afterwards, when I'd searched the web for the KAKA virus (KAKA appeared in a PATH when I right-clicked & displayed properties on a virus pop-up) I found a fair bit on what I'd call the KAKA 2009 variant (bit less problematic), it appeared that an ADOBE Window maybe had been involved and had appeared before all the problems started.

Since my virus appeared to be KAKA 2010 I never put too much thought into it until THIS AFTERNOON (Wed) - IT HAPPENED AGAIN !!

WELL VERY NEARLY (not quite as bad) anyway - I just managed to intervene and control the situation to some degree.

An ADOBE WINDOW popped up - and I remebered seeing exactly the same one yesterday

Quote:
Adobe Reader

<i> A3D data parsing error has occurred
.................................................. ................[OK]

Yesterday I just clicked on the OK button without even thinking about it.
My problems I'm now absolutely sure started a short while afterwards.

Today I DID NOT CLICK THE OK BUTTON !!!!


I opened up TASK MANAGER instead.
I found a process I'd never seen before and it had the the highest and newest PID - also the IMAGE NAME "tied in" with the Adobe window message
It was called A3DUTILITY.EXE

I checked on the web and there were reports of it's involvement in exactly the sort of virus problems I had yesterday
So I selected A3DUTILITY.EXE and hit END PROCESS

I thought (mistakenly) that that might be the end of it.
Nothing happened for a few minutes but then it started again.
Odd things happening, not working etc. FORTUNATELY my TASK MANAGER was OPEN (yesterday couldn't start it so could'nt kill any processes)
There it was AV.EXE

Killed it but my PC just wasn't 100% - after a while it reappeared & I killed it again, & again, & again etc. etc.

So I'm now back up and functioning having gone back to the SYSTEM RESTORE point on Sunday 15th for the SECOND TIME !!!

I'm still rather concerned where this is coming from and how it is getting in.(and how to stop it happening again)
Today when it happened (relatively soon after my 1st restore to Sunday), apart from visiting MSE I had done nothing else that I can remember, not even opened an email.
Definitely not been to any dodgy website - it's almost as though it's just infiltrated my PC because I'm connected to the net.

ANYWAY - just hope this helps somebody either avoid the problem or get out of it if it's already struck!

just throught id let you all know since we all sell ebooks ect,

more of this infomation can be found here
http://forums.moneysavingexpert.com/...3#post30060443

Trending Topics