Tue, Jan 21, 10:44 AM CST

Renderosity Forums / Poser - OFFICIAL



Welcome to the Poser - OFFICIAL Forum

Forum Coordinators: RedPhantom

Poser - OFFICIAL F.A.Q (Last Updated: 2025 Jan 20 11:41 am)



Subject: OT: need advice recovering from Trojan on PC


ghostship2 ( ) posted Thu, 11 December 2014 at 10:15 PM · edited Fri, 11 October 2024 at 12:44 PM

 This morning I got a pop-up that looked like an official update notice for Adobe acrobat pro (I have CS 5.5) after what looked like an official looking adobe update my anti-virus started flashing warning messages about blocked websites that the computer was trying to access. IP addresses tracked back to some jackasses in Russia.

 Instead of going the rout of paying for and loading some  removal tool I unplugged the drive and bought a new drive for the PC. The OS, updates and anti-virus software is all re-installed now. Now I have to re-load data from my runtime (I did have a backup but it was a few months old.)

Will it be safe to plug this old drive back into a SATA port and retrieve my old data? Will I need to do something special with the drive while copying files? I need to copy my runtime, my Reason folder and probably my USER folder (desktop, pics, videos, iTunes, etc.)

I'm running windows 7 ultimate  and my anti-virus software is ESET Nod32.

any help would be great and yeah, I know I should be emailing support at eset but the automated thing just pointed me at giving them more money for the cyber security product which I have doubts actually would fix my problem.  

W10, Ryzen 5 1600x, 16Gb,RTX2060Super+GTX980, PP11, 11.3.740


jura11 ( ) posted Thu, 11 December 2014 at 10:47 PM

Hi there

Please download this,this usually will delete all unwanted trojans etc 

First program which I would try is Malwarebytes Anti-Malware and then I would go down the route of the Adwcleaner and Combofix,for bellow programs here are links

http://www.bleepingcomputer.com/download/adwcleaner/

http://www.bleepingcomputer.com/download/combofix/

Usually those programs will delete anything what is unwanted or what is dangerous

Yes this happens to my brother with his laptop,when he tried to download Adobe flash

Not sue I've recovered all my files from crashed HDD and too from HDD which has been full of viruses with above programs,but be 100% sure I would go down the route of the Safe boot and then I would try to recover files 

This virus looks like is it Ransonware which are worst,does this virus started to lock yours folders or not? If yes then I would suspect you have one of the worst virus which is called Cyberlocker,but I think someone has cracked their code which is good news 

Hope this help

Thanks,Jura


FightingWolf ( ) posted Fri, 12 December 2014 at 12:54 AM

I agree with Jura 11.  First step is run Malwarebytes Anti-Malware.  Don't just run it once. Run it at least twice or until the problem is solved.  Take note of what Malwarebytes is finding and trying to remove because you may have remove it manually.  Removing malware shouldn't be a big long and complicated process that requires changing a bunch of things and coding.  

Ransomware can be defeated, it's just that some are more difficult than others to get rid of. 

Never update from a pop up even if it looks official.  Updates like that train us to just click without reading what updates are actually being installed.   If you get a pop up to update take note of what software it's for. Let it close "most official" pop ups will close on their own.  Once it closes open the software and update directly from the software.  Do this especially with Adobe Flash.  Type in adobe's website and update from there and never from a pop up in the browser.



hornet3d ( ) posted Fri, 12 December 2014 at 3:19 AM

Another in support on Malwarebytes, I have used it for years on a regular basis and it is always my first port of call if a family member or friend hands me their computer saying it is slow or has other problems.  Over the same period I have changed my anti virus programs a few times when an updated version started to play havoc with my system but Malwarebytes has remained my go to program.

 

 

I use Poser 13 on Windows 11 - For Scene set up I use a Geekcom A5 -  Ryzen 9 5900HX, with 64 gig ram and 3 TB  storage, mini PC with final rendering done on normal sized desktop using an AMD Ryzen Threadipper 1950X CPU, Corsair Hydro H100i CPU cooler, 3XS EVGA GTX 1080i SC with 11g Ram, 4 X 16gig Corsair DDR4 Ram and a Corsair RM 100 PSU .   The desktop is in a remote location with rendering done via Queue Manager which gives me a clearer desktop and quieter computer room.


piersyf ( ) posted Fri, 12 December 2014 at 4:21 AM

Ditto to the rest. Seeing as you've already set up a new HDD, load Malwarebytes and point it at the old drive before transferring data. In any case, if you have firewall software it should warn you when you copy it across. I've done this before and it works fine. A pain, but recoverable.


icprncss2 ( ) posted Fri, 12 December 2014 at 6:55 AM

Malewarabytes definitely.  I've used it in combo with HitmanPro. 


ghostship2 ( ) posted Fri, 12 December 2014 at 12:24 PM

I had loaded Malwarebytes on the old HDD thinking it was a free program but it shut down after a couple of weeks with a message that my trial software had expired. I'll take a look at it again.

W10, Ryzen 5 1600x, 16Gb,RTX2060Super+GTX980, PP11, 11.3.740


ghostship2 ( ) posted Fri, 12 December 2014 at 12:33 PM

 I'm also considering plugging that drive into another (non critical) computer and disabling the OS so nothing will boot from that drive before I start getting files off or scanning it for malware.

W10, Ryzen 5 1600x, 16Gb,RTX2060Super+GTX980, PP11, 11.3.740


icprncss2 ( ) posted Fri, 12 December 2014 at 12:49 PM

Malewarabytes has a free version.  I don't remember if there is a separate download the for the free version.  If your old drive is plugged in, try to launch Malewarabytes.  If it launches, run the update for it and then run the scan a couple of times.

If it won't launch, still consider buying it.  Even if you have a good AV suite, I found that Malwarabytes tended to pick up things the AV missed. 


markschum ( ) posted Fri, 12 December 2014 at 1:04 PM

I would go to the bleepingcomputer site and read the What to do first  part of the forum. Malwarebytes run from safe mode will kill most things.

you might start a new thread for your problem and be guided through the process.

The FBI ransom virus is nasty and you want to make sure its all gone before you do any credit card purchases or electronic banking.


hborre ( ) posted Fri, 12 December 2014 at 2:26 PM

Currently, Malwarebytes offers a yearly license which covers 3 machines.  Unless the free version options have changed, it did time out after 30 days in the past.  


ghostship2 ( ) posted Fri, 12 December 2014 at 5:35 PM

 OK. I've put down my $24 for the premium version of MB but am unable to find the controls for it to scan an attached HD. All it seems to be good for is scanning the drive that it is loaded on and the computer booted from.??????? I have emailed MB tech support but I have a fear that they will want more money for some other product..

W10, Ryzen 5 1600x, 16Gb,RTX2060Super+GTX980, PP11, 11.3.740


seachnasaigh ( ) posted Fri, 12 December 2014 at 6:27 PM · edited Fri, 12 December 2014 at 6:30 PM

  ...unable to find the controls for it to scan an attached HD.

     Open Start>computer so that you see all HDs/flash drives.  Right-click on the suspect HD;  there should be a popup menu which includes scan with MalwareBytes. file_0f28b5d49b3020afeecd95b4009adf4c.pn

Poser 12, in feet.  

OSes:  Win7Prox64, Win7Ultx64

Silo Pro 2.5.6 64bit, Vue Infinite 2014.7, Genetica 4.0 Studio, UV Mapper Pro, UV Layout Pro, PhotoImpact X3, GIF Animator 5


ghostship2 ( ) posted Fri, 12 December 2014 at 6:45 PM

 Thank you! I'll do that right now. Just seems a bit counter intuitive not to be able to do that from within the program.

W10, Ryzen 5 1600x, 16Gb,RTX2060Super+GTX980, PP11, 11.3.740


seachnasaigh ( ) posted Fri, 12 December 2014 at 7:03 PM

     I believe you can also do it from the MBytes UI;  custom scan > scan now and then browse the folder/drive you want scanned.  That is also where you'll find the option to scan for rootkits.

Poser 12, in feet.  

OSes:  Win7Prox64, Win7Ultx64

Silo Pro 2.5.6 64bit, Vue Infinite 2014.7, Genetica 4.0 Studio, UV Mapper Pro, UV Layout Pro, PhotoImpact X3, GIF Animator 5


ghostship2 ( ) posted Fri, 12 December 2014 at 7:06 PM

 Just looked for it. Does not show up in the menu. There is a menu item for scanning with my anti-virus so I'm doing that right now. Don't think I'll hear back from the folks at MB till Monday.

W10, Ryzen 5 1600x, 16Gb,RTX2060Super+GTX980, PP11, 11.3.740


seachnasaigh ( ) posted Fri, 12 December 2014 at 7:21 PM

If I open MalwareBytes UI, I see this, and I would click on scan...

file_b73ce398c39f506af761d2277d853a92.PN

Poser 12, in feet.  

OSes:  Win7Prox64, Win7Ultx64

Silo Pro 2.5.6 64bit, Vue Infinite 2014.7, Genetica 4.0 Studio, UV Mapper Pro, UV Layout Pro, PhotoImpact X3, GIF Animator 5


seachnasaigh ( ) posted Fri, 12 December 2014 at 7:23 PM

The scan menu opens.  I click on the Custom Scan radio button, then click Scan Now...

file_a597e50502f5ff68e3e25b9114205d4a.PN

Poser 12, in feet.  

OSes:  Win7Prox64, Win7Ultx64

Silo Pro 2.5.6 64bit, Vue Infinite 2014.7, Genetica 4.0 Studio, UV Mapper Pro, UV Layout Pro, PhotoImpact X3, GIF Animator 5


seachnasaigh ( ) posted Fri, 12 December 2014 at 7:25 PM

The scan configuration window opens.  I select the drive(s), and tick the desired scan options on the left, and then click Start Scan...

file_5ef059938ba799aaa845e1c2e8a762bd.PN

Poser 12, in feet.  

OSes:  Win7Prox64, Win7Ultx64

Silo Pro 2.5.6 64bit, Vue Infinite 2014.7, Genetica 4.0 Studio, UV Mapper Pro, UV Layout Pro, PhotoImpact X3, GIF Animator 5


ghostship2 ( ) posted Fri, 12 December 2014 at 7:26 PM

 God, sometimes I feel so dumb! Thanks for the help. Scanning right now.

W10, Ryzen 5 1600x, 16Gb,RTX2060Super+GTX980, PP11, 11.3.740


jura11 ( ) posted Fri, 12 December 2014 at 7:26 PM

Hi there

As above you can try to run MB from Scan-Custom Scan and then select HDD which you are suspecting is full of viruses 

Something like this 

3029elk.jpg97n24i.jpgOr you can try boot with HDD on which you are suspecting there are viruses and use above SW Combofix or AdwCleaner,I've used both SW and both are very easy to use and they're best,MB is good,but he doesn't remove fully all viruses and all traces 

Sometimes you need to use 2 or more programs to remove all viruses

Hope this help

Thanks,Jura


Privacy Notice

This site uses cookies to deliver the best experience. Our own cookies make user accounts and other features possible. Third-party cookies are used to display relevant ads and to analyze how Renderosity is used. By using our site, you acknowledge that you have read and understood our Terms of Service, including our Cookie Policy and our Privacy Policy.