1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved I need help with very strange Chinese SPAM/Malware

Discussion in 'Malware and Virus Removal Archive' started by bellisimo, 2014/05/25.

  1. 2014/06/10
    bellisimo Lifetime Subscription

    bellisimo Well-Known Member Thread Starter

    Joined:
    2008/05/26
    Messages:
    456
    Likes Received:
    1
    Hi Broni,
    It's a crafty one, this malware. I Googled a lot of websites last night and a lot more today with no problems until now, at 2:35 am on Tuesday morning. Maybe I should just use Firefox, or since I don't have any saved work on C Drive maybe I should use a back up of it that I have saved on an external drive with Acronis, one from back in February before I got infected. What do you think?
     
  2. 2014/06/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    If you don't have much to lose I'd try backup.
     

  3. to hide this advert.

  4. 2014/06/10
    bellisimo Lifetime Subscription

    bellisimo Well-Known Member Thread Starter

    Joined:
    2008/05/26
    Messages:
    456
    Likes Received:
    1
    Thanks Broni. Can malware like this attach itself to a router or a motherboard, and is it likely to know all my passwords?
     
  5. 2014/06/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I'm not really sure what it is but to answer your question...
    Motherboard can't be infected.
    Any router hijacking is solved by resetting it and we did that already couple of times.
     
  6. 2014/06/10
    bellisimo Lifetime Subscription

    bellisimo Well-Known Member Thread Starter

    Joined:
    2008/05/26
    Messages:
    456
    Likes Received:
    1
    Thank you, Broni. Do you think it could be a self-replicating Trojan or a Virus? That might explain why it keeps coming back.
     
  7. 2014/06/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I can't answer your question because I don't see anything malicious on your computer.
    None of our scans shows anything.
     
  8. 2014/06/10
    bellisimo Lifetime Subscription

    bellisimo Well-Known Member Thread Starter

    Joined:
    2008/05/26
    Messages:
    456
    Likes Received:
    1
    Thanks again, Broni. I'll try to use a True Image backup and see if that does the trick. If not, I can always format the hard drive and reinstall everything. It's a very strange malware that can be that elusive.
     
  9. 2014/06/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Let me know.
     
  10. 2014/06/10
    bellisimo Lifetime Subscription

    bellisimo Well-Known Member Thread Starter

    Joined:
    2008/05/26
    Messages:
    456
    Likes Received:
    1
    You bet:)
     
  11. 2014/06/15
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    How are things?
     
  12. 2014/06/15
    bellisimo Lifetime Subscription

    bellisimo Well-Known Member Thread Starter

    Joined:
    2008/05/26
    Messages:
    456
    Likes Received:
    1
    Hi Broni,

    I got all my apps and program disk out and ready to install, but I haven't decided to do it yet because I've only seen the malware twice since we last spoke. It doesn't seem to have done any harm to anything else that I can see, so I haven't felt pressured to format and reinstall everything.

    Something you had me do has definitely slowed it down enormously. I only wish I knew what it was. I'll probably format and reinstall everything before long. Thanks for asking.
     
  13. 2014/06/15
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    [​IMG]
     
  14. 2014/07/05
    bellisimo Lifetime Subscription

    bellisimo Well-Known Member Thread Starter

    Joined:
    2008/05/26
    Messages:
    456
    Likes Received:
    1
    Hi Broni,

    Thought I should update you as to what's going on with my malware problem.

    I haven't reinstalled Windows 7 and all my programs and apps and updates yet, because the malware only pops up now and again. I haven't seen it for a couple of days and it doesn't seem to have caused any problems to my system.

    I've Googled the web addresses of the Pop-ups I get. The web address on my version is www+Duba.com (I've replaced the dots with plus signs for obvious reasons:) There is another one, as well. Its web address is www+Duba.net. The Pop-ups on both are almost identical and are mostly fashion ads to appeal to young Chinese kids. In other words, they seem to be no more menacing than a lot of SPAM.

    I also discovered that McAfee did a study on THE Duba.net one and they say that it is non-malicious malware. I didn't find anything they said about how to get rid of it though.

    I'm in the process of trying to install Windows 7 and all my programs and apps onto a new hard drive, which I will then back up to an external drive with Acronis. The only back-ups I had done of my C Drive were done after I had been infected with the malware. Once I've done it, I will format my good C Drive and transfer all the files to it from my Acronis account.

    I'm having a small problem with installing Windows 7 onto a new hard drive, which I won't bother you with. If I can't figure it out, I'll post it in the software section of WindowsBBS.

    Thanks again, Broni,

    bellisimo
     
    Last edited: 2014/07/05
  15. 2014/07/19
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Thank you for the update.
    I just got back from vacation.
     
  16. 2014/07/19
    bellisimo Lifetime Subscription

    bellisimo Well-Known Member Thread Starter

    Joined:
    2008/05/26
    Messages:
    456
    Likes Received:
    1
    Hi Broni.

    Last week, I think I found it, but not before it had caused a few problems. I noticed some of my services had been disabled, so I went into Services in Administrative Tools and there it was under 'D' as Danger Driver, followed by a big long row of Chinese characters. I've since learned that Danger Driver is most likely a video game, and I am not a gamer. A lot of my services had been disabled and I deleted the Chinese one and re-enabled and started the ones that had been disabled. I can't be sure because I can no longer get online with C Drive. I reinstalled everything on an HHD drive for the time being.

    I'm thinking of using my Acronis backup of the C Drive, which is on my external hard drive. I've been hesitant to do it though because I've never done it, and I'm not quite sure how. If I select recovery in Acronis True Image, does it just replace the existing C Drive files with the backed up ones?

    Thanks again,

    b

    P.S. I stumbled upon this website the other day, which is 2 or 3 yeas old, but still, I find it pretty daunting. Check it out:)

    http://www.techspot.com/community/t...us-programs-and-how-to-deal-with-them.161379/
     
    Last edited: 2014/07/19
  17. 2014/07/19
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Yes...
     
  18. 2014/07/19
    bellisimo Lifetime Subscription

    bellisimo Well-Known Member Thread Starter

    Joined:
    2008/05/26
    Messages:
    456
    Likes Received:
    1
    Thank you, Broni.
     
  19. 2014/07/19
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    [​IMG]
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.