Go Back  R/C Tech Forums > General Forums > Electric On-Road
Rc Mushroom virus >

Rc Mushroom virus

Community
Wiki Posts
Search

Rc Mushroom virus

Thread Tools
 
Search this Thread
 
Old 03-20-2012, 03:53 PM
  #16  
Tech Master
Thread Starter
iTrader: (32)
 
chrisk's Avatar
 
Join Date: Sep 2007
Posts: 1,089
Trader Rating: 32 (100%+)
Default

Just to be clear there's no pop-up, once you connect to and the site gets pulled down the threat installs immediately.

correct no pop up, just appeared on my screen

c'mon Rc Mushroom clean your site
chrisk is offline  
Old 03-20-2012, 04:31 PM
  #17  
Tech Regular
iTrader: (2)
 
Coelacanth's Avatar
 
Join Date: Aug 2010
Location: Alberta, Canada
Posts: 320
Trader Rating: 2 (100%+)
Default

That's right, that's a new one for me, but I'm not surprised by much anymore these days. I did some testing (heh!) and found it was pretty easy to cripple. I Ended Task on the cryptic process it launched after searching for the location of the associated file, and deleted it right after I ended task. Sometimes a malware won't let you do that ("access denied") but this one wasn't very invasive.

It didn't add Registry RUN key entries either--or maybe it didn't have a chance to.

But indeed, it doesn't appear to have a popup. I just downloaded & ran TDSSKiller and the system appeared to be clean.
Coelacanth is offline  
Old 03-20-2012, 04:41 PM
  #18  
Tech Elite
iTrader: (6)
 
Fred Hubbard's Avatar
 
Join Date: Nov 2001
Location: Inglewood, CA
Posts: 2,721
Trader Rating: 6 (100%+)
Default

Originally Posted by Coelacanth
That's right, that's a new one for me, but I'm not surprised by much anymore these days. I did some testing (heh!) and found it was pretty easy to cripple. I Ended Task on the cryptic process it launched after searching for the location of the associated file, and deleted it right after I ended task. Sometimes a malware won't let you do that ("access denied") but this one wasn't very invasive.

It didn't add Registry RUN key entries either--or maybe it didn't have a chance to.

But indeed, it doesn't appear to have a popup. I just downloaded & ran TDSSKiller and the system appeared to be clean.
It installs its exe in the appdata directory for the currently logged in user, so bouncing the machine into safe mode and unhiding the hidden directories will allow the user to delete it from that directory.
Fred Hubbard is offline  
Old 03-20-2012, 04:54 PM
  #19  
Tech Champion
iTrader: (4)
 
oXYnary's Avatar
 
Join Date: Dec 2003
Posts: 6,301
Trader Rating: 4 (100%+)
Default

Originally Posted by Fred Hubbard
Just to be clear there's no pop-up, once you connect to and the site gets pulled down the threat installs immediately.
Are you absolutely positive it works in this manner? EXE need sometype of user feedback to install.

Also, are you all running the latest Firefox? (11.0)
oXYnary is offline  
Old 03-20-2012, 05:06 PM
  #20  
Tech Champion
iTrader: (4)
 
oXYnary's Avatar
 
Join Date: Dec 2003
Posts: 6,301
Trader Rating: 4 (100%+)
Default

OK I just tested with Firefox 11 and Windows 7 with all updates... I had no issues even upon rebooting.

I know what this rootkit looks like because I have had peoples computers I have worked on have it happen after the pop-ups saying they had a virus (inside the webpage should have been the hint it wasn't true) and installed said virus disguised as a "fix".

So either.
A: RC Mushroom Fixed.
B: It is only showing up on older un updated systems.
C: People are making a mistake and its not Mushroom versus a previous site.

Again, I want to point out, this should not be installing automatically just by going to a site. It can start like a java that makes you think something is happening and wants to have you install a fix. But the easy way to tell this is fake is that it will be using the browser program itself to say this. It wont be an actual windows pop-up.
oXYnary is offline  
Old 03-20-2012, 05:57 PM
  #21  
Tech Elite
iTrader: (6)
 
Fred Hubbard's Avatar
 
Join Date: Nov 2001
Location: Inglewood, CA
Posts: 2,721
Trader Rating: 6 (100%+)
Default

Originally Posted by oXYnary
Are you absolutely positive it works in this manner? EXE need sometype of user feedback to install.

Also, are you all running the latest Firefox? (11.0)
Yes it works that way. Whenever you access any website the your machine actually downloads the pages. I don't use FF.
Fred Hubbard is offline  
Old 03-20-2012, 06:00 PM
  #22  
Tech Champion
iTrader: (4)
 
oXYnary's Avatar
 
Join Date: Dec 2003
Posts: 6,301
Trader Rating: 4 (100%+)
Default

It downloads the cache of the page, yes. It can not execute an exe though without some sort of user input. Unless your using a very old version of IE or Windows XP without updates.

For those effected, you need to list your OS version and if you are updated as well as your browser version. But again, it could have been fixed by the time I looked at it.
oXYnary is offline  
Old 03-20-2012, 06:09 PM
  #23  
Tech Elite
iTrader: (6)
 
Fred Hubbard's Avatar
 
Join Date: Nov 2001
Location: Inglewood, CA
Posts: 2,721
Trader Rating: 6 (100%+)
Default

Originally Posted by oXYnary
It downloads the cache of the page, yes. It can not execute an exe though without some sort of user input. Unless your using a very old version of IE or Windows XP without updates.

For those effected, you need to list your OS version and if you are updated as well as your browser version. But again, it could have been fixed by the time I looked at it.
It serves me no purpose to have to mention this and I really don't want to waste energy to say this but I've OWNED an IT consultancy firm for over 11 years which has afforded me the experience to know what I'm talking about
Fred Hubbard is offline  
Old 03-20-2012, 06:16 PM
  #24  
Tech Elite
iTrader: (184)
 
pinoy69racer's Avatar
 
Join Date: Jul 2009
Location: SoCal
Posts: 3,807
Trader Rating: 184 (99%+)
Default not only rc mushroom

Originally Posted by Fred Hubbard
It serves me no purpose to have to mention this and I really don't want to waste energy to say this but I've OWNED an IT consultancy firm for over 11 years which has afforded me the experience to know what I'm talking about
+1 fred ....i almost got fired yesterday coz im using internet in my work i went to RC GOODS and they have a freaking VIRUS too......
pinoy69racer is offline  
Old 03-20-2012, 06:21 PM
  #25  
Tech Champion
iTrader: (4)
 
oXYnary's Avatar
 
Join Date: Dec 2003
Posts: 6,301
Trader Rating: 4 (100%+)
Default

Originally Posted by Fred Hubbard
It serves me no purpose to have to mention this and I really don't want to waste energy to say this but I've OWNED an IT consultancy firm for over 11 years which has afforded me the experience to know what I'm talking about
But from your original post, it sounds like it installed on your system as well?

Edit: Just checked RC Goods, no issue.
oXYnary is offline  
Old 03-20-2012, 06:24 PM
  #26  
Tech Elite
 
MAD916's Avatar
 
Join Date: Oct 2005
Location: La Center Seca
Posts: 3,117
Default

I wondered where that came from... itt has given me hell on my old laptop running XP, and IE... even with some help and malware it still has my machine crippeled.... Damn it has been a boat load of work to try and clean it up
MAD916 is offline  
Old 03-20-2012, 06:26 PM
  #27  
Tech Champion
iTrader: (4)
 
oXYnary's Avatar
 
Join Date: Dec 2003
Posts: 6,301
Trader Rating: 4 (100%+)
Default

FWIW I'm using MS Security Essentials. But I know someone who had such and it still didn't stop that exe from installing *different site, that person confirmed he clicked on the pop up telling him he supposedly had a virus*

The best is Nod32.
oXYnary is offline  
Old 03-20-2012, 06:34 PM
  #28  
Tech Elite
iTrader: (6)
 
Fred Hubbard's Avatar
 
Join Date: Nov 2001
Location: Inglewood, CA
Posts: 2,721
Trader Rating: 6 (100%+)
Default

Originally Posted by oXYnary
But from your original post, it sounds like it installed on your system as well?

Edit: Just checked RC Goods, no issue.
Correct, even with us using a trendmicro managed solution on our desktops.
Fred Hubbard is offline  
Old 03-20-2012, 06:54 PM
  #29  
Tech Lord
iTrader: (32)
 
syndr0me's Avatar
 
Join Date: Dec 2004
Location: 5280 Raceway
Posts: 13,279
Trader Rating: 32 (100%+)
Default

Running executables (or executing arbitrary code) without your input is the primary vector used to compromise machines. It happens most frequently through the browser since, for most people, the web is their only interaction with the internet.

It's foolish to rely on some site in Hong Kong to keep you safe. The internet is full of scary places. Protect yourselves.
syndr0me is offline  
Old 03-20-2012, 09:42 PM
  #30  
Tech Regular
iTrader: (2)
 
Coelacanth's Avatar
 
Join Date: Aug 2010
Location: Alberta, Canada
Posts: 320
Trader Rating: 2 (100%+)
Default

Originally Posted by oXYnary
FWIW I'm using MS Security Essentials. But I know someone who had such and it still didn't stop that exe from installing *different site, that person confirmed he clicked on the pop up telling him he supposedly had a virus*

The best is Nod32.
MS Security Essentials is Essentially Useless. I don't think I've ever seen it CATCH anything, even on computers that are obviously malware-compromised. Same goes with Windows Defender in the past. Better than nothing, but almost absolutely useless. I can't count the times Defender, MS SE, or even something as popular as Norton Antivirus, has either not detected an infection, was easily disabled by an infection, or detected an infection but couldn't do a bloody thing to remove it, when AVast--a totally free antivirus program--could detect AND remove it.
Coelacanth is offline  


Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Use of this site indicates your consent to the Terms of Use.