Technical Discussion
  >> Security Related Issues


Register (or login) on our website and you will not see this ad.


Pages in this thread: 1 | 2 | 3 | >> (show all)   Print Thread
Standard User deleted
(deleted) Mon 08-Jul-13 23:33:12
Print Post

SS32 malware? URGENT HELP needed!


[link to this post]
 
I received an email from a trusted friend with an attachment for a picture of a document asking me to help �I cannot see or download this, help please�. When I foolishly clicked on the document it executed an application ss32 and the asked to restart the computer to turn off UAC! I have not switched off the computer afraid it that ss32 may be a malicious application.
Anyone has any information on this mysterious ss32.exe?
What should I do to solve this?
Standard User Pipexer
(eat-sleep-adslguide) Mon 08-Jul-13 23:41:52
Print Post

Re: SS32 malware? URGENT HELP needed!


[re: deleted] [link to this post]
 
Disconnect the computer from the internet immediately
Kill the SS32.exe process (or whatever process you suspect has been launched) via task manager
Scan the disk for SS32.exe and delete any traces of it.
Run a full antivirus scan
Download the VIPRE Rescue Scanner (google it) and run this on the PC.
Run any additional malware scanning/protection utilities you care to.
Go into Control Panel > User Accounts > User Account Control and turn UAC back on if it appears disabled
Restart computer and assess situation, consider plugging internet connection back in if you think the threat is gone.

Zen 8000 Pro
Standard User billford
(elder) Mon 08-Jul-13 23:46:38
Print Post

Re: SS32 malware? URGENT HELP needed!


[re: deleted] [link to this post]
 
If you google for it, it doesn't seem to be anything particularly nasty... but Pipexer's advice is sound- better safe than sorry where unknown software is concerned.

Bill
A level playing field is level in both directions.________________Planes and Boats and ... _____________BQMs: IPv4 IPv6


Register (or login) on our website and you will not see this ad.

Standard User ukhardy07
(fountain of knowledge) Mon 08-Jul-13 23:46:58
Print Post

Re: SS32 malware? URGENT HELP needed!


[re: deleted] [link to this post]
 
Hi there. I am going to assume you have an antivirus already.

The best tool you can download if it's escaped your current security is malware bytes (I find this anyway and I offer IT help at work on the side - clearing infections of work colleagues machines most days as a bit on the side hehe).
Link: http://www.malwarebytes.org
Click free download
It gives you a free 14 day trial which is plenty to catch the infection and remove it.

Commonly infected machines are blocked from accessing the site or it will take you to a different site where you get more infected so you might be best to get it on another PC and then put it on a memory stick & install it.

Run a full scan, preferably in safe mode.

This finds most of the nasties and is particular good at finding what most other programs miss.

Edited by ukhardy07 (Mon 08-Jul-13 23:48:34)

Standard User Pipexer
(eat-sleep-adslguide) Mon 08-Jul-13 23:49:10
Print Post

Re: SS32 malware? URGENT HELP needed!


[re: billford] [link to this post]
 
I thought that too, but a closer look seems the OP has unfortunately come across some very new malware - http://blog.dynamoo.com/ check the blog post date, only 2 hrs ago.

Zen 8000 Pro
Standard User billford
(elder) Mon 08-Jul-13 23:51:11
Print Post

Re: SS32 malware? URGENT HELP needed!


[re: Pipexer] [link to this post]
 
Fair enough, some poor soul has to be the first frown

Bill
A level playing field is level in both directions.________________Planes and Boats and ... _____________BQMs: IPv4 IPv6
Standard User Pipexer
(eat-sleep-adslguide) Mon 08-Jul-13 23:56:47
Print Post

Re: SS32 malware? URGENT HELP needed!


[re: billford] [link to this post]
 
Indeed - I've just downloaded said file to see what happened, Windows Defender, using definitions as of now, does not detect it as malware. The OP should be very cautious and would probably be best running some rescue scanners tomorrow when new definitions have become available. Seems this (variant at least) has literally only just hit within the past few hours.

Zen 8000 Pro
Standard User deleted
(deleted) Mon 08-Jul-13 23:57:17
Print Post

Re: SS32 malware? URGENT HELP needed!


[re: Pipexer] [link to this post]
 
Running Malwarebytes at this very moment will report back to what happens!
Standard User Pipexer
(eat-sleep-adslguide) Mon 08-Jul-13 23:58:51
Print Post

Re: SS32 malware? URGENT HELP needed!


[re: deleted] [link to this post]
 
Good chance it won't detect anything as I have just seen. Go for a manual removal and the steps I mentioned at the very least before plugging computer back into network. If it is disabling UAC clearly UAC stops it working properly, so ensure you restore UAC to its ON setting.

Zen 8000 Pro
Standard User deleted
(deleted) Mon 08-Jul-13 23:59:37
Print Post

Re: SS32 malware? URGENT HELP needed!


[re: Pipexer] [link to this post]
 
This malware seems to delete all restore points too!!
Standard User XRaySpeX
(eat-sleep-adslguide) Tue 09-Jul-13 00:23:54
Print Post

Re: SS32 malware? URGENT HELP needed!


[re: Pipexer] [link to this post]
 
Norton AV detected it upon download as:
WS.Reputation.1 is a detection for files that have a low reputation score based on analyzing data from Symantec�s community of users and therefore are likely to be security risks.


1999: Freeserve 48K Dial-Up => 2005: Wanadoo 1 Meg BB => 2007: Orange 2 Meg BB => 2008: Orange 8 Meg LLU => 2010: Orange 16 Meg LLU => 2011: Orange 20 Meg WBC
Standard User deleted
(deleted) Tue 09-Jul-13 02:20:12
Print Post

Re: SS32 malware? URGENT HELP needed!


[re: Pipexer] [link to this post]
 
I killed the SS32.exe process then updated Malwarebytes and run a scan, it found the threat > in User APPDATA>Roaming folder I deleted all traces of the SS32
Files Detected: 1
C:\Users\Emer\Documents\Downloads\Document_948357853____.exe (Trojan.Downloader.VM) -> Quarantined and deleted successfully.
Did as you advised downloaded Vipre Rescue Scanner and run it.
Turned on the UAC and all seems ok except that the malware has deleted all my restore points!
Standard User deleted
(deleted) Tue 09-Jul-13 02:51:54
Print Post

Re: SS32 malware? URGENT HELP needed!


[re: ukhardy07] [link to this post]
 
I do use Malwarebytes on a regular basis. I updated the definitions and yes it did find the offending malware.
Files Detected: 1
C:\Users\Emer\Documents\Downloads\Document_948357853____.exe (Trojan.Downloader.VM)[/b[/u]] -> Quarantined and deleted successfully.
Standard User deleted
(deleted) Tue 09-Jul-13 13:55:41
Print Post

Re: SS32 malware? URGENT HELP needed!


[re: deleted] [link to this post]
 
If you want a thorough scan for rootkits and malware, go to forums.majorgeeks.com and see the Malware Removal subforum
Standard User Pipexer
(eat-sleep-adslguide) Tue 09-Jul-13 16:28:37
Print Post

Re: SS32 malware? URGENT HELP needed!


[re: deleted] [link to this post]
 
Think you're gonna have to live with your deleted restore points, or should that be live without restore points? tongue

Zen 8000 Pro
Standard User deleted
(deleted) Tue 09-Jul-13 16:46:44
Print Post

Re: SS32 malware? URGENT HELP needed!


[re: Pipexer] [link to this post]
 
I've done all as you advised plus run as many antivirus and malware applications as I could find, to make sure the pc is clean of ss32.exe turned UAC to max protection and then I created a restore point. smile

Thanks a million for your help.
Standard User ggremlin
(committed) Tue 09-Jul-13 18:56:29
Print Post

Re: SS32 malware? URGENT HELP needed!


[re: deleted] [link to this post]
 
I received an email from a trusted friend with an attachment for a picture of a document asking me to help �I cannot see or download this, help please�.
I suggest that you recommend to your friend, they change their email password.
Standard User bobble_bob
(experienced) Tue 09-Jul-13 20:42:42
Print Post

Re: SS32 malware? URGENT HELP needed!


[re: ggremlin] [link to this post]
 
May not be the case. Ive had emails from "friends" with their name in the subject and a dodgy link .Clearly wasnt them but at the same time we are only friends on Facebook, dont have each others email addresses.

From reading around, its a common thing with Facebook, especially as friends lists and email addresses are often not made private
Standard User deleted
(deleted) Wed 10-Jul-13 00:20:17
Print Post

Re: SS32 malware? URGENT HELP needed!


[re: ggremlin] [link to this post]
 
In reply to a post by ggremlin:
I received an email from a trusted friend with an attachment for a picture of a document asking me to help �I cannot see or download this, help please�.
I suggest that you recommend to your friend, they change their email password.


I did ask my friend if he had personally sent me the email, which he confirmed, as I wanted to establish if his email or other social account had been hacked.

I have changed my passwords as a precaution, which I do now and again and have told him to do likewise.
Standard User XRaySpeX
(eat-sleep-adslguide) Wed 10-Jul-13 00:42:08
Print Post

Re: SS32 malware? URGENT HELP needed!


[re: deleted] [link to this post]
 
In reply to a post by scopio:
I did ask my friend if he had personally sent me the email, which he confirmed
Why did he send you a virus? He could have clicked on it just as well as you and infected his PC instead of yours.

1999: Freeserve 48K Dial-Up => 2005: Wanadoo 1 Meg BB => 2007: Orange 2 Meg BB => 2008: Orange 8 Meg LLU => 2010: Orange 16 Meg LLU => 2011: Orange 20 Meg WBC
Standard User deleted
(deleted) Wed 10-Jul-13 11:33:23
Print Post

Re: SS32 malware? URGENT HELP needed!


[re: XRaySpeX] [link to this post]
 
In reply to a post by XRaySpeX:
Why did he send you a virus? He could have clicked on it just as well as you and infected his PC instead of yours.

That is something that I have discussed with him! He should have noticed that the email when he received it came from someone he did not know and it should have started bells ringing, particularly when it contained an attachment! He did infect his pc as he did click on it and could not see the document, which is why he sent the email to me to try and 'open' see the attached document! I fell for it because the email was coming from him and not from someone I did not know, thinking it was genuine I fell for it too!
Lesson to be learned! smile
Pages in this thread: 1 | 2 | 3 | >> (show all)   Print Thread

Jump to