Search the archive:
YaBB - Yet another Bulletin Board
 
   
 
Page Index Toggle Pages: 1
Send Topic Print
Nasty things, hiding away! (Read 2659 times)
Sep 23rd, 2012 at 5:28am

Fozzer   Offline
Colonel
An elderly FS 2004 addict!
Hereford. England. EGBS.

Posts: 24861
*****
 
Hello Chums...
I am just wondering if anyone else has got this thoroughly nasty piece of software nesting inside their computer....
"bProtect"...or "bProtector".

It can be spotted, using Ctrl+Alt+Delete to bring up the Task Manager.
It will probably contain two entries.
Quote:
bProtector is DEFINITELY a virus.  It is cleverly 'signed' (fraudulently) with a GoDaddy certificate and makes you think that it is a legitimate file by sitting hidden away in nested files.  If you delete it, it replicates itself within seconds.  If you plug in a usb memory stick or other offboard device, it replicates itself there also.  It is associated with the Babylon plugin.
Most virus software and malware checkers do NOT catch it due to it's clever setup.  I have gotten rid of it manually several times, but it seems to find it's way back somehow.  Still working on how to prevent it from reappearing.  What would make that simple is if the virus and malware programs would add it to their list and prevent it from getting access.
The person who posted that it 'obviously' was not a virus because it was on World of Warcraft most likely has a pirate copy of WoW as this worm travels freely within the pirated files domain...so beware!!
End Quote.

I don't know how I got it, (some time ago), but it is now giving me all sorts of grief.
It runs constantly in the background, slowing everything down, and also prevents a normal Shut Down process, (A Shut-down always has to be "Forced" when the process hangs, with the HDD cycling!).
It is impossible to delete, and just re-spawns if attempted to do so.
It does not appear anywhere as a; "File".

No Virus/Malware/Spyware checkers can spot it, and remove it!
A recent scan:
Starting master boot sector scan:
Master boot sector HD0
    [INFO]      No virus was found!
Master boot sector HD1
    [INFO]      No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
    [INFO]      No virus was found!
Boot sector 'F:\'
    [INFO]      No virus was found!

Starting search for hidden objects.
c:\progra~2\bprote~1\22463~1.83\protec~1.dll
c:\ProgramData\bProtectorForWindows\2.2.463.83\protector.dll
  [NOTE]      The registry entry is invisible.


Note the description; "Invisible"!

Have a peek in your Computer...Anyone else got it?

Paul... Angry...!
 

Dell Dimension 5000 BTX Tower. Win7 Home Edition, 32 Bit. Intel Pentium 4, dual 2.8 GHz. 2.5GB RAM, nVidia GF 9500GT 1GB. SATA 500GB + 80GB. Philips 17" LCD Monitor. Micronet ADSL Modem only. Saitek Cyborg Evo Force. FS 2004 + FSX. Briggs and Stratton Petrol Lawn Mower...Motor Bikes. Gas Cooker... and lots of musical instruments!.... ...!
Yamaha MO6,MM6,DX7,DX11,DX21,DX100,MK100,EMT10,PSR400,PSS780,Roland GW-8L v2,TR505,Casio MT-205,Korg CX3v2 dual manual,+ Leslie 760,M-Audio Prokeys88,KeyRig,Cubase,Keyfax4,Guitars,Orchestral,Baroque,Renaissance,Medieval Instruments.
IP Logged
 
Reply #1 - Sep 23rd, 2012 at 8:57am

Steve M   Offline
Colonel
Cambridge On.

Gender: male
Posts: 4097
*****
 
 

...
Flying with twins is a lot of fun..
IP Logged
 
Reply #2 - Sep 23rd, 2012 at 9:27am

Fozzer   Offline
Colonel
An elderly FS 2004 addict!
Hereford. England. EGBS.

Posts: 24861
*****
 
Steve M wrote on Sep 23rd, 2012 at 8:57am:


I read that, amongst many other of methods of removing it, but the method described seemed more dangerous, (involving the Registry),  than the actual program itself!

It certainly is a very nasty little bugger, and everyone effected by it seems to find it impossible to get rid of, apart from a complete HDD re-Format!

A Google search for "bProtect" reveals the nightmare!

Paul...in the middle of a "Nightmare"... Angry...!

At the moment it is occasionally freezes my Firefox Browser for short periods...running in the background!
 

Dell Dimension 5000 BTX Tower. Win7 Home Edition, 32 Bit. Intel Pentium 4, dual 2.8 GHz. 2.5GB RAM, nVidia GF 9500GT 1GB. SATA 500GB + 80GB. Philips 17" LCD Monitor. Micronet ADSL Modem only. Saitek Cyborg Evo Force. FS 2004 + FSX. Briggs and Stratton Petrol Lawn Mower...Motor Bikes. Gas Cooker... and lots of musical instruments!.... ...!
Yamaha MO6,MM6,DX7,DX11,DX21,DX100,MK100,EMT10,PSR400,PSS780,Roland GW-8L v2,TR505,Casio MT-205,Korg CX3v2 dual manual,+ Leslie 760,M-Audio Prokeys88,KeyRig,Cubase,Keyfax4,Guitars,Orchestral,Baroque,Renaissance,Medieval Instruments.
IP Logged
 
Reply #3 - Sep 23rd, 2012 at 9:43am

Bass   Offline
Colonel
Love flying.
Scandinavia

Gender: male
Posts: 996
*****
 
Where have you been "flying" Fozzer? Sorry Cool

I know how you are right now.
http://forum.raymond.cc/spyware-viruses/32547-what-the-hell-is-bprotector-engine...
 
IP Logged
 
Reply #4 - Sep 23rd, 2012 at 10:04am

Fozzer   Offline
Colonel
An elderly FS 2004 addict!
Hereford. England. EGBS.

Posts: 24861
*****
 
Bass wrote on Sep 23rd, 2012 at 9:43am:
Where have you been "flying" Fozzer? Sorry Cool

I know how you are right now.
http://forum.raymond.cc/spyware-viruses/32547-what-the-hell-is-bprotector-engine...


..... Grin....Goodness knows!

The annoying thing is, that none of the Anti-Virus, Mailware, Spyware, etc, programs detect it, and it is not listed in any of their search engines!
In every Computer location that I delete it, it re-appears somewhere else, instantly!

Paul...Its WAR I tell you.....ITS WAR!!... Angry...!

 

Dell Dimension 5000 BTX Tower. Win7 Home Edition, 32 Bit. Intel Pentium 4, dual 2.8 GHz. 2.5GB RAM, nVidia GF 9500GT 1GB. SATA 500GB + 80GB. Philips 17" LCD Monitor. Micronet ADSL Modem only. Saitek Cyborg Evo Force. FS 2004 + FSX. Briggs and Stratton Petrol Lawn Mower...Motor Bikes. Gas Cooker... and lots of musical instruments!.... ...!
Yamaha MO6,MM6,DX7,DX11,DX21,DX100,MK100,EMT10,PSR400,PSS780,Roland GW-8L v2,TR505,Casio MT-205,Korg CX3v2 dual manual,+ Leslie 760,M-Audio Prokeys88,KeyRig,Cubase,Keyfax4,Guitars,Orchestral,Baroque,Renaissance,Medieval Instruments.
IP Logged
 
Reply #5 - Sep 23rd, 2012 at 1:51pm

tinpusher   Offline
Lieutenant Colonel
FS9 forever
Netherlands (EHAM)

Gender: male
Posts: 8
*****
 
Hello,
This is indeed a serious problem.
What I would do is create a recovery point (if point is correct English) on your computer on a date  BEFORE you attracted the virus.
After renewed startup things should be back to normal again.
If unsuccesful: go see your local computershop and let them deal with the bugger the professional way.
Godspeed!!
 
IP Logged
 
Reply #6 - Sep 24th, 2012 at 10:07am

Bass   Offline
Colonel
Love flying.
Scandinavia

Gender: male
Posts: 996
*****
 
Well Fozzer, as you said, its war Cool
Have you tried the hitmanpro from my link?
 
IP Logged
 
Reply #7 - Sep 24th, 2012 at 3:18pm

Fozzer   Offline
Colonel
An elderly FS 2004 addict!
Hereford. England. EGBS.

Posts: 24861
*****
 
Bass wrote on Sep 24th, 2012 at 10:07am:
Well Fozzer, as you said, its war Cool
Have you tried the hitmanpro from my link?


That didn't find anything suspicious at all....!
(Un-installed it now).
In fact, I haven't found anything that finds, and destroys, the offending program!

Paul. ...Angry...!
 

Dell Dimension 5000 BTX Tower. Win7 Home Edition, 32 Bit. Intel Pentium 4, dual 2.8 GHz. 2.5GB RAM, nVidia GF 9500GT 1GB. SATA 500GB + 80GB. Philips 17" LCD Monitor. Micronet ADSL Modem only. Saitek Cyborg Evo Force. FS 2004 + FSX. Briggs and Stratton Petrol Lawn Mower...Motor Bikes. Gas Cooker... and lots of musical instruments!.... ...!
Yamaha MO6,MM6,DX7,DX11,DX21,DX100,MK100,EMT10,PSR400,PSS780,Roland GW-8L v2,TR505,Casio MT-205,Korg CX3v2 dual manual,+ Leslie 760,M-Audio Prokeys88,KeyRig,Cubase,Keyfax4,Guitars,Orchestral,Baroque,Renaissance,Medieval Instruments.
IP Logged
 
Page Index Toggle Pages: 1
Send Topic Print