PatColo
1st August 2013, 11:25 PM
I'm guessing I allowed the (movie) ALIEN-esque beast to commandeer my win-7 box when I allowed a program called "jucheck.exe" by verified publisher "Oracle America, Inc." to run & access registry. It touted that a JavaScript update is available.
I'd declined this request a couple times before already over the past week or so, thinking, if it aint broke don't "fix it". But with each reboot, when the desktop would come up, the screen would immediately dim and I'd get the request for this program to access registry to run. This is slightly unusual, IIRC, normally they first post a dialog box asking if I wanted to do a given update, and once I okayed that, THEN the dim screened reg-access request would come up. But this bugger seemed to bypass that and go straight to the windoze reg-access request.
So the request appears legit, and I gathered it would nag me with every reboot, so I gave in and let it "update Javascript". It seemed to do it's thing uneventfully, no more dialog boxes etc, and I launched firefox to begin doing my usual thing. Within minutes, I was getting obnoxious popups from this obviously fake "antivirus"program ("System Care Antivirus") giving me dire warnings of all the trouble I'm in, and to "click here to remove" the long list of problems. I could X-it-out and it would force me to answer if I was sure I wanted to continue unprotected. I'd confirm, and it would go away for the next 2-5 mins, when the next popup would hit, overlaying all other open programs until it was dealt with.
Every firefox page I'd try to visit, would give me the 'page blocked, contains malware, close or ignore this warning & proceed?' page. I'd ignore the warning and proceed, and it would go to the page no problem (these are my most commonly visited pages). I launched IE and it behaved the same way.
It also blocked opening programs, saying they were blocked coz they were "infected". I had a copy of the Avast! install program in my Downloads folder from when I downloaded/installed it a couple months ago, and subsequently removed it coz it was compromising my system too much. So I tried to launch that file and install Avast again, and this "System Care Antivirus" virus would block it with the "infected..." BS.
So I searched "System Care Antivirus"-- and guess what? The top search results appear to be fake 'help' pages, all describing the malware's behavior perfectly complete with the same screenshots of it's various warnings & popup consoles; warning you not to buy their $99 removal program, and after all that "good advice", then pointing you to a "removal program!" :o Some Startpage search results for "System Care Antivirus" (the ones I suspect are fake, in cahoots with the virus itself):
Remove System Care antivirus - wintips.org (http://www.wintips.org/remove-system-care-fake-antivirus/)
www.wintips.org/remove- (http://www.wintips.org/remove-)system-care-fake-antivirus/ - View by Ixquick Proxy (https://ixquick-proxy.com/do/spg/proxy?ep=47316f5552794d4c44416b2b423155494d52776a4 479555753555a5941514a4e544674634748515a4d674236474 47843444170794b46304a5042454258446b5a4755784c41457 7664777746347795542546e316e4a476c4541414e6b4a48593 346326751665141395033523255316457574151534854314d6 3776747546a784343425574473130635042516a58534266433 06f57426c706257316f535479524963454a464143465248415 92b446745654e313073577a34595355684e4255394b5251516 34432395264454a5a416935435642413843526f4f5a4649305 26a31565847516352336b664733384e486a345364317448465 35a47476b6b3247567465613377795679416647554155426b5 a4a5856775852437064636c63454279356444456f344255675 34c314d79527a355658574d664146746258566848586938494 e56424d5648315455414668586c6c4e616c787a43793949436 b4d4251313449536c68444443383d&epile=4q6n41784q7n41344q4449774r5638344r5335725n58 6o3q&edata=8c21b945876e8d3fcf6ef91a886c6a35&ek=656n4970595538326157645n617n7837575470414q6o317 762795535645438364o546p3661556o38&ekdata=2c1d8a29b0848aae0d432c9cc26759e9) - Highlight (https://ixquick-proxy.com/do/spg/highlight.pl?l=english&c=hf&cat=web&q=%22System+Care+Antivirus%22&rl=NONE&rid=OJLNRPOMMPQO&hlq=https://startpage.com/do/search&mtlanguage=english&mtpl=ff&mtcat=web&u=http:%2F%2Fwww.wintips.org%2Fremove-system-care-fake-antivirus%2F)
31 May 2013 ... System Care Antivirus is a fake antivirus and upon installed in your computer, it claims that malicious threats are found on your computer and it ...
Remove System Care Antivirus virus (TUTORIAL) - Malware Tips (http://malwaretips.com/blogs/system-care-antivirus-virus-removal/)
www.malwaretips.com/blogs/ (http://www.malwaretips.com/blogs/)system-care-antivirus-virus-removal/ - View by Ixquick Proxy (https://ixquick-proxy.com/do/spg/proxy?ep=47316f5552794d4c44416b2b423155494d52776a4 479555753555a5941514a4e544674634748515a4d674236474 47843444170794b46304a5042454258446b5a4755784c41457 7664777746347795542546e316e4a476c4541414e6b4a48593 346326751665141395033523255316457574151534854314d6 3776747546a784343425574473130635042516a58534266433 06f57426c706257316f535479524963454a464143465248415 92b446745654e313073577a34595355684e4255394b5251516 34432395264454a5a416935435642413843526f4f5a4649305 26a31565847516352336b66473338584343564c5955424d465 35a47476b6b364246466561337769586949584841414c4d307 844576b3066424752665955424d5443355948513476416b344 f4b686332577a38464841684c45464a5658316757544874364 a6b644e414474585641552f586c6c4a6177317a566e7753583 059495277316547676b5a5858315a4f4149635548674744313 438&epile=4q6n41784q7n41344q4449774r5638344r5335725n58 6o3q&edata=616a965498dcdbe0d24a08bda4c28a83&ek=656n4970595538326157645n617n7837575470414q6o317 762795535645438364o546p3661556o38&ekdata=77a5a32c31c2c8e82f1f1024a4e7e491) - Highlight (https://ixquick-proxy.com/do/spg/highlight.pl?l=english&c=hf&cat=web&q=%22System+Care+Antivirus%22&rl=NONE&rid=OJLNRPOMMPQO&hlq=https://startpage.com/do/search&mtlanguage=english&mtpl=ff&mtcat=web&u=http:%2F%2Fmalwaretips.com%2Fblogs%2Fsystem-care-antivirus-virus-removal%2F)
29 Jun 2013 ... This page is a comprehensive step by step guide on how to remove System Care Antivirus virus from your computer.
and this cleverly domain-named page http://www.systemcareantivirushelp.com which I'm not getting in the search results again for some reason, but it appeared as top result in a previous search. Notice all these (fake) 'help' pages urge you to "Download Removal Tool!", another executable, which I didn't, of course.
One of the (guessing) non-fake pages, a Yahoo! Answers page (http://nz.answers.yahoo.com/question/index?qid=20130707001223AAD1C3r), had a reply advising downloading Malwarebytes Free edition, which I did. But trying to launch it, 'guess who' blocked it, saying it was "infected!:o" So this beast is really friggin comprehensive, with their own fake 'removal help' pages topping the search result for their malware's name!
I rebooted and went to Safe-Mode With Networking. I was able to successfully run the Avast! antivirus install program from there. Ran a scan.... "No threats found"....
So I ran the Malwarebytes install prog which I'd downloaded previously but the malware was blocking me from launching. It launched and installed, scanned, and identified 2 infected files, which I had it remove. I rebooted into normal windoze, and that's where I am now-- things ALMOST appear normal again.
Abnormality is, upon reboot, I got the friggin dim-screened "jucheck.exe" by verified publisher "Oracle America, Inc." permission request again! I declined, and my box appears to be running normally otherwise. BUT there is a "System Care Antivirus" shortcut on the desktop, and I get periodic "Java Update Available" bubbles appearing from the windows "tray", which if I click on, dims the screen and wants to run the jucheck.exe virus-installer again. So this beast lives on... and will presumably continue nagging me, until further notice! I go to Add/Remove Programs, and there is nothing listed named "System Care Antivirus". Big surprise. :|~
I'd declined this request a couple times before already over the past week or so, thinking, if it aint broke don't "fix it". But with each reboot, when the desktop would come up, the screen would immediately dim and I'd get the request for this program to access registry to run. This is slightly unusual, IIRC, normally they first post a dialog box asking if I wanted to do a given update, and once I okayed that, THEN the dim screened reg-access request would come up. But this bugger seemed to bypass that and go straight to the windoze reg-access request.
So the request appears legit, and I gathered it would nag me with every reboot, so I gave in and let it "update Javascript". It seemed to do it's thing uneventfully, no more dialog boxes etc, and I launched firefox to begin doing my usual thing. Within minutes, I was getting obnoxious popups from this obviously fake "antivirus"program ("System Care Antivirus") giving me dire warnings of all the trouble I'm in, and to "click here to remove" the long list of problems. I could X-it-out and it would force me to answer if I was sure I wanted to continue unprotected. I'd confirm, and it would go away for the next 2-5 mins, when the next popup would hit, overlaying all other open programs until it was dealt with.
Every firefox page I'd try to visit, would give me the 'page blocked, contains malware, close or ignore this warning & proceed?' page. I'd ignore the warning and proceed, and it would go to the page no problem (these are my most commonly visited pages). I launched IE and it behaved the same way.
It also blocked opening programs, saying they were blocked coz they were "infected". I had a copy of the Avast! install program in my Downloads folder from when I downloaded/installed it a couple months ago, and subsequently removed it coz it was compromising my system too much. So I tried to launch that file and install Avast again, and this "System Care Antivirus" virus would block it with the "infected..." BS.
So I searched "System Care Antivirus"-- and guess what? The top search results appear to be fake 'help' pages, all describing the malware's behavior perfectly complete with the same screenshots of it's various warnings & popup consoles; warning you not to buy their $99 removal program, and after all that "good advice", then pointing you to a "removal program!" :o Some Startpage search results for "System Care Antivirus" (the ones I suspect are fake, in cahoots with the virus itself):
Remove System Care antivirus - wintips.org (http://www.wintips.org/remove-system-care-fake-antivirus/)
www.wintips.org/remove- (http://www.wintips.org/remove-)system-care-fake-antivirus/ - View by Ixquick Proxy (https://ixquick-proxy.com/do/spg/proxy?ep=47316f5552794d4c44416b2b423155494d52776a4 479555753555a5941514a4e544674634748515a4d674236474 47843444170794b46304a5042454258446b5a4755784c41457 7664777746347795542546e316e4a476c4541414e6b4a48593 346326751665141395033523255316457574151534854314d6 3776747546a784343425574473130635042516a58534266433 06f57426c706257316f535479524963454a464143465248415 92b446745654e313073577a34595355684e4255394b5251516 34432395264454a5a416935435642413843526f4f5a4649305 26a31565847516352336b664733384e486a345364317448465 35a47476b6b3247567465613377795679416647554155426b5 a4a5856775852437064636c63454279356444456f344255675 34c314d79527a355658574d664146746258566848586938494 e56424d5648315455414668586c6c4e616c787a43793949436 b4d4251313449536c68444443383d&epile=4q6n41784q7n41344q4449774r5638344r5335725n58 6o3q&edata=8c21b945876e8d3fcf6ef91a886c6a35&ek=656n4970595538326157645n617n7837575470414q6o317 762795535645438364o546p3661556o38&ekdata=2c1d8a29b0848aae0d432c9cc26759e9) - Highlight (https://ixquick-proxy.com/do/spg/highlight.pl?l=english&c=hf&cat=web&q=%22System+Care+Antivirus%22&rl=NONE&rid=OJLNRPOMMPQO&hlq=https://startpage.com/do/search&mtlanguage=english&mtpl=ff&mtcat=web&u=http:%2F%2Fwww.wintips.org%2Fremove-system-care-fake-antivirus%2F)
31 May 2013 ... System Care Antivirus is a fake antivirus and upon installed in your computer, it claims that malicious threats are found on your computer and it ...
Remove System Care Antivirus virus (TUTORIAL) - Malware Tips (http://malwaretips.com/blogs/system-care-antivirus-virus-removal/)
www.malwaretips.com/blogs/ (http://www.malwaretips.com/blogs/)system-care-antivirus-virus-removal/ - View by Ixquick Proxy (https://ixquick-proxy.com/do/spg/proxy?ep=47316f5552794d4c44416b2b423155494d52776a4 479555753555a5941514a4e544674634748515a4d674236474 47843444170794b46304a5042454258446b5a4755784c41457 7664777746347795542546e316e4a476c4541414e6b4a48593 346326751665141395033523255316457574151534854314d6 3776747546a784343425574473130635042516a58534266433 06f57426c706257316f535479524963454a464143465248415 92b446745654e313073577a34595355684e4255394b5251516 34432395264454a5a416935435642413843526f4f5a4649305 26a31565847516352336b66473338584343564c5955424d465 35a47476b6b364246466561337769586949584841414c4d307 844576b3066424752665955424d5443355948513476416b344 f4b686332577a38464841684c45464a5658316757544874364 a6b644e414474585641552f586c6c4a6177317a566e7753583 059495277316547676b5a5858315a4f4149635548674744313 438&epile=4q6n41784q7n41344q4449774r5638344r5335725n58 6o3q&edata=616a965498dcdbe0d24a08bda4c28a83&ek=656n4970595538326157645n617n7837575470414q6o317 762795535645438364o546p3661556o38&ekdata=77a5a32c31c2c8e82f1f1024a4e7e491) - Highlight (https://ixquick-proxy.com/do/spg/highlight.pl?l=english&c=hf&cat=web&q=%22System+Care+Antivirus%22&rl=NONE&rid=OJLNRPOMMPQO&hlq=https://startpage.com/do/search&mtlanguage=english&mtpl=ff&mtcat=web&u=http:%2F%2Fmalwaretips.com%2Fblogs%2Fsystem-care-antivirus-virus-removal%2F)
29 Jun 2013 ... This page is a comprehensive step by step guide on how to remove System Care Antivirus virus from your computer.
and this cleverly domain-named page http://www.systemcareantivirushelp.com which I'm not getting in the search results again for some reason, but it appeared as top result in a previous search. Notice all these (fake) 'help' pages urge you to "Download Removal Tool!", another executable, which I didn't, of course.
One of the (guessing) non-fake pages, a Yahoo! Answers page (http://nz.answers.yahoo.com/question/index?qid=20130707001223AAD1C3r), had a reply advising downloading Malwarebytes Free edition, which I did. But trying to launch it, 'guess who' blocked it, saying it was "infected!:o" So this beast is really friggin comprehensive, with their own fake 'removal help' pages topping the search result for their malware's name!
I rebooted and went to Safe-Mode With Networking. I was able to successfully run the Avast! antivirus install program from there. Ran a scan.... "No threats found"....
So I ran the Malwarebytes install prog which I'd downloaded previously but the malware was blocking me from launching. It launched and installed, scanned, and identified 2 infected files, which I had it remove. I rebooted into normal windoze, and that's where I am now-- things ALMOST appear normal again.
Abnormality is, upon reboot, I got the friggin dim-screened "jucheck.exe" by verified publisher "Oracle America, Inc." permission request again! I declined, and my box appears to be running normally otherwise. BUT there is a "System Care Antivirus" shortcut on the desktop, and I get periodic "Java Update Available" bubbles appearing from the windows "tray", which if I click on, dims the screen and wants to run the jucheck.exe virus-installer again. So this beast lives on... and will presumably continue nagging me, until further notice! I go to Add/Remove Programs, and there is nothing listed named "System Care Antivirus". Big surprise. :|~