New Trojan - Smart Fortress 2012

Status
Not open for further replies.
Joined
Mar 24, 2007
Messages
10,007
Location
Upstate NY
I got hit with a new Trojan this afternoon. It's called Smart Fortress 2012. I was running Firefox version 11.0 (no extensions), and my system is Win7 Home Premium. It's a false anti-spyware program. I was able to get rid of it (AFAIK) by booting into safe mode, running CCleaner to clear out the browser cache, and then running MalwareBytes in Chameleon mode to get rid of it. A second MBAM scan showed no infection. I'm now running Avira AV to check if it piggybacked something that MBAM didn't catch.
 
Originally Posted By: dparm
Are you not running some sort of anti-malware/anti-virus?


I got it yesterday too right past my anti virus.

It came 1 second after clicking on a site google found (and I reported that to them)

Sort of a b%$^ as it disabled my anti virus.
 
Last edited:
It sailed in right past the antivirus. Oh well.

It also disabled the Windows automatic updates. That needed to be switched back on manually.
 
Originally Posted By: sciphi
I got hit with a new Trojan this afternoon. It's called Smart Fortress 2012. I was running Firefox version 11.0 (no extensions), and my system is Win7 Home Premium. It's a false anti-spyware program. I was able to get rid of it (AFAIK) by booting into safe mode, running CCleaner to clear out the browser cache, and then running MalwareBytes in Chameleon mode to get rid of it. A second MBAM scan showed no infection. I'm now running Avira AV to check if it piggybacked something that MBAM didn't catch.


Fire Fox is up to version 11? I have 10.0.3 as the most recent version. Or was the virus hidden as FF version 11?
 
Originally Posted By: demarpaint
Originally Posted By: sciphi
I got hit with a new Trojan this afternoon. It's called Smart Fortress 2012. I was running Firefox version 11.0 (no extensions), and my system is Win7 Home Premium. It's a false anti-spyware program. I was able to get rid of it (AFAIK) by booting into safe mode, running CCleaner to clear out the browser cache, and then running MalwareBytes in Chameleon mode to get rid of it. A second MBAM scan showed no infection. I'm now running Avira AV to check if it piggybacked something that MBAM didn't catch.


Fire Fox is up to version 11? I have 10.0.3 as the most recent version. Or was the virus hidden as FF version 11?


11 is current.
 
Mozilla dropped the minor revision numbers (3.5, 3.6, 3.7, etc) and decided to simply make each release a new number even if the changes were minor.
 
Originally Posted By: OVERK1LL
I had a customer into that one last week. MWB was able to get rid of it.


What's MWB?

If the Trojan got past the anti-virus, how did you guys spot it?
 
Originally Posted By: Artem
Originally Posted By: OVERK1LL
I had a customer into that one last week. MWB was able to get rid of it.


What's MWB?

If the Trojan got past the anti-virus, how did you guys spot it?


The first clue is a big 8 by 8 box taking up most of the screen thats says
Smart Fortress
your computer is infected

(and it won't come down
 
Last edited:
Originally Posted By: OVERK1LL
Originally Posted By: demarpaint
Originally Posted By: sciphi
I got hit with a new Trojan this afternoon. It's called Smart Fortress 2012. I was running Firefox version 11.0 (no extensions), and my system is Win7 Home Premium. It's a false anti-spyware program. I was able to get rid of it (AFAIK) by booting into safe mode, running CCleaner to clear out the browser cache, and then running MalwareBytes in Chameleon mode to get rid of it. A second MBAM scan showed no infection. I'm now running Avira AV to check if it piggybacked something that MBAM didn't catch.


Fire Fox is up to version 11? I have 10.0.3 as the most recent version. Or was the virus hidden as FF version 11?


11 is current.
Mine says it's up to date. Fire Fox ESR 10.0.3 Fire Fox is up to date? Odd?

Home » Update

Firefox Free Download

Systems & Languages | Release Notes | Privacy
Congratulations!

Your Firefox is up to date.
 
Last edited:
Originally Posted By: demarpaint
Mine says it's up to date. Fire Fox ESR 10.0.3 Fire Fox is up to date? Odd?

You're running ESR version which has its own versioning and may not be on the same schedule as the main FF release. Why are you running ESR?
 
Originally Posted By: Artem
Originally Posted By: OVERK1LL
I had a customer into that one last week. MWB was able to get rid of it.


What's MWB?

Malwarebytes. Google it.
 
Originally Posted By: Quattro Pete
Originally Posted By: demarpaint
Mine says it's up to date. Fire Fox ESR 10.0.3 Fire Fox is up to date? Odd?

You're running ESR version which has its own versioning and may not be on the same schedule as the main FF release. Why are you running ESR?

No idea, that's what I downloaded 6 months ago and have been updating all along.
 
Originally Posted By: demarpaint
Originally Posted By: Quattro Pete
Originally Posted By: demarpaint
Mine says it's up to date. Fire Fox ESR 10.0.3 Fire Fox is up to date? Odd?

You're running ESR version which has its own versioning and may not be on the same schedule as the main FF release. Why are you running ESR?

No idea, that's what I downloaded 6 months ago and have been updating all along.

I guess you need to switch to standard FF if you want to be able to receive updates sooner. ESR is only updated once a year. It still receives all the security-related updates, but no other updates.

http://blog.mozilla.com/blog/2012/01/10/delivering-a-mozilla-firefox-extended-support-release/

But from what it says, ESR was only released about 2 months ago. Not sure how you got it 6 months ago.
 
It's on this machine longer than 2 months that's for sure. Oddly I have it on 2 computers one bought before Christmas and an old PC, both ESR. Maybe I did an uninstall and reinstall at some point? I don't know for sure. Anyway I'll change to Ver 11. Thanks, I don't want to hijack the OP's thread.
 
I was surprised to see this thread. My work computer got it yesterday. It popped up right as I clicked on a link to Amazon from Google. My antivirus is McAfee something.

The computers here should wipe clean whenever somebody logs out. So, in theory, I got it during that session. I did not visit any unusual sites either: yahoo, google, a couple venders, ect.
 
Status
Not open for further replies.
Back
Top Bottom