Overclock.net - Overclocking.net
     
 
Home Gallery Reviews Blogs Register Today's Posts Mark Forums Read Members List


Go Back   Overclock.net - Overclocking.net > Software, Programming and Coding > Networking & Security

Reply
 
LinkBack Thread Tools
Old 05-11-08   #1 (permalink)
New to Overclock.net
 
Field's Avatar
 
intel ati

Join Date: Apr 2008
Posts: 120

Rep: 1 Field Unknown
Unique Rep: 1
Trader Rating: 0
Default annoying malware

so i got some virus and it did a number of things to the computer

it put some new desktop that had some big warning box in the center of the screen saying 'WARNING YOUR COMPUTER IS INFECTED DOWNLOAD LATEST Something or other to get rid of it"

then theres some animation with bugs crawling on the screen if you point your mouse on it.

My firewall had been disabled.

My system restore points had been deleted.

at that point it seemed that was all it did. but i was concerned because i got it by clicking on a link to dowload when i was getting mp3s which allowed a virusto get in uncontested.

I had a disk with Spybot search and destroy on it. I ran spybot and did a scan withMcAffee. Spybot found a number of things. McAffee found nothing of course. so i got rid of the discovered items...

for one thing my internet browser still seems to load up slower than usual and web page browsing does seem slower.

then i noticed when playing games i would see a flucuating drop in framerate, so i leave the game and check out the performance graph and i see these cpu usage spikes from 20-50% i shut off the game and with no processes running the cpu graph was spiking up and down all over the place 20-50% over and over.

then now when i am on the internet these funny web pages will pop up out of nowhere once in a while

also ie been noticing keystroke errors for some odd reason like when i am typing sometimes a button will not register being pressed.



what exactly is this crap?
__________________
System: better than my last computer
CPU
E8500 @ 3.2Ghz
Motherboard
DFI DK LANPARTY X38
Memory
6GB G.Skill DDR2 800 PC2 6400
Graphics Card
Radeon HD 4870
Hard Drive
Seagate 320GB 7200rpm
Power Supply
Corsair 750W
Case
Antec Nine-Hundred
CPU cooling
Arctic Cooler 92mm
OS
Vista Home Premium X64
Monitor
LG Plantronics 20in
Field is offline   Reply With Quote
Old 05-11-08   #2 (permalink)
First Time Build
 
Turnoz's Avatar
 
intel nvidia

Join Date: Dec 2006
Location: Toronto!
Posts: 1,312

Rep: 85 Turnoz is acknowledged by some
Unique Rep: 76
Trader Rating: 4
Default

Sounds like a bad case of malware. Sometimes those virus + ad-ware scanners don't find em. I had that problem before...

Best thing to do is to back everything up and make sure nothing else but your files :P (wouldn't wanna take the virus/malware with you) and then reformat windows. That way you start fresh and clean (you will get better performance). There is also no chance of the virus carrying over (only place is through your back up).
__________________
New Build
[||||||||||||||||||||]
0$ 455$ 500$
Quote:
Originally Posted by DigitalSonata View Post
There is an obvious solution to their problem: wear a tinfoil hat

System: Finally an upgrade
CPU
E4300 333x9 @ 1.38v
Motherboard
EP45-DS3L
Memory
A-Data 800mhz
Graphics Card
XFX 8800GS
Hard Drive
250Gig WD IDE
Sound Card
Integrated
Power Supply
650W Cooler Master
Case
Antec 300
CPU cooling
GeminiII + Tricools
GPU cooling
Stock
OS
Vista 32-bit
Monitor
20.1" Metro
Turnoz is offline   Reply With Quote
Old 05-11-08   #3 (permalink)
New to Overclock.net
 
Join Date: Apr 2008
Posts: 43

Rep: 1 tris Unknown
Unique Rep: 1
Trader Rating: 0
Default

Please run HijackThis (http://www.hijackthis.de/) and give us the output.....
tris is offline   Reply With Quote
Old 05-11-08   #4 (permalink)
New to Overclock.net
 
Field's Avatar
 
intel ati

Join Date: Apr 2008
Posts: 120

Rep: 1 Field Unknown
Unique Rep: 1
Trader Rating: 0
Default

ok ill try the link below first off but then ill probly just try to reinstall windows if that doesnt work. thanks
__________________
System: better than my last computer
CPU
E8500 @ 3.2Ghz
Motherboard
DFI DK LANPARTY X38
Memory
6GB G.Skill DDR2 800 PC2 6400
Graphics Card
Radeon HD 4870
Hard Drive
Seagate 320GB 7200rpm
Power Supply
Corsair 750W
Case
Antec Nine-Hundred
CPU cooling
Arctic Cooler 92mm
OS
Vista Home Premium X64
Monitor
LG Plantronics 20in
Field is offline   Reply With Quote
Old 05-11-08   #5 (permalink)
New to Overclock.net
 
Field's Avatar
 
intel ati

Join Date: Apr 2008
Posts: 120

Rep: 1 Field Unknown
Unique Rep: 1
Trader Rating: 0
Default

oh it also says i have some process called virtumonde.dll which apparently it sees as spyware. hmm
__________________
System: better than my last computer
CPU
E8500 @ 3.2Ghz
Motherboard
DFI DK LANPARTY X38
Memory
6GB G.Skill DDR2 800 PC2 6400
Graphics Card
Radeon HD 4870
Hard Drive
Seagate 320GB 7200rpm
Power Supply
Corsair 750W
Case
Antec Nine-Hundred
CPU cooling
Arctic Cooler 92mm
OS
Vista Home Premium X64
Monitor
LG Plantronics 20in
Field is offline   Reply With Quote
Old 05-12-08   #6 (permalink)
New to Overclock.net
 
Join Date: Apr 2008
Posts: 43

Rep: 1 tris Unknown
Unique Rep: 1
Trader Rating: 0
Default

There you go
tris is offline   Reply With Quote
Old 05-12-08   #7 (permalink)
Extreme Cooler
 
onlycodered's Avatar
 
intel nvidia

Join Date: Mar 2008
Location: Rochester, NY
Posts: 2,831

Rep: 213 onlycodered is acknowledged by manyonlycodered is acknowledged by manyonlycodered is acknowledged by many
Unique Rep: 173
Folding Team Rank: 203
Team Name: The Replacements
Trader Rating: 5
Default

Ouch. That's a horrible one to try to get rid of. I was able to get rid of it using the boot-time scan in Avast antivirus on my friend's PC.
__________________
Quote:
Originally Posted by OCec3 View Post
I've put my Q6600 in cling film...
95.567% of people make up the stats in their sig. If you are part of the 4.433% who uses real stats, put this in your sig.

Fold for the cause. Fold for team 37726!
CPU-Z valid GPU-Z valid
Best CFM/noise ratio fan: Noctua NF-P12
Best air cooling budget case: Antec 300

System: The Silencer
CPU
E6600 (3.42GHz / 1.42v / lapped)
Motherboard
Gigabyte P35-DS3L rev 2
Memory
2x1GB G.SKILL DDR2 1066
Graphics Card
MSI NX8600GT (680MHz / 1800MHz)
Hard Drive
WD1600AAJS / WD3200AAJS (backup)
Sound Card
Onboard
Power Supply
Antec NeoPower 650W
Case
Antec Nine Hundred
CPU cooling
HDT-S1283 / Noctua NF-P12 / Bolt-thru
GPU cooling
AC Accelero S1 rev 2 (45-53° C)
OS
Windows Vista Business SP1 x64
Monitor
NEC 19" MultiSync 95
onlycodered is offline I fold for Overclock.net onlycodered's Gallery   Reply With Quote
Old 05-12-08   #8 (permalink)
New to Overclock.net
 
amd nvidia

Join Date: Mar 2008
Posts: 172

Rep: 6 flushentitypacket Unknown
Unique Rep: 6
Trader Rating: 0
Default

If you do reformat, here's what you should ALWAYS do FIRST. Nothing else!

1. Windows updates. DO NOT VISIT ANY OTHER WEBPAGE OR INSTALL ANY SOFTWARE. Software often has compatibility issues with un-updated Microsoft OS.

2. Antivirus software install. AVG free edition has never failed me yet in conjunction with Spybot. Careful installing more than one antivirus program, as often they read each other as threats and gum up your system. I've had no problems with Spybot/AVG though, since Spybot isn't a constantly-running program in the tray like most Antiviruses.

3. Firefox. Stops 50% of the viruses out there which are usually designed for IE.

4. Ad Block Plus and Adblock Filterset. Useful for even more than protecting your system! (you can block any ad or image that you deem annoying )

5. Do anything you want EXCEPT PRON. (Most likely driver installation)
__________________
System: Tsunami
CPU
AMD64 4000+ San Diego
Motherboard
ASUS A8N-E
Memory
1GB Corsair
Graphics Card
ASUS 6600
Hard Drive
250GB WD
Sound Card
Creative SB Audigy 2SE
Power Supply
Thermaltake 400W
Case
Thermaltake Tsunami
CPU cooling
Thermaltake "Silent Boost"
OS
Windows XP Pro x32
Monitor
Westinghouse 22W2
flushentitypacket is offline   Reply With Quote
Old 05-12-08   #9 (permalink)
Overclocker in Training
 
Austiclees's Avatar
 
amd ati

Join Date: Apr 2008
Location: Jacksonville, Florida
Posts: 97

Rep: 3 Austiclees Unknown
Unique Rep: 2
Trader Rating: 0
Default

Quote:
Originally Posted by flushentitypacket View Post
If you do reformat, here's what you should ALWAYS do FIRST. Nothing else!

1. Windows updates. DO NOT VISIT ANY OTHER WEBPAGE OR INSTALL ANY SOFTWARE. Software often has compatibility issues with un-updated Microsoft OS.

2. Antivirus software install. AVG free edition has never failed me yet in conjunction with Spybot. Careful installing more than one antivirus program, as often they read each other as threats and gum up your system. I've had no problems with Spybot/AVG though, since Spybot isn't a constantly-running program in the tray like most Antiviruses.

3. Firefox. Stops 50% of the viruses out there which are usually designed for IE.

4. Ad Block Plus and Adblock Filterset. Useful for even more than protecting your system! (you can block any ad or image that you deem annoying )

5. Do anything you want EXCEPT PRON. (Most likely driver installation)
A virus can only affect your pc the way that the current user can. Best posible solution to never get a virus...

With a clean, virus free, install of {insert M$ OS}, intall all Virus software and main programs that you want to use, i.e. M$ Office, Firefox, etc...

Then, name the ONLY admin account something weird like ButterflyPenutButter, or TapDancingJellyFish. Give it a cryptic password.

Create user accounts. One can be a test account, another can be the main account. Make sure that these accounts are only Users. You don't want them to have any permissions at all.

Remember, a virus only has the permissions of the user that dl it. So, if you are the Admin, you dl a virus, it can do ANYTHING. Mess up your registry, etc.

It can be annoying for a while, because you'll have to type in the password for everything, active x installs and stuff, but well worth it.

Let me know how it works out.

Good Luck.
__________________
System: Austiclees - PC
CPU
AMD Atholn 64 X2 6400+
Motherboard
ASUS M3A32-MVP Deluxe WiFi-AP Edition
Memory
4x 1GB Corsair XMS2 Dual Channel DDR2 PC 6400 DHX
Graphics Card
ATI Radeon HD 3870
Hard Drive
2 Maxtor 500GB sata II in RAID0
Sound Card
Motherboard
Power Supply
Ultra XPro 750 Watt 80% eff
Case
Custom
CPU cooling
Thermaltake TMG A3
GPU cooling
Built in VisionTek
OS
Dual; Vista Ultimate 64bit & XP Pro 32 bit
Monitor
Westinghouse 17" 1280x768
Austiclees is offline Austiclees's Gallery   Reply With Quote
Old 05-12-08   #10 (permalink)
New to Overclock.net
 
amd nvidia

Join Date: Mar 2008
Posts: 172

Rep: 6 flushentitypacket Unknown
Unique Rep: 6
Trader Rating: 0
Default

Quote:
Originally Posted by Austiclees View Post
A virus can only affect your pc the way that the current user can. Best posible solution to never get a virus...

With a clean, virus free, install of {insert M$ OS}, intall all Virus software and main programs that you want to use, i.e. M$ Office, Firefox, etc...

Then, name the ONLY admin account something weird like ButterflyPenutButter, or TapDancingJellyFish. Give it a cryptic password.

Create user accounts. One can be a test account, another can be the main account. Make sure that these accounts are only Users. You don't want them to have any permissions at all.

Remember, a virus only has the permissions of the user that dl it. So, if you are the Admin, you dl a virus, it can do ANYTHING. Mess up your registry, etc.

It can be annoying for a while, because you'll have to type in the password for everything, active x installs and stuff, but well worth it.

Let me know how it works out.

Good Luck.
Never heard of this method before. Sounds great. However, that would be too much of a hassle for my taste. But yeah, this sounds like a really foolproof way to keep away hijacking programs.
__________________
System: Tsunami
CPU
AMD64 4000+ San Diego
Motherboard
ASUS A8N-E
Memory
1GB Corsair
Graphics Card
ASUS 6600
Hard Drive
250GB WD
Sound Card
Creative SB Audigy 2SE
Power Supply
Thermaltake 400W
Case
Thermaltake Tsunami
CPU cooling
Thermaltake "Silent Boost"
OS
Windows XP Pro x32
Monitor
Westinghouse 22W2
flushentitypacket is offline   Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools



All times are GMT -4. The time now is 02:45 AM.


Overclock.net is a Carbon Neutral Site Creative Commons License Internet Security By ControlScan

Terms of Service / Forum Rules | Privacy Policy | Advertising | Become an Official Vendor
Copyright © 2008 Shogun Interactive Development. Most rights reserved.
Page generated in 0.22397 seconds with 9 queries