Overclock.net - Overclocking.net
     
 
Home Gallery Reviews Blogs Register Today's Posts Mark Forums Read Members List


Go Back   Overclock.net - Overclocking.net > Software, Programming and Coding > Networking & Security

Reply
 
LinkBack Thread Tools
Old 06-20-08   #1 (permalink)
Overclocker
 
voice's Avatar
 
intel nvidia

Join Date: Oct 2007
Location: Britain
Posts: 914

Rep: 27 voice is acknowledged by some
Unique Rep: 24
Trader Rating: 0
Default Need help with virii/malware on my PC

Yesterday I did something extremely foolish, i let my guard down and accidentally got a trojan, within seconds it had infected my PC, disabled a lot of things, and downloaded even more trojans with it.

Anywho, i quickly pulled out my ethernet cable and then installed Kaspersky Trial edition (and quickly replugged my ethernet cable back for a moment in to download updates).

I then ran Kaspersky, it took 5 hours (the first scan is slow, but the ones after are much quicker) with maximum security protection enabled, searching both rookits and using heuristics etc. Anyway, Kaspersky can find the malware, but can't seem to get rid of it. It has buried itself into System Restores and Windows logon (winlogon.exe?) and Explorer.exe. When i try to clean the system restores kaspersky can no longer find the malware, and although Kaspersky can clean Explorer.exe it soon becomes infected again. With the windows logon, kaspersky can't clean it. I believe this is because the windows logon must be essential to windows running.

Anywho, I have no idea what to do. I'm willing to format my harddrive but i have a good deal of data on there that i'd rather like to keep. I was thinking of downloading HijackThis but I'm not sure there would be any point as the malware activates itself before I even get into Windows. I also don't know what it does (HijackThis that is, not the malware).

I was also thinking of downloading a program like this: http://www.download.com/Process-Expl...dlPid=10847734 to help me bypass the Task Manager being disabled (the malware has also disabled a lot of start menu stuff, but they can be reenabled easily via rightclicking the taskbar and messing with the properties).

So yeah, any help you guys could give would be great, because I'm kind of at a loss here.

Thanks,
Voice.
__________________
System: The Dust Magnet
CPU
Intel E2140 @ 3.0Ghz
Motherboard
Abit IP35 Pro
Memory
Crucial Ballistix 2GB PC2-8500 DDR2
Graphics Card
BFG 8800GT
Hard Drive
Seagate Barracuda 7200.10 250GB SATA-II 16MB Cache
Sound Card
Creative X-fi Xtreme Gamer
Power Supply
Corsair HX 620W
Case
Antec Nine Hundred
CPU cooling
TRUE w/ Xilence Redwing 120mm
OS
Windows XP SP2 & Ubuntu 7.10
Monitor
Hyundai B71A 17" LCD
voice is offline   Reply With Quote
Old 06-20-08   #2 (permalink)
Folding Fanatic
 
deskjockey's Avatar
 
intel nvidia

Join Date: Jan 2007
Location: Hockeytown, USA
Posts: 1,112

Rep: 94 deskjockey is acknowledged by some
Unique Rep: 80
Folding Team Rank: 28
Trader Rating: 15
Default

turn off system restore, run your virus protection in safe mode.

use: smitfraudfix, combofix and hijackthis

You might have to dive deep into your computer but you can fix everything that has been corrupted

dont let anybody tell you that you have to reformat, thats the lazy way out
__________________
multi GPU folding on XP http://www.overclock.net/overclock-n...gfx-cards.html
think folding costs too much???http://www.overclock.net/overclock-n...ml#post4175378
Quote:
Originally Posted by Pyranite View Post
Open source supporters steal the glory and money from people who make decent products. They're like the China of the Internet, making crappy knock offs of reasonable products and distributing them for next to nothing.

System: knucklecase-now enriched with quad core!
CPU
x3210 @ 3360@1.328v after vdroop
Motherboard
Asus P5k3
Memory
gskill DDR3 pc8500
Graphics Card
xFx 8800gt Alpha Dog + Galaxy 8800gt
Hard Drive
120gb + 1tb
Power Supply
Cm 500 mod
CPU cooling
HDT
GPU cooling
stock
OS
xpp
deskjockey is offline I fold for Overclock.net   Reply With Quote
Old 06-20-08   #3 (permalink)
GH0
Security Sleuth
 
GH0's Avatar
 
amd nvidia

Join Date: Jan 2008
Location: North Carolina, USA
Posts: 1,181

Rep: 107 GH0 is acknowledged by manyGH0 is acknowledged by many
Unique Rep: 86
Folding Team Rank: 501
Trader Rating: 0
Default

Get a process explorer and search for any mischievous looking file names running.

Disable System Restore in Windows. Either by the service or by Windows System Properties.

You can try to look at registry fixers, such as CC Cleaner, Spybot S&D, etc.

Definitely use HiJack This, AV, CC Cleaner, S&D,
Definitely run Windows in Safe Mode for a good amount of time while trying to get rid of all of the things that are infected. Like discjockey said.

Another good thing, try killing explorer.exe from the tree and then shut down the computer.


As a last resort, you can do a format and reinstall. But Only as a last resort. It really just comes down to manually finding and removing them yourself.

Do you happen to know what the Virus is called?
__________________
System: Dataslum
CPU
5000+ Black Edition
Motherboard
ASUS Formula Crosshair II
Memory
4 (2x2) Muskin Memory
Graphics Card
EVGA 9800GTX+ 512 MB (SLI)
Hard Drive
Windows XP/Vista Business RAID 0, Total 2.1 TB
Sound Card
SupremeFX / Some form of cheap Creative
Power Supply
Corsair 1KW
Case
Lian-Li
CPU cooling
Xigmatek
GPU cooling
Stock
OS
Windows XP 32-bit Pro (SP2) and Vista Ultimate
Monitor
Samsung SyncMaster 906 BW, Sony 19"
GH0 is offline I fold for Overclock.net GH0's Gallery   Reply With Quote
Old 06-20-08   #4 (permalink)
Fear the Wombat
 
stanrc's Avatar
 
amd ati

Join Date: Apr 2007
Location: Alexandria, VA
Posts: 4,111

Folding Team Rank: 91
Hardware Reviews: 7
Trader Rating: 3
Default

safe mode is the key. boot into it using f8 i believe then run all your virus scaners and spyware scanners from there. good luck!
__________________

Ramrod 1.5 + DFI LANPARTY DK 790FX-M2RS + AMD Phenom 9850 BE = Ramrod 2.0! Coming soon...

System: Ramrod 1.5
CPU
AMD Athlon 64 X2 5000+ Black Edition
Motherboard
DFI Lanparty 790FX
Memory
GSkill 4GB
Graphics Card
VisionTek HD4850
Hard Drive
Seagate 7200.10 160GB & 320GB
Sound Card
X-Fi XtremeGamer
Power Supply
Antec 650w
Case
Antec 900
CPU cooling
Arctic Cooling Freezer 64 Pro
GPU cooling
Stock
OS
Ubuntu/Vista 64
Monitor
Acer 19" WS
stanrc is offline I fold for Overclock.net Overclocked Account   Reply With Quote
Old 06-20-08   #5 (permalink)
Overclocker
 
voice's Avatar
 
intel nvidia

Join Date: Oct 2007
Location: Britain
Posts: 914

Rep: 27 voice is acknowledged by some
Unique Rep: 24
Trader Rating: 0
Default

Quote:
Originally Posted by GH0 View Post
Get a process explorer and search for any mischievous looking file names running.

Disable System Restore in Windows. Either by the service or by Windows System Properties.

You can try to look at registry fixers, such as CC Cleaner, Spybot S&D, etc.

Definitely use HiJack This, AV, CC Cleaner, S&D,
Definitely run Windows in Safe Mode for a good amount of time while trying to get rid of all of the things that are infected. Like discjockey said.

Another good thing, try killing explorer.exe from the tree and then shut down the computer.


As a last resort, you can do a format and reinstall. But Only as a last resort. It really just comes down to manually finding and removing them yourself.

Do you happen to know what the Virus is called?
I'll get right on it.

Quote:
Originally Posted by deskjockey View Post
turn off system restore, run your virus protection in safe mode.

use: smitfraudfix, combofix and hijackthis

You might have to dive deep into your computer but you can fix everything that has been corrupted

dont let anybody tell you that you have to reformat, thats the lazy way out
Thanks for the advice. I'll go download those now.

Quote:
Originally Posted by stanrc View Post
safe mode is the key. boot into it using f8 i believe then run all your virus scaners and spyware scanners from there. good luck!
I tried that, but even then Kaspersky was unable to get rid of the malware.

Back in a bit guys, thanks for all the help so far.
__________________
System: The Dust Magnet
CPU
Intel E2140 @ 3.0Ghz
Motherboard
Abit IP35 Pro
Memory
Crucial Ballistix 2GB PC2-8500 DDR2
Graphics Card
BFG 8800GT
Hard Drive
Seagate Barracuda 7200.10 250GB SATA-II 16MB Cache
Sound Card
Creative X-fi Xtreme Gamer
Power Supply
Corsair HX 620W
Case
Antec Nine Hundred
CPU cooling
TRUE w/ Xilence Redwing 120mm
OS
Windows XP SP2 & Ubuntu 7.10
Monitor
Hyundai B71A 17" LCD

Last edited by voice : 06-20-08 at 01:18 PM.
voice is offline   Reply With Quote
Old 06-20-08   #6 (permalink)
GH0
Security Sleuth
 
GH0's Avatar
 
amd nvidia

Join Date: Jan 2008
Location: North Carolina, USA
Posts: 1,181

Rep: 107 GH0 is acknowledged by manyGH0 is acknowledged by many
Unique Rep: 86
Folding Team Rank: 501
Trader Rating: 0
Default

Definietely just had a complete take over of my own computer.

Did a registry restore, then used those four computers, and I was back online in less then twenty minutes.

Though, I am still scanning through every file at the moment, to make sure I got everything.
__________________
System: Dataslum
CPU
5000+ Black Edition
Motherboard
ASUS Formula Crosshair II
Memory
4 (2x2) Muskin Memory
Graphics Card
EVGA 9800GTX+ 512 MB (SLI)
Hard Drive
Windows XP/Vista Business RAID 0, Total 2.1 TB
Sound Card
SupremeFX / Some form of cheap Creative
Power Supply
Corsair 1KW
Case
Lian-Li
CPU cooling
Xigmatek
GPU cooling
Stock
OS
Windows XP 32-bit Pro (SP2) and Vista Ultimate
Monitor
Samsung SyncMaster 906 BW, Sony 19"
GH0 is offline I fold for Overclock.net GH0's Gallery   Reply With Quote
Old 06-20-08   #7 (permalink)
Folding Fanatic
 
deskjockey's Avatar
 
intel nvidia

Join Date: Jan 2007
Location: Hockeytown, USA
Posts: 1,112

Rep: 94 deskjockey is acknowledged by some
Unique Rep: 80
Folding Team Rank: 28
Trader Rating: 15
Default

what happened to you GHO???
__________________
multi GPU folding on XP http://www.overclock.net/overclock-n...gfx-cards.html
think folding costs too much???http://www.overclock.net/overclock-n...ml#post4175378
Quote:
Originally Posted by Pyranite View Post
Open source supporters steal the glory and money from people who make decent products. They're like the China of the Internet, making crappy knock offs of reasonable products and distributing them for next to nothing.

System: knucklecase-now enriched with quad core!
CPU
x3210 @ 3360@1.328v after vdroop
Motherboard
Asus P5k3
Memory
gskill DDR3 pc8500
Graphics Card
xFx 8800gt Alpha Dog + Galaxy 8800gt
Hard Drive
120gb + 1tb
Power Supply
Cm 500 mod
CPU cooling
HDT
GPU cooling
stock
OS
xpp
deskjockey is offline I fold for Overclock.net   Reply With Quote
Old 06-20-08   #8 (permalink)
GH0
Security Sleuth
 
GH0's Avatar
 
amd nvidia

Join Date: Jan 2008
Location: North Carolina, USA
Posts: 1,181

Rep: 107 GH0 is acknowledged by manyGH0 is acknowledged by many
Unique Rep: 86
Folding Team Rank: 501
Trader Rating: 0
Default

Not really sure. But it is fixed now.
__________________
System: Dataslum
CPU
5000+ Black Edition
Motherboard
ASUS Formula Crosshair II
Memory
4 (2x2) Muskin Memory
Graphics Card
EVGA 9800GTX+ 512 MB (SLI)
Hard Drive
Windows XP/Vista Business RAID 0, Total 2.1 TB
Sound Card
SupremeFX / Some form of cheap Creative
Power Supply
Corsair 1KW
Case
Lian-Li
CPU cooling
Xigmatek
GPU cooling
Stock
OS
Windows XP 32-bit Pro (SP2) and Vista Ultimate
Monitor
Samsung SyncMaster 906 BW, Sony 19"
GH0 is offline I fold for Overclock.net GH0's Gallery   Reply With Quote
Old 06-20-08   #9 (permalink)
Overclocker
 
voice's Avatar
 
intel nvidia

Join Date: Oct 2007
Location: Britain
Posts: 914

Rep: 27 voice is acknowledged by some
Unique Rep: 24
Trader Rating: 0
Default

Kaspersky identified the malware as:
Code:
Trojan.Win32.Small.fb
The one embedded in two system restores was identified as:
Code:
Heur.Trojan.Generic
I wouldn't be surprised if the Small.fb trojan implanted itself into those system restores so if i tried to system restore it would still be there.

The trojan is listed here on the viruslist.com:

http://www.viruslist.com/en/viruses/...?virusid=89116


EDIT: Also, i just dl'd all the programs that deskjockey listed, they're now on a usb stick about to be moved to my virus ridden PC, should i be worried at all about the virus copying itself onto the USB drive or anything like that? I know it may sound silly but I'm a bit of a paranoid.
__________________
System: The Dust Magnet
CPU
Intel E2140 @ 3.0Ghz
Motherboard
Abit IP35 Pro
Memory
Crucial Ballistix 2GB PC2-8500 DDR2
Graphics Card
BFG 8800GT
Hard Drive
Seagate Barracuda 7200.10 250GB SATA-II 16MB Cache
Sound Card
Creative X-fi Xtreme Gamer
Power Supply
Corsair HX 620W
Case
Antec Nine Hundred
CPU cooling
TRUE w/ Xilence Redwing 120mm
OS
Windows XP SP2 & Ubuntu 7.10
Monitor
Hyundai B71A 17" LCD

Last edited by voice : 06-20-08 at 03:38 PM.
voice is offline   Reply With Quote
Old 06-20-08   #10 (permalink)
Folding Fanatic
 
deskjockey's Avatar
 
intel nvidia

Join Date: Jan 2007
Location: Hockeytown, USA
Posts: 1,112

Rep: 94 deskjockey is acknowledged by some
Unique Rep: 80
Folding Team Rank: 28
Trader Rating: 15
Default

I have done that too, didnt have a problem with the virus "jumping" to my thumb drive


you are in safe mode right?
__________________
multi GPU folding on XP http://www.overclock.net/overclock-n...gfx-cards.html
think folding costs too much???http://www.overclock.net/overclock-n...ml#post4175378
Quote:
Originally Posted by Pyranite View Post
Open source supporters steal the glory and money from people who make decent products. They're like the China of the Internet, making crappy knock offs of reasonable products and distributing them for next to nothing.

System: knucklecase-now enriched with quad core!
CPU
x3210 @ 3360@1.328v after vdroop
Motherboard
Asus P5k3
Memory
gskill DDR3 pc8500
Graphics Card
xFx 8800gt Alpha Dog + Galaxy 8800gt
Hard Drive
120gb + 1tb
Power Supply
Cm 500 mod
CPU cooling
HDT
GPU cooling
stock
OS
xpp
deskjockey is offline I fold for Overclock.net   Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools



All times are GMT -4. The time now is 12:49 PM.


Overclock.net is a Carbon Neutral Site Creative Commons License Internet Security By ControlScan

Terms of Service / Forum Rules | Privacy Policy | Advertising | Become an Official Vendor
Copyright © 2008 Shogun Interactive Development. Most rights reserved.
Page generated in 0.30649 seconds with 10 queries