View previous topic :: View next topic |
Author |
Message |
Drkgodz Flash moderator
Reputation: 2
Joined: 17 Jul 2006 Posts: 2997 Location: Houston
|
Posted: Mon Jul 20, 2009 1:09 pm Post subject: Nasty Virus |
|
|
Will I removed a virus about a month ago and everything was fine until yesterday. It said IE8 crashed and then those virus pop ups come from the tray saying your computer is infected and everything. I checked my processes and deleted all the ones that were viruses. I eventually got the virus to stop. However when I rebooted it was back. I am using ZoneAlarm right now to make sure it doesn't download anything, but I really want to get rid of them.
This is what I have observed of the virus:
It creates many executables, many of which I suspect are the same and do the same thing. All these executables end up in the temp folder:
setup.exe
system.exe
login.exe
services.exe
debug.exe
csrss.exe
2724140706.exe
spoolsv.exe
taskmgr.exe
win.exe
They are all 20 KB.
And at random times, it creates an exe with a random 3 digit number. ie: 304.exe, 089.exe, etc. It also creates many hidden files in the temp folder and sets my view hidden files option to false.
I also have reader_s.exe. I removed all traces I could find of this, and I removed it from the registry. Hopefully this has fixed it. I will reboot now.
EDIT:
Nope. It came back and put more crap in my temp folder.
327.exe
789.exe
3915612364.exe
winlogon.exe
svchost.exe
notepad.exe
I have also notice that there is always KENEL.DLL in my temp folder. I have 2 files I cannot delete.
WPDNSE(folder)
and
~DFDBD9.tmp
The .tmp name just changed. I think it creates a different one on startup.
_________________
|
|
Back to top |
|
 |
Karakawe I post too much
Reputation: 3
Joined: 17 Apr 2007 Posts: 3899
|
Posted: Mon Jul 20, 2009 2:47 pm Post subject: |
|
|
Safe mode > Virus Scan would be the most practical first step.
|
|
Back to top |
|
 |
SF I'm a spammer
Reputation: 119
Joined: 19 Mar 2007 Posts: 6028
|
Posted: Mon Jul 20, 2009 3:09 pm Post subject: |
|
|
Run hijackthis and post the log.
In the popups, what antivirus is it claiming to be?
_________________
|
|
Back to top |
|
 |
Mania Guy I post too much
Reputation: 10
Joined: 10 Jun 2008 Posts: 2529 Location: Up
|
Posted: Mon Jul 20, 2009 3:45 pm Post subject: Re: Nasty Virus |
|
|
Drkgodz wrote: | Will I removed a virus about a month ago and everything was fine until yesterday. It said IE8 crashed and then those virus pop ups come from the tray saying your computer is infected and everything. I checked my processes and deleted all the ones that were viruses. I eventually got the virus to stop. However when I rebooted it was back. I am using ZoneAlarm right now to make sure it doesn't download anything, but I really want to get rid of them.
This is what I have observed of the virus:
It creates many executables, many of which I suspect are the same and do the same thing. All these executables end up in the temp folder:
setup.exe
system.exe
login.exe
services.exe
debug.exe
csrss.exe
2724140706.exe
spoolsv.exe
taskmgr.exe
win.exe
They are all 20 KB.
And at random times, it creates an exe with a random 3 digit number. ie: 304.exe, 089.exe, etc. It also creates many hidden files in the temp folder and sets my view hidden files option to false.
I also have reader_s.exe. I removed all traces I could find of this, and I removed it from the registry. Hopefully this has fixed it. I will reboot now.
EDIT:
Nope. It came back and put more crap in my temp folder.
327.exe
789.exe
3915612364.exe
winlogon.exe
svchost.exe
notepad.exe
I have also notice that there is always KENEL.DLL in my temp folder. I have 2 files I cannot delete.
WPDNSE(folder)
and
~DFDBD9.tmp
The .tmp name just changed. I think it creates a different one on startup. |
These are in my PC to...
_________________
|
|
Back to top |
|
 |
Luigi Grandmaster Cheater Supreme
Reputation: 1
Joined: 24 Mar 2008 Posts: 1082
|
Posted: Mon Jul 20, 2009 7:01 pm Post subject: |
|
|
ASNES wrote: | Get Spybot Search and Destroy and Avira AntiVirus. | Spybot Search and Destroy goes too quick. It actually misses a lot (I tested it personally). Go with a-squared + avira or spyware doctor + avira.
Also, before my new computer was built, I had the same exact virus. I solved it by deleting every single trace it made. It took about an hour. I then installed Malwarebytes (ftw!) to remove the rest.
|
|
Back to top |
|
 |
hcavolsdsadgadsg I'm a spammer
Reputation: 26
Joined: 11 Jun 2007 Posts: 5801
|
Posted: Mon Jul 20, 2009 7:24 pm Post subject: |
|
|
reformat.
no point in fucking around once you're infected, back whatever up and go.
|
|
Back to top |
|
 |
Luigi Grandmaster Cheater Supreme
Reputation: 1
Joined: 24 Mar 2008 Posts: 1082
|
Posted: Mon Jul 20, 2009 7:30 pm Post subject: |
|
|
slovach wrote: | reformat.
no point in fucking around once you're infected, back whatever up and go. | If all else fails.
I personally do not like reinstalling all the programs I have.
|
|
Back to top |
|
 |
Drkgodz Flash moderator
Reputation: 2
Joined: 17 Jul 2006 Posts: 2997 Location: Houston
|
Posted: Mon Jul 20, 2009 9:02 pm Post subject: |
|
|
Don't worry guys. I used AVG and it failed, but then after a quick scan with Malwarebytes Anti-Malware the virus was removed.
_________________
|
|
Back to top |
|
 |
Luigi Grandmaster Cheater Supreme
Reputation: 1
Joined: 24 Mar 2008 Posts: 1082
|
Posted: Mon Jul 20, 2009 9:20 pm Post subject: |
|
|
Drkgodz wrote: | Don't worry guys. I used AVG and it failed, but then after a quick scan with Malwarebytes Anti-Malware the virus was removed.  | Don't I deserve a -rep?
Also, keep it handy, you might need it yet another day.
And another thing, instead of AVG, try Avira. Avira will rape anything that tries to enter your system (unless of course you click the ignore button)
|
|
Back to top |
|
 |
Fap2Admin Master Cheater
Reputation: -1
Joined: 10 Feb 2008 Posts: 483 Location: Somewhere down the Road
|
Posted: Tue Jul 21, 2009 4:18 am Post subject: |
|
|
Aw man, reader_s.exe
A Virut Variant.
Got that before, and It infect all exe of mine.
If you got that VRR.tmp stuff in your Temp/Windows folder, do not delete it.
Dc18 will hide in your recycle bin.
I suggest downloading Avira or SpyBot S&D.
_________________
Best AR-TITS on CEF |
|
Back to top |
|
 |
Desolati0n Expert Cheater
Reputation: 7
Joined: 18 Jun 2009 Posts: 105 Location: 20,000 leagues under the sea
|
Posted: Tue Jul 21, 2009 5:48 am Post subject: |
|
|
That is a pretty nasty virus, what the hell were you doing when you obtained it?
Only advice I can think of is system restore.
_________________
well |
|
Back to top |
|
 |
|