Cheat Engine Forum Index Cheat Engine
The Official Site of Cheat Engine
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 


CTFmon.exe virus.

 
Post new topic   Reply to topic    Cheat Engine Forum Index -> Computer Talk
View previous topic :: View next topic  
Author Message
Hero
I'm a spammer
Reputation: 79

Joined: 16 Sep 2006
Posts: 7154

PostPosted: Fri Dec 04, 2009 10:47 pm    Post subject: CTFmon.exe virus. Reply with quote

My aunts friend got her yahoo haked and today sent a link to her and my aunt clicked it. The pc has not been rebooted, but i cannot find a solution to remove it. It is forcing hidden system files, and a fake ctfmon.exe in the msconfig.

If you would like to post some stupid comment just because in the past my netbook had compatibility issues with w7, then just dont. Its serious and the thing turned off system restore. Is there anything to do or is everyone gonna give me the idiot answer to reformat it?
Back to top
View user's profile Send private message
Haswell
Grandmaster Cheater
Reputation: 10

Joined: 24 Nov 2007
Posts: 703

PostPosted: Fri Dec 04, 2009 11:12 pm    Post subject: Reply with quote

Force-terminate + manual removal. Or just run a virus scan.
Back to top
View user's profile Send private message
Hero
I'm a spammer
Reputation: 79

Joined: 16 Sep 2006
Posts: 7154

PostPosted: Fri Dec 04, 2009 11:24 pm    Post subject: Reply with quote

I cannot find this shit on the hard drive, and it will crash any av. I got it in safe mode though and it is scanning. I'd love to reformat this thing, I really would, but for the sake of my aunts schooling, I'm trying to save it. Shes got tons of shit id rather not have to move off.
Back to top
View user's profile Send private message
Fap2Admin
Master Cheater
Reputation: -1

Joined: 10 Feb 2008
Posts: 483
Location: Somewhere down the Road

PostPosted: Sat Dec 05, 2009 4:07 am    Post subject: Reply with quote

Try to download Autoruns (http://sysinternals.com). You can find there where the virus auto-runs, where it's located and what files are associated with it.

Sounds like a daemon.exe inside System.

_________________

Best AR-TITS on CEF
Back to top
View user's profile Send private message
K, Alcohol
Expert Cheater
Reputation: 0

Joined: 25 Mar 2009
Posts: 184

PostPosted: Sat Dec 05, 2009 9:44 am    Post subject: Reply with quote

Download gmer (google it), the virus won't crash it since it uses random characters in its name. Then use Autoruns and hijackthis, as suggested. Try Mbam also (if you can run it). Google all of those.
Back to top
View user's profile Send private message
Hero
I'm a spammer
Reputation: 79

Joined: 16 Sep 2006
Posts: 7154

PostPosted: Sat Dec 05, 2009 11:09 am    Post subject: Reply with quote

Its gone. Must give the creator props, he tried hard to make it unable to be removed. He blocked sites using the host file, used a disable on registries for system restore. He used something to make the folder options reset a certain way, and the screen saver unable to be changed. I backed the shit up to a partition and decided to reboot for lols, and eset blocked all its processes, but it couldnt find it. Used malwarebytes while in safemode and it was able to clean all but the host and the registry disabling system restore.


All is fixed now.
Back to top
View user's profile Send private message
K, Alcohol
Expert Cheater
Reputation: 0

Joined: 25 Mar 2009
Posts: 184

PostPosted: Sun Dec 06, 2009 3:47 am    Post subject: Reply with quote

The hosts files can be cleaned manually, and the regedit to enable system restore is easy to find in google. Good that you cleaned it Smile
Back to top
View user's profile Send private message
Hero
I'm a spammer
Reputation: 79

Joined: 16 Sep 2006
Posts: 7154

PostPosted: Sun Dec 06, 2009 12:48 pm    Post subject: Reply with quote

K, Randomness wrote:
The hosts files can be cleaned manually, and the regedit to enable system restore is easy to find in google. Good that you cleaned it :)
Host file, I've known how to clean that since mαplefag days when nex0n fucked something up. As for the reg, I just went to the place the scanner showed and deleted it.
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Cheat Engine Forum Index -> Computer Talk All times are GMT - 6 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group

CE Wiki   IRC (#CEF)   Twitter
Third party websites