Cigar Asylum Cigar Forum  

Go Back   Cigar Asylum Cigar Forum > Non Cigar Specialty Forums > Misc > General Discussion

Reply
 
Thread Tools Display Modes
Old 02-01-2011, 10:37 AM   #21
wayner123
Country Gentleman
 
wayner123's Avatar
 
Join Date: Oct 2008
Location: Deltona, FL
Posts: 2,351
Trading: (159)
Trinidad
wayner123 has disabled reputation
Default Re: CPU virus question

Quote:
Originally Posted by BC-Axeman View Post
Don't forget Windows' built in anti-virus. It works pretty good as long as you keep it updated, which is critical in Windoze anyway. After doing an update win$ will run a scan when it reboots. Things called rootkits get around this but you probably don't have one.
I have been able to get rid of most infections by running SuperAntiSpyware followed by WinDefender followed by a security update.
If he can't run anything on her side, it is acting exactly like a rootkit. A scan with malwarebytes should show that.
__________________
'It is an honor for a man to keep aloof from strife; But every fool will be quarrelling.'
wayner123 is offline   Reply With Quote
Old 02-01-2011, 10:47 AM   #22
BC-Axeman
Guest
 
Posts: n/a
Default Re: CPU virus question

If he can get in as Administrator and get to security updates and use control panel and run Malwarebytes it's not a very good rootkit. Rootkits replace the kernel and you are no longer even running Windows, you are running malware that runs Windows for you, meanwhile it can do whatever it wants with your computer. Keep track of your every keypress, decode encrypted transactions, read any file and hide some from you, turn on your webcam and microphones, anything.
I like Malwarebytes. I just happen to carry SAS around on a thumb drive with me.
  Reply With Quote
Old 02-01-2011, 11:01 AM   #23
wayner123
Country Gentleman
 
wayner123's Avatar
 
Join Date: Oct 2008
Location: Deltona, FL
Posts: 2,351
Trading: (159)
Trinidad
wayner123 has disabled reputation
Default Re: CPU virus question

Quote:
Originally Posted by BC-Axeman View Post
If he can get in as Administrator and get to security updates and use control panel and run Malwarebytes it's not a very good rootkit. Rootkits replace the kernel and you are no longer even running Windows, you are running malware that runs Windows for you, meanwhile it can do whatever it wants with your computer. Keep track of your every keypress, decode encrypted transactions, read any file and hide some from you, turn on your webcam and microphones, anything.
I like Malwarebytes. I just happen to carry SAS around on a thumb drive with me.
That was the old rootkit's 1 and 2 that may have done that. Rootkit's 3-5 (5 no one has confirmed yet) does not work this way.
__________________
'It is an honor for a man to keep aloof from strife; But every fool will be quarrelling.'
wayner123 is offline   Reply With Quote
Old 02-01-2011, 11:33 AM   #24
jledou
Have My Own Room
 
jledou's Avatar
14
 
Join Date: Oct 2008
First Name: Jay
Location: Kansas
Posts: 2,225
Trading: (27)
Punch
jledou has a spectacular aura aboutjledou has a spectacular aura aboutjledou has a spectacular aura about
Default Re: CPU virus question

One simple solution that has taken care of some (not all) of these, is a system restore to a date before this happened. In short some are worse than others, meaning some you have to catch before they load, some have to be taken care of in DOS, and some are a restore point away from being gone. Good luck.
jledou is offline   Reply With Quote
Old 02-01-2011, 02:37 PM   #25
RandJCigars
JSR
 
Join Date: Jan 2011
First Name: Jimmy
Location: Friendswood
Posts: 105
Trading: (3)
RandJCigars is on a distinguished road
Default Re: CPU virus question

Download and Install SpyBot Search and Destroy. It's free and it's very good. Make sure to boot into safe mode to run the scans...as some virus', bots, and maleware can stop a scanner from running properly.
RandJCigars is offline   Reply With Quote
Old 02-01-2011, 02:43 PM   #26
357
Will herf for food
 
357's Avatar
 
Join Date: Oct 2008
First Name: Mike
Location: Home is where I park it
Posts: 4,075
Trading: (9)
VR
357 is a splendid one to behold357 is a splendid one to behold357 is a splendid one to behold357 is a splendid one to behold357 is a splendid one to behold357 is a splendid one to behold
Default Re: CPU virus question

It's known as "FakeAV". I have fought and beaten this exact issue. A freeware application called HitManPro will find and remove it. Install it while logged in under your profile, reboot into Safe Mode (hit F8 as it is booting up), and run a full system scan.

Many of the other common anti-malware/spyware apps will not work on this one. I have tried MalwareBytes, AVG, SpyBot, Symantec AV, McAfee AV, Trend Micro, and more. HitManPro is the only automated way. I have removed it manually by digging through the registry and tons of DLL files, but I doubt you want to venture into that.

Good luck.
__________________
“Eating and sleeping are the only activities that should be allowed to interrupt a man's enjoyment of his cigar;” Mark Twain
357 is offline   Reply With Quote
Old 02-01-2011, 02:51 PM   #27
Blueface
Gramps 4x's
 
Blueface's Avatar
4
 
Join Date: Oct 2008
First Name: Horatio Seymore Hiny
Location: Boca Raton - North of La Habana
Posts: 8,774
Trading: (8)
Bolivar
Blueface has disabled reputation
Default Re: CPU virus question

Erick, all fantastic advice given to you except the most important.

Here goes


Ready?


Get a Mac!!!

Other than that, not much else I can offer.
__________________
Little known fact: I am a former member of the Village People - The Indian
Blueface is offline   Reply With Quote
Old 02-01-2011, 02:54 PM   #28
wayner123
Country Gentleman
 
wayner123's Avatar
 
Join Date: Oct 2008
Location: Deltona, FL
Posts: 2,351
Trading: (159)
Trinidad
wayner123 has disabled reputation
Default Re: CPU virus question

Quote:
Originally Posted by 357 View Post
It's known as "FakeAV". I have fought and beaten this exact issue. A freeware application called HitManPro will find and remove it. Install it while logged in under your profile, reboot into Safe Mode (hit F8 as it is booting up), and run a full system scan.

Many of the other common anti-malware/spyware apps will not work on this one. I have tried MalwareBytes, AVG, SpyBot, Symantec AV, McAfee AV, Trend Micro, and more. HitManPro is the only automated way. I have removed it manually by digging through the registry and tons of DLL files, but I doubt you want to venture into that.

Good luck.
Kaspersky is the leader in this field. I have removed trjoans, malware, etc multiple times from multiple machines with the tdsskiller. Malewarebytes will remove all the associated files from cookies and so on, and also let you know whether it's a rootkit or not. Then run tdsskiller and it "should" be gone. If that doesn't work, I have more last option, but I am not going to list it till the OP tries the others first.

I don't mean to argue with you, and I am sure you have removed it through other programs (gmer is also a good one). I have a lot of experience with this malicious software and have read hours on hours of bleepingcomputer logs to feel confident in my advice.
__________________
'It is an honor for a man to keep aloof from strife; But every fool will be quarrelling.'
wayner123 is offline   Reply With Quote
Old 02-01-2011, 02:58 PM   #29
wayner123
Country Gentleman
 
wayner123's Avatar
 
Join Date: Oct 2008
Location: Deltona, FL
Posts: 2,351
Trading: (159)
Trinidad
wayner123 has disabled reputation
Default Re: CPU virus question

Quote:
Originally Posted by Blueface View Post
Erick, all fantastic advice given to you except the most important.

Here goes


Ready?


Get a Mac!!!

Other than that, not much else I can offer.
Unfortunately, Mac's are not immune to rootkits.
__________________
'It is an honor for a man to keep aloof from strife; But every fool will be quarrelling.'
wayner123 is offline   Reply With Quote
Old 02-02-2011, 08:24 AM   #30
357
Will herf for food
 
357's Avatar
 
Join Date: Oct 2008
First Name: Mike
Location: Home is where I park it
Posts: 4,075
Trading: (9)
VR
357 is a splendid one to behold357 is a splendid one to behold357 is a splendid one to behold357 is a splendid one to behold357 is a splendid one to behold357 is a splendid one to behold
Default Re: CPU virus question

Quote:
Originally Posted by wayner123 View Post
Kaspersky is the leader in this field. I have removed trjoans, malware, etc multiple times from multiple machines with the tdsskiller. Malewarebytes will remove all the associated files from cookies and so on, and also let you know whether it's a rootkit or not. Then run tdsskiller and it "should" be gone. If that doesn't work, I have more last option, but I am not going to list it till the OP tries the others first.

I don't mean to argue with you, and I am sure you have removed it through other programs (gmer is also a good one). I have a lot of experience with this malicious software and have read hours on hours of bleepingcomputer logs to feel confident in my advice.
I too have extensive experience with this stuff in a work environment. I do use MalwareBytes quite a bit, but I've seen it detect and remove potions of FakeAV and leave other parts behind. Maybe the newer versions do a better job. Kaspersky very well may work. It is not one I've used so I can't comment on that either way. I know HitManPro will work and it's free. Either way I feel he has good advice from guys who've done this before, not just random "try this" suggestions from folks who are trying to help but don't have the background/experience.
__________________
“Eating and sleeping are the only activities that should be allowed to interrupt a man's enjoyment of his cigar;” Mark Twain
357 is offline   Reply With Quote
Old 02-02-2011, 08:51 AM   #31
MiamiE
I'm nuts for the place
 
MiamiE's Avatar
 
Join Date: Feb 2009
First Name: Erick
Location: Miami, FL
Posts: 2,892
Trading: (38)
RA
MiamiE will become famous soon enoughMiamiE will become famous soon enough
Default Re: CPU virus question

I did the Malwarebytes and Comodo AV full scans. It detected the 4 viruses and deleted them, but my wife's IE still doesn't work. Says there no connection to the proxy server. This may be due to Comodo creating a unique IP? She can open all her files again. Thanks for all your help guys! Much appreciated.
MiamiE is offline   Reply With Quote
Old 02-02-2011, 09:02 AM   #32
wayner123
Country Gentleman
 
wayner123's Avatar
 
Join Date: Oct 2008
Location: Deltona, FL
Posts: 2,351
Trading: (159)
Trinidad
wayner123 has disabled reputation
Default Re: CPU virus question

Quote:
Originally Posted by MiamiE View Post
I did the Malwarebytes and Comodo AV full scans. It detected the 4 viruses and deleted them, but my wife's IE still doesn't work. Says there no connection to the proxy server. This may be due to Comodo creating a unique IP? She can open all her files again. Thanks for all your help guys! Much appreciated.
Did you run tdsskiller?
__________________
'It is an honor for a man to keep aloof from strife; But every fool will be quarrelling.'
wayner123 is offline   Reply With Quote
Old 02-02-2011, 09:28 AM   #33
MiamiE
I'm nuts for the place
 
MiamiE's Avatar
 
Join Date: Feb 2009
First Name: Erick
Location: Miami, FL
Posts: 2,892
Trading: (38)
RA
MiamiE will become famous soon enoughMiamiE will become famous soon enough
Default Re: CPU virus question

I am going to have to do that one later.
MiamiE is offline   Reply With Quote
Old 02-02-2011, 09:31 AM   #34
mosesbotbol
That's a Corgi
 
mosesbotbol's Avatar
 
Join Date: Oct 2008
First Name: Moses
Location: Boston
Posts: 6,171
Trading: (6)
Punch
mosesbotbol is a jewel in the roughmosesbotbol is a jewel in the roughmosesbotbol is a jewel in the rough
Default Re: CPU virus question

Copy her files such as documents, favorite, mail settings...

Delete her profile and create a new one until you find the AV software to dig deeper.
__________________
Port Wine & Claret | British Cars | Welsh Corgi's
mosesbotbol is offline   Reply With Quote
Old 02-02-2011, 09:33 AM   #35
Bageland2000
On another adventure
 
Bageland2000's Avatar
 
Join Date: Jan 2011
First Name: Andrew
Location: Chicago, IL
Posts: 352
Trading: (2)
RyJ Army (Active)
Bageland2000 is on a distinguished road
Default Re: CPU virus question

Quote:
Originally Posted by MiamiE View Post
I did the Malwarebytes and Comodo AV full scans. It detected the 4 viruses and deleted them, but my wife's IE still doesn't work. Says there no connection to the proxy server. This may be due to Comodo creating a unique IP? She can open all her files again. Thanks for all your help guys! Much appreciated.
Are you trying to connect to a proxy server!? I doubt you are... A better question may be, how do you connect to the internet (modem, dsl, cable etc)
__________________
Favorites: Arturo Fuente Sun Grown Rosado, Oliva Serie V, CAO La Traviata/Brazilia, Perdomo 10th An. Champagne
Bageland2000 is offline   Reply With Quote
Old 02-02-2011, 09:49 AM   #36
MiamiE
I'm nuts for the place
 
MiamiE's Avatar
 
Join Date: Feb 2009
First Name: Erick
Location: Miami, FL
Posts: 2,892
Trading: (38)
RA
MiamiE will become famous soon enoughMiamiE will become famous soon enough
Default Re: CPU virus question

I have DSL. When I loaded Comodo it asked if I wanted to create a different IP.
MiamiE is offline   Reply With Quote
Old 02-02-2011, 10:01 AM   #37
357
Will herf for food
 
357's Avatar
 
Join Date: Oct 2008
First Name: Mike
Location: Home is where I park it
Posts: 4,075
Trading: (9)
VR
357 is a splendid one to behold357 is a splendid one to behold357 is a splendid one to behold357 is a splendid one to behold357 is a splendid one to behold357 is a splendid one to behold
Default Re: CPU virus question

Quote:
Originally Posted by MiamiE View Post
I have DSL. When I loaded Comodo it asked if I wanted to create a different IP.
In IE, click tools, Internet options, then click the Connections Tab. Near the bottom click "LAN Settings" and uncheck the "Use Proxy" option. You'll have to close IE completely and re-open it. Some viruses (Virii) setup bogus proxies in IE to steal personal information. You can also get to these options in Control Panel under Internet Options.

For most DSL/Cable providers it is not necessary to use a proxy. Sometimes their install CD points you to one, but that is only for their benefit. They sell the tracking info of where you go, what you browse, and how often you make purchases, and where. They do no collect personal info, but I still don't like participating. Comcast amongst others does this with their proxies. This is why I don't install their CD. You don't need it to get online. Just an IP address, gateway, and a subnet mask. 99% of the time that is automatically provided by DHCP to the cable/DSL modem, so you're good.
__________________
“Eating and sleeping are the only activities that should be allowed to interrupt a man's enjoyment of his cigar;” Mark Twain
357 is offline   Reply With Quote
Old 02-02-2011, 08:39 PM   #38
MiamiE
I'm nuts for the place
 
MiamiE's Avatar
 
Join Date: Feb 2009
First Name: Erick
Location: Miami, FL
Posts: 2,892
Trading: (38)
RA
MiamiE will become famous soon enoughMiamiE will become famous soon enough
Default Re: CPU virus question

Quote:
Originally Posted by wayner123 View Post
Did you run tdsskiller?
Just ran this and it found no threats. My wifes IE has reverted back to F'd up after a restart...
MiamiE is offline   Reply With Quote
Old 02-02-2011, 09:07 PM   #39
MiamiE
I'm nuts for the place
 
MiamiE's Avatar
 
Join Date: Feb 2009
First Name: Erick
Location: Miami, FL
Posts: 2,892
Trading: (38)
RA
MiamiE will become famous soon enoughMiamiE will become famous soon enough
Default Re: CPU virus question

Found the bastard with Hitman Pro 3.5.8

3 Trojans, 1 Malware, 1 Rootkit, and 3 Tracking Cookie. Question is what do I do now? Delete, quarantine, or ignore?
MiamiE is offline   Reply With Quote
Old 02-02-2011, 09:25 PM   #40
wayner123
Country Gentleman
 
wayner123's Avatar
 
Join Date: Oct 2008
Location: Deltona, FL
Posts: 2,351
Trading: (159)
Trinidad
wayner123 has disabled reputation
Default Re: CPU virus question

I am not familiar with hitmanpro, but if it found something that tdsskiller did not, I would be wary.

Quarantine it and see what happens.

You can always go with my last option which is combofix.exe but let me know before you choose to do this step.

I also forgot to mention that you MUST run and save the tdsskiller.exe on your desktop. Or it won't work properly. Here is the basic use for it: http://www.bleepingcomputer.com/forums/topic377240.html
__________________
'It is an honor for a man to keep aloof from strife; But every fool will be quarrelling.'
wayner123 is offline   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -6. The time now is 11:03 AM.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
All content is copyrighted jointly by Cigar Asylum and the content provider.