Malware Hiding on me?

Have just checked with malwarebytes and they say that their latest definitions catch this beast so may want to update defs and re-scan
 

My Computers

System One System Two

  • Operating System
    Windows 10 Pro x64 Latest Release Preview
    Monitor(s) Displays
    Acer G276HL 27", (DVi) + Samsung 39" HDTV (HDMI)
    Screen Resolution
    2 x 1920x1080 @50Hz
  • Manufacturer/Model
    Real World Computers (Custom by Me)
    CPU
    AMD FX8350 Vishera 8 Core @4GHz
    Motherboard
    Asus M5A78L-M USB3
    Memory
    32GB [4x8GB] DDR3 1600 MHz
    Graphics card(s)
    Asus nVidia GTX750TI-OC-2GD5 (2GB DDR5)
    Sound Card
    ASUS Xoner DG + SPDIF to 5.1 System + HDMI
    Monitor(s) Displays
    Samsung 32" TV
    Screen Resolution
    1920 x 1080
    Hard Drives
    Internal
    Crucial CT256MX100SSD1 256GB SSD,
    Seagate ST2000DM001-1CH1 2TB,

    External (USB3)
    Seagate Backup+ Hub BK SCSI Disk 8TB
    2.5/3.5 Hot Swap Cradle, USB3 + eSata (client HDDs)
    NAS 4TB
    PSU
    Aerocool Templarius Imperator 750W 80+ Silver
    Case
    AeroCool X-Warrior Red Devil Tower
    Cooling
    Hyper103 CPU, Rear 120mm, Front 2x120mm, Side 2x120mm
    Internet Speed
    68 MB Down 18.5 MB Up
    Other Info
    Six Sensor Auto / Manual Digital cooling (Fan) control with Touch control Panel
What you really need to do is get Hijackthis and run it and post your results on castlecops or wilders security forum they can help you with the problem in more detail there.... Not that you cant get a resolution here but they deal with this stuff all the time.
 

My Computer

Nigel,
All of the things you told me to delete are deleted and the popup is still there
anything else?
ben

The problem with this @##$%%** is that it hides itself as something else and almost seems to mutate. Once you click on the teaser and it installs itself it's got you. I've never really got rid of it. The last part of Nigels advice about a reinstall was what I have had to do on most ocassions I have seen it. I've never been infected (touch wood), but I've been given enough computers that were to know it's cunning. I once found the .exe file file for Antivirus 2008 in Documents/My Pictures.
 

My Computer

System One

  • Manufacturer/Model
    Scratch Built
    CPU
    Intel Quad Core 6600
    Motherboard
    Asus P5B
    Memory
    4096 MB Xtreme-Dark 800mhz
    Graphics Card(s)
    Zotac Amp Edition 8800GT - 512MB DDR3, O/C 700mhz
    Monitor(s) Displays
    Samsung 206BW
    Screen Resolution
    1680 X 1024
    Hard Drives
    4 X Samsung 500GB 7200rpm Serial ATA-II HDD w. 16MB Cache .
    PSU
    550 w
    Case
    Thermaltake
    Cooling
    3 x octua NF-S12-1200 - 120mm 1200RPM Sound Optimised Fans
    Keyboard
    Microsoft
    Mouse
    Targus
    Internet Speed
    1500kbs
    Other Info
    Self built.
Hi Ben,

Yep , Norm's right. If you are not too badly infected and you can get rid of it fairly quickly with malwarebytes, and deleting a few files , then great.

If you have tried that and are still infected, then it's not worth mucking about endlessly with the thing. I would save the pain and reinstall.

Odd you didn't get a disc - do you have the option to create one - if so , worth doing straight away.

Reinstalling or reimaging from the recovery partition is probably quicker than from a disc, but you need a disc for the future in case you can't boot, or the recovery partition is corrupted.

If you are lucky, the recovery partition might contain WAU files - you can make a good disc from those easily.

Here's how it's done with the recovery partition

http://www.ehow.com/how_2134715_dell-windows-vista-factory-settings.html

Hope it helps

SIW2
 
Last edited:

My Computers

System One System Two

  • Operating System
    Vista
    CPU
    Intel E8400
    Motherboard
    ASRock1333-GLAN R2.0
    Memory
    4gb DDR2 800
    Graphics Card(s)
    nvidia 9500GT 1gb
  • Operating System
    win7/vista
    CPU
    intel i5-8400
    Motherboard
    gigabyte b365m ds3h
    Memory
    ballistix 2x8gb 3200
Nigel,
All of the things you told me to delete are deleted and the popup is still there
anything else?
ben

The problem with this @##$%%** is that it hides itself as something else and almost seems to mutate. Once you click on the teaser and it installs itself it's got you. I've never really got rid of it. The last part of Nigels advice about a reinstall was what I have had to do on most ocassions I have seen it. I've never been infected (touch wood), but I've been given enough computers that were to know it's cunning. I once found the .exe file file for Antivirus 2008 in Documents/My Pictures.

Guess what!:mad: Just lost all my .exe associations. Then lost half my icon cache. Had to do a system restore from Vista install disk. Guess what I found then :-

Capture.JPG

Famous last words Eh!:cry::cry:
images.jpg


 

My Computer

System One

  • Manufacturer/Model
    Scratch Built
    CPU
    Intel Quad Core 6600
    Motherboard
    Asus P5B
    Memory
    4096 MB Xtreme-Dark 800mhz
    Graphics Card(s)
    Zotac Amp Edition 8800GT - 512MB DDR3, O/C 700mhz
    Monitor(s) Displays
    Samsung 206BW
    Screen Resolution
    1680 X 1024
    Hard Drives
    4 X Samsung 500GB 7200rpm Serial ATA-II HDD w. 16MB Cache .
    PSU
    550 w
    Case
    Thermaltake
    Cooling
    3 x octua NF-S12-1200 - 120mm 1200RPM Sound Optimised Fans
    Keyboard
    Microsoft
    Mouse
    Targus
    Internet Speed
    1500kbs
    Other Info
    Self built.
UPDATE. Ran Malabytes Rogue Remover with the 2 shortcuts still in start menu. Clean bill of Health. Kaspersky Scan - No threat. Defender - Your Computer is running normally, So these little beasties got in, screwed with me, are now lurking, but the tools that are supposed to find them don't. Just had firefox freeze on me? Doing a full restore from Acronis to Tuesday 11th (Last Acronis Backup). I am pretty sure I was clean until this morning. That's when I had issues. Restored to backup. Seems OK now. Whew!!

mad_at_computer copy.jpg
 
Last edited:

My Computer

System One

  • Manufacturer/Model
    Scratch Built
    CPU
    Intel Quad Core 6600
    Motherboard
    Asus P5B
    Memory
    4096 MB Xtreme-Dark 800mhz
    Graphics Card(s)
    Zotac Amp Edition 8800GT - 512MB DDR3, O/C 700mhz
    Monitor(s) Displays
    Samsung 206BW
    Screen Resolution
    1680 X 1024
    Hard Drives
    4 X Samsung 500GB 7200rpm Serial ATA-II HDD w. 16MB Cache .
    PSU
    550 w
    Case
    Thermaltake
    Cooling
    3 x octua NF-S12-1200 - 120mm 1200RPM Sound Optimised Fans
    Keyboard
    Microsoft
    Mouse
    Targus
    Internet Speed
    1500kbs
    Other Info
    Self built.
Here is a list of things. This is rediculously suspicious becasue i have NOTHING for Google and i never installed anyhting on 11/8 and that is the day this all started. So i am about 95% sure this is it. There are a bunchh of pics. I am currently running a Malware Bites Scan and will inform u all once it is done. If it doesnt get it i will delete it and reboot then report back. Thanks everyone,
Ben
 

Attachments

  • Capture1.JPG
    Capture1.JPG
    64.4 KB · Views: 22
  • 3.JPG
    3.JPG
    27.7 KB · Views: 65
  • 42445.JPG
    42445.JPG
    47.6 KB · Views: 18
  • 2345654.JPG
    2345654.JPG
    18.3 KB · Views: 24
  • 6546541.JPG
    6546541.JPG
    25.2 KB · Views: 21

My Computer

System One

  • Manufacturer/Model
    Dell
    CPU
    Intel(R) Celeron(R) CPU 420 @1.60 GHz
    Motherboard
    Dell Inspion 530 Default
    Memory
    PNY 4GB 240-Pin SDRAM DDR2 800 (PC2 6400) Dual Channel
    Graphics Card(s)
    ATI Radeon HD 2400 PRO
    Sound Card
    Realtek HD Audio
    Monitor(s) Displays
    Gateway PnP Monitor
    Screen Resolution
    1024x768 @ 75 Hz
    Hard Drives
    Seagate 250G ATA SATA-II
    Case
    Dell Inspiron 530
    Cooling
    None
    Keyboard
    Logitech EX100 Combo
    Mouse
    Logitech EX100 Combo
    Internet Speed
    100 MB/s
Try doing this

1. Start up computer in Safe Mode.
2. Locate the file "visfdw.exe".
("C:\Users\USER_NAME\AppData\Roaming\Google\visfdw.exe")
3. Delete that file.
4. Go into your registry.
(Start > Run > (type in "regedit"))
5. Expand the following folders in this order:
'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run'
6. Locate "winlogone".
7. Delete the registry entry.
8. Restart your computer.
 

My Computer

System One

  • Manufacturer/Model
    HP Compaq Presario/SR5113WM
    CPU
    AMD Athlon 64 X2 3600+ 1.9Ghz
    Motherboard
    Asus M2N68-LA
    Memory
    PNY Optima Memory DDR2 2GB 2x1 kit
    Graphics Card(s)
    PNY Nvidia 8400 GS 256MB
    Sound Card
    On board RealTek
    Monitor(s) Displays
    Acer X163W LCD
    Screen Resolution
    1366x768
    Hard Drives
    Western Digital 160 GB SATA 3G (3.0Gb/sec)
    7200 rpm
    Western Digital 160 GB IDE
    PSU
    Dynex 400w
    Case
    Nothin Special
    Cooling
    Stock
    Keyboard
    Standard 102 key with volume and sleep buttons
    Mouse
    Wireless Logitech LX7
    Internet Speed
    Comcrap 10mb cable
    Other Info
    Insignia 2.1 speakers, wireless Xbox 360 controller w/plug n play charger, Belkin wireless G + mimo usb network adapter.
I think i found it!
Here are some pictures from unlocker and others that i took with the snipping tool!!!
Look at the unlocker screenshot as i am saying this
  1. All of these things are running
  2. I realized a few days ago i had 2 explorers running and when i deleted one nothing happened
  3. I have been getting this weird popup from ATI (which i should have thought of before) every time i start my computer. ( it is one of the captures and doesnt make sense since i updated it at the beginning of the month)
  4. And finally because i couldnt delete this weird visfdw.exe file. I never installed it. and i never have used any google things so y would it be in a google folder?
  5. I am going to delete the files, empty the recycle bin, run ccleaner, and restart my computer. I will do what i usually do (go on this site and work on my webpage from Dreamweaver) and see if it comes up in an hour or two.
I will make sure to keep you all informed!
Ben
 

Attachments

  • 2345654.JPG
    2345654.JPG
    18.3 KB · Views: 20
  • 21351350654.JPG
    21351350654.JPG
    14.7 KB · Views: 22
  • 321321312321.JPG
    321321312321.JPG
    99.3 KB · Views: 23
  • Capture.JPG
    Capture.JPG
    15.6 KB · Views: 29

My Computer

System One

  • Manufacturer/Model
    Dell
    CPU
    Intel(R) Celeron(R) CPU 420 @1.60 GHz
    Motherboard
    Dell Inspion 530 Default
    Memory
    PNY 4GB 240-Pin SDRAM DDR2 800 (PC2 6400) Dual Channel
    Graphics Card(s)
    ATI Radeon HD 2400 PRO
    Sound Card
    Realtek HD Audio
    Monitor(s) Displays
    Gateway PnP Monitor
    Screen Resolution
    1024x768 @ 75 Hz
    Hard Drives
    Seagate 250G ATA SATA-II
    Case
    Dell Inspiron 530
    Cooling
    None
    Keyboard
    Logitech EX100 Combo
    Mouse
    Logitech EX100 Combo
    Internet Speed
    100 MB/s
Hi ben ,

Looks like that's it . The Windows Defender Software Explorer shows a registry entry in the right hand pane - have a look and see if you can delete it

ANTIVIRUS2009 2008-11-13_231452.jpg

let us know how you get on

SIW2
 

My Computers

System One System Two

  • Operating System
    Vista
    CPU
    Intel E8400
    Motherboard
    ASRock1333-GLAN R2.0
    Memory
    4gb DDR2 800
    Graphics Card(s)
    nvidia 9500GT 1gb
  • Operating System
    win7/vista
    CPU
    intel i5-8400
    Motherboard
    gigabyte b365m ds3h
    Memory
    ballistix 2x8gb 3200
SIW2 and everyone else Thank you all so much for this!
We have offically stopped this horrible thing on my computer.
I hope you all will join me in vistax64's new security team. You all have done a wonderful job and i can not thank you all enough!
Thanks,
Ben
 

My Computer

System One

  • Manufacturer/Model
    Dell
    CPU
    Intel(R) Celeron(R) CPU 420 @1.60 GHz
    Motherboard
    Dell Inspion 530 Default
    Memory
    PNY 4GB 240-Pin SDRAM DDR2 800 (PC2 6400) Dual Channel
    Graphics Card(s)
    ATI Radeon HD 2400 PRO
    Sound Card
    Realtek HD Audio
    Monitor(s) Displays
    Gateway PnP Monitor
    Screen Resolution
    1024x768 @ 75 Hz
    Hard Drives
    Seagate 250G ATA SATA-II
    Case
    Dell Inspiron 530
    Cooling
    None
    Keyboard
    Logitech EX100 Combo
    Mouse
    Logitech EX100 Combo
    Internet Speed
    100 MB/s
Hi, ben

:party:that's good news :party:

as far as I can find out this is a new variant of a of the old AV2008 set of viruses it gets in as a "website Drive By" the only way I know of combating this type of infection is Firefox's No Script add-on. this particular beastie was only added to things such as malwarebytes in the last 48 hours so was basically a 0-day infection.

it may be an idea to change the title of your first post to something like "visfdw.exe virus infection" and mark it solved - just to help any others unfortunate enough to get infected

Have joined the Security group and posted my first info :geek::D I get several security related articles sent to me each day so will post any I thing are of general interest
 

My Computers

System One System Two

  • Operating System
    Windows 10 Pro x64 Latest Release Preview
    Monitor(s) Displays
    Acer G276HL 27", (DVi) + Samsung 39" HDTV (HDMI)
    Screen Resolution
    2 x 1920x1080 @50Hz
  • Manufacturer/Model
    Real World Computers (Custom by Me)
    CPU
    AMD FX8350 Vishera 8 Core @4GHz
    Motherboard
    Asus M5A78L-M USB3
    Memory
    32GB [4x8GB] DDR3 1600 MHz
    Graphics card(s)
    Asus nVidia GTX750TI-OC-2GD5 (2GB DDR5)
    Sound Card
    ASUS Xoner DG + SPDIF to 5.1 System + HDMI
    Monitor(s) Displays
    Samsung 32" TV
    Screen Resolution
    1920 x 1080
    Hard Drives
    Internal
    Crucial CT256MX100SSD1 256GB SSD,
    Seagate ST2000DM001-1CH1 2TB,

    External (USB3)
    Seagate Backup+ Hub BK SCSI Disk 8TB
    2.5/3.5 Hot Swap Cradle, USB3 + eSata (client HDDs)
    NAS 4TB
    PSU
    Aerocool Templarius Imperator 750W 80+ Silver
    Case
    AeroCool X-Warrior Red Devil Tower
    Cooling
    Hyper103 CPU, Rear 120mm, Front 2x120mm, Side 2x120mm
    Internet Speed
    68 MB Down 18.5 MB Up
    Other Info
    Six Sensor Auto / Manual Digital cooling (Fan) control with Touch control Panel
Barman58,
I am going to post a link in our Security Group to this forum and also inform Brink so he could possibly write a new tutorial on how to defeat this insanly huge threat!
Thanks yall soo much,
Ben

Hi, ben

:party:that's good news :party:

as far as I can find out this is a new variant of a of the old AV2008 set of viruses it gets in as a "website Drive By" the only way I know of combating this type of infection is Firefox's No Script add-on. this particular beastie was only added to things such as malwarebytes in the last 48 hours so was basically a 0-day infection.

it may be an idea to change the title of your first post to something like "visfdw.exe virus infection" and mark it solved - just to help any others unfortunate enough to get infected

Have joined the Security group and posted my first info :geek::D I get several security related articles sent to me each day so will post any I thing are of general interest
 

My Computer

System One

  • Manufacturer/Model
    Dell
    CPU
    Intel(R) Celeron(R) CPU 420 @1.60 GHz
    Motherboard
    Dell Inspion 530 Default
    Memory
    PNY 4GB 240-Pin SDRAM DDR2 800 (PC2 6400) Dual Channel
    Graphics Card(s)
    ATI Radeon HD 2400 PRO
    Sound Card
    Realtek HD Audio
    Monitor(s) Displays
    Gateway PnP Monitor
    Screen Resolution
    1024x768 @ 75 Hz
    Hard Drives
    Seagate 250G ATA SATA-II
    Case
    Dell Inspiron 530
    Cooling
    None
    Keyboard
    Logitech EX100 Combo
    Mouse
    Logitech EX100 Combo
    Internet Speed
    100 MB/s
Back
Top