Solved Most malicious virus I have ever seen/had

Timford

Member
I have a HP-mini-note hence the avatar xD.

Today I downloaded a demo off torrents and usually I am a very safe person on the internet and have never had the need of virus software, I feel a bit of a fool now but i'm pretty sure this malware could of got passed my avast anyway.

Some things it's done/doing:

  • Blocked use of Task Manager
  • Blocked use of Regedit
  • Blocked use of display control
  • Many pop up's asking for me to download software to stop "malicious software"!!!!!
  • When I finally got taskmanager, regedit and display control working from some program like gpedit and changing the privalages.
  • Controlling my firefox use, not allowing any access to a potential threat to the malware being removed, such as letting me visit forums, google etc. but avg, avast, spybot sites are all blocked
  • Changed clock to VIRUS ALERT. Now fixed
  • Slowed my computer down beyond belief
  • Opening iexploder all the time
  • This is doing my head in, and seen as I can't get in to safe mode because it BSOD's and says something about my graphics card not working yet it works in full mode.
  • Putting gay porn icons on my desktop :(
I refuse to re-install windows again as well. I need this laptop for everyday use. Anyone an expert in malware removal on XP on this forum? I would use smitrem if I had access to safe mode.
 

My Computer

I think your computer is to far infected, you safest route would be to reinstall.
 

My Computer

System One

  • Manufacturer/Model
    HP Compaq Presario/SR5113WM
    CPU
    AMD Athlon 64 X2 3600+ 1.9Ghz
    Motherboard
    Asus M2N68-LA
    Memory
    PNY Optima Memory DDR2 2GB 2x1 kit
    Graphics Card(s)
    PNY Nvidia 8400 GS 256MB
    Sound Card
    On board RealTek
    Monitor(s) Displays
    Acer X163W LCD
    Screen Resolution
    1366x768
    Hard Drives
    Western Digital 160 GB SATA 3G (3.0Gb/sec)
    7200 rpm
    Western Digital 160 GB IDE
    PSU
    Dynex 400w
    Case
    Nothin Special
    Cooling
    Stock
    Keyboard
    Standard 102 key with volume and sleep buttons
    Mouse
    Wireless Logitech LX7
    Internet Speed
    Comcrap 10mb cable
    Other Info
    Insignia 2.1 speakers, wireless Xbox 360 controller w/plug n play charger, Belkin wireless G + mimo usb network adapter.
I think I could do it If it is handled one part at a time though, I can get back my taks manager privelages with little trouble, I have got rid of the gay porn icons, I have restored the clock and got a standard XP wallpaper and theme on there where as before it was just a "you have been infected wallpaper" and a classic windows theme. It will all come together hopefully.

I think a lot of the things that will fix it are in the registry, but seen as i'm not a registry "pro" I am not sure as to what should and shouldn't be there. These pop ups are to do with it, I have analyzed the task manager and can't see anything out of the ordinary, killed a few I have found suspicious but they return quickly. I will keep working on it for the week, If I don't have it fixed by friday I will re-install.

I like a challenge :P
 

My Computer

download superanti spyware & do a full scan to see & check if it picks up any infections.
 

My Computer

System One

  • CPU
    T4200 Intel
    Memory
    2 X 1GB DDR2
    Graphics Card(s)
    Intel Integrated
    Hard Drives
    1 X 250GB 7200RPM

My Computer

System One

  • Manufacturer/Model
    * BFK Customs *
    CPU
    Intel C2Q 9550 Yorkfield
    Motherboard
    ASUS P5Q Pro
    Memory
    8GB Dominator 8500C5D
    Graphics Card(s)
    XFX ATI 1GB 4870 XXX
    Sound Card
    Realtek HD 7-1
    Monitor(s) Displays
    1x 47" LCD HDMI & 2x 26" LCD HDMI
    Screen Resolution
    1920x1080P & 1920x1200
    Hard Drives
    2x 500GB 7200RPM 32MB Cache WD Caviar Black
    PSU
    Corsair 620HX
    Case
    CM Cosmos RC-1000
    Cooling
    Tuniq Tower 120, 2x 140mm and 3x 120mm case fans
    Keyboard
    HP Enhansed Multimedia
    Mouse
    Razer Diamondback 3G
    Internet Speed
    18.6Mb/s
    Other Info
    My First Build ;)
Hey download Malware Bytes Anti Malware and perform a full scan. Update the software before scan. download link:

Malwarebytes.org
 
Last edited by a moderator:

My Computer

System One

  • Manufacturer/Model
    Compaq
    CPU
    intel core 2 duo T 5550 @ 1.83 MHz
    Motherboard
    intel 965 chipset family
    Memory
    2 GB DDR 2 SD RAM @ 667 MHz
    Graphics Card(s)
    On board upto 358 MB RAM
    Sound Card
    Onboard
    Monitor(s) Displays
    15"
    Hard Drives
    160 GB WDC
I put a few hours into it and it's been one heck of a ride, I'm pretty sure I could own just about any malware problem now.

I removed the registry keys it inserted which came back after restarts however, managed to get my task manager back and found some dodgey exe files located them by win+r c:\ to get me on filemanager, searched the computer for each exe. I found the exe's all had a relation in the name for the most of them it was j0e. I searched this and removed every file. Found some DLL files I am not farmiliar with and deleted them after a quick google check on them. By now I had all rights back and my start menu was displaying properly. Then finally a qucik CCleaner and Avast! on boot and it was back up to full speed again. For the most part it was a manual fix. Limited amounts of software was used. Firefox also searches propperly now.
 

My Computer

Hello again.

I'm glad you're getting it straightened out.

You might want to give this a run.

The home of Spybot-S&D!

Continue to keep us informed!









Later :shock: Ted
 
Last edited by a moderator:

My Computer

System One

  • Manufacturer/Model
    * BFK Customs *
    CPU
    Intel C2Q 9550 Yorkfield
    Motherboard
    ASUS P5Q Pro
    Memory
    8GB Dominator 8500C5D
    Graphics Card(s)
    XFX ATI 1GB 4870 XXX
    Sound Card
    Realtek HD 7-1
    Monitor(s) Displays
    1x 47" LCD HDMI & 2x 26" LCD HDMI
    Screen Resolution
    1920x1080P & 1920x1200
    Hard Drives
    2x 500GB 7200RPM 32MB Cache WD Caviar Black
    PSU
    Corsair 620HX
    Case
    CM Cosmos RC-1000
    Cooling
    Tuniq Tower 120, 2x 140mm and 3x 120mm case fans
    Keyboard
    HP Enhansed Multimedia
    Mouse
    Razer Diamondback 3G
    Internet Speed
    18.6Mb/s
    Other Info
    My First Build ;)
Nice job Timford I would have just formatted and reinstall my os.
 

My Computer

System One

  • Manufacturer/Model
    HP Compaq Presario/SR5113WM
    CPU
    AMD Athlon 64 X2 3600+ 1.9Ghz
    Motherboard
    Asus M2N68-LA
    Memory
    PNY Optima Memory DDR2 2GB 2x1 kit
    Graphics Card(s)
    PNY Nvidia 8400 GS 256MB
    Sound Card
    On board RealTek
    Monitor(s) Displays
    Acer X163W LCD
    Screen Resolution
    1366x768
    Hard Drives
    Western Digital 160 GB SATA 3G (3.0Gb/sec)
    7200 rpm
    Western Digital 160 GB IDE
    PSU
    Dynex 400w
    Case
    Nothin Special
    Cooling
    Stock
    Keyboard
    Standard 102 key with volume and sleep buttons
    Mouse
    Wireless Logitech LX7
    Internet Speed
    Comcrap 10mb cable
    Other Info
    Insignia 2.1 speakers, wireless Xbox 360 controller w/plug n play charger, Belkin wireless G + mimo usb network adapter.
I find it more interesting my way xD. You learn things you didn't know before, and I hate reinstalling everything after a reinstall.


I know what you mean. Nothing like a problem to enforce education. It usually takes me a month to get around to re-installing/tweaking every little thing. There's always an element of 'do it later, forget, remember, do it later....)

As for the virus, at least it was 'nice' enough to give you a wallpaper telling you your infected ;) Good to hear you're winning the battle.
 

My Computer

System One

  • Manufacturer/Model
    Self Built
    CPU
    i7 3770K HT ON 4.7GHz
    Motherboard
    P8Z68 Deluxe Gen 3
    Memory
    8GB G.Skill Ripjaws X 2133mhz
    Graphics Card(s)
    2x Gigabyte GTX 670 OC WindForce SLI
    Sound Card
    X-FI Forte + ATH-AD900
    Monitor(s) Displays
    x2 Dell U2410 / 58" Samsung / "40 Sony
    Screen Resolution
    1920*1200 / 1920x1080
    Hard Drives
    2x Intel 520 240GB * Crucial M4 128GB * 2x Samsung F3 1TB (RAID 0) * 2x WD Caviar Blacks 2TB (RAID 0)
    PSU
    Corsair AX1200W
    Case
    Lian Li PC-V1020A
    Cooling
    NH-D14: 3x140mm Gelid Wing 14: Sunbeam Rheobus Extreme
    Keyboard
    Topre Realforce // Ducky Shine Cherry MX Black
    Mouse
    Razer Imperator + Thermaltake Theron
    Other Info
    Laptop Specs:
    Clevo Sager P170HM //
    17.3 Matte 1920x1200 //
    i7 2720QM // 8GB 1333mhz //
    Dedicated GTX 485M //
    240GB Intel 520 + 750GB + Blu-Ray //

    Samsung Story 2TB USB 3.0
Heh - I have learned almost all of my knowledge of computers just that way - I broke something and had to figure out how to fix it.

These days a full backup helps - a lot - but I install and uninstall so much stuff, including games (and demos) that every 6 months o so I go through the pains of a reinstall.

Glad you got yours back in working order. Now, backup, dangit!
 

My Computers

System One System Two

  • Operating System
    Windows 10 Pro X64 Insider Preview (Skip Ahead) latest build
    Manufacturer/Model
    The Beast Model V (homebrew)
    CPU
    Intel Core i7 965 EE @ 3.6 GHz
    Motherboard
    eVGA X58 Classified 3 (141-GT-E770-A1)
    Memory
    3 * Mushkin 998981 Redline Enhanced triple channel DDR3 4 GB CL7 DDR3 1600 MHz (PC3-12800)
    Graphics Card(s)
    eVGA GeForce GTX 970 SSC ACX 2.0 (04G-P4-3979-KB)
    Sound Card
    Realtek HD Audio (onboard)
    Monitor(s) Displays
    2 * Lenovo LT2323pwA Widescreeen
    Screen Resolution
    2 * 1920 x 1080
    Hard Drives
    SanDisk Ultra SDSSDHII-960G-G25 960 GB SATA III SSD (System)
    Crucial MX100 CT256MX100SSD1 256GB SATA III SSD (User Tree)
    2 * Seagate Barracuda 7200.12 ST31000528AS 1TB 7200 RPM SATA II Mech. HD
    Seagate ST1500DL001-9VT15L Barracuda 7200.12 1.5 TB S
    PSU
    Thermaltake Black Widow TX TR2 850W 80+ Bronze Semi-Mod ATX
    Case
    ThermalTake Level 10 GT (Black)
    Cooling
    Corsair H100 (CPU, dual 140 mm fans on radiator) + Air (2 *
    Keyboard
    Logitech G15 (gen 2)
    Mouse
    Logitech MX Master (shared)
    Internet Speed
    AT&T Lightspeed Gigabit duplex
  • Operating System
    Sabayon Linux (current, weekly updates, 5.1.x kernel)
    Manufacturer/Model
    Lenovo ThinkPad E545
    CPU
    AMD A6-5350M APU
    Motherboard
    Lenovo
    Memory
    8 GB
    Graphics card(s)
    Radeon HD (Embedded)
    Sound Card
    Conextant 20671 SmartAudio HD
    Monitor(s) Displays
    Lenovo 15" Matte
    Screen Resolution
    1680 * 1050
    Hard Drives
    INTEL Cherryvill 520 Series SSDSC2CW180A 180 GB SSD
    PSU
    Lenovo
    Case
    Lenovo
    Cooling
    Lenovo
    Mouse
    Logitech MX Master (shared) | Synaptics TouchPad
    Keyboard
    Lenovo
    Internet Speed
    AT&T LightSpeed Gigabit Duplex
I think I had the same virus you have and I was using AVG FREE at the time, downloaded the trial of live one care from microsoft and it removed it for me after a couple of reboots. I did uninstall it afterwards and now I am using avast and comodo never had any problems since
 

My Computer

System One

  • Manufacturer/Model
    HOME BREW
    CPU
    Core 2 E8500 3.16Ghz @ 4.05Ghz
    Motherboard
    EVGA NVIDIA NFORCE 750i SLI FTW
    Memory
    2x2Gb Patriot PC2-6400 LL
    Graphics Card(s)
    Inno3D GeForce GTX260 216 SP
    Monitor(s) Displays
    ASUS VW222U 22" 2ms Response time
    Screen Resolution
    1680x1050
    Hard Drives
    SATA 150GB
    SATA II 250GB
    USB IDE 300GB Ext.
    PSU
    HYTEC 600W & Thermaltake Toughpower Power Express 650W
    Case
    Thermaltake Armor LCS (Liquid Cooling System)
    Cooling
    Liquid Cooling System
    Keyboard
    Logitech G15 Gaming Keyboard
    Mouse
    Logitech G9 Gaming Mouse
Yes, I can relate as well, mine was a Cyper-Defense to scan for viruses. At lease I use a back up disk everynight as having the medium version of Norton. I would rather pay the 59.99 than have to pay for headaches and going w/o a computer for a couple of days.

Hope it is resolved sooner than later.
 

My Computer

Back
Top