Main Restorations Software Audio/Jukebox/MP3 Everything Else Buy/Sell/Trade
Project Announcements Monitor/Video GroovyMAME Merit/JVL Touchscreen Meet Up Retail Vendors
Driving & Racing Woodworking Software Support Forums Consoles Project Arcade Reviews
Automated Projects Artwork Frontend Support Forums Pinball Forum Discussion Old Boards
Raspberry Pi & Dev Board controls.dat Linux Miscellaneous Arcade Wiki Discussion Old Archives
Lightguns Arcade1Up Try the site in https mode Site News

Unread posts | New Replies | Recent posts | Rules | Chatroom | Wiki | File Repository | RSS | Submit news

  

Author Topic: I've got a virus/trojan/worm I can't lock down. Suggestions?  (Read 2589 times)

0 Members and 1 Guest are viewing this topic.

quarterback

  • King Of The Night Time World!
  • Trade Count: (+6)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 3089
  • Last login:February 26, 2025, 12:22:43 pm
I've got a virus/trojan/worm I can't lock down. Suggestions?
« on: September 24, 2005, 07:58:04 pm »
I used to have some little program that would let me see (and disable) everything that would start automatically when WinXP boots up.

It had sections for things that are in your registry, things that are in your startup folder and things in .ini files.
« Last Edit: September 24, 2005, 09:50:58 pm by quarterback »
No crap, don't put your kids in a real fridge.
-- Chad Tower

Mr-Megalo

  • Trade Count: (0)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 315
  • Last login:July 13, 2006, 08:36:28 am
  • Piano fingered Capcom Addict
Re: I've got a virus/trojan/worm, quick question
« Reply #1 on: September 24, 2005, 08:00:21 pm »
I think you may mean MSCONFIG

start>Run type MSCONFIG


edit:might be best to do it in safe mode - hit F8 when your machine starting up and choose safe mode

quarterback

  • King Of The Night Time World!
  • Trade Count: (+6)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 3089
  • Last login:February 26, 2025, 12:22:43 pm
Re: I've got a virus/trojan/worm, quick question
« Reply #2 on: September 24, 2005, 08:01:01 pm »
That's it!

Thanks.  I thought it was around here somewhere.

Thanks

I think you may mean MSCONFIG

start>Run type MSCONFIG


No crap, don't put your kids in a real fridge.
-- Chad Tower

Mr-Megalo

  • Trade Count: (0)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 315
  • Last login:July 13, 2006, 08:36:28 am
  • Piano fingered Capcom Addict
Re: I've got a virus/trojan/worm, quick question
« Reply #3 on: September 24, 2005, 08:02:04 pm »
your welcome - hope you get it sorted, trojans/Virii are a pain in a Windows users --I'm attempting to get by the auto-censor and should be beaten after I re-read the rules--

quarterback

  • King Of The Night Time World!
  • Trade Count: (+6)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 3089
  • Last login:February 26, 2025, 12:22:43 pm
Re: I've got a virus/trojan/worm, quick question
« Reply #4 on: September 24, 2005, 09:48:57 pm »
And this one is definitely a pain.
No crap, don't put your kids in a real fridge.
-- Chad Tower

quarterback

  • King Of The Night Time World!
  • Trade Count: (+6)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 3089
  • Last login:February 26, 2025, 12:22:43 pm
Re: I've got a virus/trojan/worm I can't lock down. Suggestions?
« Reply #5 on: September 24, 2005, 09:51:44 pm »
I've updated the Subject line.   If anybody knows of an app that will track this thing down or clear it out, I'd appreciate it.
No crap, don't put your kids in a real fridge.
-- Chad Tower

Harry Potter

  • Smite-bait
  • Trade Count: (0)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 2844
  • Last login:May 27, 2024, 03:33:28 am
  • Sober until banned. Can post but still can't read.
Re: I've got a virus/trojan/worm I can't lock down. Suggestions?
« Reply #6 on: September 24, 2005, 10:23:49 pm »
Spybot maybe.
Now in a tasty new flavour.

MaximRecoil

  • Trade Count: (+1)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 1729
  • Last login:September 12, 2022, 09:50:44 pm
Re: I've got a virus/trojan/worm I can't lock down. Suggestions?
« Reply #7 on: September 24, 2005, 10:35:47 pm »
Try one of the online virus scans such as Trend Micro's House Call. Also, run Spybot Search & Destroy. A program called HiJackThis can take care of most anything, but you need to know what you are doing. Fortunately there are forums that you can post the HiJackThis log on and they can help you interpret it and tell you what to do.

Also, it might help if you post a screenshot of your Task Manager and Msconfig windows (and if you have XP SP2, in an IE browser window go to Tools > Internet Options > Progams > Manage Add-ons > Add-ons currently loaded in IE and get a screenshot of that too) here to see if anything stands out.

BTW, doesn't your firewall give you the name of the application that is trying to "phone home"? If not, get one that does such as Sygate Personal Firewall (there is a free version that is fine).

It is most likely an activeX dll. If you find out which one it is, you can usually just unregister the dll using regsvr32.exe with the /u switch and then delete the dll.
« Last Edit: September 25, 2005, 12:37:52 am by MaximRecoil »

M3talhead

  • Trade Count: (0)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 747
  • Last login:October 09, 2020, 07:35:12 pm
  • Dont let Donkey Kong use your toilet.......
Re: I've got a virus/trojan/worm I can't lock down. Suggestions?
« Reply #8 on: September 24, 2005, 10:45:45 pm »
Dont listen to any of them. They dont know what they're talking about. Just sell me your computer for $10 and I'll take care of it for you.
Signature tags are dumb.

quarterback

  • King Of The Night Time World!
  • Trade Count: (+6)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 3089
  • Last login:February 26, 2025, 12:22:43 pm
Re: I've got a virus/trojan/worm I can't lock down. Suggestions?
« Reply #9 on: September 25, 2005, 04:21:29 am »
Try one of the online virus scans such as Trend Micro's House Call. Also, run Spybot Search & Destroy.

Yeah, I had tried spybot but it didn't come up with anything. (I mention it above but I know I'm sometimes verbose :))

Quote
A program called HiJackThis can take care of most anything, but you need to know what you are doing. Fortunately there are forums that you can post the HiJackThis log on and they can help you interpret it and tell you what to do.

I've not tried HiJack This because it seems so freakin complicated, but I've seen people posting their logs, so maybe that's my next step.

Quote
BTW, doesn't your firewall give you the name of the application that is trying to "phone home"? If not, get one that does such as Sygate Personal Firewall (there is a free version that is fine).


Yeah, it's Windows Explorer that's trying to connect to the Russian site.  Since Windows Explorer is all tied in with everything else in Windows, it tough (for me, at least) to track down what's really at work.

Quote
It is most likely an activeX dll. If you find out which one it is, you can usually just unregister the dll using regsvr32.exe with the /u switch and then delete the dll.


Yeah, I'm assuming it was an ActiveX deal that started it all, but I'm not sure where to go from there.  The good news (I guess) is that I haven't heard from it since.  I've rebooted a couple times but, so far, my firewall (Outpost) hasn't alerted me to anything out of the ordinary.

Sigh.  Oh well, maybe HiJack This is in my future.
Thanks y'all
No crap, don't put your kids in a real fridge.
-- Chad Tower

MaximRecoil

  • Trade Count: (+1)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 1729
  • Last login:September 12, 2022, 09:50:44 pm
Re: I've got a virus/trojan/worm I can't lock down. Suggestions?
« Reply #10 on: September 25, 2005, 05:18:01 am »
Quote
Yeah, it's Windows Explorer that's trying to connect to the Russian site.
« Last Edit: September 25, 2005, 05:30:06 am by MaximRecoil »

missioncontrol

  • MC-Retro says Wot!
  • Trade Count: (+13)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 7855
  • Last login:November 06, 2024, 06:22:12 pm
Re: I've got a virus/trojan/worm I can't lock down. Suggestions?
« Reply #11 on: September 25, 2005, 10:46:57 am »
you did make sure to update your definitions before sunning ad-aware and your anti-Virus right???

abrannan

  • Trade Count: (0)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 858
  • Last login:July 25, 2012, 11:32:14 am
  • Building a cabinet in perpetuity since 2002
Re: I've got a virus/trojan/worm I can't lock down. Suggestions?
« Reply #12 on: September 25, 2005, 11:29:30 am »
Also, try some google searches on the domain that it's trying to connect to with additional words like virus and spyware.  You should be able to turn up some support forums where people say what they needed to kill it.  Also check the HKLM/Software/Microsoft/Windows/CurrentVersion/Run key, as that's likely where the startup programs are being run from.  Remove anything that isn't identifiable, and run a google search anything that looks like it may be a Windows component (a favorite hiding strategy of virus/spyware authors).  It's probably got some rootkit style components that are hiding it from spyware/virus scanners, so you need to be able to find and stop it from running first.
If no one feeds the trolls, we're just going to keep eating your goats.

shmokes

  • Just think of all the suffering in this world that could have been avoided had I just been a little better informed. :)
  • Trade Count: (0)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 10397
  • Last login:September 24, 2016, 06:50:42 pm
  • Don't tread on me.
    • Jake Moses
Re: I've got a virus/trojan/worm I can't lock down. Suggestions?
« Reply #13 on: September 25, 2005, 06:40:40 pm »
McAfee has a program called Stinger that will search for and remove many common worms.  It can be downloaded for free from their site.
Check out my website for in-depth reviews of children's books, games, and educational apps for the iPad:

Best Kid iPad Apps

hanelyp

  • Trade Count: (0)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 72
  • Last login:January 10, 2009, 11:08:19 pm
Re: I've got a virus/trojan/worm I can't lock down. Suggestions?
« Reply #14 on: September 25, 2005, 07:48:06 pm »
Use anything but internet explorer or you'll likely be reinfected.  If you must use that browser, up the security settings.  Same goes for outlook.

If a parasite program (or popup code in a web page)  is trying to contact a site by name, an entry in you HOSTS file (somewhere under your windows directory) can block it.

127.0.0.1   trouble.site

if adaware, spybot S&D, and a good virus scan all find nothing, I don't know what will find the infection.  I'm wondering if your problem might be in a web page you frequent.

quarterback

  • King Of The Night Time World!
  • Trade Count: (+6)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 3089
  • Last login:February 26, 2025, 12:22:43 pm
Re: I've got a virus/trojan/worm I can't lock down. Suggestions?
« Reply #15 on: September 25, 2005, 11:40:35 pm »

Definitely an ActiveX module which will be a dll. Do you have XP SP2? See what add-ons are currently loaded by IE and also what add-ons have previously been loaded by Windows like I described above.

I've got a bunch of them listed in there.
« Last Edit: September 25, 2005, 11:42:10 pm by quarterback »
No crap, don't put your kids in a real fridge.
-- Chad Tower

SOAPboy

  • Trade Count: (0)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 1778
  • Last login:August 01, 2009, 03:36:12 am
  • ..::GeeK::..
Re: I've got a virus/trojan/worm I can't lock down. Suggestions?
« Reply #16 on: September 26, 2005, 05:17:38 am »
Wow...

Suggesting Anti SPYWARE  Tools for viruses..

Highlighted the KEYWORD here

Best bet imo, Backup IMPORTANT files, Format..

Youll NEVER fully get rid of anything that hardcore, itll stick around, and something will trigger it again..


MajorHavoc

  • Trade Count: (0)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 114
  • Last login:December 04, 2015, 09:08:40 am
  • I want to build my own arcade controls!
Re: I've got a virus/trojan/worm I can't lock down. Suggestions?
« Reply #17 on: September 26, 2005, 07:47:24 am »
I know it's a PITA but get ahold of Hijack This.  Install it and go here http://housecall.trendmicro.com/housecall/start_corp.asp
run the online virus scan.  When that is complete, disconnect your cable modem or DSL or phone line, restart in safe mode and run spybot and adaware.  Now run HJT.  Save the results as a text file.   reenable your internet connection, restart and post it to any one of the many HJT assistance websites along with a description of your problem and the steps you've taken so far to isolate and identify the culprit.  If you are of a more independant bent, go over the HJT results.  Do a systematic search using yahoo or google to research each and every line of the HJT results.  This can be time consuming but it usually works for me.  Who knows, you may find a command line
CallRussia.exe  (kind of optimistic but it could happen).
If you are running XP you may be able to use to the goback feature but more and more of the newer virii get into the goback file and make it a useless effort.  Am I an expert virus hunter?  No!  Merely the parent of a teenager who has never met  a download she didn't like   ;)

Good luck
Mike

Captain_Dingo

  • Trade Count: (0)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 65
  • Last login:November 28, 2018, 05:57:32 pm
Re: I've got a virus/trojan/worm I can't lock down. Suggestions?
« Reply #18 on: September 26, 2005, 09:38:08 am »
quarterback:

You might have one of the many trojans that infects your wininet.dll.  I found it was able to hide from most active scans (adaware, ewido, spybot, etc.), especially in safe mode where I was booting with no networking.

Search for a tool called smitRem.exe, and another script called Silent Runners.vbs.  Both of these are run in safe mode, and helped me clean the last remnants of one of these PITA trojans.

I found references to these on some of the sites that had people posting HJT logs.

SirPoonga

  • Puck'em Up
  • Global Moderator
  • Trade Count: (+1)
  • Full Member
  • *****
  • Offline Offline
  • Posts: 8187
  • Last login:July 07, 2025, 08:16:26 pm
  • The Bears Still Suck!
Re: I've got a virus/trojan/worm I can't lock down. Suggestions?
« Reply #19 on: September 26, 2005, 02:03:27 pm »
I've got something on my PC that tries to contact some Russian website everytime I start my pc.  After my pc has been running for a while, all/half the programs in my tray will shut down and restart themselves and, simultaneously, Windows will try to connect with this website.
FYI, those two actions are probably not related.  Your explorer is probably rebooting for some odd reason and the Russian thing gets executed when that happens.

Hardware or software firewall?

quarterback

  • King Of The Night Time World!
  • Trade Count: (+6)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 3089
  • Last login:February 26, 2025, 12:22:43 pm
Re: I've got a virus/trojan/worm I can't lock down. Suggestions?
« Reply #20 on: September 26, 2005, 10:38:06 pm »
Thanks again for all the replies.  I've gotten some feedback on my HiJack This logs and I think I've got this thing beat.

FWIW, it looks like it was "Vundo", "Vundo.b" or probably some other variant (since none of the spyware or virus checkers could identify it)

http://securityresponse.symantec.com/avcenter/venc/data/trojan.vundo.b.html

What a freakin pita.
No crap, don't put your kids in a real fridge.
-- Chad Tower

HaRuMaN

  • Supreme Solder King
  • Global Moderator
  • Trade Count: (+45)
  • Full Member
  • *****
  • Offline Offline
  • Posts: 10328
  • Last login:July 03, 2025, 05:20:15 pm
  • boom
    • Arcade Madness
Re: I've got a virus/trojan/worm I can't lock down. Suggestions?
« Reply #21 on: September 27, 2005, 05:30:04 am »
Quit downloading pr0n/warez and you'll be fine.   ;)

quarterback

  • King Of The Night Time World!
  • Trade Count: (+6)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 3089
  • Last login:February 26, 2025, 12:22:43 pm
Re: I've got a virus/trojan/worm I can't lock down. Suggestions?
« Reply #22 on: September 27, 2005, 11:19:46 am »
Quit downloading pr0n/warez and you'll be fine.
No crap, don't put your kids in a real fridge.
-- Chad Tower