System infected with a Virus

vasujain

New member
Local time
2:25 AM
Messages
69
Location
NCR,India
I am using an AV "nod32 v3 Full Version"
and since last 3-4 years i hadnt ever had any virus attack on my pc/lapy.
few days ago i used flashdrive of a friend ofmine for formating and since then my lapy catched a virus from it.

Exactly what it did was

all folders in my data drives (g h) were hidden and i could see them only when i unchecked "show operating system files " in folder options.

still i coudnt make them visible folders.

on later research i found each folder has a msocache folder with 5 files. "e,g,ghost.mp3,,ghost2.bmp"
i deleted them all but still not able to restore my pc back to health.
also tried using latest update and versions of nod32,avast,winsword to get rid of that but no relief.
 

Attachments

  • Ghost2 [].jpg
    Ghost2 [].jpg
    8 KB · Views: 240
Last edited by a moderator:

My Computer My Computer

At a glance

Windows 7 RC ,Windows Vista Ultimate ,Windows...Core 2 Duo 2.4 Ghz4 GB Ram
OS
Windows 7 RC ,Windows Vista Ultimate ,Windows XP SP3,Ubuntu 8.01
CPU
Core 2 Duo 2.4 Ghz
Motherboard
Intel 945 G
Memory
4 GB Ram
Hard Drives
WD SATA 250 GB
Hitachi SATA 80 GB

My Computer My Computer

At a glance

Windows XPIntel Celeron ULV (max 900 mhz; set to 630 mhz)1 GB DDR2Intel GMA 900 64 MB
Computer Manufacturer/Model Number
Asus EEE PC 900HD
OS
Windows XP
CPU
Intel Celeron ULV (max 900 mhz; set to 630 mhz)
Memory
1 GB DDR2
Graphics Card(s)
Intel GMA 900 64 MB
Sound Card
Realtek HD Audio
Monitor(s) Displays
8.9 inch LED backlight display
Screen Resolution
1024 by 600
Hard Drives
160 GB
PSU
35 watt
Keyboard
just fine
Mouse
multi-touch touchpad
Internet Speed
slow
Other Info
Using a netbook currently for travel. Also own a Dell 755 and a T500 and a Toshiba P105.
it looks like but it aint.....i have searched about this on net and found it to be win32.sality

and what about my all folders getting hidden...i have no way to restore them back
 

My Computer My Computer

At a glance

Windows 7 RC ,Windows Vista Ultimate ,Windows...Core 2 Duo 2.4 Ghz4 GB Ram
OS
Windows 7 RC ,Windows Vista Ultimate ,Windows XP SP3,Ubuntu 8.01
CPU
Core 2 Duo 2.4 Ghz
Motherboard
Intel 945 G
Memory
4 GB Ram
Hard Drives
WD SATA 250 GB
Hitachi SATA 80 GB

My Computer My Computer

At a glance

W7 RTM Ultimate x64Intel Q8400 @ 2.66GHZ4GB DDR2-800Gainward GTS 450 GLH 1GB Edition
Computer Manufacturer/Model Number
Custom Build
OS
W7 RTM Ultimate x64
CPU
Intel Q8400 @ 2.66GHZ
Motherboard
Gigabyte GA-EG45M-UD2H
Memory
4GB DDR2-800
Graphics Card(s)
Gainward GTS 450 GLH 1GB Edition
Sound Card
Integrated 8 Channel
Monitor(s) Displays
AOC 23.6 Inch Widescreen LCD
Screen Resolution
1920x1080
Hard Drives
Seagate 500GB Internal
Western Digital 1TB Internal

Hitachi 1TB External
PSU
Apevia Java Power 500W
Case
Cooler Master HAF 922 Black
Cooling
Stock Intel CPU Fan
Keyboard
HP SK-2960 Multimedia Keyboard
Mouse
Logitech M350 Wireless Gaming Mouse
Internet Speed
1.5MB
no use yet...the problem persists... :(
 

My Computer My Computer

At a glance

Windows 7 RC ,Windows Vista Ultimate ,Windows...Core 2 Duo 2.4 Ghz4 GB Ram
OS
Windows 7 RC ,Windows Vista Ultimate ,Windows XP SP3,Ubuntu 8.01
CPU
Core 2 Duo 2.4 Ghz
Motherboard
Intel 945 G
Memory
4 GB Ram
Hard Drives
WD SATA 250 GB
Hitachi SATA 80 GB

My Computer My Computer

At a glance

Windows 7 Ultimate x86AMD Sempron 3600+ATI Radeon Xpress 1150
Computer Manufacturer/Model Number
Dell Vostro 1000
OS
Windows 7 Ultimate x86
CPU
AMD Sempron 3600+
Graphics Card(s)
ATI Radeon Xpress 1150
Monitor(s) Displays
Generic PnP Monitor
Screen Resolution
1200 x 800
Hard Drives
WD Scorpio Blue 500 GB (WD5000BEVT)
Mouse
Logitech V320 Cordless Optical Mouse
or just update eset to v4 ;)

theres been ton of module updates with eset v4 and It should be able to remove infection.

eset 3 was good but not as good as v4 ;P


but theres nothing you can do with the damage(hidden files)

just make sure you don't get infected next time :P


more info of the virus.

Eset - Win32/Sality.NAR
http://www.eset.eu/buxus/generate_page.php?page_id=20180
http://www.eset.sk/encyclopaedia/sality_naj_virus_sality_q_sality_x_sality_u?lng=en

ps: eset has detected this virus since 2008 so if you were updated you should not be infected o.O

though I don't think sality does what your description says lol O.O;
 

My Computer My Computer

At a glance

Windows 7 32bit RTM
OS
Windows 7 32bit RTM
Or just format and say goodbye forever!
 

My Computer My Computer

At a glance

Windows 7 Ultimate x64.i5 760 @ 4.2Ghz. 1.18v4g Corsair xms3 ddr3, 1600Mhz.Gigabyte GTX-560Ti soc edition
Computer Manufacturer/Model Number
Custom Build.
OS
Windows 7 Ultimate x64.
CPU
i5 760 @ 4.2Ghz. 1.18v
Motherboard
Gigabyte - H55M-USB3
Memory
4g Corsair xms3 ddr3, 1600Mhz.
Graphics Card(s)
Gigabyte GTX-560Ti soc edition
Sound Card
Asus Xonar Dx - Logitech Z5500.
Monitor(s) Displays
Acer 22" LCD Wide screen 1680-1050 -Samsung 42" Plasma....
Screen Resolution
1680/1050 -----1920/1080p.
Hard Drives
2x 2TB Seagate Go Flex,
1x 1TB Seagate,
1x 640WD Black,
x16 Gig sandisc flash drive,
1x8Gig sandisc flash drive.
PSU
XigmaTek 80plus NRP-PC702 - 700w dual 30a.
Case
Venus Gamers Midi Tower Case with LED Display
Cooling
Arctic Freezer 7 Pro Rev 2... x2 Arctic F8 case fans........
Keyboard
Logitech G15-v2 Gaming.
Mouse
Microsoft Sidewinder X8.
Internet Speed
Virgin Media - 50mb down- 8mb up.
Other Info
x2 Xbox 360 wireless controllers...

Dual layer optical disc drive...

Chrome 79million

A.V = MSE
if sality doesnt do what i have been telling then which virus is this....
i tried eset v4 too...and i hv latest definitions of my eset still the virus came..although all new folders i m having are not hidden like dat....
 

My Computer My Computer

At a glance

Windows 7 RC ,Windows Vista Ultimate ,Windows...Core 2 Duo 2.4 Ghz4 GB Ram
OS
Windows 7 RC ,Windows Vista Ultimate ,Windows XP SP3,Ubuntu 8.01
CPU
Core 2 Duo 2.4 Ghz
Motherboard
Intel 945 G
Memory
4 GB Ram
Hard Drives
WD SATA 250 GB
Hitachi SATA 80 GB
Try Norton Internet Security 2009 ...;)
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
i have tried a variety of av and security solutions...let me try norton as well...
 

My Computer My Computer

At a glance

Windows 7 RC ,Windows Vista Ultimate ,Windows...Core 2 Duo 2.4 Ghz4 GB Ram
OS
Windows 7 RC ,Windows Vista Ultimate ,Windows XP SP3,Ubuntu 8.01
CPU
Core 2 Duo 2.4 Ghz
Motherboard
Intel 945 G
Memory
4 GB Ram
Hard Drives
WD SATA 250 GB
Hitachi SATA 80 GB
This infection is a password stealer. Your "critical" identity is being harvested and sent to another domain.
Please read this article:
Win32/Sality Family - CA

Since you are Beta testing Win7, my advice would be to do a clean install of the OS.
****Before you do that tho', find a known clean computer, and change all your passwords. If you have used any online banking or credit cards with the infected computer, be sure to notify your bank.
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32bit SP1Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz4 GBATI Radeon HD 2600 Pro
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
To be honest with you, I'd be more concerned of the fact that you "catched" a virus, I'll pray for you meng :(
 

My Computer My Computer

At a glance

Microsoft Windows 7 x64 UltimateIntel Core i7 720M 1.6-2.8GHz6GB DDR3 1066MHz RAMNVIDIA GeForce 230M
Computer Manufacturer/Model Number
HP dv7-3080us
OS
Microsoft Windows 7 x64 Ultimate
CPU
Intel Core i7 720M 1.6-2.8GHz
Motherboard
HP dv7-3080us
Memory
6GB DDR3 1066MHz RAM
Graphics Card(s)
NVIDIA GeForce 230M
Sound Card
HP dv7-3080us
Monitor(s) Displays
17.3" BrightView LED/LCD (1650x900) ViewSonic 22" LCD 1080p
Screen Resolution
17.3" BrightView LED/LCD (1650x900) ViewSonic 22" LCD 1080p
Hard Drives
500GB OS Drive
100GB OS Partition
400GB Media Partition

640GB Secondary Drive for Movies
PSU
HP dv7-3080us
Case
HP dv7-3080us
Cooling
HP dv7-3080us
Keyboard
HP dv7-3080us - Microsoft Wireless Keyboard 6000 v3.0
Mouse
Logitech G7
This infection is a password stealer. Your "critical" identity is being harvested and sent to another domain.
Please read this article:
Win32/Sality Family - CA

Since you are Beta testing Win7, my advice would be to do a clean install of the OS.
****Before you do that tho', find a known clean computer, and change all your passwords. If you have used any online banking or credit cards with the infected computer, be sure to notify your bank.

i am not even sure if it is the one...this virus goes undetected throughout all the antiviruses i have tried mcafee norton avast stinger truesword etc....

i cn do the formatting but hw can i know this is the win32.sality

i came 2 know it is win32.sality coz when i googled the keywords in the ghost2.bmp i found a site mentioning it 2 b win32.sality

my symptoms are the unique one.

and can u please telll more symptoms of win32,sality?
and do teme if there is any possible way 2 revert the changes back...hidden folders to normal
 

My Computer My Computer

At a glance

Windows 7 RC ,Windows Vista Ultimate ,Windows...Core 2 Duo 2.4 Ghz4 GB Ram
OS
Windows 7 RC ,Windows Vista Ultimate ,Windows XP SP3,Ubuntu 8.01
CPU
Core 2 Duo 2.4 Ghz
Motherboard
Intel 945 G
Memory
4 GB Ram
Hard Drives
WD SATA 250 GB
Hitachi SATA 80 GB
- Which operating system does your laptop run on ?



»Download and install Malwarebytes Anti-Malware and run it on safe mode.

»Run a full system scan, after it has finished scanning remove all infections when prompted.

»Boot windows normal mode.
 

My Computer My Computer

At a glance

Windows 7 Home Premium SP1 64-bitIntel™ Core™ i7 920 2.66 ghzOCZ 6gb (triple 2gb) ddr3-1333 (Gold Edition)Nvidia 9800 GT 1GB - x2 SLI
OS
Windows 7 Home Premium SP1 64-bit
CPU
Intel™ Core™ i7 920 2.66 ghz
Motherboard
Asus P6T Deluxe V2
Memory
OCZ 6gb (triple 2gb) ddr3-1333 (Gold Edition)
Graphics Card(s)
Nvidia 9800 GT 1GB - x2 SLI
Sound Card
On board
Monitor(s) Displays
19" LCD Wide Screen / Built-in TV Tuner
Screen Resolution
1440x900
Hard Drives
250 GB Maxtor
+
1 TB Seagate
PSU
Corsair GX 800 (800watts)
Case
Thermaltake Level 10 GT
Cooling
Antec Kuhler 920
Mouse
CM Storm Sentinel Advanced
Internet Speed
1MBps
here is the screenshot which explains the problem deeper...and i am using windows 7 Rc
 

Attachments

  • virus_infect [].jpg
    virus_infect [].jpg
    14.3 KB · Views: 59

My Computer My Computer

At a glance

Windows 7 RC ,Windows Vista Ultimate ,Windows...Core 2 Duo 2.4 Ghz4 GB Ram
OS
Windows 7 RC ,Windows Vista Ultimate ,Windows XP SP3,Ubuntu 8.01
CPU
Core 2 Duo 2.4 Ghz
Motherboard
Intel 945 G
Memory
4 GB Ram
Hard Drives
WD SATA 250 GB
Hitachi SATA 80 GB
- Which operating system does your laptop run on ?



»Download and install Malwarebytes Anti-Malware and run it on safe mode.

»Run a full system scan, after it has finished scanning remove all infections when prompted.

»Boot windows normal mode.
i hv done that as wll also i hv run a boot time scan by avast...but still now i hvnt found anything of much help
 

My Computer My Computer

At a glance

Windows 7 RC ,Windows Vista Ultimate ,Windows...Core 2 Duo 2.4 Ghz4 GB Ram
OS
Windows 7 RC ,Windows Vista Ultimate ,Windows XP SP3,Ubuntu 8.01
CPU
Core 2 Duo 2.4 Ghz
Motherboard
Intel 945 G
Memory
4 GB Ram
Hard Drives
WD SATA 250 GB
Hitachi SATA 80 GB

My Computer My Computer

At a glance

Windows 7 Home Premium SP1 64-bitIntel™ Core™ i7 920 2.66 ghzOCZ 6gb (triple 2gb) ddr3-1333 (Gold Edition)Nvidia 9800 GT 1GB - x2 SLI
OS
Windows 7 Home Premium SP1 64-bit
CPU
Intel™ Core™ i7 920 2.66 ghz
Motherboard
Asus P6T Deluxe V2
Memory
OCZ 6gb (triple 2gb) ddr3-1333 (Gold Edition)
Graphics Card(s)
Nvidia 9800 GT 1GB - x2 SLI
Sound Card
On board
Monitor(s) Displays
19" LCD Wide Screen / Built-in TV Tuner
Screen Resolution
1440x900
Hard Drives
250 GB Maxtor
+
1 TB Seagate
PSU
Corsair GX 800 (800watts)
Case
Thermaltake Level 10 GT
Cooling
Antec Kuhler 920
Mouse
CM Storm Sentinel Advanced
Internet Speed
1MBps
ohk i wud try that too...any clue about the symptoms i told...and hv u checked out the screenshot that gives detailed description of my problem
 

My Computer My Computer

At a glance

Windows 7 RC ,Windows Vista Ultimate ,Windows...Core 2 Duo 2.4 Ghz4 GB Ram
OS
Windows 7 RC ,Windows Vista Ultimate ,Windows XP SP3,Ubuntu 8.01
CPU
Core 2 Duo 2.4 Ghz
Motherboard
Intel 945 G
Memory
4 GB Ram
Hard Drives
WD SATA 250 GB
Hitachi SATA 80 GB
I'm sorry but I haven't encountered anything like that one before. :(
 

My Computer My Computer

At a glance

Windows 7 Home Premium SP1 64-bitIntel™ Core™ i7 920 2.66 ghzOCZ 6gb (triple 2gb) ddr3-1333 (Gold Edition)Nvidia 9800 GT 1GB - x2 SLI
OS
Windows 7 Home Premium SP1 64-bit
CPU
Intel™ Core™ i7 920 2.66 ghz
Motherboard
Asus P6T Deluxe V2
Memory
OCZ 6gb (triple 2gb) ddr3-1333 (Gold Edition)
Graphics Card(s)
Nvidia 9800 GT 1GB - x2 SLI
Sound Card
On board
Monitor(s) Displays
19" LCD Wide Screen / Built-in TV Tuner
Screen Resolution
1440x900
Hard Drives
250 GB Maxtor
+
1 TB Seagate
PSU
Corsair GX 800 (800watts)
Case
Thermaltake Level 10 GT
Cooling
Antec Kuhler 920
Mouse
CM Storm Sentinel Advanced
Internet Speed
1MBps
Back
Top