A Nasty Virus

Copyright

New member
Member
VIP
Local time
1:02 PM
Messages
102
I have a nasty virus, and I need some advice of what to do. First of all, it won't go away, I've scanned with malwarebytes, and like 5 different AV scanners. For this reason I'm thinking it was more of a physical prank then a virus. Basically my user account got turned into a guest. The administrator account is disabled, I can't enable it, or do anything which requires administrator privileges. In safe mode, I can only login to my (guest) account. I'm not sure what to do, and I can't even backup my files, make a new partition, etc.
 

My Computer

Computer Manufacturer/Model Number
Dell Laptop Studio 1537
OS
Windows 7 x64 7229
CPU
Intel Core 2 Duo CPU T6400
Memory
4 GB
Graphics Card(s)
Mobile Intel 45 Chipset
Clean install? Barring that, you might need to create a boot disk. McAfee, Norton and others allow you to do this online.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build/Mod
OS
Windows 7 Home Premium x64
CPU
Intel QX9650 Extreme 4.0 GHz
Motherboard
ASUS Rampage Extreme Rev2
Memory
8GB (4x2) Corsair Dominator DDR3
Graphics Card(s)
2x Radeon R390X [8GB]
Sound Card
SupremeFX X-Fi
Monitor(s) Displays
Dell 2408WFP 26" Panel
Screen Resolution
1920x1200
Hard Drives
4x WD 2TB (8TB+ Total)
2x Crucial SSD 128GB (RAID-0)
1x LG Blu-ray read/write
1x Phillips LightScribe DVD read/write
PSU
Corsair HX1000
Case
CoolerMaster - Cosmos S
Cooling
Custom Liquid - 320mm rad w/ 3x 80mm fans, CPU/NB/SB Blocks
Keyboard
Logitech Illuminater Pro
Mouse
Logitech
Internet Speed
Fractional T1 - 125Mbps
Antivirus
ESET Security Suite / Microsoft Security Essentials
Browser
Cyberfox Intel x64
Other Info
OC'd to 5.0GHz @ 44c under full load
I really don't think it's a virus, as this computer isn't even connected to the internet. What other options can I try?
 

My Computer

Computer Manufacturer/Model Number
Dell Laptop Studio 1537
OS
Windows 7 x64 7229
CPU
Intel Core 2 Duo CPU T6400
Memory
4 GB
Graphics Card(s)
Mobile Intel 45 Chipset
Is admin account disabled by default (vista)?
I dont know if it will work from guest accnt but u can anable it by running a cmd window as admin and typing this:

net user administrator /active:yes

If you have another account with admin privledges u can use Offline NT Password & Registry Editor
to change the password on it.

Other than that...... Clean Load.
 

My Computer

OS
Windows 7 Ultimate x64 Retail RTM, Ubuntu 9.10
Is admin account disabled by default (vista)?
I dont know if it will work from guest accnt but u can anable it by running a cmd window as admin and typing this:

net user administrator /active:yes

If you have another account with admin privledges u can use Offline NT Password & Registry Editor
to change the password on it.

Other than that...... Clean Load.
I've tried both of those, I can't do anything, the only admin account is disabled.
 

My Computer

Computer Manufacturer/Model Number
Dell Laptop Studio 1537
OS
Windows 7 x64 7229
CPU
Intel Core 2 Duo CPU T6400
Memory
4 GB
Graphics Card(s)
Mobile Intel 45 Chipset
This is sounding like a potential rootkit based on some of the symptoms you've describe. You can try Sysinternal's Rootkit Revealer, in either free download or online scan modes. I'd run it live, especially if you can't get in as admin. Let us know how that works for you.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build/Mod
OS
Windows 7 Home Premium x64
CPU
Intel QX9650 Extreme 4.0 GHz
Motherboard
ASUS Rampage Extreme Rev2
Memory
8GB (4x2) Corsair Dominator DDR3
Graphics Card(s)
2x Radeon R390X [8GB]
Sound Card
SupremeFX X-Fi
Monitor(s) Displays
Dell 2408WFP 26" Panel
Screen Resolution
1920x1200
Hard Drives
4x WD 2TB (8TB+ Total)
2x Crucial SSD 128GB (RAID-0)
1x LG Blu-ray read/write
1x Phillips LightScribe DVD read/write
PSU
Corsair HX1000
Case
CoolerMaster - Cosmos S
Cooling
Custom Liquid - 320mm rad w/ 3x 80mm fans, CPU/NB/SB Blocks
Keyboard
Logitech Illuminater Pro
Mouse
Logitech
Internet Speed
Fractional T1 - 125Mbps
Antivirus
ESET Security Suite / Microsoft Security Essentials
Browser
Cyberfox Intel x64
Other Info
OC'd to 5.0GHz @ 44c under full load

My Computer

Computer Manufacturer/Model Number
Custom Build
OS
W7 RTM Ultimate x64
CPU
Intel Q8400 @ 2.66GHZ
Motherboard
Gigabyte GA-EG45M-UD2H
Memory
4GB DDR2-800
Graphics Card(s)
Gainward GTS 450 GLH 1GB Edition
Sound Card
Integrated 8 Channel
Monitor(s) Displays
AOC 23.6 Inch Widescreen LCD
Screen Resolution
1920x1080
Hard Drives
Seagate 500GB Internal
Western Digital 1TB Internal

Hitachi 1TB External
PSU
Apevia Java Power 500W
Case
Cooler Master HAF 922 Black
Cooling
Stock Intel CPU Fan
Keyboard
HP SK-2960 Multimedia Keyboard
Mouse
Logitech M350 Wireless Gaming Mouse
Internet Speed
1.5MB
What was the last item that you downloaded and installed? Did you use a flash drive?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Hi there
I don't know HOW your machine got infected or even what the virus is but there is only one decent way you can get this computer clean again.

1) Download from the net a LIVE CD of any OS that has a proper hard disk erase utility. You need a Live CD since the OS can't be written to by any infections lurking in specific Disk sectors when you launch a program.

2) Run the erase utility. This should erase THE ENTIRE DISK (if you've partitioned it erase ALL partitions / logical drives). This ERASE should do a physical write to EVERY SECTOR ON THE DISK of binary zeros and preferably set to run for 3 or 4 passes. This should flush out ANY virus lurking in "un-erased" areas of your Disk.

Note a Windows or an Operating system delete doesn't actually physically delete data - it just marks that area on the disk is available for use again - and it could be a LONG time before new data overwites what was on the disk before. That's how these "Undelete" and "Unformat" type of utilities work.

3) Now re-install your OS from a KNOWN VIRUS FREE COPY. Install your AV software and then your applications checking carefully that they are all clean.

NOTE NOTE NOTE it's 100% important you run the Secure Erase type utility on your ENTIRE DISK(S). This - apart from buying a totally new set of disks is the only reasonably certain way of cleaning an infected machine.

Any other method that doesn't completely erase the disks via a "destructive write" i.e writes binary zeros to every sector on the disk can't be guaranteed to be effective these days -- there's some really clever stuff out there.



Note also that the advice above is for when a computer is actually infected. Normal AV protection hopefully should stop your machine getting infected in the first place but once you have an infection getting rid of it is not as simple as a lot of the AV software seems to think it is.

Trojans etc don't need the drastic action that I've specified above but the best safety mechanism is to do all your downloads on to a specific stand alone machine and only when it's passed the av scan check should you copy the data to the machine you want to use it on. Something like a network switch should enable you to switch the disks from the stand alone machine to the applicatopn machine.

If you can only use one machine then download say to an external device like a usb disk and scan it completely before allowing the data to be moved to a directory where you want to use it.

Cheers
jimbo
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom built, several laptops HP/ASUS
OS
Linux CENTOS 7 / various Windows OS'es and servers
CPU
Intel i7 Intel i5
Memory
8GB, 16GB
Graphics Card(s)
On Motherboard
Sound Card
Realtek HD audio
Monitor(s) Displays
Apple Cinema display, Samsung LCD
Screen Resolution
1920 X 1080
Hard Drives
4 X 1TB SATA
Mouse
Toshiba wireless laser
Internet Speed
> 20MB up
Maybe what you should do is to use HiJackThis: http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis, and after post the log file that way we can see if anything truly is messed up.
Also I am good with virus removal and crap like that, so what products have you used other than Malwarebyte's Anti-Malware? I might be able to provide you with assistance.
Do you have an MSN,AIM, or Yahoo messenger account? If so PM me, so we don't spam the forums.
 

My Computer

Computer Manufacturer/Model Number
Compaq Presario C751NR Notebook PC
OS
Windows Vista Ult. x86/Windows 7 Ult. x86 RC1
CPU
Intel Pentium Dual-Core
Memory
3Gb
Monitor(s) Displays
Generic PnP Monitor (Mobile)
Screen Resolution
1280 X 800
Hard Drives
FUJITSU MHY2120BH ATA Device
Back
Top