ukash infection

ahmedilyas

New member
Member
Local time
9:30 PM
Messages
50
no idea how. last night all was ok, did not download anything at all.
this morning, I woke up to find my remote computer being infected with the ukash virus/trojan!

all my Windows is updated as is my AV (symantec SBE) - no idea how i got this infection. The worst part is that I wont be home for another few days and have got important things on the computer.

how does one get infected with this virus and how can I remove it? I am based in the UK.

it doesnt make sense what happened in those 9 hours between last night and this morning.... i cant CTRL+ALT+DELETE but can do an ALTGR + Del however any key presses or switching between tasks/apps does not work.
 

My Computer

Computer type
PC/Desktop
OS
Microsoft Windows 7 Ultimate 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
Intel(R) Core(TM) i7 CPU X 990 @ 3.47GHz
Motherboard
ASUSTeK Computer INC. P6X58D-E
Memory
24.00 GB
Graphics Card(s)
NVIDIA GeForce GTX 550 Ti
Sound Card
(1) NVIDIA High Definition Audio (2) NVIDIA High Definitio
Screen Resolution
1920 x 1200 x 32 bits (4294967296 colors) @ 59 Hz
Hard Drives
(1) OCZ-AGILITY3 ATA Device (2) WDC WD2002FAEX-007BA0 ATA Device (3) WDC WD2002FAEX-007BA0 ATA Device (4) WDC WD30EZRX-00DC0B0 ATA Device (5) WDC WD30EZRX-00MMMB0 ATA Device (6) WDC WD5000AAKS-00A7B0 ATA Device

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
thanks.
well I am running WS2008R2 - so im hoping this will work with it (same kernel pretty much as Win7)

but im so annoyed and frustrated i cant do anything remotely until i get home in 4 days time. its my main system
 

My Computer

Computer type
PC/Desktop
OS
Microsoft Windows 7 Ultimate 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
Intel(R) Core(TM) i7 CPU X 990 @ 3.47GHz
Motherboard
ASUSTeK Computer INC. P6X58D-E
Memory
24.00 GB
Graphics Card(s)
NVIDIA GeForce GTX 550 Ti
Sound Card
(1) NVIDIA High Definition Audio (2) NVIDIA High Definitio
Screen Resolution
1920 x 1200 x 32 bits (4294967296 colors) @ 59 Hz
Hard Drives
(1) OCZ-AGILITY3 ATA Device (2) WDC WD2002FAEX-007BA0 ATA Device (3) WDC WD2002FAEX-007BA0 ATA Device (4) WDC WD30EZRX-00DC0B0 ATA Device (5) WDC WD30EZRX-00MMMB0 ATA Device (6) WDC WD5000AAKS-00A7B0 ATA Device
If it does find virus ect. let us know which ones. As far as I know it should work.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
i will do for sure.

damn it. cant do anything remotely.
 

My Computer

Computer type
PC/Desktop
OS
Microsoft Windows 7 Ultimate 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
Intel(R) Core(TM) i7 CPU X 990 @ 3.47GHz
Motherboard
ASUSTeK Computer INC. P6X58D-E
Memory
24.00 GB
Graphics Card(s)
NVIDIA GeForce GTX 550 Ti
Sound Card
(1) NVIDIA High Definition Audio (2) NVIDIA High Definitio
Screen Resolution
1920 x 1200 x 32 bits (4294967296 colors) @ 59 Hz
Hard Drives
(1) OCZ-AGILITY3 ATA Device (2) WDC WD2002FAEX-007BA0 ATA Device (3) WDC WD2002FAEX-007BA0 ATA Device (4) WDC WD30EZRX-00DC0B0 ATA Device (5) WDC WD30EZRX-00MMMB0 ATA Device (6) WDC WD5000AAKS-00A7B0 ATA Device
I take it there is currently no way of doing this remotely via RDP? Even to kill that process of the trojan? Anything at all remotely?
 

My Computer

Computer type
PC/Desktop
OS
Microsoft Windows 7 Ultimate 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
Intel(R) Core(TM) i7 CPU X 990 @ 3.47GHz
Motherboard
ASUSTeK Computer INC. P6X58D-E
Memory
24.00 GB
Graphics Card(s)
NVIDIA GeForce GTX 550 Ti
Sound Card
(1) NVIDIA High Definition Audio (2) NVIDIA High Definitio
Screen Resolution
1920 x 1200 x 32 bits (4294967296 colors) @ 59 Hz
Hard Drives
(1) OCZ-AGILITY3 ATA Device (2) WDC WD2002FAEX-007BA0 ATA Device (3) WDC WD2002FAEX-007BA0 ATA Device (4) WDC WD30EZRX-00DC0B0 ATA Device (5) WDC WD30EZRX-00MMMB0 ATA Device (6) WDC WD5000AAKS-00A7B0 ATA Device
Not as far as I know.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
ok im home now. im currently using the Windows Defender offline on the usb stick and its doing a quick scan.

it just told me that the preliminary scan results show that malicious or potentially unwanted software may exist (im hoping that it is the ukash virus/trojan)

once, hopefully, removed - what are the next steps to see if anything has been either jepordized OR if it still exists on the system?
 

My Computer

Computer type
PC/Desktop
OS
Microsoft Windows 7 Ultimate 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
Intel(R) Core(TM) i7 CPU X 990 @ 3.47GHz
Motherboard
ASUSTeK Computer INC. P6X58D-E
Memory
24.00 GB
Graphics Card(s)
NVIDIA GeForce GTX 550 Ti
Sound Card
(1) NVIDIA High Definition Audio (2) NVIDIA High Definitio
Screen Resolution
1920 x 1200 x 32 bits (4294967296 colors) @ 59 Hz
Hard Drives
(1) OCZ-AGILITY3 ATA Device (2) WDC WD2002FAEX-007BA0 ATA Device (3) WDC WD2002FAEX-007BA0 ATA Device (4) WDC WD30EZRX-00DC0B0 ATA Device (5) WDC WD30EZRX-00MMMB0 ATA Device (6) WDC WD5000AAKS-00A7B0 ATA Device
so it found win32/karagany.i. I pressed remove and said actions were successfully carried out. now doing another quick scan again and seeing if it picks up anything else.

other than that - anything else I need to do? is there another way I can scan the system to see if there are traces of the virus or its varient?

to me, from what ive been reading - does not sound like the ukash virus....
 

My Computer

Computer type
PC/Desktop
OS
Microsoft Windows 7 Ultimate 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
Intel(R) Core(TM) i7 CPU X 990 @ 3.47GHz
Motherboard
ASUSTeK Computer INC. P6X58D-E
Memory
24.00 GB
Graphics Card(s)
NVIDIA GeForce GTX 550 Ti
Sound Card
(1) NVIDIA High Definition Audio (2) NVIDIA High Definitio
Screen Resolution
1920 x 1200 x 32 bits (4294967296 colors) @ 59 Hz
Hard Drives
(1) OCZ-AGILITY3 ATA Device (2) WDC WD2002FAEX-007BA0 ATA Device (3) WDC WD2002FAEX-007BA0 ATA Device (4) WDC WD30EZRX-00DC0B0 ATA Device (5) WDC WD30EZRX-00MMMB0 ATA Device (6) WDC WD5000AAKS-00A7B0 ATA Device
Back
Top