Welcome Guest ( Login | Register )
        


Horribly destructive infection, please help Expand / Collapse
Author
Message
Posted 5/16/2008 8:32 PM
New Member

New MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew Member

Group: Forum Members
Last Login: 5/19/2008 8:32 PM
Posts: 12, Visits: 36
Hi. Yesterday I picked up on some rogue processes, and then over until this afternoon those few sprouted into many including (not precise) "mrofinu", "syst3m32.exe", "DILx.tmp" with "x" being a number between 1-15, and another I can't remember now. Amongst all this many important files became corrupt, including explorer.exe, and the internet was almost completely non-fucntional up until Generic Host Process (svchost.exe) crashed and took me offline properly until I restarted.

This evening I reformatted because I didn't see any possible salvage, but the problem seems to have brilliantly survived the wipe. My Temp folder is now full of DILx.tmp files again, and explorer among other things (the process that handles 16bit applications) have started to fail again. New processes, or ones I didn't notice before, have appeared, including ___r.exe and ___synmgr.exe.

I heard things can survive in the MBR, but I have no idea how to tackle this and in what order so as to actually contain the spread.

Help?

Edit: As a side note, most of the drivers I need to be installing are 16 bit, so I don't even have a working AGP chipset.
  Post #239599
 
Posted 5/17/2008 3:46 AM


Senior Forum Moderator

Senior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum Moderator

Group: Moderators
Last Login: 8/9/2008 10:14 AM
Posts: 31,427, Visits: 54,734
Welcome
Download Trend Micro HijackThis 2.0.2 to your desktop:
Double click on HJTInstall.exe,it will prompt you to extract hijackthis.exe to C:\Program Files\Trend Micro\HijackThis.
When the install is complete,HijackThis will automatically launch.
When the license agreement appears,select "I Accept" and then click on the "Do a system scan only" button.
When the scan is complete,click on the "Save Log" button,then save it to your desktop.
Copy and paste the entire contents of that log into a new topic in the HijackThis Logs forum, not here.


_______________________________________________________________



ASAP & UNITE member since 2006



Use OpenDNS
  Post #239611
 
Posted 5/17/2008 5:07 AM
New Member

New MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew Member

Group: Forum Members
Last Login: 5/19/2008 8:32 PM
Posts: 12, Visits: 36
Thanks for the reply.

http://forum.tweaks.com/forum/Topic239612-29-1.aspx
  Post #239613
 
Posted 5/18/2008 2:50 AM


Senior Forum Moderator

Senior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum Moderator

Group: Moderators
Last Login: 8/9/2008 10:14 AM
Posts: 31,427, Visits: 54,734
You're welcome

_______________________________________________________________



ASAP & UNITE member since 2006



Use OpenDNS
  Post #239666
 
Posted 5/26/2008 5:23 PM


New Member

New MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew Member

Group: Forum Members
Last Login: 8/6/2008 12:16 PM
Posts: 53, Visits: 272
You know, there is a VERY easy method to stop the problem child(s) you are seeing... & you ALREADY OWN THE TOOLS:

RECOVERY CONSOLE

(Boot from your XP/Server 2003/VISTA install media, & run it there (via bootoptions menus choices then))

OR, just install it to your OS drive, via :

1.Insert the Windows XP CD into the CD-ROM drive.
2.Click Start, and then click Run.
3.In the Open box, type d:\i386\winnt32.exe /cmdcons where d is the drive letter for the CD-ROM drive.
4.A Windows Setup Dialog Box appears. The Windows Setup Dialog Box describes the Recovery Console option. To confirm the installation, click Yes.
5.Restart the computer. The next time that you start your computer, "Microsoft Windows Recovery Console" appears on the startup menu.

Then once you are booted & logged into it, use:

FixMBR

&

DEL (filename)

Once in the folder/directory (via CD dos command) where those rogue files are, burn them, in RC... using DEL.

* This type of info. is in my "HOW TO SECURE Windows 2000/XP/Server 2003 & VISTA, & make it 'fun to do', via CIS Tool Guidance" post in this section of these forums in fact.

(Specifically in its VIRUS/SPYWARE/ROOTKIT REMOVAL section).

You MAY have to use SECPOL.msc & give yourself rights to folders other than %windir% & its subordinates though, if the rogue files aren't underneath Windows itself... because RC's default ACL to those things is just %windir% & its subordinate folders only.

Start in Left-hand side pane of secpol.msc -> Security Settings -> Local Policies -> Security Options (now right-hand side pane of secpol.msc) -> Recovery Console: Allow Floppy Copy and Access to all drives and folders

APK


"I'm Reese: Sgt. TechComVN38416, assigned to protect you - Youve been TARGETTED FOR TERMINATION!"
  Post #240134
 
Posted 5/26/2008 6:21 PM


Senior Forum Moderator

Senior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum Moderator

Group: Moderators
Last Login: 8/9/2008 10:14 AM
Posts: 31,427, Visits: 54,734
APK,this is an old topic which has since been resolved.

_______________________________________________________________



ASAP & UNITE member since 2006



Use OpenDNS
  Post #240138
 
Posted 5/27/2008 8:49 AM


New Member

New MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew Member

Group: Forum Members
Last Login: 8/6/2008 12:16 PM
Posts: 53, Visits: 272
It's only 7 days old... & the point of MY reply was to simply point out that you DON'T really need 3rd party tools for many removals... inclusive of bootsector originated ROOTKITS (fixmbr takes care of those, "lickety split, no XXXX") & as far as "trojan files" too, DEL command in RC does the job on those, same effort/speed (fast & painless).

APK


"I'm Reese: Sgt. TechComVN38416, assigned to protect you - Youve been TARGETTED FOR TERMINATION!"
  Post #240164
 
Posted 5/28/2008 6:22 AM


Forum Moderator

Forum ModeratorForum ModeratorForum ModeratorForum ModeratorForum ModeratorForum ModeratorForum ModeratorForum ModeratorForum ModeratorForum Moderator

Group: Moderators
Last Login: 8/8/2008 6:28 AM
Posts: 2,821, Visits: 7,025
...& as far as "trojan files" too, DEL command in RC does the job...

The infection and the malware files have to be identified first. Most average users don't know how to do that. Malware Removal Experts like RichieUK are able to assist them with easy to understand directions using specialized fix tools developed by other experts. That's why we have this and the HJT forum. And as part of the disinfection process we help them understand how they got infected and how to keep from getting reinfected.


__________________________________________

"THE BAD GUYS DON'T NEED A SEARCH WARRANT. ARE YOU PROTECTED?"





Microsoft MVP - Windows Security 2007-2009
  Post #240219
 
Posted 5/30/2008 10:18 AM


New Member

New MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew Member

Group: Forum Members
Last Login: 8/6/2008 12:16 PM
Posts: 53, Visits: 272
quietman7 (5/28/2008)
[quote]Most average users don't know how to do that.


Seems the original poster DID though... he had rogue filenames.

quietman7 (5/28/2008)
[quote]And as part of the disinfection process we help them understand how they got infected and how to keep from getting reinfected


Fact is, you don't REALLY need automatic remover tools... not really & also, as to making it so it REALLY never happens again (IF you can obey some simple rules)?

All here -> HOW TO SECURE Windows 2000/XP/Server 2003 & VISTA even (so you DON'T "get hit" again):

http://forum.tweaks.com/forum/Topic230980-28-1.aspx

In that post's "VIRUS SPYWARE REMOVAL SECTION" ?

I outline HOW to use RC (possibly ProcessExplorer also) for that (determining culprits & also, destroying them), & finding what the user's hassle is in rogue processes that are LOCKED while inside RPL3/Ring3/Usermode operations under Explorer.exe shell!

(Also, vs. rootkits he suspected (bootsector type))

[b]quietman7 (5/28/2008)
[quote]Malware Removal Experts like RichieUK are able to assist them with easy to understand directions using specialized fix tools developed by other experts.


ON "Experts" - a purely relative term... but, not knocking Rich... & that's where * I THINK * you have me wrong... I was merely pointing out alternate methods, period, that need nothing more than free tools or ones you have already (no 'automators' necessary really).

(YES - Automatic "killer" programs are nice & "time savers" too... 'script kiddie tools' really (this is no putdown, they ARE someone's hard work & time freely given many times), & they DO move faster than folks can... but, I have also seen them generate "false positives" too, on that note. "Want a job done right? DO IT YOURSELF" if possible)

I'd largely wager? He'll tell you the same, & on MOST accounts noted here.

APK

P.S.=> On virus removals & such? As part of my duties, professionally since 1994?? I've done literally 1,000's for paying customers, ranging from home users all the way up thru corporate networks under attack (by those & far worse) @ the tune of $150 per hour or more...

Personally speaking, & I'd wager Ritchie will agree? Once you get a GOOD set of tools & some understanding of what is needed??? This isn't "rocket science"... I'd bet even Ritchie will tell you that! Only takes a small amount of time studying a few with the right tools, & you don't even NEED "automatic virus/spyware killers" etc. really! apk


"I'm Reese: Sgt. TechComVN38416, assigned to protect you - Youve been TARGETTED FOR TERMINATION!"
  Post #240367
 
« Prev Topic | Next Topic »



All times are GMT -6:00, Time now is 3:45pm

Powered By InstantForum.NET v4.1.4 © 2009
Execution: 0.090. 9 queries. Compression Disabled.