Nasty virus / malware / rootkit / something

Status
Not open for further replies.
M

Matt²

Ran into a nasty piece of work today.. definitely trojan viruses, porn, malware, vango, gamevance, shoppercrap, vundo, + + + etc etc etc...

clean.. reboot. Explorer crashes. Deep clean (take hard drive out and scan from a different computer) .. some found.. cleaned (I use Avast and Malwarebytes) .. thinks it's clean, load back into it's own computer, boot up.. looks good. Reboot .. Upon that reboot, Explorer doesn't run period, and when you try to run it it tells you you don't have permission. Going to try siccing Nod32 on it and then resetting the permissions in the morning, but I spent from 1pm - 9:30pm tonight on it and I'm beat. I "closed" at 6pm.

This computer had no antivirus protection running at all. Nuking it from orbit would be much more pleasurable at this point.
 
Might want to check your hosts file, and see if it set up a proxy in Internet options. Other than that, it depends on what virus/malware it is that caused it. Sometimes you can find specific instructions on cleaning it out. Usually if it's that persistent it's just better for a clean install though.
 
M

Matt²

Might want to check your hosts file, and see if it set up a proxy in Internet options. Other than that, it depends on what virus/malware it is that caused it. Sometimes you can find specific instructions on cleaning it out. Usually if it's that persistent it's just better for a clean install though.
it did, though I had reset it back to normal. There's too many viruses that have been on it to be sure, one of the latest ones was "Bamital-x" which I looked for and did not find further traces of.

Be going for the repair option in a little bit.
 
M

Matt²

Finally got it fixed. Winlogon shell was being redirectred to "Explorer" not "explorer" (I wouldn't think it would make a difference, but .. ehh.)
Avast saw viruses but declared them not viruses (???) so it but wouldn't do anything with it.. same with Malwarebytes, and Hit Man Pro 3.5. Combofix finally saw the rootkit, and rebooted several times to clean it up, at first skipping the proxy, but then hitman pro fixed that (finally). All done without doing a repair install. Rebooted about 5x to be sure with each profile.

takin a break!!
 
Status
Not open for further replies.
Top