Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | An encounter with something nasty


You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion

An encounter with something nasty
Reply
 
Thread Tools
Old 07-03-2005, 23:40   #1
 
 
Join Date: Nov 2003
Location: Leeds - the dog house
Age: 31
Services: Email me for a current price list
Posts: 8,241
greencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny star
greencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny star
Angry An encounter with something nasty

Had customer today with a spyware problem. Customer had run Spybot but no joy - spyware kept coming back. The problem was lots of pop-ups just appearing, and IE exception errors. I managed to find a few dodgy dlls, including one called "sd.dll" lurking in the Windows temp folder. They were also listed as BHOs in IE. The home page had been hijacked. I immunized the system and downloaded SpywareBlaster but it would not run - installation is damaged or something. I think the spyware was blocking it from running. Try as I might, everytime I killed the dodgy run32dll process that was using the dlls, deleted the files, and remove the startup entry, the damn thing would reappear again on reboot Spent an hour on it before giving up and advising the customer to speak to their Health Authority - see if an engineer could be sent out.

Any useful URLs or listed of spyware out there? No point searching Google - never know what you might catch
__________________
Consistency is the last refuge of the unimaginative [Wilde]
greencreeper is offline   Reply With Quote
Old 08-03-2005, 00:17   #2
Cable Forum Team
 
Rob M's Avatar
 
Join Date: Feb 2004
Location: /root/
Age: 31
Services: netstat -tula > /home/raistlin/netstat.txt
Posts: 8,179
Rob M has a pair of shiny starsRob M has a pair of shiny stars
Rob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny stars
Re: An encounter with something nasty

This is quite a good site with a fairly comprehensive listing of running processes.

Not sure if it helps you here though.....

http://www.answersthatwork.com/Taskl...s/tasklist.htm
__________________
Formerly known as 'Raistlin'
Pausing Live TV and Eating Wotsits
Rob M is offline   Reply With Quote
Old 08-03-2005, 00:22   #3
lifeless
 
Join Date: Aug 2003
Location: nowhere
Posts: 718
iron25 is the helpful oneiron25 is the helpful oneiron25 is the helpful oneiron25 is the helpful oneiron25 is the helpful oneiron25 is the helpful oneiron25 is the helpful oneiron25 is the helpful oneiron25 is the helpful oneiron25 is the helpful oneiron25 is the helpful oneiron25 is the helpful oneiron25 is the helpful oneiron25 is the helpful oneiron25 is the helpful oneiron25 is the helpful oneiron25 is the helpful one
Re: An encounter with something nasty

The dll or service is still running so despite what you do it recreates itself on startup. I had a similar experience not so long ago where I had identified the spyware, removed all traces of it in the registry and files but it still kept coming back and the virus checker kept reporting a file that did not exist, even a search in explorer could not find it. I was going to give up after about 1.5 hours until I remembered back to my DOS days and ran an attrib command to find the file and once I had done that I had it clean in under 10 minutes

I can't remember what one it was but I did a search in Google and all the so called solutions were as much help as used toilet roll. As long as you have removed all traces of the files from the hard disk and the registry, then a boot into safe mode and a check of the files using attrib can be very helpful because alot of spyware programs add the hidden attributes to the files so even a search in explorer won't, pick them up.
iron25 is offline   Reply With Quote
Old 09-03-2005, 17:56   #4
cf.mega poster
 
AndrewJ's Avatar
 
Join Date: Nov 2004
Posts: 7,737
AndrewJ has a nice shiny star
AndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny star
Re: An encounter with something nasty

If it is so badly infected and he removes such files, could there not be a chance some of the core Windows files could be corrupted?? would a format and total reinstallation of software with spyblaster/spybot/adaware se 1.05 be wise with a good av/firewall??

Start with a fresh slate and learn from the mistake?
AndrewJ is offline   Reply With Quote
Old 09-03-2005, 17:57   #5
vista home premium user
 
nffc's Avatar
 
Join Date: Jul 2004
Location: chavy Nottingham
Age: 24
Services: Freeview, Sky+ on big TV, 2 Mb/s NTL BB, mega PC, PSP, PDA, N95
Posts: 6,366
nffc has a nice shiny star
nffc has a nice shiny starnffc has a nice shiny starnffc has a nice shiny star
Re: An encounter with something nasty

Quote:
Originally Posted by Raistlin
This is quite a good site with a fairly comprehensive listing of running processes.

Not sure if it helps you here though.....

http://www.answersthatwork.com/Taskl...s/tasklist.htm
Crikey that's a link and a half. Rep time!
__________________
PC: X2 4200+, 2GB RAM, X1650, 940GB HDDs, Audigy2ZS Platinum, HVR1100, Vista Home Premium Laptop: Advent 7203 (T5300, 2GB RAM, 80GB HDD, VHP) Server: WHS (XP 2800+, 1GB RAM, 820GB HDD)
10111 pts
nffc is offline   Reply With Quote
Old 09-03-2005, 20:54   #6
Cable Forum Team
 
Maggy J's Avatar
 
Join Date: Jun 2003
Location: between Portsmouth and Southampton.
Age: 56
Services: VM DTV,VM 2MB,VM Phone
Posts: 19,620
Maggy J has a lot of silver blingMaggy J has a lot of silver blingMaggy J has a lot of silver blingMaggy J has a lot of silver bling
Maggy J has a lot of silver blingMaggy J has a lot of silver blingMaggy J has a lot of silver blingMaggy J has a lot of silver blingMaggy J has a lot of silver blingMaggy J has a lot of silver blingMaggy J has a lot of silver blingMaggy J has a lot of silver blingMaggy J has a lot of silver blingMaggy J has a lot of silver blingMaggy J has a lot of silver blingMaggy J has a lot of silver blingMaggy J has a lot of silver blingMaggy J has a lot of silver blingMaggy J has a lot of silver blingMaggy J has a lot of silver blingMaggy J has a lot of silver blingMaggy J has a lot of silver bling
Send a message via AIM to Maggy J Send a message via Yahoo to Maggy J
Re: An encounter with something nasty

Quote:
Originally Posted by nffc
Crikey that's a link and a half. Rep time!
Worth a mention in the Helpful Post Thread for this month perhaps?
__________________
Prejudice is opinion without judgement...Voltaire.
Is still Incognitas at heart.
If it's bold it is a moderation technique.
If it's soft it's Coggy speaking.
Maggy J is offline   Reply With Quote
Old 09-03-2005, 21:08   #7
vista home premium user
 
nffc's Avatar
 
Join Date: Jul 2004
Location: chavy Nottingham
Age: 24
Services: Freeview, Sky+ on big TV, 2 Mb/s NTL BB, mega PC, PSP, PDA, N95
Posts: 6,366
nffc has a nice shiny star
nffc has a nice shiny starnffc has a nice shiny starnffc has a nice shiny star
Re: An encounter with something nasty

Quote:
Originally Posted by Incognitas
Quote:
Originally Posted by nffc
Crikey that's a link and a half. Rep time!
Worth a mention in the Helpful Post Thread for this month perhaps?
Bribery. Yes OK then...
__________________
PC: X2 4200+, 2GB RAM, X1650, 940GB HDDs, Audigy2ZS Platinum, HVR1100, Vista Home Premium Laptop: Advent 7203 (T5300, 2GB RAM, 80GB HDD, VHP) Server: WHS (XP 2800+, 1GB RAM, 820GB HDD)
10111 pts
nffc is offline   Reply With Quote
Old 09-03-2005, 21:26   #8
Android
 
purenuman's Avatar
 
Join Date: Nov 2003
Location: Madchester
Age: 42
Services: SKY+ & NTL 2mb
Posts: 512
purenuman is just so famous around these partspurenuman is just so famous around these partspurenuman is just so famous around these partspurenuman is just so famous around these partspurenuman is just so famous around these partspurenuman is just so famous around these partspurenuman is just so famous around these partspurenuman is just so famous around these partspurenuman is just so famous around these partspurenuman is just so famous around these partspurenuman is just so famous around these partspurenuman is just so famous around these partspurenuman is just so famous around these partspurenuman is just so famous around these partspurenuman is just so famous around these parts
Re: An encounter with something nasty

Quote:
CWS is a robust infection that exhibits robust intelligence, technical prowess and a determination to survive removal attempts. CWS wants to live.

The difficulty of removing CWS from a user's system is significant. In the early variants, CWS was slightly tricky to remove, but it could be done, carefully, by a knowledgeable Windows user.

However, CWS has stepped up the battle and recent variants are virtually impossible to remove manually. Some CWS variants even use methods of hiding and running themselves that had never been used before in any other spyware strains.

The chronological order in which the CWS variants appeared is detailed here, along with the approximate dates when they appeared online.
http://www.softpedia.com/get/Interne...Shredder.shtml
purenuman is offline   Reply With Quote
Old 09-03-2005, 22:40   #9
cf.mega poster
 
Millay's Avatar
 
Join Date: Oct 2003
Location: Portsmouth
Age: 30
Posts: 1,684
Millay has reached the bronze age
Millay has reached the bronze ageMillay has reached the bronze ageMillay has reached the bronze ageMillay has reached the bronze ageMillay has reached the bronze ageMillay has reached the bronze ageMillay has reached the bronze age
Send a message via MSN to Millay Send a message via Yahoo to Millay
Re: An encounter with something nasty

I recently had a very similar situation, it eventually comes down to the amount of time its going to take to clean the infections and stabilise the system, to how long it would take to build the machine from the ground up, as AndrewJames mentiond.. I find sometimes this is the cheapest route for my customers. and it can be quite helpfull in the long run as you can set the machine up properly from the get go. rather than constantly trying to firefight.
Millay is offline   Reply With Quote
Old 09-03-2005, 23:03   #10
cf.geek
 
Join Date: Aug 2003
Location: Asleep down in the server room
Age: 44
Posts: 516
tkiely is a name known to alltkiely is a name known to alltkiely is a name known to alltkiely is a name known to alltkiely is a name known to alltkiely is a name known to alltkiely is a name known to alltkiely is a name known to all
Send a message via MSN to tkiely
Re: An encounter with something nasty

wipe and reload, only sensible way forward.
__________________
www.f2s.com They used to be good b4 Pipex got 'em

now on BT who are em.........pretty good...sorry
tkiely is offline   Reply With Quote
Old 09-03-2005, 23:08   #11
cf.mega poster
 
ian@huth's Avatar
 
Join Date: Jun 2003
Location: Huthwaite, Nottinghamshire
Services: VM 2Mb, VM phone 5p plan, 2xSky+ boxes (Family pack, sports & movies)
Posts: 4,520
ian@huth is cast in bronzeian@huth is cast in bronzeian@huth is cast in bronzeian@huth is cast in bronze
ian@huth is cast in bronzeian@huth is cast in bronzeian@huth is cast in bronzeian@huth is cast in bronzeian@huth is cast in bronzeian@huth is cast in bronzeian@huth is cast in bronzeian@huth is cast in bronzeian@huth is cast in bronze
Re: An encounter with something nasty

Quote:
Originally Posted by tkiely
wipe and reload, only sensible way forward.
Having first checked with the customer to see that there was nothing of vital importance that he wanted saving.
__________________
Please put brain in gear before posting.
There is no such thing as the average man (or woman).

DigiGuide - the best by far source for planning your TV viewing http://getdigiguide.com/?p=1&r=11440
ian@huth is offline   Reply With Quote
Old 09-03-2005, 23:32   #12
cf.mega poster
 
AndrewJ's Avatar
 
Join Date: Nov 2004
Posts: 7,737
AndrewJ has a nice shiny star
AndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny star
Re: An encounter with something nasty

Agreed, curious thought does your customer have system restore enabled?? if so could it be that this program is using a restore point to come back again and again..

I am sure I have heard of a malware program doing such a thing.
AndrewJ is offline   Reply With Quote
Old 09-03-2005, 23:36   #13
 
 
Join Date: Nov 2003
Location: Leeds - the dog house
Age: 31
Services: Email me for a current price list
Posts: 8,241
greencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny star
greencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny star
Re: An encounter with something nasty

Ta for the input all. Rep fairy has visited, though she got carried away with the ctrl+v key and may have pasted half a comment here and there

I've got rid of this sort of thing before, but it's not something you can easily remove remotely and without Internet access to do research or download tools. It's the first time I've encountered something so stubborn and nasty though. My own system has various security measures so there's no chance of me getting anything nasty Shame that others are so complacent. Would an AV scanner pick up spyware? I know f-prot for DOS will flag up and clean keystroke loggers.

I have accidentally deleted user files before now, so I've learnt to exercise caution

edit:

The OS is good old Windows 98 SE, no doubt unpatched, so options are limited.
__________________
Consistency is the last refuge of the unimaginative [Wilde]
greencreeper is offline   Reply With Quote
Old 09-03-2005, 23:40   #14
Cable Forum Team
 
Rob M's Avatar
 
Join Date: Feb 2004
Location: /root/
Age: 31
Services: netstat -tula > /home/raistlin/netstat.txt
Posts: 8,179
Rob M has a pair of shiny starsRob M has a pair of shiny stars
Rob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny stars
Re: An encounter with something nasty

I know that this is probably a silly question but did you try deleting it (or running your spyware prog's) through Safe Mode?

In Safe Mode (in theory at least) it shouldn't be running so you should be able to get shot of it easil enough. Also worth (as already suggested) deleting the restore points (turn system restore off and then back on) just in case.

Glad you liked the link BTW, it's in constant use I can assure you.

Oh, and you think you have problems. Imagine the look on the face of the guy who's computer I have just rebuilt when I told him:

"Sorry, this is gonna take longer than expected. The 789 Virus Infected Files (thank you Avast) and 389 Malicious Programs (thank you Ad-Aware) that were on your machine have corrupted the Windows install to such a degree that I'm going to have to rebuild it from scratch!"
__________________

Ah, just read the OS bit, ignore the system restore comments.

Safe Mode still stands, but if you're doing things remotely that could be.....tricky.....
__________________
Formerly known as 'Raistlin'
Pausing Live TV and Eating Wotsits
Rob M is offline   Reply With Quote
Old 09-03-2005, 23:44   #15
 
 
Join Date: Nov 2003
Location: Leeds - the dog house
Age: 31
Services: Email me for a current price list
Posts: 8,241
greencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny star
greencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny star
Re: An encounter with something nasty

Quote:
Originally Posted by Raistlin
"Sorry, this is gonna take longer than expected. The 789 Virus Infected Files (thank you Avast) and 389 Malicious Programs (thank you Ad-Aware) that were on your machine have corrupted the Windows install to such a degree that I'm going to have to rebuild it from scratch!"
You should have been on today's customer care course Communicating the problem to the user so that they understand that you're working with them to resolve the problem


Quote:
Originally Posted by Raistlin
Ah, just read the OS bit, ignore the system restore comments.

Safe Mode still stands, but if you're doing things remotely that could be.....tricky.....
F8. No F - F for foxtrot - at the top of the keyboard. Yes - that's it. Now hit that key repeatedly as soon as the computer starts - you've got to be quick. No - you've missed it. Let's try again but this time, hit the key much faster - like a woodpecker. HP restore utils? I think you've hit the F8 too soon. Let's try that again...
__________________
Consistency is the last refuge of the unimaginative [Wilde]
greencreeper is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 23:51.


Links
Google
 
Web www.cableforum.co.uk


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0
Copyright © 2003 - 2008, Cable Forum.
(s204569790.onlinehome.info)