Finally been caught out :(
07-06-2009, 11:51
|
#1
|
|
Cable Forum Team
Join Date: Dec 2007
Age: 43
Posts: 16,278
|
Finally been caught out :(
Show's how complacent I've been getting lately
Went to run a setup file within an ISO and just noticed as I clicked run that the dates were out of sequence...
Virus warning flashed up, locked out of registry, administrator account, internet redirected, two keyloggers, one botnet...
Instantly hit the power switch and restarted in safe mode..
Recovered registry access in GP, removed all the naughties, used hijackthis and undll to remove some more stuff
Can't figure out how the admin accoutns been locked out as all the security policies look OK..
BHO's and redirects removed from network
No data loss
Gonna back-up and re-install...
At least the only other machine live on the network looks OK..otherwise Jen would have killed me (well after I reloaded her PC she would have killed me  )
|
|
|
07-06-2009, 12:22
|
#2
|
|
Keep smiling! ♥
Join Date: Mar 2006
Location: Doncaster, UK.
Age: 23
Services: VM: 20 (18)Mb
Posts: 7,574
|
Re: Finally been caught out :(
Where'd you get the ISO?
If it's somewhere legal you should report it to the site owners really.
Otherwise, well, glad you can reinstall.
|
|
|
07-06-2009, 12:27
|
#3
|
|
Cable Forum Team
Join Date: Dec 2007
Age: 43
Posts: 16,278
|
Re: Finally been caught out :(
Quote:
Originally Posted by Druchii
Where'd you get the ISO?
If it's somewhere legal you should report it to the site owners really.
Otherwise, well, glad you can reinstall.
|
Errrrrr.....
/kymmy sits here twiddling her finger and 13 toes wondering why people ask where the iso came from
---------- Post added at 12:27 ---------- Previous post was at 12:26 ----------
Before anyone says anything....YEP, serves me right  even though it was only to replace a damaged disk....
|
|
|
07-06-2009, 12:48
|
#4
|
|
Hello !
Join Date: Mar 2004
Location: East Midlands
Services: VMedia 10mb
Posts: 14,877
|
Re: Finally been caught out :(
Virus scan everything!
Any file I download from anywhere gets virus scanned before being opened.
|
|
|
07-06-2009, 12:49
|
#5
|
|
Cable Forum Team
Join Date: Dec 2007
Age: 43
Posts: 16,278
|
Re: Finally been caught out :(
I did do... but if the virus is encrypted within an installer no AV scan will find it
Anyway my Group and security policies are all over the place, so off to rebuild, catch you all later
|
|
|
07-06-2009, 12:52
|
#6
|
|
Hello !
Join Date: Mar 2004
Location: East Midlands
Services: VMedia 10mb
Posts: 14,877
|
Re: Finally been caught out :(
Good luck. Hope it all goes well.
|
|
|
07-06-2009, 12:57
|
#7
|
|
Keep smiling! ♥
Join Date: Mar 2006
Location: Doncaster, UK.
Age: 23
Services: VM: 20 (18)Mb
Posts: 7,574
|
Re: Finally been caught out :(
Quote:
Originally Posted by Kymmy
Errrrrr.....
/kymmy sits here twiddling her finger and 13 toes wondering why people ask where the iso came from
---------- Post added at 12:27 ---------- Previous post was at 12:26 ----------
Before anyone says anything....YEP, serves me right  even though it was only to replace a damaged disk....
|
Hehe.
Innocence eh?
|
|
|
07-06-2009, 15:00
|
#8
|
|
Cable Forum Team
Join Date: Dec 2007
Age: 43
Posts: 16,278
|
Re: Finally been caught out :(
Anyone now know a free AV for win7 (64 bit preferred)
|
|
|
07-06-2009, 15:03
|
#9
|
|
Keep smiling! ♥
Join Date: Mar 2006
Location: Doncaster, UK.
Age: 23
Services: VM: 20 (18)Mb
Posts: 7,574
|
Re: Finally been caught out :(
Quote:
Originally Posted by Kymmy
Anyone now know a free AV for win7 (64 bit preferred)
|
Avast works.
|
|
|
07-06-2009, 15:21
|
#10
|
|
CF Resident Dog
Join Date: Mar 2005
Location: Cambridgeshire
Age: 44
Posts: 6,067
|
Re: Finally been caught out :(
Quote:
Originally Posted by Kymmy
Anyone now know a free AV for win7 (64 bit preferred)
|
I'm using the 32bit version of Comodo Firewall and it's working great on Windows 7.
Link.
[edit]
Just noticed it was an AV you were after and not a Firewall!
Last edited by SnoopZ; 07-06-2009 at 15:54.
|
|
|
07-06-2009, 15:46
|
#11
|
|
Cable Forum Team
Join Date: Dec 2007
Age: 43
Posts: 16,278
|
Re: Finally been caught out :(
Will try AVAST till I get something more permanent
|
|
|
07-06-2009, 16:42
|
#12
|
|
Old dog, New tricks
Join Date: Dec 2006
Location: Lincoln UK
Age: 63
Services: 50Mb, TV & Phone
Posts: 3,511
|
Re: Finally been caught out :(
Avira works too
__________________
-= David =-
Under socialism ideology always trumps rationality.
|
|
|
07-06-2009, 17:29
|
#13
|
|
cf.mega poster
Join Date: Jan 2006
Posts: 3,270
|
Re: Finally been caught out :(
windows?, make yourself a UBCD4Win livecd and use the tools on there to check it again, and use one of the drive image tools to make a new backup after you get the PCs back to how you like them for next time you need to reinstall your main or a virtualBox PC later.
DriveImage XML for instance..
http://ubcd4win.com/forum/index.php?act=idx
http://ubcd4win.com/contents.htm
Last edited by popper; 07-06-2009 at 17:33.
|
|
|
08-06-2009, 17:38
|
#14
|
|
Inactive
Join Date: Mar 2009
Location: Ask an admin for my location if you're really that bothered
Services: Poor service and network abuse from Virginmedia.
Posts: 51
|
Re: Finally been caught out :(
seen this before on a compromised machine, you need to get nordahls admin password recovery tool, look at the accounts in the SAM and you'll note that one of them has been locked, it will save you a rebuild.
PS - you could put the installer through www.virustotal.com just to make sure you've got a fingerprint of the issue, of course using SSL.... (10Mb size limit)
|
|
|
|
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
|
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT +1. The time now is 08:31.
|