Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Finally been caught out :(


You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion

Finally been caught out :(
Reply
 
Thread Tools
Old 07-06-2009, 11:51   #1
Kymmy
Cable Forum Team
 
Kymmy's Avatar
 
Join Date: Dec 2007
Age: 43
Posts: 16,278
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Finally been caught out :(

Show's how complacent I've been getting lately

Went to run a setup file within an ISO and just noticed as I clicked run that the dates were out of sequence...

Virus warning flashed up, locked out of registry, administrator account, internet redirected, two keyloggers, one botnet...

Instantly hit the power switch and restarted in safe mode..

Recovered registry access in GP, removed all the naughties, used hijackthis and undll to remove some more stuff

Can't figure out how the admin accoutns been locked out as all the security policies look OK..

BHO's and redirects removed from network

No data loss

Gonna back-up and re-install...

At least the only other machine live on the network looks OK..otherwise Jen would have killed me (well after I reloaded her PC she would have killed me )
Kymmy is offline   Reply With Quote
Advertisement
Old 07-06-2009, 12:22   #2
Druchii
Keep smiling! ♥
 
Druchii's Avatar
 
Join Date: Mar 2006
Location: Doncaster, UK.
Age: 23
Services: VM: 20 (18)Mb
Posts: 7,574
Druchii has a nice shiny star
Druchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny star
Re: Finally been caught out :(

Where'd you get the ISO?
If it's somewhere legal you should report it to the site owners really.

Otherwise, well, glad you can reinstall.
Druchii is offline   Reply With Quote
Old 07-06-2009, 12:27   #3
Kymmy
Cable Forum Team
 
Kymmy's Avatar
 
Join Date: Dec 2007
Age: 43
Posts: 16,278
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Re: Finally been caught out :(

Quote:
Originally Posted by Druchii View Post
Where'd you get the ISO?
If it's somewhere legal you should report it to the site owners really.

Otherwise, well, glad you can reinstall.


Errrrrr.....

/kymmy sits here twiddling her finger and 13 toes wondering why people ask where the iso came from





---------- Post added at 12:27 ---------- Previous post was at 12:26 ----------

Before anyone says anything....YEP, serves me right even though it was only to replace a damaged disk....
Kymmy is offline   Reply With Quote
Old 07-06-2009, 12:48   #4
Halcyon
Hello !
 
Halcyon's Avatar
 
Join Date: Mar 2004
Location: East Midlands
Services: VMedia 10mb
Posts: 14,877
Halcyon has a pair of shiny starsHalcyon has a pair of shiny starsHalcyon has a pair of shiny starsHalcyon has a pair of shiny starsHalcyon has a pair of shiny starsHalcyon has a pair of shiny stars
Halcyon has a pair of shiny starsHalcyon has a pair of shiny starsHalcyon has a pair of shiny starsHalcyon has a pair of shiny starsHalcyon has a pair of shiny starsHalcyon has a pair of shiny starsHalcyon has a pair of shiny starsHalcyon has a pair of shiny starsHalcyon has a pair of shiny starsHalcyon has a pair of shiny starsHalcyon has a pair of shiny stars
Re: Finally been caught out :(

Virus scan everything!

Any file I download from anywhere gets virus scanned before being opened.
__________________
.
-

Halcyon is online now   Reply With Quote
Old 07-06-2009, 12:49   #5
Kymmy
Cable Forum Team
 
Kymmy's Avatar
 
Join Date: Dec 2007
Age: 43
Posts: 16,278
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Re: Finally been caught out :(

I did do... but if the virus is encrypted within an installer no AV scan will find it

Anyway my Group and security policies are all over the place, so off to rebuild, catch you all later
Kymmy is offline   Reply With Quote
Old 07-06-2009, 12:52   #6
Halcyon
Hello !
 
Halcyon's Avatar
 
Join Date: Mar 2004
Location: East Midlands
Services: VMedia 10mb
Posts: 14,877
Halcyon has a pair of shiny starsHalcyon has a pair of shiny starsHalcyon has a pair of shiny starsHalcyon has a pair of shiny starsHalcyon has a pair of shiny starsHalcyon has a pair of shiny stars
Halcyon has a pair of shiny starsHalcyon has a pair of shiny starsHalcyon has a pair of shiny starsHalcyon has a pair of shiny starsHalcyon has a pair of shiny starsHalcyon has a pair of shiny starsHalcyon has a pair of shiny starsHalcyon has a pair of shiny starsHalcyon has a pair of shiny starsHalcyon has a pair of shiny starsHalcyon has a pair of shiny stars
Re: Finally been caught out :(

Good luck. Hope it all goes well.
__________________
.
-

Halcyon is online now   Reply With Quote
Old 07-06-2009, 12:57   #7
Druchii
Keep smiling! ♥
 
Druchii's Avatar
 
Join Date: Mar 2006
Location: Doncaster, UK.
Age: 23
Services: VM: 20 (18)Mb
Posts: 7,574
Druchii has a nice shiny star
Druchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny star
Re: Finally been caught out :(

Quote:
Originally Posted by Kymmy View Post


Errrrrr.....

/kymmy sits here twiddling her finger and 13 toes wondering why people ask where the iso came from





---------- Post added at 12:27 ---------- Previous post was at 12:26 ----------

Before anyone says anything....YEP, serves me right even though it was only to replace a damaged disk....
Hehe.

Innocence eh?
Druchii is offline   Reply With Quote
Old 07-06-2009, 15:00   #8
Kymmy
Cable Forum Team
 
Kymmy's Avatar
 
Join Date: Dec 2007
Age: 43
Posts: 16,278
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Re: Finally been caught out :(

Anyone now know a free AV for win7 (64 bit preferred)
Kymmy is offline   Reply With Quote
Old 07-06-2009, 15:03   #9
Druchii
Keep smiling! ♥
 
Druchii's Avatar
 
Join Date: Mar 2006
Location: Doncaster, UK.
Age: 23
Services: VM: 20 (18)Mb
Posts: 7,574
Druchii has a nice shiny star
Druchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny star
Re: Finally been caught out :(

Quote:
Originally Posted by Kymmy View Post
Anyone now know a free AV for win7 (64 bit preferred)
Avast works.
Druchii is offline   Reply With Quote
Old 07-06-2009, 15:21   #10
SnoopZ
CF Resident Dog
 
SnoopZ's Avatar
 
Join Date: Mar 2005
Location: Cambridgeshire
Age: 44
Posts: 6,067
SnoopZ has a nice shiny starSnoopZ has a nice shiny starSnoopZ has a nice shiny starSnoopZ has a nice shiny star
SnoopZ has a nice shiny starSnoopZ has a nice shiny starSnoopZ has a nice shiny starSnoopZ has a nice shiny starSnoopZ has a nice shiny starSnoopZ has a nice shiny starSnoopZ has a nice shiny starSnoopZ has a nice shiny starSnoopZ has a nice shiny starSnoopZ has a nice shiny starSnoopZ has a nice shiny starSnoopZ has a nice shiny starSnoopZ has a nice shiny starSnoopZ has a nice shiny starSnoopZ has a nice shiny starSnoopZ has a nice shiny star
Re: Finally been caught out :(

Quote:
Originally Posted by Kymmy View Post
Anyone now know a free AV for win7 (64 bit preferred)
I'm using the 32bit version of Comodo Firewall and it's working great on Windows 7.

Link.

[edit]

Just noticed it was an AV you were after and not a Firewall!

Last edited by SnoopZ; 07-06-2009 at 15:54.
SnoopZ is offline   Reply With Quote
Old 07-06-2009, 15:46   #11
Kymmy
Cable Forum Team
 
Kymmy's Avatar
 
Join Date: Dec 2007
Age: 43
Posts: 16,278
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Re: Finally been caught out :(

Will try AVAST till I get something more permanent
Kymmy is offline   Reply With Quote
Old 07-06-2009, 16:42   #12
DaiNasty
Old dog, New tricks
 
DaiNasty's Avatar
 
Join Date: Dec 2006
Location: Lincoln UK
Age: 63
Services: 50Mb, TV & Phone
Posts: 3,511
DaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronze
DaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronze
Send a message via MSN to DaiNasty
Re: Finally been caught out :(

Avira works too
__________________
-= David =-

Under socialism ideology always trumps rationality.
DaiNasty is offline   Reply With Quote
Old 07-06-2009, 17:29   #13
popper
cf.mega poster
 
Join Date: Jan 2006
Posts: 3,270
popper has a bronze arraypopper has a bronze arraypopper has a bronze array
popper has a bronze arraypopper has a bronze arraypopper has a bronze arraypopper has a bronze arraypopper has a bronze arraypopper has a bronze array
Re: Finally been caught out :(

windows?, make yourself a UBCD4Win livecd and use the tools on there to check it again, and use one of the drive image tools to make a new backup after you get the PCs back to how you like them for next time you need to reinstall your main or a virtualBox PC later.

DriveImage XML for instance..

http://ubcd4win.com/forum/index.php?act=idx

http://ubcd4win.com/contents.htm

Last edited by popper; 07-06-2009 at 17:33.
popper is offline   Reply With Quote
Old 08-06-2009, 17:38   #14
nicolodeon
Inactive
 
Join Date: Mar 2009
Location: Ask an admin for my location if you're really that bothered
Services: Poor service and network abuse from Virginmedia.
Posts: 51
nicolodeon is an unknown quantity at this point
Re: Finally been caught out :(

seen this before on a compromised machine, you need to get nordahls admin password recovery tool, look at the accounts in the SAM and you'll note that one of them has been locked, it will save you a rebuild.

PS - you could put the installer through www.virustotal.com just to make sure you've got a fingerprint of the issue, of course using SSL.... (10Mb size limit)
nicolodeon is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Google Search




All times are GMT +1. The time now is 08:31.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
Copyright © 2003 - 2012, Cable Forum.
(server1.cableforum.co.uk)

SEO by vBSEO 3.3.2