Author Topic: Malware?  (Read 1549 times)

Offline Ghosth

  • AH Training Corps (retired)
  • Plutonium Member
  • *******
  • Posts: 8497
      • http://332nd.org
Re: Malware?
« Reply #15 on: February 09, 2011, 03:29:42 PM »
TY Denholm, many Linux distro's come with a boot from cd option which includes basic functionality including good virus scanners. Because your running off a temp os the files in question are not protected. Rendering them easier to dispose of.

Ubuntu is one such, but there are many to choose from.


Offline Stoney

  • Gold Member
  • *****
  • Posts: 3482
Re: Malware?
« Reply #16 on: February 10, 2011, 01:27:26 AM »
Ok, I've got a boot disk that I made tonight.  The TRK had a lot of utilities available.  How can I get into the start menu to delete that file, or will one of those anti-virus utilities pick it up?  I ran one scan that took over 4 hours before I interrupted it.  Looks like my old system restore files took the majority of the time to scan.  Can I just go erase those except for the last few?
"Can we be incorrect at times, absolutely, but I do believe 15 years of experience does deserve a little more credence and respect than you have given from your very first post."

HiTech

Offline Denholm

  • Plutonium Member
  • *******
  • Posts: 9667
      • No. 603 Squadron
Re: Malware?
« Reply #17 on: February 10, 2011, 06:24:33 AM »
You can erase start menu entries by looking in two separate folders. Chances are, it's in the "All Users" portion of the Start Menu, yet you may want to check your private portion of the Start Menu.

To check the "All Users" portion of Start Menu, browse to:
[your disk label]\Documents and Settings\All Users\Start Menu\Programs

To check your private portion of the Start Menu, browse to:
[your disk label]\Documents and Settings\[your user name]\Start Menu\Programs


Hopefully this helps.
Get your Daily Dose of Flame!
FlameThink.com
No. 603 Squadron... Visit us on the web, if you dare.

Drug addicts are always disappointed after eating Pot Pies.

Offline Charge

  • Gold Member
  • *****
  • Posts: 3414
Re: Malware?
« Reply #18 on: February 10, 2011, 08:08:55 AM »
I still suggest you track down which files use that DLL. It may not have anything to do with a virus but it may be a vital component of running program which starts it again if it sees it's missing. I think many Windows components are able to do that too.

You could also do a search and find the file and change its name to xxx.OLD. If it is created again then it is possibly created by a virus, but if it does not you may find that some program you use does not work anymore in which case you have found the parent to that DLL. Then just change the file name back to xxx.DLL.

I once had a difficult virus and as Ripley said the parent program changed its name constantly so if you deleted the parent it was soon again in system with different name. In a way the virus was always in a piggyback mode so that the actual virus had a backup running which knew the name of the running file, which was the parent to several DLLs, and if the running file was deleted the backup activated and created the EXEs and DLLs and a backup with random name -which again ensured that if the parent was destroyed the virus itself would survive. I saw it in its working directory as a newly created file but didn't realize what it was until later.

-C+
"When you wish upon a falling star, your dreams can come true. Unless it's really a giant meteor hurtling to the earth which will destroy all life. Then you're pretty much screwed no matter what you wish for. Unless of course, it's death by meteorite."

Offline Stoney

  • Gold Member
  • *****
  • Posts: 3482
Re: Malware?
« Reply #19 on: February 10, 2011, 09:23:32 AM »
Here's the listing in the startup menu:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>

@Amiwuguxavigamerundll32.exe "C:\WINDOWS\usehijucivic.dll",Startup = rundll32.exe "C:\WINDOWS\usehijucivic.dll",Startup
"Can we be incorrect at times, absolutely, but I do believe 15 years of experience does deserve a little more credence and respect than you have given from your very first post."

HiTech

Offline MrRiplEy[H]

  • Persona Non Grata
  • Plutonium Member
  • *******
  • Posts: 11633
Re: Malware?
« Reply #20 on: February 10, 2011, 09:44:10 AM »
Here's the listing in the startup menu:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>

@Amiwuguxavigamerundll32.exe "C:\WINDOWS\usehijucivic.dll",Startup = rundll32.exe "C:\WINDOWS\usehijucivic.dll",Startup

I'd nuke it from orbit. I hope you have backups.
Definiteness of purpose is the starting point of all achievement. –W. Clement Stone

Offline Stoney

  • Gold Member
  • *****
  • Posts: 3482
Re: Malware?
« Reply #21 on: February 10, 2011, 10:25:06 AM »
You can erase start menu entries by looking in two separate folders. Chances are, it's in the "All Users" portion of the Start Menu, yet you may want to check your private portion of the Start Menu.

To check the "All Users" portion of Start Menu, browse to:
[your disk label]\Documents and Settings\All Users\Start Menu\Programs

To check your private portion of the Start Menu, browse to:
[your disk label]\Documents and Settings\[your user name]\Start Menu\Programs


Hopefully this helps.

I don't see it listed in either of those folders...
"Can we be incorrect at times, absolutely, but I do believe 15 years of experience does deserve a little more credence and respect than you have given from your very first post."

HiTech

Offline Stoney

  • Gold Member
  • *****
  • Posts: 3482
Re: Malware?
« Reply #22 on: February 10, 2011, 10:35:43 AM »
Final update:  I was finally able to find the file and delete it.  Upon reboot, it did not return to my start menu.

Thanks everyone for the help.
"Can we be incorrect at times, absolutely, but I do believe 15 years of experience does deserve a little more credence and respect than you have given from your very first post."

HiTech

Offline gpwurzel

  • Gold Member
  • *****
  • Posts: 3836
Re: Malware?
« Reply #23 on: February 10, 2011, 11:17:31 AM »
Just an update as I continue to work on this...

Found this file in my Temp directory:  perflib_perfdata_614.dat  Can't delete this file at all with any of my utilities and from a google search, it looks like its a known rootkit, or maybe a windows file?

For Ghost and GPwurzel, I don't have any experience with Linux.  Are those applications self-contained or do I need to install Linux first, then run them?

(GPwurzel) Just saw you're in the Stumps--USMC?



Sorry Stoney, just woke up and saw this - TRK runs from its own engine, so no need to install linux first. And yep, I'm in the stumps, but not USMC (English expat - ex Royal Navy). Its a long long story lol......


Wurzel
I'm the worst pilot ingame ya know!!!

It's all unrealistic crap requested by people who want pie in the sky actions performed without an understanding of how things work and who can't grasp reality.


Offline MrRiplEy[H]

  • Persona Non Grata
  • Plutonium Member
  • *******
  • Posts: 11633
Re: Malware?
« Reply #24 on: February 10, 2011, 11:38:09 AM »
Final update:  I was finally able to find the file and delete it.  Upon reboot, it did not return to my start menu.

Thanks everyone for the help.

I wouldn't trust any computer that has had suspicious files and someone just manually deleted the most likely cause. There could be 10 others hidden. This is exactly how computer botnets grow, people continuing to use the machines even after discovering that it's compromised.

Of course you can go ahead and trust it's gone. I hope you don't do banking over internet or anything important on it though ;)
Definiteness of purpose is the starting point of all achievement. –W. Clement Stone

Offline Stoney

  • Gold Member
  • *****
  • Posts: 3482
Re: Malware?
« Reply #25 on: February 10, 2011, 03:19:36 PM »
I wouldn't trust any computer that has had suspicious files and someone just manually deleted the most likely cause. There could be 10 others hidden. This is exactly how computer botnets grow, people continuing to use the machines even after discovering that it's compromised.

Of course you can go ahead and trust it's gone. I hope you don't do banking over internet or anything important on it though ;)

I've scanned my rig with everything I can get my hands on, and now its showing clean.  The scans were showing clean even when this one file was still there.  Anyway, there's nothing nefarious going on with my rig right now, so I can't do anything other than assume that its clean.  Unless someone knows of something else I should do?
"Can we be incorrect at times, absolutely, but I do believe 15 years of experience does deserve a little more credence and respect than you have given from your very first post."

HiTech

Offline Denholm

  • Plutonium Member
  • *******
  • Posts: 9667
      • No. 603 Squadron
Re: Malware?
« Reply #26 on: February 10, 2011, 03:24:31 PM »
The recommendation is to reformat your computer. Basically, you wipe the hard-drive clean and re-install windows. This procedure removes all malicious software in one sweep.

Yes, your personal files will be lost during this procedure, thus the comments regarding backups.
Get your Daily Dose of Flame!
FlameThink.com
No. 603 Squadron... Visit us on the web, if you dare.

Drug addicts are always disappointed after eating Pot Pies.

Offline Stoney

  • Gold Member
  • *****
  • Posts: 3482
Re: Malware?
« Reply #27 on: February 10, 2011, 03:32:47 PM »
The recommendation is to reformat your computer. Basically, you wipe the hard-drive clean and re-install windows. This procedure removes all malicious software in one sweep.

Yes, your personal files will be lost during this procedure, thus the comments regarding backups.

Well, I can transfer my personal files to backup CDs / USB and then do it.  Since most of this stuff lays around in the registry and other system components of Windows, just backing up the files should be ok, right.  No chance the malware gets transferred over into the normal files? (pictures, documents, etc.)
"Can we be incorrect at times, absolutely, but I do believe 15 years of experience does deserve a little more credence and respect than you have given from your very first post."

HiTech

Offline Denholm

  • Plutonium Member
  • *******
  • Posts: 9667
      • No. 603 Squadron
Re: Malware?
« Reply #28 on: February 10, 2011, 03:37:42 PM »
The chances are low. I'd give it a shot.
Get your Daily Dose of Flame!
FlameThink.com
No. 603 Squadron... Visit us on the web, if you dare.

Drug addicts are always disappointed after eating Pot Pies.

Offline cattb

  • Silver Member
  • ****
  • Posts: 1163
Re: Malware?
« Reply #29 on: February 10, 2011, 04:33:10 PM »
Just a suggestion, if you (Stoney) reformat, make a shadow or a image of your new install. If fact make a couple, like one with and one without updates to the OS.
Do regular backups of your data after up and running. (Keydrive,Extra HD, whatever)
Now you'll be ready for future problems like malware or component failure in your computer as examples.
:Salute Easy8 EEK GUS Betty