Author Topic: Need help getting rid of a Win2K service/virus  (Read 455 times)

Offline Saintaw

  • Platinum Member
  • ******
  • Posts: 6692
      • My blog
Need help getting rid of a Win2K service/virus
« on: February 27, 2003, 02:12:13 PM »
UMRG32.exe is infected by a trojan (so my AV software says: BKDR_BO2K.10). I can't delete the file, not stop the service (tried deleting the file & stopping the services, both were denied to me, eventhough I am logged as admin).

How can I get rid of it ?
Saw
Dirty, nasty furriner.

Offline Wlfgng

  • Platinum Member
  • ******
  • Posts: 5252
      • http://www.nick-tucker.com
Need help getting rid of a Win2K service/virus
« Reply #1 on: February 27, 2003, 02:49:15 PM »
try booting to safe mode and deleting the file.

Offline qts

  • Nickel Member
  • ***
  • Posts: 782
      • None yet
Need help getting rid of a Win2K service/virus
« Reply #2 on: February 27, 2003, 02:54:22 PM »
Boot to a command line and copy a clean version from your install directory.

Offline Siaf__csf

  • Gold Member
  • *****
  • Posts: 2213
Need help getting rid of a Win2K service/virus
« Reply #3 on: February 28, 2003, 02:55:43 AM »
How did you manage to get back orifice to your computer?

Tsk tsk..

http://www.hackfix.org/bofix/fix2k.shtml

Offline Saintaw

  • Platinum Member
  • ******
  • Posts: 6692
      • My blog
Need help getting rid of a Win2K service/virus
« Reply #4 on: February 28, 2003, 03:25:35 AM »
It is not actually mine (I'm running XP) but my neighbours...I have no clue on how he managed to get that one, as he is as computer savy as my inlaw ;) (j/k Michel!) I'll try the above fixes when I get back home this evening, thanks :)
« Last Edit: February 28, 2003, 03:28:06 AM by Saintaw »
Saw
Dirty, nasty furriner.

Offline straffo

  • Persona Non Grata
  • Plutonium Member
  • *******
  • Posts: 10029
Need help getting rid of a Win2K service/virus
« Reply #5 on: February 28, 2003, 03:46:23 AM »
In this case you can mount his HD on your computer

Offline Chairboy

  • Probation
  • Plutonium Member
  • *******
  • Posts: 8221
      • hallert.net
Need help getting rid of a Win2K service/virus
« Reply #6 on: February 28, 2003, 09:19:50 AM »
What antivirus program do you have?  NAV can remove it.  If you can't get rid of something from inside windows w/ NAV, you just boot from the NAV (or NIS  or NSW(which comes w/ NAV)) CD and run the virus removal tool.  Since your OS isn't running, there are no files in  use.
"When fascism comes to America it will be wrapped in the flag and carrying a cross." - Sinclair Lewis

Offline SKurj

  • Gold Member
  • *****
  • Posts: 3630
Need help getting rid of a Win2K service/virus
« Reply #7 on: February 28, 2003, 10:42:20 AM »
Tried deleting it from a dos box?


SKurj

Offline AKIron

  • Plutonium Member
  • *******
  • Posts: 12795
Need help getting rid of a Win2K service/virus
« Reply #8 on: February 28, 2003, 11:42:14 AM »
If his drive is FAT32 you can boot from a floppy and replace the file. If not, you can boot from his Win2K CD and run install in repair mode.
Here we put salt on Margaritas, not sidewalks.

Offline Siaf__csf

  • Gold Member
  • *****
  • Posts: 2213
Need help getting rid of a Win2K service/virus
« Reply #9 on: February 28, 2003, 01:00:23 PM »
Yeah or he can do it the easy way as described on the instructions on the net LOL.

Offline Saintaw

  • Platinum Member
  • ******
  • Posts: 6692
      • My blog
Need help getting rid of a Win2K service/virus
« Reply #10 on: March 01, 2003, 02:09:19 AM »
It's been done, thanks :)
Saw
Dirty, nasty furriner.

Offline Siaf__csf

  • Gold Member
  • *****
  • Posts: 2213
Need help getting rid of a Win2K service/virus
« Reply #11 on: March 02, 2003, 03:57:22 AM »
It's always a good idea to keep an eye on the process list also. I found out once that a server of a friend of mine was compromised.. Someone was using it to share warez on the net :)

How did I find it out? I browsed the task list and saw processes running that shouldn't be there. I then opened google and saw those processes were related to irc and hacking.. :)