Uncover Reality Forum
 

Go Back   Uncover Reality Forum > General > Technical Stuff

Technical Stuff Help, tips and advice about all things technical.


Welcome to the Uncover Reality Forum .

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. As a guest you are able to view thumbnails but you will need to register to view the full size images. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features, such as viewing the images posted on the site . Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact contact us.
Reply
 
Thread Tools Display Modes
Old November 4th, 2009, 02:28 PM   #1 (permalink)
EMPIRE
 
EATTHEDEAD's Avatar
 
Join Date: Jan 2007
Location: Saving money on car insurance.
Posts: 3,254
Fucking Virus!!!

Just a few minutes ago I got a warning while playing a game offline. Some bullshit program called "Security Tool" decided to download itself and make itself at home. Now I can't run my anti-virus or my Malware Bytes and I'm getting little pop ups in the taskbar telling me that both my anti-virus AND malware bytes are infected. I know this is bullshit. It won't allow me to start in safe mode and everything on my desktop has vanished, just a black screen. Has anyone had to deal with this? If so, would someone please help me to eradicate this shit from my PC?
__________________
"If its true that our species is alone in the universe, then I'd have to say the universe aimed rather low and settled for very little" -- George Carlin (1937-2008)
EATTHEDEAD is offline   Reply With Quote
Old November 4th, 2009, 03:08 PM   #2 (permalink)
Administrator
 
RORER-714's Avatar
 
Join Date: May 2006
Posts: 11,523
http://housecall.trendmicro.com/
__________________
.
RORER-714 is offline   Reply With Quote
Old November 4th, 2009, 03:17 PM   #3 (permalink)
EMPIRE
 
EATTHEDEAD's Avatar
 
Join Date: Jan 2007
Location: Saving money on car insurance.
Posts: 3,254
It won't let me run the application Rorer. I can't download anything and run it. I need a manual way to get rid of this thing. Goddamn thing won't let me run my registry edit either. I can't even get the task manager to open. Well, it opens, for about 1.3 seconds and then this virus tells me it's infected and shuts it down. It is telling me everything is infected, even the program I dwnlded from your link.
__________________
"If its true that our species is alone in the universe, then I'd have to say the universe aimed rather low and settled for very little" -- George Carlin (1937-2008)
EATTHEDEAD is offline   Reply With Quote
Old November 4th, 2009, 03:27 PM   #4 (permalink)
Moderator
 
Curdled_Pus's Avatar
 
Join Date: May 2009
Location: In the Freezer with Your Dead EX
Posts: 3,425
Arrow

I read what you said.
You cannot Download this? http://download.bleepingcomputer.com/grinler/rkill.com
If so I will be waiting here. I have to restart Fx so will be right. This is a nasty one. Is this what it looks like?
And just to confirm. You can't start in Safe mode right.

__________________
Are your programs up to date? Check out this freebie * FileHippo Update Checker
Quote:
What is it?
The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases. These are then neatly displayed in your browser for you to download. Please note that not all programs are supported.
http://www.filehippo.com/updatechecker

Last edited by Curdled_Pus; November 4th, 2009 at 04:43 PM.. Reason: Spelling
Curdled_Pus is offline   Reply With Quote
Old November 4th, 2009, 03:31 PM   #5 (permalink)
EMPIRE
 
EATTHEDEAD's Avatar
 
Join Date: Jan 2007
Location: Saving money on car insurance.
Posts: 3,254
I haven't visited your link yet, but yeah it won't let me into safe mode.
Going to your link now. Hope this works.
__________________
"If its true that our species is alone in the universe, then I'd have to say the universe aimed rather low and settled for very little" -- George Carlin (1937-2008)
EATTHEDEAD is offline   Reply With Quote
Old November 4th, 2009, 03:33 PM   #6 (permalink)
EMPIRE
 
EATTHEDEAD's Avatar
 
Join Date: Jan 2007
Location: Saving money on car insurance.
Posts: 3,254
Nope. it says rkill.com is infected too. The virus is known as "Lsas.Blaster.Keylogger. Your pic above is accurate.
__________________
"If its true that our species is alone in the universe, then I'd have to say the universe aimed rather low and settled for very little" -- George Carlin (1937-2008)
EATTHEDEAD is offline   Reply With Quote
Old November 4th, 2009, 03:48 PM   #7 (permalink)
Moderator
 
Curdled_Pus's Avatar
 
Join Date: May 2009
Location: In the Freezer with Your Dead EX
Posts: 3,425
Arrow

It appears that it is associated with vundo which has always been a real nasty one.

I am going by this guide but will look further & see what I can find as all the actions I would suggest are disabled for now http://www.bleepingcomputer.com/viru...-security-tool
I would HIGHLY suggest you open a new tab & make an account at http://www.bleepingcomputer.com/foru...ct=Reg&CODE=00
and post there & keep this tab opened & refresh it as someone may be experienced with this booger. You need professional help with this one. In the subject I would the name of the infection & give the link above.
I would like to follow the thread there if you would be so inclined.

EDIT:By a wild chance in the brief moment the task manager opens if you can right click real quick & find & kill this nasty. It's wild I know
__________________
Are your programs up to date? Check out this freebie * FileHippo Update Checker
Quote:
What is it?
The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases. These are then neatly displayed in your browser for you to download. Please note that not all programs are supported.
http://www.filehippo.com/updatechecker

Last edited by Curdled_Pus; November 4th, 2009 at 03:50 PM..
Curdled_Pus is offline   Reply With Quote
Old November 4th, 2009, 03:56 PM   #8 (permalink)
Psycho Moderator
 
Gogo's Avatar
 
Join Date: Jun 2009
Location: detox
Posts: 1,301
EATTHEDEAD, I got that one too...the only solution was to lose everything and reinstall my entire system to factory condition.
Was a pain in the ass, but I tried everything else...
Best of luck.
__________________
blood blood gimme blood - bloody bloody bloody - bloody blood
Gogo is offline   Reply With Quote
Old November 4th, 2009, 03:56 PM   #9 (permalink)
Moderator
 
Curdled_Pus's Avatar
 
Join Date: May 2009
Location: In the Freezer with Your Dead EX
Posts: 3,425
Arrow

Do you have another PC that has net access to? If no in your house what about a neighbors? I've had to do that one myself when I thought I had a key-logger.
Before answering can you open & play a CD?? I found a possible workaround with tools I have pushed here before
__________________
Are your programs up to date? Check out this freebie * FileHippo Update Checker
Quote:
What is it?
The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases. These are then neatly displayed in your browser for you to download. Please note that not all programs are supported.
http://www.filehippo.com/updatechecker

Last edited by Curdled_Pus; November 4th, 2009 at 04:00 PM.. Reason: Spelling
Curdled_Pus is offline   Reply With Quote
Old November 4th, 2009, 03:59 PM   #10 (permalink)
Moderator
 
Curdled_Pus's Avatar
 
Join Date: May 2009
Location: In the Freezer with Your Dead EX
Posts: 3,425
Arrow

Quote:
Originally Posted by Gogo View Post
EATTHEDEAD, I got that one too...the only solution was to lose everything and reinstall my entire system to factory condition.
Was a pain in the ass, but I tried everything else...
Best of luck.
Yeah, that's a last resort & that is if he has recent backups. If he has a key-logger or a real nasty Trojan buried in the bios real deep after reformatting it may still be there.

EDIT: ETD On a side note, what anti-virus are you using?
__________________
Are your programs up to date? Check out this freebie * FileHippo Update Checker
Quote:
What is it?
The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases. These are then neatly displayed in your browser for you to download. Please note that not all programs are supported.
http://www.filehippo.com/updatechecker

Last edited by Curdled_Pus; November 4th, 2009 at 04:02 PM..
Curdled_Pus is offline   Reply With Quote
Old November 4th, 2009, 04:06 PM   #11 (permalink)
Moderator
 
Curdled_Pus's Avatar
 
Join Date: May 2009
Location: In the Freezer with Your Dead EX
Posts: 3,425
Arrow

We need access to your task manager. If we can get in there it's licked
__________________
Are your programs up to date? Check out this freebie * FileHippo Update Checker
Quote:
What is it?
The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases. These are then neatly displayed in your browser for you to download. Please note that not all programs are supported.
http://www.filehippo.com/updatechecker

Last edited by Curdled_Pus; November 4th, 2009 at 04:07 PM.. Reason: Added
Curdled_Pus is offline   Reply With Quote
Old November 4th, 2009, 04:12 PM   #12 (permalink)
Moderator
 
Curdled_Pus's Avatar
 
Join Date: May 2009
Location: In the Freezer with Your Dead EX
Posts: 3,425
Arrow

Do you have HijackThis installed on your PC? http://free.antivirus.com/hijackthis/
If by chance wild can you run it?

EDIT: Or killbox? http://www.killbox.net/

We want to somehow download & install Process Explorer http://www.filehippo.com/download_process_explorer/
If so you need to rename procexp.exe to explorer.exe then you should be able to open this tool.
If you find a way Process Explorer is immune to this infection as log as it is renamed.

ETD has logged off so can add here.

Right clicked the icon for total security, open the properties, and look at where the .exe file is located. It probably has a numbered file folder "xxxxxxx". Look inside the folder & find the Icon with a xxxxx.exe file. Chang the last number in the folder and exe file. Reboot your PC. The PC might/should come up to where you can run Malwarebytes.
__________________
Are your programs up to date? Check out this freebie * FileHippo Update Checker
Quote:
What is it?
The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases. These are then neatly displayed in your browser for you to download. Please note that not all programs are supported.
http://www.filehippo.com/updatechecker

Last edited by Curdled_Pus; November 4th, 2009 at 04:35 PM..
Curdled_Pus is offline   Reply With Quote
Old November 4th, 2009, 04:36 PM   #13 (permalink)
EMPIRE
 
EATTHEDEAD's Avatar
 
Join Date: Jan 2007
Location: Saving money on car insurance.
Posts: 3,254
I registered at Bleeping Computer and am waiting for a response to my queries. I am going to try what you suggested C_P and will get back to you. Thank you for all of your help. I WILL beat this motherfucker into submission! BTW, using AVG free, latest version. It also tells me that Windows Media Player is infected and won't let it open.
__________________
"If its true that our species is alone in the universe, then I'd have to say the universe aimed rather low and settled for very little" -- George Carlin (1937-2008)

Last edited by EATTHEDEAD; November 4th, 2009 at 04:38 PM..
EATTHEDEAD is offline   Reply With Quote
Old November 4th, 2009, 04:46 PM   #14 (permalink)
Moderator
 
Curdled_Pus's Avatar
 
Join Date: May 2009
Location: In the Freezer with Your Dead EX
Posts: 3,425
Arrow

What, you so stressed out you need to listen to some relaxing music? Lol
__________________
Are your programs up to date? Check out this freebie * FileHippo Update Checker
Quote:
What is it?
The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases. These are then neatly displayed in your browser for you to download. Please note that not all programs are supported.
http://www.filehippo.com/updatechecker
Curdled_Pus is offline   Reply With Quote
Old November 4th, 2009, 04:50 PM   #15 (permalink)
EMPIRE
 
EATTHEDEAD's Avatar
 
Join Date: Jan 2007
Location: Saving money on car insurance.
Posts: 3,254
Quote:
Originally Posted by Curdled_Pus View Post
What, you so stressed out you need to listen to some relaxing music? Lol
If the PC would allow it LOL. I'm going through the hoops to get into an online college and the last thing I need right now is a computer that is retarded.
__________________
"If its true that our species is alone in the universe, then I'd have to say the universe aimed rather low and settled for very little" -- George Carlin (1937-2008)
EATTHEDEAD is offline   Reply With Quote
Reply

Bookmarks

Tags
fucking, virus

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Forum Jump


Visit Recoveryandsupport.com

All times are GMT -4. The time now is 11:09 PM.

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 ©2008, Crawlability, Inc.