» Site Navigation | | | » Advertisement | | | » Recent Threads | | | Journaling 11-17-2009 06:53 PM Today 08:38 PM 4 Replies, 45 Views | | | SO GOOD Today 08:27 PM Today 08:33 PM 7 Replies, 29 Views | | | |  | |  | -_- i got hit... |  |
07-11-2009, 10:46 PM
|
#1 (permalink)
| ohai
Join Date: May 2009 Location: E meja eh ouin byhdc Age: 20 Posts: 1,184
GPoints: 7,248 Rep Power: 5 | -_- i got hit... My computer is so full of Trojans and malware that it can't even download a anti-virus program. If you want the list, i got hit by: Trojan-Dropper.Win32.Agent.albv
Wipes out all protection, and disables downloads.
Terminates these:
avesvc.exe
ashdisp.exe
avgrsx.exe
bdss.exe
spider.exe
avp.exe
nod32krn.exe
cclaw.exe
dvpapi.exe
ewidoctrl.exe
mcshield.exe
pavfires.exe
almon.exe
ccapp.exe
pccntmon.exe
fssm32.exe
issvc.exe
vsmon.exe
cpf.exe
ca.exe
tnbutil.exe
avp.exe
mpfservice.exe
npfmsg.exe
outpost.exe
tpsrv.exe
pavfires.exe
kpf4ss.exe
persfw.exe
vsserv.exe
smc.exe It also attempts to disable the following services associated with antivirus and firewall programs:
AntiVir
Avast Antivirus
AVG Antivirus
BitDefender
Dr.Web
Kaspersky Antivirus
Nod32
Norman
Authentium Antivirus
Ewido Security Suite
McAfee VirusScan
Panda Antivirus/Firewall
Sophos
Symantec/Norton
PC-cillin Antivirus
F-Secure
Norton Personal Firewall
ZoneAlarm
Comodo Firewall
eTrust EZ Firewall
F-Secure Internet Security
Kaspersky Antihacker
McAfee Personal Firewall
Norman Personal Firewall
Outpost Personal Firewall
Panda Internet Seciruty Suite
Panda Anti-Virus/Firewall
Kerio Personal Firewall
Tiny Personal Firewall
BitDefender / Bull Guard Antivirus
Sygate Personal Firewall
The Trojan also harvests passwords to web sites saved to the cache of the browsers shown below:
Mozilla FireFox
Internet Explorer
It also harvests passwords and account data for the following IM clients:
Trillian
Miranda
Yahoo Messenger
MySpace IM
Gaim
This is one of the worst viruses you can ever get, so be
careful of your downloads. Trojan-Downloader.Win32.Kido.a
Pretty much self explanatory, enables downloads of Trojans without the computer owner's consent.
I had thought that my anti-virus was real, but in actuality it was a backdoor file, so basically i was hacked from the beginning.
Even system recovery doesn't work. I'm going to get a professional out here, cuz im not qualified to remove it.
I would suggest you be careful with what you download, cuz i don't think you want to end up with a hacker finding all your passwords and shit.
Don't have Firefox or IE save your passwords, cuz you never know where the virus might strike.
If you have any way i might get my computer back up, please tell me so, cuz its pretty much dead. Youtube doesn't work, playlist doesn't, and pretty much anything flash online doesn't work. The First virus is the worst one i've gotten before. | |
| |  |
07-11-2009, 10:50 PM
|
#2 (permalink)
| zombie wants mah brehns.
Join Date: Jun 2008 Age: 17 Posts: 3,348
GPoints: 443 Rep Power: 14 | Ehh, reformat it and reinstall your OS?
__________________
Quote: |
Originally Posted by Queen Bex 'RUZZEH, YOUR VAGINA IS ON FIRE AND NEEDS TO BE HOSED DOWN BY MY TONGUE' | | |
| |
07-11-2009, 10:54 PM
|
#3 (permalink)
| ohai
Join Date: May 2009 Location: E meja eh ouin byhdc Age: 20 Posts: 1,184
GPoints: 7,248 Rep Power: 5 | can't. reformat just fucks it up even more. and the OS software? computer isnt accepting it. says that "content is not safe, please download from this site." and then lists some Trojan infected site. I actually had to switch to firefox just to use anything at all. IE7&8 do not work on my computer at all. I have to get a new harddrive and shit. after i do that, im making my own anti-virus, cuz this is fucking ridiculous. | |
| |
07-11-2009, 11:04 PM
|
#4 (permalink)
| Banned
Join Date: May 2008 Posts: 198
GPoints: 1,682 Rep Power: 0 | flamespiritzenon, you make me lol too much.
reformat shouldn't make the computer's condition worse, reformatting is basically wiping the computer's slate clean so you shouldn't really have any problems!!
maybe are you confusing system restore with reformatting? | |
| | | The Following User Says Thank You to Andrew For This Useful Post: | |
07-11-2009, 11:04 PM
|
#5 (permalink)
| zombie wants mah brehns.
Join Date: Jun 2008 Age: 17 Posts: 3,348
GPoints: 443 Rep Power: 14 | Yeah, system restore is virtually useless against the newer trojans.
__________________
Quote: |
Originally Posted by Queen Bex 'RUZZEH, YOUR VAGINA IS ON FIRE AND NEEDS TO BE HOSED DOWN BY MY TONGUE' | | |
| |  | |  |
07-12-2009, 12:06 AM
|
#6 (permalink)
| Full Member
Join Date: Jun 2009 Location: In a land far, far away, long, long ago... you know the rest Posts: 374
GPoints: 3,026 Rep Power: 3 | Use any of these bootable anti virus programs, download, burn to cd, boot up with it and scan your system:
Trinity Rescue Kit, contains 4 anti virus engines: ClamAV, AVG, F-Prot, BitDefender Trinity Rescue Kit | CPR for your computer
Avira AntiVir Removal Tool Avira AntiVir Removal Tool
Bitdefender Rescue CD Index of /rescue_cd
Both links below are same place, just different mirror
Kaspersky Rescue Disk Index of /devbuilds/RescueDisk/ Index of /devbuilds/RescueDisk/
After you scanned and removed part, if not all of the crap created by the trojans, download a real anti virus from download.com. You can get Avira AntiVir, Avast!, AVG, Bitdefender or whatever one you prefer. Also get Malwarebyte's Antimalware, it'll find any of the more hard to find malware.
Conflicker, aka Kido, Downadup, probably needs to be thoroughly cleaned, if the antivirus program didn't remove it, use this to remove it: Troubleshooting
or Sophos Conficker Cleanup Tool - Free software downloads and reviews - CNET Download.com
Last edited by zts; 07-12-2009 at 12:10 AM..
| |
| |  |
07-12-2009, 12:54 AM
|
#7 (permalink)
| Full Member
Join Date: Jun 2009 Location: California Posts: 142
GPoints: 1,520 Rep Power: 2 | Why does it terminate all those processes? That would make it really obvious. And since it jacks your passwords, wouldn't it be smarter to make it undetectable as possible? But that's just me, not some hacker.
Yeah, reformat. Insert your disc into the drive. Boot from disc when you start up. Wipe your partition, make a new one. Format it, and reinstall the OS.
__________________ My Guides
The Delicate Art of Item Inflation (Read it!)
| |
| |
07-12-2009, 01:31 AM
|
#8 (permalink)
| Full Member
Join Date: Jan 2009 Posts: 562
GPoints: 6,456 Rep Power: 4 | Have you tried following the removal instruction on the link you posted? Quote:
If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:
1. Use Task Manager to terminate the malicious program’s process.
2. Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine).
3. Delete the following system registry key parameter: [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WSVCHO" = "%WinDir%\system\svhost.exe"
4. Delete the following file: %WinDir%\system\svhost.exe
5. Empty the temporary directory (%Temp%).
6. Delete the files shown below from all removable storage media: <X>:\autorun.inf
<X>:\wlan.exe,
with X being the disk
7. Update your antivirus databases and perform a full scan of the computer.
| | |
| |  |
07-13-2009, 02:10 PM
|
#9 (permalink)
| Full Member
Join Date: May 2009 Posts: 272
GPoints: 2,074 Rep Power: 0 | Reinstall you OS,Because I know A couple of them including spider.exe Cant Be Taken Off By Virus Protection
If You Can't Do That Try "ThiSwine41"'s Idea Very helpful
__________________
Peter What are you doing, Crack, WHAT THE FUCK, at least i'm not drinking Brian, yeah but this isnt exactlty A good substitute, Where'd you get crack, Blacks, What, Yeah right behind Blacks hardware store theres a White guy selling it ._.
| |
| |
07-14-2009, 01:51 PM
|
#10 (permalink)
| ohai
Join Date: May 2009 Location: E meja eh ouin byhdc Age: 20 Posts: 1,184
GPoints: 7,248 Rep Power: 5 | the main problem is that the file saved itself as a system32 file, and im not sure which one it is yet. cuz my sys32 folder is full of files. when i found one of these viruses a while back, it was semi-dormant, so i was able to quarantine my computer, but apparently i missed the backdoor one, and that's how the trojan dropper got on my computer. im about to wipe my harddrive, so i wont be on for a while. | |
| |  | | |
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | | | | Thread Tools | | | | Display Modes | Linear Mode |
Posting Rules
| You may not post new threads You may not post replies You may not post attachments You may not edit your posts HTML code is Off | | | |