Tech ARP Forums

Go Back   Tech ARP Forums > Software Discussion > General Software
Register
FAQ Members List Calendar Arcade Mark Forums Read

Google Web www.techarp.com forums.techarp.com

General Software This is the forum for general discussions about software.

Reply
 
LinkBack Thread Tools
Old 5th Jun 2007, 12:42 PM   #1 (permalink)
Super Active
 
cypris's Avatar
 
Join Date: 21 Feb 2005
Location: Tropicana~
Posts: 1,792
Reputation: 2878
cypris has a reputation beyond reputecypris has a reputation beyond reputecypris has a reputation beyond reputecypris has a reputation beyond reputecypris has a reputation beyond reputecypris has a reputation beyond reputecypris has a reputation beyond reputecypris has a reputation beyond reputecypris has a reputation beyond reputecypris has a reputation beyond reputecypris has a reputation beyond repute
Rep Power: 35
Exclamation ATTACKED BY CHINESE SPYWARE!!!

I had a VERY VERY BAAD experience last night when I connected my USB thumbdrive to my PC. I've been using this thumbdrive to transport my college work and progress to and from college pcs to my home pc. Now, I normally scan my thumbdrive first but most of the time if it is infected, either norton or spyware doctor will immediately prompt me upon auto-running the thumbdrive that it is infected yadayadayada.

But because I was in a bit of a rush last night I accidentally opened the uUSB drive without scanning it first and as I permanently put my folder settings to view hidden files I saw two very-obviously-not-my-files and they're very obviously spyware/worms.

What I didn't expect was that none of the american anti virus / anti spyware programs could not detect / could not remove it. Worst still, it wasn't just ONE worm , it was several malicious keyloggers, trojans and browser hijackers all packed in one.

It spawned into all 5 of my drives!! You wouldn't even believe the number of keylogs it created! I could not even remove any of them, restarting and trying to go into safe mode only ended in getting the blue screen. The virus totally prevented me from going into safe mode.

The reason why none of the american antivirus/spyware products that I have did not respond to it is because the shit that was in my thumbdrive was written in Chinese and obviously by Chinese!! None of the softwares even have logs of this spyware/virus in their websites. And the stupidest thing is I happen to get infected by a very new virus that only launched on th 29th of 28th of May.

When I googled the names of the viruses, only chinese websites and forums turned up, and unfortunately for me, I can't bleeding read chinese if my life depended on it. So had to use the Alta-Vista Babelfish Translator and try to make sense of the direct and more often than not wrong translations.

Oh and another thing, it screwed up my time and sent it back to year 1899 or something like that and it renders the folder option to view hidden files useless. So can't see any of the hidden files at all.

This morning I ran norton antivirus and spyware doctor and lavasoft ad-aware and I found that I still had the Trojan viruses (89 hits on Spyware Doctor)

I'M GOING NUTS!! I NEED HELP!!!! ARGH!!!
Someone translate those instructions from chinese to english on how remove these evil things for my precious pc!

The names of the viruses are:
Trojan.PWS.QQRob.V
Trojan.Agent.ABF

mal-Files:
wocfiba.exe
gnkjkrl.exe
__________________
|| AMD X2 5000 BE @ 3.1 || 4GB DDR2 || K9N || 9600GT ||
|| 2x320GB WD|| 200GB Maxtor || 1TB WD || 250GB Maxtor ||
|| Dell 2007WFP|| Dell 1707FP || CM5 || VS4121 ||
cypris is offline   Reply With Quote
SPONSOR
Old 5th Jun 2007, 01:38 PM   #2 (permalink)
zy
zynine.com
 
zy's Avatar
 
Join Date: 16 Dec 2002
Location: Buffalo NY
Posts: 13,496
Reputation: 2276
zy has a reputation beyond reputezy has a reputation beyond reputezy has a reputation beyond reputezy has a reputation beyond reputezy has a reputation beyond reputezy has a reputation beyond reputezy has a reputation beyond reputezy has a reputation beyond reputezy has a reputation beyond reputezy has a reputation beyond reputezy has a reputation beyond repute
Rep Power: 43
Default

u need to terminate a lot of suspicious processes first
then go through your autorun list to disable lots of suspicious stuffs
then run full system scan

i usually use Sysinternals Autorun & process explorer
__________________

zy is online now   Reply With Quote
Old 5th Jun 2007, 01:46 PM   #3 (permalink)
ARP Webmaster
 
peaz's Avatar
 
Join Date: 13 Oct 2002
Location: http://atpeaz.com/
Posts: 8,595
Reputation: 1673
peaz has a brilliant futurepeaz has a brilliant futurepeaz has a brilliant futurepeaz has a brilliant futurepeaz has a brilliant futurepeaz has a brilliant futurepeaz has a brilliant futurepeaz has a brilliant futurepeaz has a brilliant futurepeaz has a brilliant futurepeaz has a brilliant future
Rep Power: 32
Default

Ouch this usually sucks. Hmmm

You'd definitely need to go into safe mode and try to kill/delete all the suspicious stuff. You'd also have to explore the registry to remove the suspicious looking startup apps. It helps to have a notebook or another PC to check the exes listed to see if they are legit or not.
__________________
Ken Ng
Tech ARP
Follow me at Twitter
Blogs @ http://www.atpeaz.com/
peaz is offline   Reply With Quote
Old 5th Jun 2007, 03:21 PM   #4 (permalink)
Da Boss
 
Join Date: 10 Oct 2002
Location: In front of my ASUS F8V notebook!
Posts: 33,150
Reputation: 3730
Adrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond repute
Rep Power: 78
Default

Hmm.. IMHO, the best way would be to use a SECOND PC, one that's loaded with the latest antivirus definitions. Then use this PC to scan and clean your infected hard drives.

Loading your current operating system, even in safe mode, will not help. They will almost certainly still load up. Safest way would be to use another PC to do the cleaning job.

Alternatively, install another hard drive, install a new OS and antivirus software and then boot up using that hard drive to scan your infected hard drives. The point is to boot up with a clean OS and run an updated antivirus software to clean your infected hard drives.
__________________
Dr. Adrian Wong
Tech ARP | Blog @ Tech ARP | The Free Trade Zone


DYKT : The only offshore account I have is at the sand bank?

We need PROGRAMMERS and TECHNICAL WRITERS! Contact us if you are a hot shot programmer or technical writer!

My items for sale : 50x SD Card | Memory Stick PRO | Cyclone Energy Saver | Seiko SS watch | Tiger/Carlsberg beer jugs | Travel Speakers | Motorola V600 | Nokia N90 SOLD! | New Lowepro Mini Trekker AW

Other items for sale @ the FTZ : Zalman CNPS9500 LED @ $20 | Zalman CNPS7700 Cu @ $20 | Zalman CNPS7000 Cu @ $20 | Swarovski bracelet watches | Dell 17" LCD | Hi-Fi speakers | English DIVX movies | HP LaserJet toners! | Office chairs
Adrian Wong is offline   Reply With Quote
Old 5th Jun 2007, 03:32 PM   #5 (permalink)
Super Active
 
cypris's Avatar
 
Join Date: 21 Feb 2005
Location: Tropicana~
Posts: 1,792
Reputation: 2878
cypris has a reputation beyond reputecypris has a reputation beyond reputecypris has a reputation beyond reputecypris has a reputation beyond reputecypris has a reputation beyond reputecypris has a reputation beyond reputecypris has a reputation beyond reputecypris has a reputation beyond reputecypris has a reputation beyond reputecypris has a reputation beyond reputecypris has a reputation beyond repute
Rep Power: 35
Default

Problem is, the trojan wont allow you to boot into safe mode. A blue screen will appear once Safe Mode is selected.
__________________
|| AMD X2 5000 BE @ 3.1 || 4GB DDR2 || K9N || 9600GT ||
|| 2x320GB WD|| 200GB Maxtor || 1TB WD || 250GB Maxtor ||
|| Dell 2007WFP|| Dell 1707FP || CM5 || VS4121 ||
cypris is offline   Reply With Quote
Old 5th Jun 2007, 03:38 PM   #6 (permalink)
I'm a regular
 
sherwin's Avatar
 
Join Date: 15 Oct 2003
Location: Penang <> KL
Posts: 294
Reputation: 2143
sherwin has a reputation beyond reputesherwin has a reputation beyond reputesherwin has a reputation beyond reputesherwin has a reputation beyond reputesherwin has a reputation beyond reputesherwin has a reputation beyond reputesherwin has a reputation beyond reputesherwin has a reputation beyond reputesherwin has a reputation beyond reputesherwin has a reputation beyond reputesherwin has a reputation beyond repute
Rep Power: 28
Default

For every attempt to kill it, it will add 30-40 registry entries.. and respawn itself. And this trojan will infect all your drives, it copies an autorun.inf & exe file with hidden attributes. After which it will then mess up your registry so that the Show or Hide all hidden files in XP is disabled.

Took an hour and a half to manually delete the registry entries, disable autoplay and ran a batch script to kill & force delete the exe file.
__________________
sherwin is offline   Reply With Quote
Old 5th Jun 2007, 04:24 PM   #7 (permalink)
Da Boss
 
Join Date: 10 Oct 2002
Location: In front of my ASUS F8V notebook!
Posts: 33,150
Reputation: 3730
Adrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond repute
Rep Power: 78
Default

Quote:
Originally Posted by cypris View Post
Problem is, the trojan wont allow you to boot into safe mode. A blue screen will appear once Safe Mode is selected.
EXACTLY. That's why you need a CLEAN PC.
__________________
Dr. Adrian Wong
Tech ARP | Blog @ Tech ARP | The Free Trade Zone


DYKT : The only offshore account I have is at the sand bank?

We need PROGRAMMERS and TECHNICAL WRITERS! Contact us if you are a hot shot programmer or technical writer!

My items for sale : 50x SD Card | Memory Stick PRO | Cyclone Energy Saver | Seiko SS watch | Tiger/Carlsberg beer jugs | Travel Speakers | Motorola V600 | Nokia N90 SOLD! | New Lowepro Mini Trekker AW

Other items for sale @ the FTZ : Zalman CNPS9500 LED @ $20 | Zalman CNPS7700 Cu @ $20 | Zalman CNPS7000 Cu @ $20 | Swarovski bracelet watches | Dell 17" LCD | Hi-Fi speakers | English DIVX movies | HP LaserJet toners! | Office chairs
Adrian Wong is offline   Reply With Quote
Old 5th Jun 2007, 04:25 PM   #8 (permalink)
Da Boss
 
Join Date: 10 Oct 2002
Location: In front of my ASUS F8V notebook!
Posts: 33,150
Reputation: 3730
Adrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond repute
Rep Power: 78
Default

Quote:
Originally Posted by sherwin View Post
For every attempt to kill it, it will add 30-40 registry entries.. and respawn itself. And this trojan will infect all your drives, it copies an autorun.inf & exe file with hidden attributes. After which it will then mess up your registry so that the Show or Hide all hidden files in XP is disabled.

Took an hour and a half to manually delete the registry entries, disable autoplay and ran a batch script to kill & force delete the exe file.
Hmm.. Personally, I would just use a second PC to clean up the hard drive. The registry entries will still be there, but at least the infecting binaries will be removed. You can clean up the registry later on.
__________________
Dr. Adrian Wong
Tech ARP | Blog @ Tech ARP | The Free Trade Zone


DYKT : The only offshore account I have is at the sand bank?

We need PROGRAMMERS and TECHNICAL WRITERS! Contact us if you are a hot shot programmer or technical writer!

My items for sale : 50x SD Card | Memory Stick PRO | Cyclone Energy Saver | Seiko SS watch | Tiger/Carlsberg beer jugs | Travel Speakers | Motorola V600 | Nokia N90 SOLD! | New Lowepro Mini Trekker AW

Other items for sale @ the FTZ : Zalman CNPS9500 LED @ $20 | Zalman CNPS7700 Cu @ $20 | Zalman CNPS7000 Cu @ $20 | Swarovski bracelet watches | Dell 17" LCD | Hi-Fi speakers | English DIVX movies | HP LaserJet toners! | Office chairs
Adrian Wong is offline   Reply With Quote
Old 5th Jun 2007, 04:59 PM   #9 (permalink)
Active
 
Join Date: 3 Mar 2005
Posts: 525
Reputation: 335
jamotto is a jewel in the roughjamotto is a jewel in the roughjamotto is a jewel in the roughjamotto is a jewel in the rough
Rep Power: 9
Default

Would it be possible to use a linux live cd or one of the many emergency boot CD's that one can find on the internet to clean the pc?
jamotto is offline   Reply With Quote
Old 5th Jun 2007, 05:38 PM   #10 (permalink)
Hold me back! I can't stop posting!!!
 
Join Date: 16 Dec 2002
Location: Floating Island Of Mandango
Posts: 8,810
Reputation: 3294
ZuePhok has a reputation beyond reputeZuePhok has a reputation beyond reputeZuePhok has a reputation beyond reputeZuePhok has a reputation beyond reputeZuePhok has a reputation beyond reputeZuePhok has a reputation beyond reputeZuePhok has a reputation beyond reputeZuePhok has a reputation beyond reputeZuePhok has a reputation beyond reputeZuePhok has a reputation beyond reputeZuePhok has a reputation beyond repute
Rep Power: 48
Default

ohh.. 完全被拥有

the best is follow the method suggested by adrian.
safer..
__________________
my motto: poison first, think later.
ZuePhok is offline   Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
The Emergency Spyware Removal Guide TEB General Software 13 9th Jul 2008 01:09 PM
Spyware takes aim at Mozilla browsers! Dashken News 11 5th Mar 2008 07:03 PM
Different Chinese groups in Malaysia Falcone Lounge 60 7th Sep 2004 10:46 PM


All times are GMT +8. The time now is 01:57 AM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0
Copyright © 1998-2009 Tech ARP. All rights reserved.