Author Topic: Weird Virus  (Read 3351 times)

0 Members and 1 Guest are viewing this topic.

tdjw

  • Guest
Weird Virus
« on: December 31, 2007, 03:17:06 AM »
G'day all,

First and most important, Merry Christmas and a happy new year!

Last night I noticed a process called geeda.exe running on my machine. After deleting it, I've noticed that 4 processes have duplicated themselves and are using alot of memory, one being an avast one, ashdisp.exe. Msnmgr.exe, StyleXp.exe and Ctsysvol.exe and they multiply by putting a space at the end, like this ashdisp .exe while the original one still runs.

I've done 2 full thorough system scans, and have run spybot and nothing comes up, suggestions anyone?

Thanks,
Tim




Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Weird Virus
« Reply #1 on: December 31, 2007, 03:28:36 AM »
Yuo have a nasty, nasty version of vundo and you may have to consider backing up you improtant document etc. Developements in removal are on going.

I'll post the current prescribed approach in my next reply, so stick around.

tdjw

  • Guest
Re: Weird Virus
« Reply #2 on: December 31, 2007, 03:35:28 AM »
ok mate, thanks alot for your help

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Weird Virus
« Reply #3 on: December 31, 2007, 03:47:26 AM »
This is what's being used presently, but no guarantees

Download ComboFix from Here or Here to your Desktop.

Double click combofix.exe and follow the prompts.

When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall.


Download RenV from the link below

1. Save it to your Desktop.
2. Double-click RenV.exe
3. It shall produce a log for you. Please post that log in your reply.

http://download.bleepingcomputer.com/sUBs/Beta/RenV.exe


Using your left mouse drag Log.txt into RenV.exe, see image below.

When finished, it shall produce a new log for you. Post that log in your next reply along with the other logs.


do an online scan with kaspersy

http://www.kaspersky.com/service?chapter=161739400

Click on Kaspersky Online Scanner

You will be promoted to install an ActiveX component from Kaspersky, Click Yes.
The program will launch and then begin downloading the latest definition files:
Once the files have been downloaded click on NEXT

Now click on Scan Settings
In the scan settings make that the following are selected:
Scan using the following Anti-Virus database:
Extended (if available otherwise Standard)
Scan Options:
Scan Archives
Scan Mail Bases
Click OK
Now under select a target to scan:
Select My Computer
This will program will start and scan your system.
The scan will take a while so be patient and let it run.
Once the scan is complete it will display if your system has been infected.
Now click on the Save as Text button:
Save the file to your desktop.
Copy and paste or attach that information in your next post.

Note: pause or stop avast's standard shield during the scan, re-enable afterwards.


Try  not to restart or turn off your computer if possible, if combofix want to restart the computer let it. Also avoid opening programs and applications as we don't know which are effected.

You can download HJT from here

Click here to download HJTsetup.exe
  • Save HJTsetup.exe to your desktop.
  • Doubleclick on the HJTsetup.exe icon on your desktop.
  • By default it will install to C:\Program Files\Hijack This.
  • Continue to click Next in the setup dialogue boxes until you get to the Select Addition Tasks dialogue.
  • Put a check by Create a desktop icon then click Next again.
  • Continue to follow the rest of the prompts from there.
  • At the final dialogue box click Finish and it will launch Hijack This.
  • Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
  • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
  • Come back here to this thread and Paste the log in your next reply.
  • DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required.

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Weird Virus
« Reply #4 on: December 31, 2007, 04:28:11 AM »
I meant to mention you should post the RENV log before doing the second part of it, so you can be advised on editing the renv log.

To animate the image in the above post, click on it.

tdjw

  • Guest
Re: Weird Virus
« Reply #5 on: December 31, 2007, 04:53:54 AM »
Well, thanks for all the help anyway , but after running combofix, it rebooted and the virus must have been attached to something important as now my system won't boot. Luckily, thanks to oldman's advice i had backed up all my important files and nothing was lost.

Thanks for all your help, its been much appreciated.

Cheers,
Tim

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Weird Virus
« Reply #6 on: December 31, 2007, 06:22:36 AM »
I'm glad you had everything backed up. This thing is very nasty. This is the first time I heard of what happened to you. Hope you can get reformatted and your OS reinstalled. Just make sure you scan the h___ out of everthing you are going to restore.

As I mentioned, the removal strategy is being developed daily on the fly.