Virus Attack! (invasion continues :P)

mohd.itqan

Right off the assembly line
Since I am not able to access my earlier thread for for odd reason : *www.thinkdigit.com/forum/software-q/168401-virus-attack.html , after contacting admin and waiting for more than 12-13 hours (i think), I thought I should create a new thread instead. Retrieving data from cached copy, heres the previous discussion:

Original problem:
My PC (Win XP SP2 32bit) is infected by a some virus which doesn't let me install antivirus, I tried installing kaspersky and NOD32 but installation failed. It has also somehow blocked my Internet (tata docomo gprs) and it turns off windows firewall some time after windows start, I tried using Kaspersky Virus removal tool & Microsoft malicious software removal utility but they are not able to detect it. Previously I had avast running on my pc but virus messed up with some component and my computer would hang as soon as windows would start, due to which I had to remove it (via safe mode) and my windows has been hijacked by this program ever since then.
Can anyone please tell me how to get rid of this thing?
There seems to be quite a bit tools on kaspersky's website but I am not able to understand which one use?
Virus-fighting utilities


doomgiver said:
follow these steps :

1. download Hiren's bootCD from here :
*thepiratebay.se/torrent/7946..._CD_full_xp_w7
2. burn to CD/DVD
3. boot from it OR run HBCDMenu.cmd from the disk.
4. run Startup > HijackThis.
5. Click "system scan and save logfile"
6. grab the logfile from its location and upload it/copy contents here.

try and boot into 'safe mode', when running HBCDMenu.cmd

^ im doing this to know what sort of "virus" is in your PC.

after this, i will give you detailed steps to follow. can you do that?

I tried to use Hijack this on the infected XP and it generated this log:
PasteAll.org

Also here are logs from Spybot search and destroy (scan and startup items):
PasteAll.org
PasteAll.org

Downloading that CD would a bit difficult task since it around 700 MB in size, If you can please try to find something from these logs it would be awesome :p , otherwise i'll try to get it downloaded later. :)

@Naxal: thank you, I think that would be the last resort. :/
 

whitestar_999

Super Moderator
Staff member
GMER - Rootkit Detector and Remover
if there is a rootkit on your system which i suspect then don't waste your time & full format(not quick format) the C drive because fully removing a sophisticated rootkit is not possible without advanced level knowledge of debugging windows system exe's,dll's & assembly language(toughest & fundamental computer language).
 

pranav0091

I am not an Owl
Boot from a linux live CD, download Hijack this and process explorer and some antivirus of your choice, say the Kaspersky trial version. Copy them to a USB drive and boot into Windows. Run process explorer and post the screenshot here.


Edit:
I checked the logs.

Uninstall all existing anti-virus and restart pc.

Run process explorer like I mentioned and suspend (NOT kill) the following processes (right click on the required process > suspend):
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\NCLAUNCH.EXe
C:\Program Files\Messenger\msmsgs.exe (thanks doomgiver, I missed this one :) )

Now reinstall with anti-virus you downloaded earlier and scan the pc with it. If you are asked to restart the pc, do it and follow the step above (suspend). Now scan the pc. That should do it.
If it were me, I'd prefer to remove the virus manually as it helps you know things better. But if you are not comfortable with it, use an anti-virus.
 
Last edited:

doomgiver

Warframe
this looks suspicious :
C:\Program Files\Messenger\msmsgs.exe
VERY suspicious :
C:\WINDOWS\NCLAUNCH.EXe

did you install zonealarm before or after this "virus" happened?

also, your startup items are filled with garbage that is only slowing down your startup speed.
does your system take more then 2 minutes to bootup?
 

Zangetsu

I am the master of my Fate.
My PC (Win XP SP2 32bit) is infected by a some virus which doesn't let me install antivirus, I tried installing kaspersky and NOD32 but installation failed. It has also somehow blocked my Internet

just download escan scanning tool (mwav.exe) from its website..and run the tool it will run in a sandbox environment & will remove all viruses
 
OP
M

mohd.itqan

Right off the assembly line
GMER - Rootkit Detector and Remover
if there is a rootkit on your system which i suspect then don't waste your time & full format(not quick format) the C drive because fully removing a sophisticated rootkit is not possible without advanced level knowledge of debugging windows system exe's,dll's & assembly language(toughest & fundamental computer language).
Tried this tool, it is not able to detect that virus. I am thinking of formating but i am worried virus may come back if its hiding in system volume information of other drives. Anyways thank you.

I was thinking are there any potential dangers of deleting system volume information folder of all drives? Can it lead to XP mistaking them for free space leading to loss in data?
I remember once 3 partitions of my XP had disappeared after a reformat, but I am not sure that could have happened due to deleting "system volume information" folder?


Boot from a linux live CD, download Hijack this and process explorer and some antivirus of your choice, say the Kaspersky trial version. Copy them to a USB drive and boot into Windows. Run process explorer and post the screenshot here.


Edit:
I checked the logs.

Uninstall all existing anti-virus and restart pc.

Run process explorer like I mentioned and suspend (NOT kill) the following processes (right click on the required process > suspend):
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\NCLAUNCH.EXe
C:\Program Files\Messenger\msmsgs.exe (thanks doomgiver, I missed this one :) )

Now reinstall with anti-virus you downloaded earlier and scan the pc with it. If you are asked to restart the pc, do it and follow the step above (suspend). Now scan the pc. That should do it.
If it were me, I'd prefer to remove the virus manually as it helps you know things better. But if you are not comfortable with it, use an anti-virus.

Tried what you said, but its not working, again when I try to instally any antivirus system crashes and restarts towards the end of installation. Maybe Virus could be hiding in svchost.exe? :tired:

Heres the screenshot of process explorer (after exit few programs like flashget, skype,etc to make list small:
*www.pasteall.org/pic/show.php?id=43022

Anyways Thank you.

this looks suspicious :
C:\Program Files\Messenger\msmsgs.exe
I think thats windows messenger running in background.

VERY suspicious :
C:\WINDOWS\NCLAUNCH.EXe

did you install zonealarm before or after this "virus" happened?

also, your startup items are filled with garbage that is only slowing down your startup speed.
does your system take more then 2 minutes to bootup?

Yes, I had installed zonealarm after the virus thing happened, yeah I know theres too much startup garbage atm. :p Yes it taking quite a bit time to start 3-4 mins.

Thank you.

just download escan scanning tool (mwav.exe) from its website..and run the tool it will run in a sandbox environment & will remove all viruses
Thanks I'll try to download it.
 

whitestar_999

Super Moderator
Staff member
system volume information folders usually contain restore points data.download & install kaspersky IS 2013 on another pc & save it on a formatted & scanned pendrive.full format your C drive & install xp(i recommend win 7 though as it is much better unless your system is single core/less than 1 gb ram).disconnect any lan/internet connection while installing & immediately after install connect pen drive & open it from address bar of explorer(not double click/right click pen drive icon in my computer) & launch kaspersky setup.once installed connect net connection & activate trial version & start updating it.it will take ~1 hour on a 256kbps connection & after that start scanning your entire hard disk/full scan.
 

doomgiver

Warframe
yeah I know theres too much startup garbage atm. :p Yes it taking quite a bit time to start 3-4 mins.

1. press WIN+R
2. enter "msconfig"
3. click "startup" tab
4. remove the following entries :

C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
E:\Program Files\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Messenger\msmsgs.exe
D:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe

its totally safe to disable these programs, because they reduce startup time.

also, if you use a program right from the system start, you can leave that enabled (eg, you might need skype as soon as you start the computer, so dont uncheck it)

i use windows 7, no antivirus/firewall, and with minimum services.
i only have the audio (realtek RTHDVCPL.exe), video (AMD catalyst), unlocker assistant, launchy, steam and daemon tools as startup, and my computer boots to full desktop in less than 30 seconds.

if your computer is booting in more than 2 minutes, and you are on decent hardware (dual core and above, 1+ gb ram), then something is definitely wrong with your windows startup.
 
OP
M

mohd.itqan

Right off the assembly line
Ok I have decided to full format my C:/ and reinstall XP, I am thinking of deleting the other potential hiding places of virus in other drives [via ubuntu linux live cd im currently using], So I want to ask:

1. Is it safe to delete "System Volume information" folder?
2. Any other folder I should delete?
3. Anyone know what is this khw (maybe its a text file since it open with text editor but doesn't have any data)?

*www.pasteall.org/pic/show.php?id=43190

Thank you.
 

CyberKID

In search for Tech Gyan!
Saw your logs. It is a difficult task to identify all the processes running on your system except some common tasks, unless someone knows what programs are installed on your system. Some advanced viruses inject the code in system files like the pagefile.sys or hiberfile.sys, which makes it very difficult to remove or to identify as most, if not all, antivirus programs do ignore these files when scanning for viruses.
I understand that you are unable to install some antiviruses. and probably this won't work either, but, I'll suggest give this a try.

1. Disable Windows Paging File (Also known as Virtual Memory). Control Panel > System > Under System Properties, select the tab Advanced >Under Performance, click Settings> Select Advanced tab and then under Virtual Memory, click on the button "Change", and then select the option "No Paging File". Doing this will remove the system protected pagefile.sys (one possible hiding location of the virus/trojan/worm).
2.If you have Hibernation enabled, Go to Power Options, under control panel, Click on the tab named "Hibernate" and uncheck the "Enable Hibernation" check box. This will do away with the other possible hideout of the virus (hiberfile.sys).
3. Once done with these, download a small utility named Unlocker from UNLOCKER 1.9.1 BY CEDRICK 'NITCH' COLLOMB and install it.
4. Now, try to unhide the hidden files from Folder Options. This will show you some hidden files and folders(Just be informed that there are a few important system files which are very important for system's integration, which, if deleted might corrupt your system altogether - Files named like ntdetect, ntldr, autoexec.bat, boot.sys, boot.inf, etc are a few) file as well as the autorun.inf file in your C drive. Try deleting autorun.inf, with unlocker running in the background and the process creating/accessing this particular file, would stop windows explorer from deleting this file and in a few seconds unlocker would present an option with the culprit process.
5. You unfortunately did remove Avast, whose Boot Time Scan comes in pretty handy in such scenarios. Even if it isn't able to run on the system due to the virus infection, you can actually schedule a boot time scan using the command line utility, by running cmd.exe as a user with Administrator rights, navigating to the location where avast is installed, usually C:/Program Files/Avast Software/Avast using CD command, then type sched.exe /A:* which specifies the application to schedule a boot time scan and /A: - defines the area to scan for the viruses, while * specifies it to scan all the drives.
6. Try installing Avast again, if possible, and schedule a boot time scan if you're successful in installing it. That'll help you avoid the pain of formatting your HDD.
 

Minion

Conversation Architect
why don't you download Dr web rescue Disk burn it boot form cd and scan.
LINK
Download Dr.Web LiveCD 6.0.2 Free - Emergency System Recovery Disk - Softpedia
 
Top Bottom