ClanKiller.com https://forums.clankiller.com/ |
|
Possible a very weird windows virus https://forums.clankiller.com/viewtopic.php?f=8&t=2486 |
Page 1 of 1 |
Author: | RB [ Sat Aug 04, 2007 11:51 am ] |
Post subject: | Possible a very weird windows virus |
Yesterday my firewall started noticing that every EXE file that passes his diff control has been changed. Funny thing about that was that some of these programs that are well known (Firefox, Skype, DAP) seemed to work properly, while some less known (qip, x-chat) simply refused to work and some of them even reported corruption of EXE file. When even explorer process started to bug, forcing me to kill and restart it from time to time, I reinstalled windows today. Well, that wasn't the end of the story. Short after the reinstallation has been done (full reinstallation, HDD formated), the same thing started occurring again, not even letting me time to reinstall all the software. This is weird since I never had problems with viruses. I don't even have an antivirus or I ever needed it. This windows installation I have I dunno since when and it never 'hooked' anything. Well, now it obviously gets some really bad plague, and it gets it very fast and automatically. Now I'm trying to figure out what happens. I isolated an example of a corrupted and non-corrupted file, am downloading some free antiviruses, will do some checks and if nothing works I will switch to a linux distribution, till I figure out what is fucking going out here. Well it IS something going out when a fresh installed version of XP gets infected by simple surfing on wikipedia, clankiller, my site and google again and again. Will report later. |
Author: | Mole [ Sat Aug 04, 2007 12:04 pm ] |
Post subject: | Re: Possible a very weird windows virus |
Author: | RB [ Sat Aug 04, 2007 12:26 pm ] |
Post subject: | Re: Possible a very weird windows virus |
Author: | RB [ Sat Aug 04, 2007 1:09 pm ] |
Post subject: | |
Okay aftermath here. I am amazed how it succeeded to infect a zillion of files within just about 8 hours, which is how long this windows installation lives. I deleted it everywhere antivirus had found it and am doing some additional scans. I will be looking for the reason why it actually had happened. I have some assumptions but won't do/tell anything before I am sure. (it is always hard to point anywhere) Damage: huge. Almost all EXE files removed from the computer. Many programs to be reinstalled. It is an irony that it even destroyed my instance of borland c++ compiler, which was used to finalize it (yes, this virus has been finalized in bcc32). As well, I had a ROFLMAO when I saw the virus infected even my own 3D engine executable. I hate the bastard who has made it, that's sure. Anyway, the myth about how I do not need an antivirus has been busted. For now I will definitely keep this AVG for it has done a good job. |
Author: | RB [ Sat Aug 04, 2007 1:26 pm ] |
Post subject: | |
One more weird fact. Just the last night I had a dream where my computer started to shut down over and over again, till in the end I got a spooky message "bring your mech to the neurosurgery, you idiot" with an ugly smiley over the whole screen. Duh, sixth sense? |
Author: | Satis [ Sun Aug 05, 2007 10:13 am ] |
Post subject: | |
lol...pretty good dream. Regarding the issue, yea, definetely sounds like your Lan is the culprit. Probably used some xp exploit to get file system access and begin replicating itself. I actually watched a virus copy itself into a share folder I had open... freaked me out. Anyway, good job kicking its ass. AVG is indeed a decent AV product, especially considering the price. I keep it loaded and running. |
Author: | RB [ Sun Aug 05, 2007 10:27 am ] |
Post subject: | |
What I've read about Parite doesn't imply it is capable of sneaking through network. So someone had to infiltrate it here and initiate the first run (not that hard I suppose, since I'm windows user). BitComet is the other possibility since it has its flaws too. The firefox and the programs that I ran ain't an option as I wasn't downloading anything that could have carried the virus (exe/scr files) in the evening I got it. I was just watching a movie and went early to bed as the problems started occurring. In the end.. it's gone. |
Page 1 of 1 | All times are UTC - 6 hours |
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group http://www.phpbb.com/ |