Virus??

Ryansta

Senior Member
Joined
Nov 26, 2008
Messages
724
Hey guys
I've got a pc here at work thats being an idiot. It randomly crashes and restarts, It wont install anti-viruses and it wont install anti spyware. I've taken the hdd and scanned it in another pc with AVG 8 free, no viruses. I've stopped all services on start up(except windows one obviously). I've used advance system care to try fix broken registry, it found lots of probs and removed/fixed them, but theres no change. I've used hackthis and removed bad registries and nothing. Any thing else i could try?
 

wishblade

Senior Member
Joined
Jan 14, 2009
Messages
635
Sounds surprisingly similar to a rootkit issue I was investigating recently :) Do a rootkit scan using a proper scanner... :)
 

Ryansta

Senior Member
Joined
Nov 26, 2008
Messages
724
Tried the panda one but it stops the .exe as well. Cant do any scans:(
 

dablakmark8

Honorary Master
Joined
Feb 28, 2005
Messages
14,488
how does memtest work in this situation:D..its fubar:D
anyway lets try safe mode first
 

SuperAntMD

Expert Member
Joined
Apr 29, 2005
Messages
1,063
get a copy of ubuntu, run it off the livecd feature install avg or similiar and try scanning from there?
 

wishblade

Senior Member
Joined
Jan 14, 2009
Messages
635

SirFooK'nG

Executive Member
Joined
Feb 13, 2009
Messages
8,338
I had a similar virus just recently, couldnt update any apps online, not even ms updates. So I used another computer to download the "malicious file remover tool" from MS. Ran it and presto. Updated everything and scanned the crap out of my PC for two days!

By the way, the virus managed to infect my pc even though I have windows defender, ZoneAlarm Internet Security Suite and Netlimiter Pro Firewall enabled!
 

wishblade

Senior Member
Joined
Jan 14, 2009
Messages
635
By the way, the virus managed to infect my pc even though I have windows defender, ZoneAlarm Internet Security Suite and Netlimiter Pro Firewall enabled!

Could have been a new variant, or what I was thinking in the first place for the original issue: rootkit.

I did a technical read up on how the mebroot rootkit works, and I must say, it is pretty ingenious at staying under the radar. In simple terms, it performs a few tasks under the radar of AV scanners (no suspicions raised), and then when a reboot happens, it replaces your MBR with its own, which virtually means that it can do whatever it wants on your system without being detected. Pretty clever and obviously a lot of time went into designing it...
 

spiderz

Honorary Master
Joined
Mar 24, 2006
Messages
35,106
Load Ubuntu, the Virus is called "windows" :D
/me crawls back under my rock.
 
Top