Calgarypuck Forums - The Unofficial Calgary Flames Fan Community

Go Back   Calgarypuck Forums - The Unofficial Calgary Flames Fan Community > Main Forums > The Off Topic Forum > Tech Talk
Register Forum Rules FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Search this Thread
Old 04-04-2009, 11:00 AM   #1
Hack&Lube
Atomic Nerd
 
Join Date: Jul 2004
Location: Calgary
Exp:
Default Crazy virus rootkit madness Win32/Agent.ODC

So somehow I've just gotten a rootkit infecting my system, it's resident in memory and might even be in the boot sector. I didn't do anything other than open an attached Jpeg file from a friend that I thought was corrupted.



I'm having major problems with this. ESET NOT detects it but it cannot clean it. Both my Malwarebytes and Spybot S&D won't execute when I run them because this thing blocks them. I have tried Gmer in safe mode to detect the rootkits and it finds several entries but they are greyed out and there are no options to delete the services.
Hack&Lube is offline   Reply With Quote
Old 04-04-2009, 11:09 AM   #2
Rathji
Franchise Player
 
Rathji's Avatar
 
Join Date: Nov 2006
Location: Supporting Urban Sprawl
Exp:
Default

Try hijack this!

Just be careful. You can screw your registry if you don't know what you are doing.
__________________
"Wake up, Luigi! The only time plumbers sleep on the job is when we're working by the hour."
Rathji is offline   Reply With Quote
Old 04-04-2009, 12:12 PM   #3
rbochan
Scoring Winger
 
rbochan's Avatar
 
Join Date: May 2008
Location: Syracuse, NY
Exp:
Default

It might be a tumor.
__________________
...Rob
The American Dream isn't an SUV and a house in the suburbs;
it's Don't Tread On Me.
rbochan is offline   Reply With Quote
The Following User Says Thank You to rbochan For This Useful Post:
Old 04-06-2009, 09:16 AM   #4
Bobblehead
Franchise Player
 
Bobblehead's Avatar
 
Join Date: Jul 2005
Location: in your blind spot.
Exp:
Default

Did you get this solved, H&L ?
__________________
"The problem with any ideology is that it gives the answer before you look at the evidence."
—Bill Clinton
"The greatest obstacle to discovery is not ignorance--it is the illusion of knowledge."
—Daniel J. Boorstin, historian, former Librarian of Congress
"But the Senator, while insisting he was not intoxicated, could not explain his nudity"
—WKRP in Cincinatti
Bobblehead is offline   Reply With Quote
Old 04-06-2009, 10:05 AM   #5
llama64
First Line Centre
 
llama64's Avatar
 
Join Date: Nov 2006
Location: /dev/null
Exp:
Default

Buy a Mac.

j/k... Root kits suck.
llama64 is offline   Reply With Quote
Old 04-06-2009, 11:05 AM   #6
Cliche
Powerplay Quarterback
 
Cliche's Avatar
 
Join Date: Apr 2006
Location: Wherever you go there you are.
Exp:
Default

Ripley: I say we take off and nuke the entire site from orbit. It's the only way to be sure.

Yeah, for cases like this, it'd probably be best to just nuke everything and reload it.

Alternatively if you are really determined to eliminate this, then booting the system from another place(EG. Winpe) and running virus tools on the affected drive should work.
__________________
Tacitus: Rara temporum felicitate, ubi sentire quae velis, et quae sentias dicere licet.
Cliche is offline   Reply With Quote
Old 04-06-2009, 11:36 AM   #7
Bobblehead
Franchise Player
 
Bobblehead's Avatar
 
Join Date: Jul 2005
Location: in your blind spot.
Exp:
Default

It is things like this that makes me consider buying a version of Arconis for home. Then something (anything) bad happens and instead of a rebuild just do a restore.
__________________
"The problem with any ideology is that it gives the answer before you look at the evidence."
—Bill Clinton
"The greatest obstacle to discovery is not ignorance--it is the illusion of knowledge."
—Daniel J. Boorstin, historian, former Librarian of Congress
"But the Senator, while insisting he was not intoxicated, could not explain his nudity"
—WKRP in Cincinatti
Bobblehead is offline   Reply With Quote
Old 04-06-2009, 12:31 PM   #8
Kipper is King
Pants Tent
 
Kipper is King's Avatar
 
Join Date: Apr 2006
Exp:
Default

Why don't we just exterminate all computer viruses?
__________________
KIPPER IS KING
Kipper is King is offline   Reply With Quote
Old 04-07-2009, 10:15 AM   #9
Hack&Lube
Atomic Nerd
 
Join Date: Jul 2004
Location: Calgary
Exp:
Default

Quote:
Originally Posted by Bobblehead View Post
It is things like this that makes me consider buying a version of Arconis for home. Then something (anything) bad happens and instead of a rebuild just do a restore.
I actually do have Arconis, but I also have my entire harddrive mirrored on an external harddrive in an enclosure. If my first harddrive fails, I plug my enclosure into esata and I boot my computer from it.

Regarding this rootkit, after a lot of googling, it looks like a lot of people got it around the end of march and seeing as how many of my antivirus programs didn't even catch or cure it, I suspect a lot of people might have it. Most sites recommended using GMER to detect and remove rootkits. GMER found them but it couldn't remove them in my case.

Eventually, I downloaded the latest combofix and renamed it to rootkitssuckass.exe and that got rid of the main problem. I was then able to run malwarebytes in safemode after 3 reboots to take care of the rest.
Hack&Lube is offline   Reply With Quote
The Following User Says Thank You to Hack&Lube For This Useful Post:
Old 04-07-2009, 10:52 AM   #10
woob
#1 Goaltender
 
woob's Avatar
 
Join Date: Jan 2006
Exp:
Default

Quote:
Originally Posted by Hack&Lube View Post
Eventually, I downloaded the latest combofix and renamed it to rootkitssuckass.exe and that got rid of the main problem. I was then able to run malwarebytes in safemode after 3 reboots to take care of the rest.
Gotta love combofix!! Many times it has gotten me out of a bind when dealing with crap, often resolving the issues, or like you, being the big first stepping stone in the process.
woob is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -6. The time now is 12:30 PM.

Calgary Flames
2023-24




Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Copyright Calgarypuck 2021