 |
 |
 |
 |
#327350 - 01/20/10 03:36 PM
The Worm from Hell
|
Misanthropic Cow
Registered: 03/31/03
Loc: Pasture
|
I got a worm in my computer that keeps redirecting me to useless search engines like newserversearch.com and adsense.com.
The trick is this: this worm has installed itself in WinLogon.exe. It has other hidden copies of itself. When I boot, if the worm is not running, it installs itself in the registry and starts with Windows.
To kill it, I have to terminate it in each process (Process Explorer does the trick), clean the registry (RegCleaner), delete it from the browsers (HijackThis!), disable any suspicious start program (Autoruns) and terminate WinLogon itself (using Killbox).
Of course, that means the computer reboots. Then, since the worm has made dozens of copies of itself (I've found many, but others are still there: it does NOT change the modified time! and it appends itself to legit exe and dll files!), it just re-installs itself and starts sending me to crap search web sites and makes my computer slow as molasses.
Short of doing a full reinstall, this one is a nightmare. Of course, I've run the usual course of antivirus, antimalware, antispyware and antiworm software (AVG, Avast, Spybot, etc. --nothing that is not free, though).
Any ideas? This is the Worm from Hell.
_________________________
This a spiritual thing and I am the laughing Buddha sitting on top of the world. Donnalee. "Populace above, populace below! What are 'poor' and 'rich' at present! That distinction did I unlearn,—then did I flee away further and ever further, until I came to those kine." -- Thus Spake Zarathustra / Friedrich Nietzsche. http://my.funtrivia.com/tournament/Callies-quiz-75578.html
|
|
Top
|
|
|
|
|
 |
 |
 |
 |
 |
 |
 |
 |
#327359 - 01/20/10 06:05 PM
Re: The Worm from Hell
[Re: Bye]
|
Misanthropic Cow
Registered: 03/31/03
Loc: Pasture
|
Oh, but I know exactly in what process the worm is hiding: Windows Logon (winlogon.exe).
Even in safe mode, it's one of the essential processes that is ALWAYS there (like System, svchost, services and rundll32).
The only way to clean is to nuke the process, which means the computer shuts down, and to pre-select deletion of infected files on reboot (Killbox can do that).
The bad thing is that the worm doesn't leave any detectable cues behind: it doesn't change the time stamp and all antiworms/antivirus fail to detect it. I've found it inside some files only because they are running when they shouldn't be, or their size appears unfamiliar (I'm enough of a geekette to notice when my RCMan.exe is bigger than it should be).
So, unless I manage to mark ALL infected files for deletion upon reboot in Killbox, and I've killed all the processes/threads related to it in Process Manager before, it will come back again and again.
A pest.
_________________________
This a spiritual thing and I am the laughing Buddha sitting on top of the world. Donnalee. "Populace above, populace below! What are 'poor' and 'rich' at present! That distinction did I unlearn,—then did I flee away further and ever further, until I came to those kine." -- Thus Spake Zarathustra / Friedrich Nietzsche. http://my.funtrivia.com/tournament/Callies-quiz-75578.html
|
|
Top
|
|
|
|
|
 |
 |
 |
 |
|
|