 |
 |
 |
 |
#327350 - 01/20/10 03:36 PM
The Worm from Hell
|
Misanthropic Cow
Registered: 03/31/03
Loc: Pasture
|
I got a worm in my computer that keeps redirecting me to useless search engines like newserversearch.com and adsense.com.
The trick is this: this worm has installed itself in WinLogon.exe. It has other hidden copies of itself. When I boot, if the worm is not running, it installs itself in the registry and starts with Windows.
To kill it, I have to terminate it in each process (Process Explorer does the trick), clean the registry (RegCleaner), delete it from the browsers (HijackThis!), disable any suspicious start program (Autoruns) and terminate WinLogon itself (using Killbox).
Of course, that means the computer reboots. Then, since the worm has made dozens of copies of itself (I've found many, but others are still there: it does NOT change the modified time! and it appends itself to legit exe and dll files!), it just re-installs itself and starts sending me to crap search web sites and makes my computer slow as molasses.
Short of doing a full reinstall, this one is a nightmare. Of course, I've run the usual course of antivirus, antimalware, antispyware and antiworm software (AVG, Avast, Spybot, etc. --nothing that is not free, though).
Any ideas? This is the Worm from Hell.
_________________________
This a spiritual thing and I am the laughing Buddha sitting on top of the world. Donnalee. "Populace above, populace below! What are 'poor' and 'rich' at present! That distinction did I unlearn,—then did I flee away further and ever further, until I came to those kine." -- Thus Spake Zarathustra / Friedrich Nietzsche. http://my.funtrivia.com/tournament/Callies-quiz-75578.html
|
|
Top
|
|
|
|
|
 |
 |
 |
 |
 |
 |
 |
 |
#327359 - 01/20/10 06:05 PM
Re: The Worm from Hell
[Re: Bye]
|
Misanthropic Cow
Registered: 03/31/03
Loc: Pasture
|
Oh, but I know exactly in what process the worm is hiding: Windows Logon (winlogon.exe).
Even in safe mode, it's one of the essential processes that is ALWAYS there (like System, svchost, services and rundll32).
The only way to clean is to nuke the process, which means the computer shuts down, and to pre-select deletion of infected files on reboot (Killbox can do that).
The bad thing is that the worm doesn't leave any detectable cues behind: it doesn't change the time stamp and all antiworms/antivirus fail to detect it. I've found it inside some files only because they are running when they shouldn't be, or their size appears unfamiliar (I'm enough of a geekette to notice when my RCMan.exe is bigger than it should be).
So, unless I manage to mark ALL infected files for deletion upon reboot in Killbox, and I've killed all the processes/threads related to it in Process Manager before, it will come back again and again.
A pest.
_________________________
This a spiritual thing and I am the laughing Buddha sitting on top of the world. Donnalee. "Populace above, populace below! What are 'poor' and 'rich' at present! That distinction did I unlearn,—then did I flee away further and ever further, until I came to those kine." -- Thus Spake Zarathustra / Friedrich Nietzsche. http://my.funtrivia.com/tournament/Callies-quiz-75578.html
|
|
Top
|
|
|
|
|
 |
 |
 |
 |
 |
 |
 |
 |
#327989 - 01/24/10 08:43 PM
Re: The Worm from Hell
[Re: Bye]
|
Misanthropic Cow
Registered: 03/31/03
Loc: Pasture
|
Warez??? What warez???
Actually, it's movies. Can't get the versions in Spanish around here, only English and French, and I don't order online because of credit card paranoia.
Since my mom only understands Spanish and Italian, I have to get copies in those languages for her to watch, when I want her to see a movie (that I own in English or French, but she cannot understand those).
Sucks, no?
_________________________
This a spiritual thing and I am the laughing Buddha sitting on top of the world. Donnalee. "Populace above, populace below! What are 'poor' and 'rich' at present! That distinction did I unlearn,—then did I flee away further and ever further, until I came to those kine." -- Thus Spake Zarathustra / Friedrich Nietzsche. http://my.funtrivia.com/tournament/Callies-quiz-75578.html
|
|
Top
|
|
|
|
|
 |
 |
 |
 |
 |
 |
 |
 |
#331315 - 02/24/10 11:18 PM
Re: The Worm from Hell
[Re: Marcella]
|
Ultimate Goddess
Registered: 05/16/03
Loc: Northern California
|
Isn't that in itself a bit risky? A program that will need to send stuff from your computer to the company that produces it? You need to trust that company completely, make sure they won't be sending your cacheed bank passwords and card numbers. Yes it is risky. The Hitman Pro folks have a good reputation, but yes, in the end that is all you have. They do upload only executables, or so they say. Yes, you need to trust them. But no, "trust completely" is probably overstating it. Many folks are blissfully unaware of just how risky their computing is already. As I alluded to, Hitman Pro can cure some really really nasties when nothing else will, but it is not a cure of first resort. To everyone, you will know you have big problems when clicking on a Google search result frequently takes you to unexpected spam.
_________________________
Holly - who believes that it may be better to live under robber barons than under omnipotent, moral busybodies. The robber baron's cruelty may sometimes sleep, his cupidity may at some point be satiated; but those who torment us for our own good will torment us without end for they do so with the approval of their own conscience.... (C.S.Lewis - Irish author 1898-1963)
|
|
Top
|
|
|
|
|
 |
 |
 |
 |
|
|