also @ TechSpot: Top PC Games for this Holiday Season and Beyond
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.

Go Back   TechSpot OpenBoards > Operating Systems & Software > Virus & Malware removal

Antivirus XP 08, Rootkit, Trojan.gaslide. PC infested.

Closed Thread
Page 4 of 5 123 4 5
Bookmark Thread Tools
  #61  
Old 08-14-2008
xxdanielxx's Avatar
TechSpot Addict
 
Location: Southern CA
Member since: Aug 2006, 1,212 posts
there is nothing much just removing malware last thing he tried to run was combofix. But he could not run it so he rebooted and the loops started to happen first thought was he corupted the reg but he cant even get into the recovery console so that points me to bad hardware
  #62  
Old 08-14-2008
kimsland's Avatar
TS Special Forces
 
Location: Australia
Member since: Dec 2007, 17,027 posts
Yep

I'd say HardDrive
Best to backup (externally to another computer, mounted as a slave)
Then install Windows clean
Why?
Because this will eliminate Hardware
To remove this ad, sign in. To register for a new account, click here.
  
  #63  
Old 08-14-2008
TechSpot Member
 
Member since: Jul 2008, 52 posts
how do i backup using another computer?
also, i have an external hardrive i use for my laptop, not sure if that helps any, but i figured i should say it...
  #64  
Old 08-14-2008
kimsland's Avatar
TS Special Forces
 
Location: Australia
Member since: Dec 2007, 17,027 posts
You need to physically remove your existing (possible faulty) HardDrive
Then go to a Desktop computer
Unplug the Slave ( being the CD/DVD drive)
Plug in your HardDrive

Boot from the Desktop normally
But in "My Computer" the Desktop will now have 2 Drives (C drive, and yours)
You can then "back up" your drive
  #65  
Old 08-14-2008
TechSpot Member
 
Member since: Jul 2008, 52 posts
do i have to worry about the hardrive giving the other computer any of the malware that infected the first one?
also, can i just reinstall windows without backing it up? i realize i would lose everything stored on the hd, but i might be able to convince my father (its his pc) to do it....i don't think he had anything vital on it, he just wanted to avoid the hassle...
  #66  
Old 08-14-2008
xxdanielxx's Avatar
TechSpot Addict
 
Location: Southern CA
Member since: Aug 2006, 1,212 posts
yes you can just reinstall windows at this point it would be the best and easiest way. Use your system recovery disc
  #67  
Old 08-14-2008
TechSpot Member
 
Member since: Jul 2008, 52 posts
reinstalled windows, and everything appears fine.
however, i downloaded spyware doctor, and it found 4 infections of trojan.virtumonde. ??????? how is that possible? shouldn't reinstalling have wiped everything clean?
  #68  
Old 08-14-2008
TechSpot Member
 
Member since: Jul 2008, 52 posts
also, what should i have on the pc to prevent this from happening again? he originally had AVG, and i now have spyware doctor, should i have something else?
  #69  
Old 08-14-2008
TechSpot Member
 
Member since: Jul 2008, 52 posts
should i download HJT and post a log? I have disconnected it from the internet since i ran the Spyware doctor scan and found the virtumonde. Is it possible that something was left behind when i reinstalled XP? I immediately downloaded all the windows/java updates i was told to, and the only sites i have gone to are the emachines page, because it was the default homepage, and pc tools.com to download Spyware doc....
To remove this ad, sign in. To register for a new account, click here.
  
  #70  
Old 08-14-2008
kimsland's Avatar
TS Special Forces
 
Location: Australia
Member since: Dec 2007, 17,027 posts
Quote:
i downloaded spyware doctor, and it found 4 infections of trojan.virtumonde. ??????? how is that possible?
You know how you "re-installed" Windows (from restore discs)

Was this a clean install (new formatted install)
Or just a repair install?

I can only think that you must have Trojans in the restore discs, or spyware doctor itself is giving false positives, or is in fact corrupted, itself.
Do you have extra drives installed, maybe?
  #71  
Old 08-14-2008
TechSpot Member
 
Member since: Jul 2008, 52 posts
i did the "destructive" install, using "emachines Microsoft Windows XP media center edition 2005 system recovery CD/DVD"
i had used the same disc on another identical pc before, about a year ago, with no problems...
i have none of the same symptoms, just 4 infections showed up in the scan. i scanned again, and found nothing. the 4 are currently quarantined.

what do you mean by extra drives installed?
  #72  
Old 08-14-2008
kimsland's Avatar
TS Special Forces
 
Location: Australia
Member since: Dec 2007, 17,027 posts
Any extra Partitions (Hidden?) in My Computer
You can use Gparted live CD to see any hidden partitions
  #73  
Old 08-15-2008
TechSpot Member
 
Member since: Jul 2008, 52 posts
not exactly sure what this means, but this is what Gparted is showing me

partition filesystem size used unused flags

/dev/dha2 fat32 4.21GiB 3.21GiB 1016.36MiB

/dev/dha1 ntfs 182.1 GiB 7.28GiB 174.82GiB boot
  #74  
Old 08-15-2008
kimsland's Avatar
TS Special Forces
 
Location: Australia
Member since: Dec 2007, 17,027 posts
Quote:
Originally Posted by patrick713 View Post
not exactly sure what this means, but this is what Gparted is showing me

partition filesystem size used unused flags

/dev/dha2 fat32 4.21GiB 3.21GiB 1016.36MiB <-Hidden Partition

/dev/dha1 ntfs 182.1 GiB 7.28GiB 174.82GiB boot
Ah Huh!
We found a hidden partition! About 4 Gig in size

What's this other Partition? It's probably the small recovery partition for Windows (Xp or Vista?)

How do you access this partition?
Well usually there is a prompt (like F10) or something, when you turn on the computer. Selecting this prompt will allow you to restore your entire computer back to when it was delivered.
But...
If you format, or install Windows clean using a Windows CD, the prompt will also be removed (very annoying I know) mind you, it also contains Trojans!

Now what to do with this new found partition (I don't like removing them basically)
You could contact the computer manufacture support page, and actually get this prompt back (usually a small boot config program to load up)
But...
The Trojans!!!
And scanning it, may remove important system files from being restored one day
???
Thinking again

What are your thoughts on this?
  #75  
Old 08-15-2008
TechSpot Member
 
Member since: Jul 2008, 52 posts
so you're saying i cant just delete it? and if i access it, it releases the trojans?
great...
so was this partition already there, and the trojans infiltrated it? or did they actually create it?
  #76  
Old 08-15-2008
SNGX1275's Avatar
TS Special Forces
 
Location: Rolla, Missouri, USA
Member since: Feb 2002, 9,289 posts
System specs
Quote:
Originally Posted by patrick713 View Post
so was this partition already there, and the trojans infiltrated it? or did they actually create it?
They didn't create it, it was already there.
  #77  
Old 08-15-2008
rezzzy's Avatar
Newcomer, in training
 
Member since: Aug 2008, 9 posts
Reboot safe mode pressing F8 in windows boot and scan with malwarebytes that you can find here http://www.besttechie.net/mbam/mbam-setup.exe
  #78  
Old 08-15-2008
TechSpot Member
 
Member since: Jul 2008, 52 posts
MBAM found absolutely nothing.
  #79  
Old 08-15-2008
kimsland's Avatar
TS Special Forces
 
Location: Australia
Member since: Dec 2007, 17,027 posts
Well if you want to remove the Hidden Partition, that will be OK (using Gparted)
Basically, I thought, well if you have the discs anyway
I can't see how or if any Trojans got in there, but I also can't work out where they have come from, after a format
Removing the Hidden partition will not hurt your Main Drive or data or Windows or anything, but Backup first, just in case you remove the wrong one, or Windows stops booting (it is possible)
  #80  
Old 08-16-2008
TechSpot Member
 
Member since: Jul 2008, 52 posts
I deleted the partition, and everything seems fine.
Is there any way I can be sure that the PC is safe to use, or have i pretty much done that?
and thanks for helping me with this
Closed Thread
Page 4 of 5 123 4 5

Tip: Download Advanced SystemCare 3 Freeware - 1 Click A Day to Clean, Repair, Protect & Optimize your PC.

Thread Tools


Similar Topics
Topic Category Replies Last Post
Computer infested, please help Windows OS 5 04-24-2008 01:28 AM
Please help... Hacktool.rootkit, trojan.virantix... spamming me to death Windows OS 3 03-01-2008 12:34 AM
Ran all tests, rootkit/trojan Virus & Malware removal 2 02-03-2008 02:22 PM
Nasty Trojan disables regedit, msconfig, antivirus, firewall, task manager, etc Virus & Malware removal 13 12-22-2006 09:11 AM


All times are GMT -4. The time now is 05:39 PM.