#1
Posted 27 February 2012 - 06:06 PM
#2
Posted 27 February 2012 - 06:12 PM
#3
Posted 27 February 2012 - 06:14 PM
#4
Posted 27 February 2012 - 06:23 PM
#5
Posted 27 February 2012 - 06:24 PM
#6
Posted 27 February 2012 - 06:28 PM
#7
Posted 27 February 2012 - 06:31 PM
I found these files under C:\ProgramData\<random-alpha-numeric-string> on a W7 Pro machine. It intercepts Task Manager from launching among other things, so far I have a stable system in Safe Mode - it could be contained to just the user's profile at this point I'm hoping.
Attached Files
#8
Posted 27 February 2012 - 06:33 PM
#9
Posted 27 February 2012 - 06:35 PM
#10
Posted 27 February 2012 - 06:35 PM
#11
Posted 27 February 2012 - 06:36 PM
cwq1, on 27 February 2012 - 06:31 PM, said:
I found these files under C:\ProgramData\<random-alpha-numeric-string> on a W7 Pro machine. It intercepts Task Manager from launching among other things, so far I have a stable system in Safe Mode - it could be contained to just the user's profile at this point I'm hoping.
I have not been able to boot into safe mode, is it possible this trojan could be preventing that? I know whenever I try to open the uninstall program option in Control Panel, it blocks it. As well as several other programs like EndItAll and my AV program.
#12
Posted 27 February 2012 - 06:37 PM
https://www.virustot...sis/1330385554/
8 / 43 scanners recognize it as something. I guess I'll go try the tools that found it, to see if they will remove it.
#13
Posted 27 February 2012 - 06:41 PM
Looks like you all have something that is very new,the only google result for the name is pointing back to this forum so they dont come any hotter off the press then this..
We don't usually work on malware removal in this part of the forums so for those that need further assistance.
Please read and follow the directions here, skipping any steps you are unable to complete. Then create a NEW topic here.
One of the expert helpers there will give you one on one assistance when one becomes available.
Please note that it may take 48 hours or more for you to receive a response in the malware removal forum, as it is often busy at times. Please do not reply to your own post asking for help unless its been more than 48 hours since you originally posted, as this can make it appear as though you are being helped and take longer for you to get help.
If you are unable to do all or any of the steps in the link to the directions above, just post your problem into the forum I gave you a link to anyway and someone will be able to assist you.
If you prefer to be assisted via email you may contact support@malwarebytes.org and one of our support staff members will assist you directly.
If you are a reseller, affiliate, technician, corporate, business, educational, government or non-profit customer then please contact corporate-support@malwarebytes.org and include full contact details along with your Reference # when you do to ensure that you receive prompt assistance.
Thank you
#14
Posted 27 February 2012 - 06:43 PM
cwq1, on 27 February 2012 - 06:31 PM, said:
I found these files under C:\ProgramData\<random-alpha-numeric-string> on a W7 Pro machine. It intercepts Task Manager from launching among other things, so far I have a stable system in Safe Mode - it could be contained to just the user's profile at this point I'm hoping.
cwq1, on 27 February 2012 - 06:37 PM, said:
https://www.virustot...sis/1330385554/
8 / 43 scanners recognize it as something. I guess I'll go try the tools that found it, to see if they will remove it.
Looking into this data now guys...Thankyou for your assistance
#15
Posted 27 February 2012 - 06:47 PM
#16
Posted 27 February 2012 - 06:49 PM
For me (Win XP 32bit), it's located in C:\Documents and Settings\All Users\Application Data\F4D561B4000BEA160003C315D151FC84\
I'm guessing the last bit is random, but you never know...
It's 2 files:
F4D561B4000BEA160003C315D151FC84.exe (360.448 bytes)
And just plain
F4D561B4000BEA160003C315D151FC84 (328 bytes)
I can't remove the .exe, but I can rename it. It'll rename itself back, though.
The other file can be removed, but gets remade,
So, any idea how to remove this thing? It shuts down everything I try to start.
#17
Posted 27 February 2012 - 06:53 PM
Estevek, on 27 February 2012 - 06:47 PM, said:
I can almost guarantee you are running outdated programs on your computer, which causes a hacked website or malvertisement to slip this goody onto your OS.
My suggestion is to use Secunia PSI to check for outdated programs. I have a guide on that here.
http://www.bleepingc...th-secunia-psi/
#18
Posted 27 February 2012 - 07:01 PM
Cerbrus, on 27 February 2012 - 06:49 PM, said:
For me (Win XP 32bit), it's located in C:\Documents and Settings\All Users\Application Data\F4D561B4000BEA160003C315D151FC84\
I'm guessing the last bit is random, but you never know...
It's 2 files:
F4D561B4000BEA160003C315D151FC84.exe (360.448 bytes)
And just plain
F4D561B4000BEA160003C315D151FC84 (328 bytes)
I can't remove the .exe, but I can rename it. It'll rename itself back, though.
The other file can be removed, but gets remade,
So, any idea how to remove this thing? It shuts down everything I try to start.
There is more to it then just that..It has created an execution hijack in the registry so that it launches itself everytime you try to run something new.
Trying to work a fix for it
#19
Posted 27 February 2012 - 07:01 PM
It did prevent the virus from starting on a reboot, now I've just gotta get rid of it.
#20
Posted 27 February 2012 - 07:02 PM
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users



This topic is locked










