Ride or Die OCA4LIFE!
Log In:

Notices

XP Ol' Reliable...

Reply
 
Thread Tools Display Modes
  #1  
Old 01-31-2010
Witchdoctor's Avatar
Witchdoctor Witchdoctor is offline
OCA Gladiator
 
Join Date: Nov 2009
Posts: 6,039
Rep Power: 21
Witchdoctor will become famous soon enough
Default Net Sky

Just got a machien in that someone brought to me ...

XP is totaly infected with netsky ...... anyone heard of this. Tried using the removal tool on Symanic with no luck ..... anyone know a way to kill it or just better off wipping it clean

Brutal Virus

if this is in the wrong section please move to right location


Thanks and as always any help would be appreciated
__________________
You don't need a reason to help people
Reply With Quote
  #2  
Old 02-01-2010
DrNip's Avatar
DrNip DrNip is offline
Don't Know
 
Join Date: Feb 2009
Location: OKC
Posts: 5,144
Rep Power: 10
DrNip might just be on to something hereDrNip might just be on to something here
Default

Viruses lately have become retarded. I use to be able to clean them up with no problem but lately I found it easier just to reload. "Aboutblank" virus is the one that kicked my ass. They prolly have work arounds now for it now.
Reply With Quote
  #3  
Old 02-01-2010
Witchdoctor's Avatar
Witchdoctor Witchdoctor is offline
OCA Gladiator
 
Join Date: Nov 2009
Posts: 6,039
Rep Power: 21
Witchdoctor will become famous soon enough
Default

yea I hear ya bro. it is not my machein and has a lot of crap on it

guess I need to back it all up and slap a new OS on ..... sucks ....

They should lock these dudes up and throw away the key
__________________
You don't need a reason to help people
Reply With Quote
  #4  
Old 02-01-2010
Neuromancer's Avatar
Neuromancer Neuromancer is offline
OCA Gladiator
 
Join Date: Jun 2009
Location: South Jersey, USA
Posts: 5,645
Rep Power: 21
Neuromancer might just be on to something hereNeuromancer might just be on to something here
Default

I have had to clean a few bugs lately on other peoples computers

I used to go through carefully. Now I just take their hdd and scan it in my PC in 30 minutes and done.

Mostly cleaning up that antivirus virus
__________________
"Don't You understand? This is Greek to me! Except I spek Greek, this is like Aramaic to me, and not the Western Dialect I can read a little." - Dr. Walter Bishop

Special relativity is not "Eat Two Big Macs."
Reply With Quote
  #5  
Old 02-01-2010
Witchdoctor's Avatar
Witchdoctor Witchdoctor is offline
OCA Gladiator
 
Join Date: Nov 2009
Posts: 6,039
Rep Power: 21
Witchdoctor will become famous soon enough
Default

yea this is nasty ..... you can find it and when you reboot it runs system restore and replaces it self .... won't let you turn it off, but it does appear to let you shut it off it still runs at start up ..... changed a lot of valeus in the boot sequence in the registry ... and the values are so close to what they are supposed to be you have have to be in that stuff everyday to see the subtile changes like \ instead of / that type stuff. It is by far the most devistating virus I have seen

reading more on this it seems they caught this dude .... 30 years in prison

should have been life
__________________
You don't need a reason to help people
Reply With Quote
  #6  
Old 02-01-2010
Buckeye's Avatar
Buckeye Buckeye is offline
Senior Overclockaholic
 
Join Date: Jun 2009
Posts: 1,162
Rep Power: 16
Buckeye will become famous soon enough
Default

I have not heard of that one, but had a friend a few weeks ago pick up one call Fraudpack something. It was extremely nasty.

Of course he wanted files saved on the HD LOL

I ended up taking the C drive out and connecting it up to another machine, scrubbing the heck out of it with Kaspersky. Installing back on his rig and cleaning it again. It worked but was not easy to do and who knows what else is still on it, root kit or what.
Reply With Quote
  #7  
Old 02-01-2010
punx223's Avatar
punx223 punx223 is offline
OCA Gladiator
 
Join Date: Jun 2009
Posts: 2,106
Rep Power: 17
punx223 will become famous soon enough
Default

witchdoctor... try opening the run command and running MRT


that is thw windows malicious removal tool. You would be suprised how much that will actually remove
__________________







Quote:
Originally Posted by Gunslinger View Post
You mean you don't have one of the uber secret 6.6GHz Gulftown pots?
Reply With Quote
  #8  
Old 02-01-2010
Witchdoctor's Avatar
Witchdoctor Witchdoctor is offline
OCA Gladiator
 
Join Date: Nov 2009
Posts: 6,039
Rep Power: 21
Witchdoctor will become famous soon enough
Default

Thanks for the tip I will give it a whirl when I get home form work

This is the nastiest one I have ever seen ......
__________________
You don't need a reason to help people
Reply With Quote
  #9  
Old 02-01-2010
Buckeye's Avatar
Buckeye Buckeye is offline
Senior Overclockaholic
 
Join Date: Jun 2009
Posts: 1,162
Rep Power: 16
Buckeye will become famous soon enough
Default

Good tip Shannon

The Fraudpack one I posted about would not let you run anything, on boot up it would get almost to the desktop, with no icons on the background, and a pop up would show its nasty face. No matter what I did I could not get past that dam pop up. Safe mode would do the same freaking thing. It really locked the computer down by a root kit I believe.

I tried many things from booting from a DVD, to almost throwing it out the window, that didn't even scare it

Booting from a second machine with the C drive from that one attached to a SATA port did the trick tho. At least the machine is now running with out to many problems, besides it being a old HP machine LOL.

Nothing like wasting 2 whole days fixing something like this, all because a user could not resist clicking on some stupid pop up and BAM.

I did look over the machine pretty good after I got it up and running, he was pretty clean in his use. Just had WoW and a few small apps. Browser history showed no bad websites visited that I could see. He was just using crappy virus protect call Bit-Defender that did basiclly nothing. Kaspersky is the only one I use and it seemed to have cleaned him up good.

Last edited by Buckeye; 02-01-2010 at 05:15 AM.
Reply With Quote
  #10  
Old 02-01-2010
ocgmj's Avatar
ocgmj ocgmj is offline
Senior Overclockaholic
 
Join Date: Jun 2009
Location: SoCal
Posts: 1,216
Rep Power: 16
ocgmj is on a distinguished road
Default

Use Dr. Web live CD bootable ISO that runs on linux. Can you found here: Link
__________________
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump



All times are GMT -10. The time now is 10:13 AM.

Copyright ©2009-2014, Overclockaholics

Designed by: vBSkinworks