[skip all navigation]

Goddamn Stubborn Computer Virus, Windows XP Security 2012

Creator: TiKels
Time: Jan 12 2012, 12:08 am

Post #21     l)ark_ssj9kevin Jan 12 2012, 6:13 am

[Avatar]
offlinecontact
Rank: Regular
yeah, this virus (security 2012 and ping.exe) is new enough that you can't just do this alone: you need to post on one of those special websites for help.
or you can just reinstall, of course.

Top

Post #22     DevliN Jan 12 2012, 6:51 am

[Avatar]
SOMETHING STATUS GO
onlinecontact
Rank: Administrator
At this rate it seems like it would be faster to start over. :/

:devlin: CURRENTLY WORKING ON :devlin:
Shadowlands | Demonic: Urban Apocalypse
Invasion: Ares | Recon | OMG TEH ZOMBIES!!!
Top

Post #23     NudeRaider Jan 12 2012, 11:58 am

[Avatar]
You're not old until the past seems more fun than the future.
offlinecontact
Rank: Veteran
Quote from TiKels
edat:My goal is to not wipe my computer and still get rid of the virus.
Your desire is understandable but you're probably overestimating anti-virus tools. You can never be sure that your computer has been fully cleaned after such a heavy infection.
Ask any expert and he'll tell you that formatting the harddrive is the recommended procedure to kill viruses.

Partitioning into a small C: drive and the rest for a data drive D: makes this much more convenient, especially when you can use the transfer settings feature of Windows without reinfecting yourself.

(user posted image)
Devilesk: "AND OUT OF THE GOODNESS OF MY HEART [...]" - wait what??
Top

Post #24     ClansAreForGays Jan 12 2012, 3:57 pm

[Avatar]
offlinecontact
Rank: Veteran
Friend got the same virus, along with ping.exe

I was able to beat it just by googling the things that came up. I'm surprised you haven't...

Top

Post #25     Lanthanide Jan 12 2012, 7:51 pm

[Avatar]
offlinecontact
Rank: Regular
Yeah, since you know the name of it, it should be pretty straight forward. The instructions I came across didn't look like much, just deleting a few registry entries and a few files.

O)FaRTy1billion -- "Lanthanide -- surely you have photos of yourself dressed up as a girl, az?" I don't have pictures of me dressed up as a girl.
O)FaRTy1billion -- One time I was jumping on a trampoline (at that very friend's house xD) with water balloons in my shirt held up by a belt.
Azrael.Wrath -- ...
Top

Post #26     O)FaRTy1billion Jan 12 2012, 10:15 pm

[Avatar]
‮.rapsdleF
onlinecontact
Rank: Elite
Ohey I saw this one once.

ping.exe is constantly created by some other process ..but I forgot what it was. I just remember all the internet tabs would close and some retarded "Anti-virus" window would appear randomly.
I did the malware removal guide in the sticky topic after I was manually deleting .exes. Stuff stopped breaking and working badly, so I assume it worked. :P (I reformatted after). (First virus that I'm aware I've encountered in a looong time.)

Oh, also with programs running as themselves I just did open with and selected itself.
This post was edited 1 time, last edit by FaRTy1billion: Jan 12 2012, 10:21 pm.

SC2 Map Texture Mask Importer/Exporter - Edit texture placement in an image editor!
TinyMap2 - Latest in map compression!
MapSketch - New image->map generator!
EUD Action Enabler - Lightweight EUD/EPD support! (ChaosLauncher/MPQDraft support!)
EUDDB - Now has .dat references! Help out by adding your EUDs!
EUDTrig - Quickly and easily convert offsets to EUDs! (extended players supported)
(user posted image) This page has been viewed (user posted image) times!
Top

Post #27     c(O.Oc) Jan 24 2012, 7:06 am

[Avatar]
offlinecontact
Rank: Member
I don't think you're on the right website for virus help. Try going to this website here. The people on here are pros at this kinda stuff and have helped me numerous times with my computer issues in the past. The help is free and all you need is an account for the help forums, and a few tools that they use to gauge the virus's attributes, spread, and the best way to remove it. Gl.

Top

Post #28     DT_Battlekruser Jan 24 2012, 9:21 pm

[Avatar]
offlinecontact
Rank: Elite
I actually had to deal with the virus a few weeks ago - it's surprisingly insidious yet also quite easy to get rid of. If you know anything about computers, do the following:

The virus controls your program execution by overwriting the registry executor keys for .exe files. Use any method to access a terminal (safe mode with command prompt if necessary), and then do the following

>cd %LocalAppData%

Here, you should notice two things. There will be some executable you don't recognize, named xyz.exe where xyz is a random 3-character string (this will match a process running named xyz.exe), and a folder called longstring (some really long random string). Briefly memorize these strings so you can pick them out.

(note: I use cygwin, so you might need to switch to dos commands)

>rm xyz.exe
>rm longstring
>cd %CommonAppData%
>rm longstring
>cd %Temp%
>rm longstring
>cd %UserProfile%/Templates
>rm longstring

This is all the places the virus has written itself to your computer. Now, to fix the registry, remove the following keys, if they look infected:

HKEY_CURRENT_USER\Software\Classes\.exe "(Default)" = 'ah'
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "%LocalAppData%\<random 3 chars>.exe" -a "%1" %*
HKEY_CLASSES_ROOT\ah
HKEY_CURRENT_USER\Software\Classes\ah "(Default)" = 'Application'
HKEY_CURRENT_USER\Software\Classes\ah "Content Type" = 'application/x-msdownload'
HKEY_CURRENT_USER\Software\Classes\ah\DefaultIcon "(Default)" = '%1'
HKEY_CURRENT_USER\Software\Classes\ah\shell\open\command "(Default)" = "%LocalAppData%\<random 3 chars>.exe" -a "%1" %*
HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = "%LocalAppData%\<random 3 chars>.exe" -a "%1" %*
HKEY_CLASSES_ROOT\ah\shell\open\command "(Default)" = "%LocalAppData%\<random 3 chars>.exe" -a "%1" %*
HKEY_CLASSES_ROOT\ah\shell\open\command "IsolatedCommand"

Repair the registry with the following correct key copy (I attached it).

If you don't know what I am talking about, try finding someone to help you.
Attachments:
reg file
FixNCR.reg (1.18 kb)
0 hits.

"Three can keep a secret, if two are dead." -Benjamin Franklin

"Had, having, and in quest to have, extreme;
A bliss in proof, and proved, a very woe;
Before, a joy proposed; behind, a dream.
All this the world well knows; yet none knows well
To shun the heaven that leads men to this hell."
-William Shakespeare
Top
0 members in this topic (italic members are currently writing a reply): None
+ guest(s)


[09:08 pm]
Azrael -- <3 Sac.
[09:08 pm]
Raccoon -- az turns pls
[09:06 pm]
Azrael -- :kame:
[09:06 pm]
Raccoon -- wheres lovel
[09:05 pm]
Sacrieur -- yes of course
[09:05 pm]
Fire_Kame -- Four Seasons is leading...
[09:01 pm]
Dem0nS1ayer -- 22 minerals. do i dare play the boxes? D:
Please log in to shout.