Trojan / Worm

Hastelloy

Golden Oldie
Golden Oldie
May 11, 2006
697
8
105
Stone, UK
ok befire i post this thread i would like to state that it is not in anyway intended to start rumours/flame any1 etc, its merely one asking for advice and to potentially warn the people involved about their files =X

ok a week ago, i decided to get my dad onto pwnage (he hasnt played a mir2 server for about 5 years) jus to proove it could be just as good as mir3. i downloaded and installed OS client then downloaded and overwrote all files associated with pwnage server so that he would have everything he needed to play.
we went online for a bit until the server went off and decided to call it a night. he didnt go on his pc again until today when i went down due to work commitments etc and we turned the pc on and took the dogs out for a walk (it was sunny spur of the moment thing)
came back and the pc was having a bit of a tantrum, cpu usage was on about 99% and there was a program open that looked like a virus scanner (although it wasnt any of the actualy scanners that he uses) and the filenames it was going through at the time were his msn details. we thought it looked odd so closed it down, had to do it via CTRL, ALT & DEL.
the moment it closed down the pc froze, which was again a bit odd.

the pc was restarted and the first sign that something was wrong was instead of just one account (Dad) there was a second which had not been there before (Administrator), we logged in the first and the background had changed, and there was a number of virus alerts from the protection programs. the programs indicated that there were 8 trojans, a worm and something else i cant quite remember all located in the mir2 folder. these were deleted straight off (at least we think) by the programs but when we tried to check we found there was no C drive... again thats a little odd. on the start menu there was no control panel... if we tried accessing the internet all pages were http errors. its a sata harddrive, nothing would autoplay (cd's for reformat etc) command prompt wouldnt load etc even my dads friend who works for BT couldnt do anything to it.
iv installed the same set of files beforehand and the only problem i have experienced is with my internet. i randomly get http errors or a message saying "ww.soren.co.uk does not exist please contact dataforce" this is mainly when on lomcn though :S. the weirdest message so far has been one on google when i have searched for case law, its come up with a message saying the page cannot load due to my pc attempting an illegal request?!?!?

im really stuck for answers because im not really an expert, one thing i would like to say though is that maybe the owners of the files (OS and Pwnage) could check that the site they have hosted them on hasnt attached anything nasty etc

my pc uses a mix of AVG and some Netgear wireless firewall thing
my dads uses a mix of Avast, AVG and ZoneAlarm.

any ideas/comments please?
-Jay
 

Hastelloy

Golden Oldie
Golden Oldie
May 11, 2006
697
8
105
Stone, UK
just had the soren thing again while opening lomcn



sum1 help >< iv scanned my pc a number of times and it says theres nothing bad on it but there obv is :(
 

stephenking

I HAVE A DREAM!!
Developer
Aug 28, 2005
616
39
155
Netherlands
download kaspersky anti-virus use the 30day trial key to activate kaspersky fully now go into safe mode and let kaspersky do a full system scan let it also scan your system memmory etc.

im almost sure kaspersky can find every single malware,adware,hacker soft,trojans,viruses,worms etc

http://www.kaspersky.com/

this is my advise
 

Turtle

Dedicated Member
Dedicated Member
Mar 24, 2003
96
0
82
in a box
download kaspersky anti-virus use the 30day trial key to activate kaspersky fully now go into safe mode and let kaspersky do a full system scan let it also scan your system memmory etc.

im almost sure kaspersky can find every single malware,adware,hacker soft,trojans,viruses,worms etc

http://www.kaspersky.com/

this is my advise

it cant find every as u could write a new one today that wouldnt be in there db's yet

the full os client has been on my ftp for over 6months (not autopatcher) the "virus" that avg is showing is due to thedeaths coding

where u doing anything else at the time?
 

Hastelloy

Golden Oldie
Golden Oldie
May 11, 2006
697
8
105
Stone, UK
it cant find every as u could write a new one today that wouldnt be in there db's yet

the full os client has been on my ftp for over 6months (not autopatcher) the "virus" that avg is showing is due to thedeaths coding

where u doing anything else at the time?
ah ok

no we did nothing else at the time, no msn etc the only programs open were internet explorer, 1 page for lomcn the other for downloads etc.

im just running the kapersky thing on my pc now hope it finds whatever is on my pc, as for my dads i have no way of putting kapersky on it, and does any1 know if it is actually possible to reformat a sata HD or is it well and truly stuffed

thanks for responses

-Jay

*edit* it still doesnt explain why the pc removed "C" drive and deleted control panel and all the rest of the problems :(
 

stephenking

I HAVE A DREAM!!
Developer
Aug 28, 2005
616
39
155
Netherlands
it cant find every as u could write a new one today that wouldnt be in there db's yet

its not about new one's its about the actions it takes
for example if id write a new proggie that looks at what your keyboard does kaspersky will still recognise it as a keylogger

its about the actions that makes it a trojan,virus etc
like changing files or rewriting register codes
just creating a new one will still be recognized most of the time

and thats where kaspersky comes in as you can set the options to monitor every single action your pc does

it still doesnt explain why the pc removed "C" drive and deleted control panel and all the rest of the problems


at this stage id say its already to late for any virusscan to undo whats already done
 

Hastelloy

Golden Oldie
Golden Oldie
May 11, 2006
697
8
105
Stone, UK
its not about new one's its about the actions it takes
for example if id write a new proggie that looks at what your keyboard does kaspersky will still recognise it as a keylogger

its about the actions that makes it a trojan,virus etc
like changing files or rewriting register codes
just creating a new one will still be recognized most of the time

and thats where kaspersky comes in as you can set the options to monitor every single action your pc does




at this stage id say its already to late for any virusscan to undo whats already done

yeh we already thought that when we couldnt do anything with the HD lol (when we tried it on his m8s pc) but hopefully my pc can b saved before it comes to that, i guess its a good time to back up to a external hd =X
 

Neptune

Golden Oldie
Golden Oldie
Nov 19, 2003
1,473
9
175
Chester :P
take a screen shot of the prgrams running in taskmanager.

from what ur dads got, hes got what i had (by the sound of it) if u can take a screeny of his taskmanager, and send it thru the router to a diff PC thats fine and uplaod it, there might still be somethin we can do.

to restore the HD on ur dads PC, just insert CD and Reboot, then it will look at the disk and ask if u wana load from the disk (if it doesnt ask this) check ur setup (normally pressing delete or F2 on start up repeatidly till it loads up).

the usual boot options u want id CD drivve first (then floppy drive (normally) but can vary on certain PC's) then from ur local drive.

the administrator account will show up when the PC is ran in Safe Mode. if u can access the pc in safe mode, try click run from start menu (if run isnt in the options there, right click the tool bar thats next to the start button then click properties, then start menu from the top, then customize, look for the show run command and tick the box on the left then ok and ok again) this will show it on the start menu. when the run box open type in RegEdit, if it says its been disabled by a admin account, then u have the virus i had, only way to remove it is by reformatting, (stated as above).

before the format try these or even try a simple repair the OS system, so u can keep ur pics / what ever. post the task manager from both the pc's (urs and ur dads) and ill have a look and see whats running, to see if there is anythin ither myself or any 1 else can help u out with.

P.S, quickly loads both the pcs up in Safe Mode (F8 on start up), and follow this guide to password protect ur PC quickly http://www.lomcn.co.uk/forum/showthread.php?t=58141 the reest of it (With IE etc can be done later on) this will help u if the virus hasnt had time to set in properly yet
 
Last edited:

Hastelloy

Golden Oldie
Golden Oldie
May 11, 2006
697
8
105
Stone, UK
to restore the HD on ur dads PC, just insert CD and Reboot, then it will look at the disk and ask if u wana load from the disk (if it doesnt ask this) check ur setup (normally pressing delete or F2 on start up repeatidly till it loads up).


wont work, CD's dont auto run and the driver isnt recognized, cant force it to autorun either by using the run function in start menu

no way of getting the cd to start
 

Neptune

Golden Oldie
Golden Oldie
Nov 19, 2003
1,473
9
175
Chester :P
wont work, CD's dont auto run and the driver isnt recognized, cant force it to autorun either by using the run function in start menu

no way of getting the cd to start

all windows disks should auto run from the start up. r they norm cds or copys??

u tryed looking at the boot up process in start up config??
 

Hastelloy

Golden Oldie
Golden Oldie
May 11, 2006
697
8
105
Stone, UK
all windows disks should auto run from the start up. r they norm cds or copys??

u tryed looking at the boot up process in start up config??

normal, its like the pc doesnt think teh dvd drive is even there, we had his mate around who works for BT servers n stuff like that dno what specifically but he couldnt do anythin with it lol
 

Xanan

LOMCN Veteran
Veteran
Loyal Member
Jan 5, 2006
1,203
10
124
take it your dad still thinks mir3's better?
 

stephenking

I HAVE A DREAM!!
Developer
Aug 28, 2005
616
39
155
Netherlands
wont work, CD's dont auto run and the driver isnt recognized, cant force it to autorun either by using the run function in start menu

no way of getting the cd to start

press Del key at bootscreen when your pc startsup set your boot to your cd/dvd drive , restart pc with windows cd in it and it should startup from cd/dvd
 

Neptune

Golden Oldie
Golden Oldie
Nov 19, 2003
1,473
9
175
Chester :P
its ither Del or F2, my laptop is F2 + Del but my home PC is just F2, just do a combination lol