﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Tweaks.com Forum  / Windows &amp; System Security / Virus / Spyware Problems and Security Software Issues  / Horribly destructive infection, please help / Latest Posts</title><generator>InstantForum.NET v4.1.4</generator><description>Tweaks.com Forum </description><link>http://forum.tweaks.com/forum/</link><webMaster>forum@tweaks.com</webMaster><lastBuildDate>Thu, 21 Aug 2008 17:34:26 GMT</lastBuildDate><ttl>20</ttl><item><title>RE: Horribly destructive infection, please help</title><link>http://forum.tweaks.com/forum/Topic239599-28-1.aspx</link><description>[quote][b]quietman7 (5/28/2008)[/b][hr][quote]Most average users don't know how to do that.[/quote]&lt;br&gt;&lt;br&gt;Seems the original poster DID though... he had rogue filenames.&lt;br&gt;&lt;br&gt;[quote][b]quietman7 (5/28/2008)[/b][hr][quote]And as part of the disinfection process we help them understand how they got infected and how to keep from getting reinfected[/quote]&lt;br&gt;&lt;br&gt;Fact is, you don't REALLY need automatic remover tools... not really &amp; also, as to making it so it REALLY never happens again (IF you can obey some simple rules)?&lt;br&gt;&lt;br&gt;All here -&gt; [b] HOW TO SECURE Windows 2000/XP/Server 2003 &amp; VISTA even (so you DON'T "get hit" again):[/b]&lt;br&gt;&lt;br&gt;[url]http://forum.tweaks.com/forum/Topic230980-28-1.aspx[/url]&lt;br&gt;&lt;br&gt;In that post's "VIRUS SPYWARE REMOVAL SECTION" ?&lt;br&gt;&lt;br&gt;[b]I outline HOW to use RC (possibly ProcessExplorer also) for that (determining culprits &amp; also, destroying them), &amp; finding what the user's hassle is in rogue processes that are LOCKED while inside RPL3/Ring3/Usermode operations under Explorer.exe shell!&lt;br&gt;&lt;br&gt;(Also, vs. rootkits he suspected (bootsector type))&lt;br&gt;&lt;br&gt;[quote][b]quietman7 (5/28/2008)[/b][hr][quote]Malware Removal Experts like RichieUK are able to assist them with easy to understand directions using specialized fix tools developed by other experts.[/quote]&lt;br&gt;&lt;br&gt;ON "Experts" - a purely relative term... but, not knocking Rich... &amp; that's where * I THINK * you have me wrong... I was merely pointing out alternate methods, period, that need nothing more than free tools or ones you have already (no 'automators' necessary really).&lt;br&gt;&lt;br&gt;(YES - Automatic "killer" programs are nice &amp; "time savers" too... 'script kiddie tools' really (this is no putdown, they ARE someone's hard work &amp; time freely given many times), &amp; they DO move faster than folks can... but, I have also seen them generate "false positives" too, on that note. "Want a job done right? DO IT YOURSELF" if possible)&lt;br&gt;&lt;br&gt;I'd largely wager? He'll tell you the same, &amp; on MOST accounts noted here.&lt;br&gt;&lt;br&gt;APK&lt;br&gt;&lt;br&gt;P.S.=&gt; On virus removals &amp; such? As part of my duties, professionally since 1994?? I've done literally 1,000's for paying customers, ranging from home users all the way up thru corporate networks under attack (by those &amp; far worse) @ the tune of $150 per hour or more... &lt;br&gt;&lt;br&gt;Personally speaking, &amp; I'd wager Ritchie will agree? Once you get a GOOD set of tools &amp; some understanding of what is needed??? This isn't "rocket science"... I'd bet even Ritchie will tell you that! Only takes a small amount of time studying a few with the right tools, &amp; you don't even NEED "automatic virus/spyware killers" etc. really! apk</description><pubDate>Fri, 30 May 2008 10:18:01 GMT</pubDate><dc:creator>APK</dc:creator></item><item><title>RE: Horribly destructive infection, please help</title><link>http://forum.tweaks.com/forum/Topic239599-28-1.aspx</link><description>[quote]...&amp; as far as "trojan files" too, DEL command in RC does the job...[/quote]&lt;br&gt;The infection and the malware files have to be identified first. Most average users don't know how to do that. Malware Removal Experts like RichieUK are able to assist them with easy to understand directions using specialized fix tools developed by other experts. That's why we have this and the HJT forum. And as part of the disinfection process we help them understand how they got infected and how to keep from getting reinfected.</description><pubDate>Wed, 28 May 2008 06:22:18 GMT</pubDate><dc:creator>quietman7</dc:creator></item><item><title>RE: Horribly destructive infection, please help</title><link>http://forum.tweaks.com/forum/Topic239599-28-1.aspx</link><description>It's only 7 days old... &amp; the point of MY reply was to simply point out that you DON'T really need 3rd party tools for many removals... inclusive of bootsector originated ROOTKITS (fixmbr takes care of those, "lickety split, no XXXX") &amp; as far as "trojan files" too, DEL command in RC does the job on those, same effort/speed (fast &amp; painless).&lt;br&gt;&lt;br&gt;APK</description><pubDate>Tue, 27 May 2008 08:49:18 GMT</pubDate><dc:creator>APK</dc:creator></item><item><title>RE: Horribly destructive infection, please help</title><link>http://forum.tweaks.com/forum/Topic239599-28-1.aspx</link><description>APK,this is an old topic which has since been resolved.</description><pubDate>Mon, 26 May 2008 18:21:11 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: Horribly destructive infection, please help</title><link>http://forum.tweaks.com/forum/Topic239599-28-1.aspx</link><description>You know, there is a VERY easy method to stop the problem child(s) you are seeing... &amp; you ALREADY OWN THE TOOLS:&lt;br&gt;&lt;br&gt;[b]RECOVERY CONSOLE[/b]&lt;br&gt;&lt;br&gt;(Boot from your XP/Server 2003/VISTA install media, &amp; run it there (via bootoptions menus choices then))&lt;br&gt;&lt;br&gt;OR, just install it to your OS drive, via :&lt;br&gt;&lt;br&gt;1.Insert the Windows XP CD into the CD-ROM drive.&lt;br&gt;2.Click Start, and then click Run.&lt;br&gt;3.In the Open box, type d:\i386\winnt32.exe /cmdcons where d is the drive letter for the CD-ROM drive.&lt;br&gt;4.A Windows Setup Dialog Box appears. The Windows Setup Dialog Box describes the Recovery Console option. To confirm the installation, click Yes.&lt;br&gt;5.Restart the computer. The next time that you start your computer, "Microsoft Windows Recovery Console" appears on the startup menu.&lt;br&gt;&lt;br&gt;Then once you are booted &amp; logged into it, use:&lt;br&gt;&lt;br&gt;FixMBR&lt;br&gt;&lt;br&gt;&amp;&lt;br&gt;&lt;br&gt;DEL (filename)&lt;br&gt;&lt;br&gt;Once in the folder/directory (via CD dos command) where those rogue files are, burn them, in RC... using DEL.&lt;br&gt;&lt;br&gt;* This type of info. is in my "HOW TO SECURE Windows 2000/XP/Server 2003 &amp; VISTA, &amp; make it 'fun to do', via CIS Tool Guidance" post in this section of these forums in fact.&lt;br&gt;&lt;br&gt;(Specifically in its VIRUS/SPYWARE/ROOTKIT REMOVAL section).&lt;br&gt;&lt;br&gt;You MAY have to use SECPOL.msc &amp; give yourself rights to folders other than %windir% &amp; its subordinates though, if the rogue files aren't underneath Windows itself... because RC's default ACL to those things is just %windir% &amp; its subordinate folders only.&lt;br&gt;&lt;br&gt;Start in Left-hand side pane of secpol.msc -&gt; Security Settings -&gt; Local Policies -&gt; Security Options (now right-hand side pane of secpol.msc) -&gt; Recovery Console: Allow Floppy Copy and Access to all drives and folders&lt;br&gt;&lt;br&gt;APK</description><pubDate>Mon, 26 May 2008 17:23:10 GMT</pubDate><dc:creator>APK</dc:creator></item><item><title>RE: Horribly destructive infection, please help</title><link>http://forum.tweaks.com/forum/Topic239599-28-1.aspx</link><description>You're welcome:)</description><pubDate>Sun, 18 May 2008 02:50:00 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: Horribly destructive infection, please help</title><link>http://forum.tweaks.com/forum/Topic239599-28-1.aspx</link><description>Thanks for the reply. &lt;br&gt;&lt;br&gt;http://forum.tweaks.com/forum/Topic239612-29-1.aspx</description><pubDate>Sat, 17 May 2008 05:07:00 GMT</pubDate><dc:creator>Fennesz</dc:creator></item><item><title>RE: Horribly destructive infection, please help</title><link>http://forum.tweaks.com/forum/Topic239599-28-1.aspx</link><description>Welcome:)&lt;br&gt;Download [b][url=http://download.bleepingcomputer.com/hijackthis/HJTInstall.exe][color="red"]Trend Micro HijackThis 2.0.2[/color][/url][/b] to your desktop:&lt;br&gt;Double click on HJTInstall.exe,it will prompt you to extract hijackthis.exe to C:\Program Files\Trend Micro\HijackThis. &lt;br&gt;When the install is complete,HijackThis will automatically launch. &lt;br&gt;When the license agreement appears,select "I Accept" and then click on the "Do a system scan only" button. &lt;br&gt;When the scan is complete,click on the "Save Log" button,then save it to your desktop.&lt;br&gt;Copy and paste the entire contents of that log into a new topic in the [b][url=http://forum.tweaks.com/forum/Forum29-1.aspx]HijackThis Logs forum[/url][/b],[b][color="red"] not here.[/color][/b]</description><pubDate>Sat, 17 May 2008 03:46:14 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>Horribly destructive infection, please help</title><link>http://forum.tweaks.com/forum/Topic239599-28-1.aspx</link><description>Hi. Yesterday I picked up on some rogue processes, and then over until this afternoon those few sprouted into many including (not precise) "mrofinu", "syst3m32.exe", "DILx.tmp" with "x" being a number between 1-15, and another I can't remember now. Amongst all this many important files became corrupt, including explorer.exe, and the internet was almost completely non-fucntional up until Generic Host Process (svchost.exe) crashed and took me offline properly until I restarted. &lt;br&gt;&lt;br&gt;This evening I reformatted because I didn't see any possible salvage, but the problem seems to have brilliantly survived the wipe. My Temp folder is now full of DILx.tmp files again, and explorer among other things (the process that handles 16bit applications) have started to fail again. New processes, or ones I didn't notice before, have appeared, including ___r.exe and ___synmgr.exe. &lt;br&gt;&lt;br&gt;I heard things can survive in the MBR, but I have no idea how to tackle this and in what order so as to actually contain the spread.&lt;br&gt;&lt;br&gt;Help?&lt;br&gt;&lt;br&gt;Edit: As a side note, most of the drivers I need to be installing are 16 bit, so I don't even have a working AGP chipset.</description><pubDate>Fri, 16 May 2008 20:32:09 GMT</pubDate><dc:creator>Fennesz</dc:creator></item></channel></rss>