Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 3rd, 2010, 06:15 AM
Godzestla Godzestla is offline
Infrequent Poster
 
Join Date: Aug 2010
Posts: 6
Default My PC date Time rolls back

Hi,

this is my first post here so my apologies if it's not the correct way.
Since 1 week, my PC date_time goes back. When i boot my machine, the time and hour displaied is the dat_time of last machine stop. I reset that manually and suddenly during my work, the time (and date) goes back some around 15 or 30 minutes.

This is a professional machine so i'm not allowed to install whatever i'd like to check and clean.

I'm using (mandatory) Symantec Endpoint protection 11 (Virus and Firewall).
The full scan has not found any malicious process, unfortunately.

I've tried malwareBytes that had helped me in the past, but nothing is also found.

I've noticed in my active process that WMIPRVSE.EXE is running twice, what i never saw before. My queries on the web explained that WMIPRVSE.EXE should be located in \system32\wbem, and that's the case. (so no a infected version in \system32 directly).

I've use Sybot S&D to checkout all the startup processes (procs and services) and i have desactivated all the unnecessary ones.

No improvement.

I really loose my nerves on that and don't know what i can use to try to find this malicious process.

Could someone give me some tips to fight this problem ?

Thanks in advance.

Godzestla.
  #2  
Old August 3rd, 2010, 08:20 AM
Peter2150's Avatar
Peter2150 Peter2150 is offline
Global Moderator
 
Join Date: Sep 2003
Posts: 11,805
Default Re: My PC date Time rolls back

Have you replaced the batter on the mother board.
  #3  
Old August 3rd, 2010, 09:52 AM
tobacco's Avatar
tobacco tobacco is offline
Frequent Poster
 
Join Date: Nov 2005
Location: British Columbia
Posts: 1,460
Default Re: My PC date Time rolls back

Quote:
Originally Posted by Peter2150
Have you replaced the batter on the mother board.

Sounds "tasty" Pete!
__________________
Sent From My New "ipod killer" - the Samsung Galaxy Media Player 5.0
  #4  
Old August 3rd, 2010, 09:59 AM
xxJackxx's Avatar
xxJackxx xxJackxx is offline
Very Frequent Poster
 
Join Date: Oct 2008
Location: USA
Posts: 2,533
Default Re: My PC date Time rolls back

CMOS battery is a good start. Also make sure you are set for the correct time zone. If neither of those is an issue, are you on a domain? Maybe it is syncing with a domain controller that has the wrong time, or is possibly in another time zone. Just throwing out some possibilities.
  #5  
Old August 3rd, 2010, 10:02 AM
Godzestla Godzestla is offline
Infrequent Poster
 
Join Date: Aug 2010
Posts: 6
Default Re: My PC date Time rolls back

Hi Peter2150,

Thanks for the reply.
This is planned to be done, but i don't think the battery 'low' issue could explain that since my today's boot , time rolls back and back and back. The delay between the current time and the computer one is now 4 hours, compared to zero last time i boot and reset the difference. (around 4 hours ago).
This brings such a chaos in the event viewer than i cannot find what is actual or not.
But despite that and the obvious ennoying impact , this sounds a bit funny.

I'm actually running the Windows XP Cleaning Procedure (MajorGeeks) linked from this site and so far a Trojan.Agent/Gen-FakeAlert(Local) has been detected by SuperAntiSpyware (still scanning).

Life sucks.
  #6  
Old August 3rd, 2010, 10:03 AM
Peter2150's Avatar
Peter2150 Peter2150 is offline
Global Moderator
 
Join Date: Sep 2003
Posts: 11,805
Default Re: My PC date Time rolls back

Quote:
Originally Posted by tobacco
Sounds "tasty" Pete!

Groan
  #7  
Old August 3rd, 2010, 10:04 AM
Godzestla Godzestla is offline
Infrequent Poster
 
Join Date: Aug 2010
Posts: 6
Default Re: My PC date Time rolls back

XXjackXX,

the time zone is correct. The domain is effectively attached but only my computer is rolling back the time, the 100 others are ok.

What the f.... is it ?
  #8  
Old August 3rd, 2010, 10:17 AM
xxJackxx's Avatar
xxJackxx xxJackxx is offline
Very Frequent Poster
 
Join Date: Oct 2008
Location: USA
Posts: 2,533
Default Re: My PC date Time rolls back

It sounds like that if SUPERAntiSpyware found Trojan.Agent/Gen-FakeAlert(Local) then you are off to a good start on solving the problem.
  #9  
Old August 3rd, 2010, 10:23 AM
Godzestla Godzestla is offline
Infrequent Poster
 
Join Date: Aug 2010
Posts: 6
Default Re: My PC date Time rolls back

I hope you are right, despite the object found sounds like a normal 'server team provided one'.

Let's set the time correct, reboot and see.

See you.
  #10  
Old August 3rd, 2010, 10:59 AM
Searching_ _ _'s Avatar
Searching_ _ _ Searching_ _ _ is offline
Very Frequent Poster
 
Join Date: Jan 2008
Location: iAnywhere
Posts: 1,988
Default Re: My PC date Time rolls back

Don't forget to check the BIOS time to see if it changed.

Try surfing with Sandboxie. Might help prevent things in the box changing things outside the box.
__________________
Americans are the enemy? Mil. can arrest you?
What the heck is going on?
  #11  
Old August 4th, 2010, 04:12 AM
Godzestla Godzestla is offline
Infrequent Poster
 
Join Date: Aug 2010
Posts: 6
Default Re: My PC date Time rolls back

Hi,

the Trojan was not the cause.

My pc is now rebooted with bad date and time and the time is now rolling back again.

I'll reboot and check the Bios date.
  #12  
Old August 4th, 2010, 10:23 AM
xxJackxx's Avatar
xxJackxx xxJackxx is offline
Very Frequent Poster
 
Join Date: Oct 2008
Location: USA
Posts: 2,533
Default Re: My PC date Time rolls back

BIOS date won't likely be different. Has the battery been replaced yet?

Also, though it may not matter, what OS are you running?
  #13  
Old August 4th, 2010, 11:35 AM
Searching_ _ _'s Avatar
Searching_ _ _ Searching_ _ _ is offline
Very Frequent Poster
 
Join Date: Jan 2008
Location: iAnywhere
Posts: 1,988
Default Re: My PC date Time rolls back

I have had problems in the past with malware changing the BIOS time.
Whether through windows or actually changing CMOS, I don't know.

Goes like this:
Windows time changes, usually 3 or 4 hours.
Reboot, check BIOS time, no change.
Reset time in Windows to correct the time, reboot.
Time is changed by 1 hour, what happened, I corrected it already.
Reboot, check BIOS time, It's now 3-4 hours different.

Maybe it's a trick to get you to reboot so it can be installed deeper.

Malware was changing the time in the BIOS.
I fixed using UBCD and the WipeCMOS tool.
Since I use Sandboxie religiously, no more time changes, go figure.

It doesn't hurt to check/replace the battery either.
__________________
Americans are the enemy? Mil. can arrest you?
What the heck is going on?
  #14  
Old August 5th, 2010, 04:50 AM
Godzestla Godzestla is offline
Infrequent Poster
 
Join Date: Aug 2010
Posts: 6
Thumbs up Re: My PC date Time rolls back

Hi,

i've replaced the battery, synchronized BIOS date_time and windows one and now it seems to be correct and permanent.

Very strange this rolling back date_time phenomenon when the machine run. I'm not able to understand the link with the battery, but i have to accept that there is a link.

Computers ! Not to understand.

For info, my OS is XP 32 Bits SP3.

Thanks to all of you for your help.

Regards.

G@dz
  #15  
Old August 5th, 2010, 08:47 AM
lotuseclat79 lotuseclat79 is offline
Very Frequent Poster
 
Join Date: Jun 2005
Posts: 1,912
Default Re: My PC date Time rolls back

Why not install and run an NTP time server (there should be one at your place of work as you mention that this is a professional machine), or at home is doing consulting work.

The NTP time server will automatically keep correct time for your location based on its correct configuration.

-- Tom
  #16  
Old August 6th, 2010, 10:27 AM
xxJackxx's Avatar
xxJackxx xxJackxx is offline
Very Frequent Poster
 
Join Date: Oct 2008
Location: USA
Posts: 2,533
Default Re: My PC date Time rolls back

The domain he is on would likely override any NTP settings he would have so it would be pretty pointless to bother with. Great to hear it is fixed!
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 03:58 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums