Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old December 17th, 2011, 05:10 PM
Brandonn2010's Avatar
Brandonn2010 Brandonn2010 is offline
Very Frequent Poster
 
Join Date: Jan 2011
Posts: 1,211
Default Vista Security Center 2012

Whew. Somehow my mom's GeSWall was expired so this pos got on her computer. It blocked most programs from running, even in safe mode. I couldn't use a bootable AV because they couldn't update and I'm not sure how to connect to the Internet from them.

I finally tricked it by hitting ctrl+alt+del and getting to task manager from there instead of right-clicking the taskbar to get to it, hehe. I noticed PING.exe was consuming a large portion of the CPU and I killed it, but it kept coming back. I then noticed "hvw" running using less than 1MB of memory. I opened the file location and it had an apple icon?

Note that Panda Cloud and SpyShelter could both still run. I right-clicked hvw and uploaded to virustotal, which bypassed the rogue's Internet blocking capabilities. It got several hits for heuristics and rogues. I deleted the file (after getting a copy to upload to other AV vendors) and the rogue program disappeared.

However, now no exes can run. I have to change an exe to a com to get it to run. How do I fix this? And where can I upload the infection so other AVs can get a definition for it?
__________________
OS: Windows 7 Pro x64 | First-Line: Norton DNS + Google Chrome | Realtime: Bitdefender Free Antivirus | On-Demand: HitmanPro Free + Malwarebytes Free | My Computer Security Website: Link
  #2  
Old December 17th, 2011, 06:18 PM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: Vista Security Center 2012

Hi Brandonn2010, this one, or the same family...check out the fix.
Quote:
Originally Posted by Brandonn2010
However, now no exes can run
Quote:
To fix this we must first download a Registry file that will fix these changes.
you should follow the caned fix or ask to deal with all the idiosyncrasies of this malware.

edit: del quote
__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld

Last edited by Meriadoc : December 17th, 2011 at 07:10 PM.
  #3  
Old December 17th, 2011, 08:15 PM
TheKid7's Avatar
TheKid7 TheKid7 is offline
Very Frequent Poster
 
Join Date: Jul 2006
Posts: 2,480
Default Re: Vista Security Center 2012

The Avira Rescue System CD and the Dr.Web Live CD have either up-to-date Malware signatures or very close to up-to-date Malware signatures at the time of the ISO Image download. If you made a fresh CD, you would not need to update prior to scanning the infected PC.
__________________
NOD32, Sandboxie (Paid), AppGuard, Malwarebytes Anti-Malware, Emsisoft Emergency Kit, DrWeb Cureit, AVIRA Rescue CD, Image for Windows/Image for DOS/Image for Linux, Firefox (Adblock Plus, Subscriptions: EasyList+EasyPrivacy+Malware Domains), Norton DNS
  #4  
Old December 17th, 2011, 08:57 PM
Brandonn2010's Avatar
Brandonn2010 Brandonn2010 is offline
Very Frequent Poster
 
Join Date: Jan 2011
Posts: 1,211
Default Re: Vista Security Center 2012

@Meriadoc

I actually read that right after I posted. It worked and all is well.

@TheKid7

I keep several bootable AVs on my SARDU thumb drive so I would like to be able to update them on the go rather than burn a new ISO every time I need it. What is a proxy server that would work? Or how do you configure a connection on those?

And also where can I submit the file so all AVs will be able to detect it?
__________________
OS: Windows 7 Pro x64 | First-Line: Norton DNS + Google Chrome | Realtime: Bitdefender Free Antivirus | On-Demand: HitmanPro Free + Malwarebytes Free | My Computer Security Website: Link
  #5  
Old December 17th, 2011, 10:31 PM
TheKid7's Avatar
TheKid7 TheKid7 is offline
Very Frequent Poster
 
Join Date: Jul 2006
Posts: 2,480
Default Re: Vista Security Center 2012

Quote:
Originally Posted by Brandonn2010
I keep several bootable AVs on my SARDU thumb drive so I would like to be able to update them on the go rather than burn a new ISO every time I need it. What is a proxy server that would work? Or how do you configure a connection on those?
Do you have a wired or wireless Internet connection?
__________________
NOD32, Sandboxie (Paid), AppGuard, Malwarebytes Anti-Malware, Emsisoft Emergency Kit, DrWeb Cureit, AVIRA Rescue CD, Image for Windows/Image for DOS/Image for Linux, Firefox (Adblock Plus, Subscriptions: EasyList+EasyPrivacy+Malware Domains), Norton DNS
  #6  
Old December 17th, 2011, 10:54 PM
Brandonn2010's Avatar
Brandonn2010 Brandonn2010 is offline
Very Frequent Poster
 
Join Date: Jan 2011
Posts: 1,211
Default Re: Vista Security Center 2012

Quote:
Originally Posted by TheKid7
Do you have a wired or wireless Internet connection?

Wireless. Basically every computer I've worked on has a wireless connection. After trying a bunch of them, Bitdefender was the only one I could establish a connection, because it has the GUI network tool similar to the Network and Sharing Center in Windows, where it displayed our home network and I was able to click on it and enter our password.
__________________
OS: Windows 7 Pro x64 | First-Line: Norton DNS + Google Chrome | Realtime: Bitdefender Free Antivirus | On-Demand: HitmanPro Free + Malwarebytes Free | My Computer Security Website: Link
  #7  
Old December 17th, 2011, 11:28 PM
Brandonn2010's Avatar
Brandonn2010 Brandonn2010 is offline
Very Frequent Poster
 
Join Date: Jan 2011
Posts: 1,211
Default Re: Vista Security Center 2012

Oh here are the Virustotal results

~ VirusTotal Results Removed per Policy ~

Is there any way to submit it to all the vendors that missed it, because I've sent it to like 6 already and it is annoying.
__________________
OS: Windows 7 Pro x64 | First-Line: Norton DNS + Google Chrome | Realtime: Bitdefender Free Antivirus | On-Demand: HitmanPro Free + Malwarebytes Free | My Computer Security Website: Link

Last edited by JRViejo : December 18th, 2011 at 12:32 AM. Reason: VT Results URL Removed - JRViejo
  #8  
Old December 18th, 2011, 09:29 AM
TheKid7's Avatar
TheKid7 TheKid7 is offline
Very Frequent Poster
 
Join Date: Jul 2006
Posts: 2,480
Default Re: Vista Security Center 2012

Quote:
Originally Posted by Brandonn2010
Is there any way to submit it to all the vendors that missed it, because I've sent it to like 6 already and it is annoying.
I don't know of any way to do this. Here is a list of the E-Mail addresses:

http://www.wilderssecurity.com/showthread.php?t=277780
__________________
NOD32, Sandboxie (Paid), AppGuard, Malwarebytes Anti-Malware, Emsisoft Emergency Kit, DrWeb Cureit, AVIRA Rescue CD, Image for Windows/Image for DOS/Image for Linux, Firefox (Adblock Plus, Subscriptions: EasyList+EasyPrivacy+Malware Domains), Norton DNS
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:08 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums