Query on the dreaded desktoplayer.exe virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by Kuznetsov, Aug 30, 2010.

  1. Kuznetsov

    Kuznetsov Private E-2

    I've been infected with this for a while and today I have decided that the best option is to reformat and reinstall windows 7.


    However I'm very concerned about something...


    I backed up installation files and drivers plus my steam games/personal files onto my seagate external HD. No system files or direct exe's apart from the steam ones I guess.

    Now this is the scary part, when I went to eject disk it refused to do it until I deleted desktoplayer.exe (yet again) in C:\Program Files (x86)\Microsoft (oh boy it's already back since I browsed there to copy paste that location...)


    I'm very worried now that it's snuck its way onto the shuttle... erm external HD (does the film Alien spring to mind?)


    I know that this one's a real demon and people everywhere are still finding out about it. So, I don't request any help on running combo fix or anything, it's too late for that. (Apologies therefore, if this is posted in the wrong section!)

    What I would like to know is if people here already know about it's tendencies to do this with external hard drives, if not, then well here's some info for you :) if so, should I just scrap ever using any files off it, reformat it later and use the slow and painful way of retrieving all my files again?

    Thanks for any help.


    Edit: oh also, what behaviours could it possibly do once on my drive? I'm wondering if it's simply a case of latching itself to any system files or direct exe's, or is this thing capable of hiding itself and jumping right back onto my system as soon as I connect to my nice clean system? Even if I set up any anti virus program, I get the feeling it still wouldn't detect it when scanning after connecting my drive...
     
    Last edited: Aug 30, 2010
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not recalling it latching onto external drives. But the best course of action is to have your AV software in place and updated and then once you attach the external drive, scan it with that as well as with SAS and then MBAM. You may also want to install:
    AutoEater.


    We have dealt with a few of these infections successfully in the past.
     
  3. Kuznetsov

    Kuznetsov Private E-2

    The version I picked up certainly does unfortunetly! It seems to be the full package.

    I believe it's a version of the 'Ramnit' virus.

    Since my first post, I tested my backup HD with an old XP laptop and in seconds it was infected, eating system files, hooking itself to winlogon and disabling scvhost processes, eventually when I turned the laptop back on it immediately tried to shut itself down. This thing travels and spreads efficiently.


    The problem is, no AV software I've used thus far ever picked it up. This virus was first heard of in July, it seems people are still finding a fix and updating AV programs with it.


    The first thing it did when it jumped off my HD onto the XP machine was disable Adaware and shut it down.


    I ran these in safe mode on my Windows 7 laptop before reformatting with no success:

    Spybot
    Adaware
    SUPERAntiSpyware
    HijackThis (useless, as the entries came right back)
    Windows Defender scan
    Sophos online scan
    Avira (tihs one went bananas and flagged everything as dangerous)
    Malwarebytes deep scan
    Also a few anti rootkits

    I think I'm going to have to wait until programs like the above can recognise it and remove all traces of it before I consider using my HD again. It's too new and it will do too much damage as soon as I connect it before I can even begin to scan it.


    Thank you, I'll try that program on the HD once the XP laptop is stable enough.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    With your external drive connected, go to C:\MGTools\FindRN.bat and run it. Then attack the new MGLogs.zip.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds