Virus infecting all exe files

Discussion in 'Malware Help (A Specialist Will Reply)' started by 000022, Aug 5, 2008.

  1. 000022

    000022 Private E-2

    This virus seems to infect all of my exe processes, causing them to attempt to rewrite the security registry policies if changed.
    The two registries are disabletaskmgr and disableregistrytools.

    I know this because Kaspersky would detect the processes attempting to change the policies, but could do nothing against the virus. I could end some processes, but then the next one would do the same.

    For example, DWM.exe would start, if i end it, my bluetooth services would start, if I end that too, even AVP (kaspersky) itself would start doing it and then I will not be able to block its attempt cause AVP itself is doing it.

    Anyone has any experience on this kind of virus? It's really screwing my laptop up..
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    If you truly have one of the many infections that infect ALL executable files, you will more than likely be reinstalling from scratch since your PC will be unreliable and the act of fixing it could make it unbootable since infected system files may be deleted when they cannot be fixed.


    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.




    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    Notes:

    1. If you run into problems trying to run theREAD & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  3. 000022

    000022 Private E-2

    Before posting, I've already tried numerous malware check (I have a bit hands-on experience with viruses) including using hijackthis, sdfix and combofix, but to avail, nothing works, I reformatted my pc, gave up after 2 days of traumatizing events.

    For one, sdfix wouldn't work because of the registry policy i mentioned earlier, and this isn't a simple task of ending the "unusual" process because when I end the process overwriting the policies, another would take its place, and all of it are the usual processes (explorer, DWM, even my kaspersky)

    Combofix don't work either, SFC /scannow can't detect any abnormalities, scruns. I had to use process explorer as taskmgr has been disabled, but it works only once, after that, the virus seems to prevent it from working. Hijackthis works, but only in terms of doing a system scan, the fixing function doesn't (registry restriction).

    The system lags as well, as one process is constantly eating up at least half of the system's resources (continuosly adding the same restrictions regardless). The worst part? It infects Hijackthis.exe (i'd put it in my usb pen drive to use it on the infected computer), when i plugged it in to my laptop and started hijackthis, hell broke loose. I know ,stupid of me to do so. So, after formatting both my laptop and computer, I just want to document my find. BTW, my kaspersky was up to date, and I scanned the usb drive when i inserted it.

    Safe mode wouldn't work too, The virus has probably tempered with my safe boot registry, and there's nothing I could do about it. Although I managed to access it once, by removing the restriction then quickly adding the .reg to fix my tempered safeboot registry. But even then, the virus is still in working condition.

    If the infected system is ever online, the virus will be prompted to download more trojans and companions onto the infected computer. Like a UPX trojan.

    I also used Hiren, but even with all its tools and antivirus, nothing works. Nothing seems to be able to erradicate this virus.

    One last thing, the virus likes to cause explorer to hang. Alot. Thank god CMD was still useable.

    Nothing of improtance here, just thought I'd document my find, and forgive me for not providing logs and finds as I'm afraid of the virus infecting my laptop.Again.



    *UPDATE : after writing all that, I plugged in my usb again (with Norton Protection Center), strangely enough, it detected win32.Sality.AE, in all of my exe files and purged them. I had first thought of this virus when my computer was infected with it, but mcafee and kaspersky, both which should have countered Sality didn't respond. A new stronger variant perhaps?
     
    Last edited: Aug 5, 2008
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well as I stated earlier, the most reliable fix for PE type infections is a total clean reinstall. So the when you did that, you were better off anyway.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds