Windows sucks

Discuss whatever insanity comes to mind. Please keep it friendly and clean though.

Moderator: General Mods

Post Reply
corronchilejano
Transmutation Specialist
Posts: 724
Joined: Tue Feb 08, 2005 5:17 pm
Location: Colombia (and no, not on the jungle)
Contact:

Windows sucks

Post by corronchilejano »

Allright I have this werm in my pc. I'm not mispelling, it will ACTUALLY turn my pc off if I write anything that gives off it's name. It loads some programs into the PC (lsass, winlogon, services and another one I forgot) and doesn't let me change the settings to view hidden files.

Anybody here know this worm? It seems it shares the emails I have in Messenger and also deleted previous checkpoints in the PC by copying and renaming the admin account to administrador.000 and administrador.001, so I can't just get a previous checkpoint.

Anybody know this thing or has any idea how to delete it?

It's bronstab
[size=67]
Playing:
[color=green]Blur, Front Mission DS, Fire Emblem: Shadow Dragon, The Last Remnant[/color]
In Line:
[color=red]Far Cry II, Final Fantasy XIII, Revenant Wings[/color]
[/size]
casualsax3
Veteran
Posts: 743
Joined: Tue Aug 10, 2004 4:38 pm

Post by casualsax3 »

Do yourself a favor and reinstall. What are the specs of the machine?
AntoineWG
Trooper
Posts: 530
Joined: Thu Jul 29, 2004 6:59 pm
Location: 127.0.0.1
Contact:

Post by AntoineWG »

Try HijackThis! If that can't remove it, re-install
[i]"It is better to have tried and failed than to have failed to try, but the result's the same." - Mike Dennison[/i]
corronchilejano
Transmutation Specialist
Posts: 724
Joined: Tue Feb 08, 2005 5:17 pm
Location: Colombia (and no, not on the jungle)
Contact:

Post by corronchilejano »

*sigh*

I don't have a copy of XP where I am.
[size=67]
Playing:
[color=green]Blur, Front Mission DS, Fire Emblem: Shadow Dragon, The Last Remnant[/color]
In Line:
[color=red]Far Cry II, Final Fantasy XIII, Revenant Wings[/color]
[/size]
PHoNyMiKe
Retrosexual
Posts: 1011
Joined: Wed Jul 28, 2004 2:09 am
Location: Rapture

Post by PHoNyMiKe »

click start, run, msconfig, go to the startup tab. write down anything that sounds weird. reboot, keep pressing F8, and go into safe mode with networking. try searching the net for those things.

I had some sort of thing AVG kept catching, but it kept coming back. the net was no help. I saw something in ie's add-ons that looked weird. I believe I logged in as an admin, uncheck "use simple file sharing" in windows explorer, right click properties on the file, go to the security tab, and I set the permissions of the file so nobody could execute it (admin, myself, system, everybody) and I was able to delete the file.
[url=http://www.alexchiu.com/affiliates/clickthru.cgi?id=phonymike]ultimate immortality[/url]
[url=http://www.sloganizer.net/en/][img]http://www.sloganizer.net/en/image,zsnes,white,purple.png[/img][/url]
corronchilejano
Transmutation Specialist
Posts: 724
Joined: Tue Feb 08, 2005 5:17 pm
Location: Colombia (and no, not on the jungle)
Contact:

Post by corronchilejano »

phOnYmIkE wrote:click start, run, msconfig, go to the startup tab. write down anything that sounds weird. reboot, keep pressing F8, and go into safe mode with networking. try searching the net for those things.

I had some sort of thing AVG kept catching, but it kept coming back. the net was no help. I saw something in ie's add-ons that looked weird. I believe I logged in as an admin, uncheck "use simple file sharing" in windows explorer, right click properties on the file, go to the security tab, and I set the permissions of the file so nobody could execute it (admin, myself, system, everybody) and I was able to delete the file.
It's in memory even in safe mode... it's unbeateable.
[size=67]
Playing:
[color=green]Blur, Front Mission DS, Fire Emblem: Shadow Dragon, The Last Remnant[/color]
In Line:
[color=red]Far Cry II, Final Fantasy XIII, Revenant Wings[/color]
[/size]
darkbenny
Box Car Superhero
Posts: 596
Joined: Mon Aug 09, 2004 6:26 pm

Post by darkbenny »

how did you catch this??
bringing Zsnes back
Tallgeese
Justice is Blind
Posts: 620
Joined: Wed Jul 28, 2004 3:33 pm
Location: Test
Contact:

Post by Tallgeese »

Isn't there a DOS command to kill it even if it's in memory?
corronchilejano
Transmutation Specialist
Posts: 724
Joined: Tue Feb 08, 2005 5:17 pm
Location: Colombia (and no, not on the jungle)
Contact:

Post by corronchilejano »

darkbenny wrote:how did you catch this??
I think playing Counter Strike 1.6 in a chinnesse server, Twins clan I recall.
[size=67]
Playing:
[color=green]Blur, Front Mission DS, Fire Emblem: Shadow Dragon, The Last Remnant[/color]
In Line:
[color=red]Far Cry II, Final Fantasy XIII, Revenant Wings[/color]
[/size]
Tallgeese
Justice is Blind
Posts: 620
Joined: Wed Jul 28, 2004 3:33 pm
Location: Test
Contact:

Post by Tallgeese »

...You caught malware playing on a game server.
creaothceann
Seen it all
Posts: 2302
Joined: Mon Jan 03, 2005 5:04 pm
Location: Germany
Contact:

Post by creaothceann »

Metatron wrote:Isn't there a DOS command to kill it even if it's in memory?
You mean, like fdisk?
vSNES | Delphi 10 BPLs
bsnes launcher with recent files list
corronchilejano
Transmutation Specialist
Posts: 724
Joined: Tue Feb 08, 2005 5:17 pm
Location: Colombia (and no, not on the jungle)
Contact:

Post by corronchilejano »

Metatron wrote:...You caught malware playing on a game server.
That's my best guess... now I have to buy a pirated copy of Xp for 5000 pesos... *sigh*... that's like US$2.
[size=67]
Playing:
[color=green]Blur, Front Mission DS, Fire Emblem: Shadow Dragon, The Last Remnant[/color]
In Line:
[color=red]Far Cry II, Final Fantasy XIII, Revenant Wings[/color]
[/size]
bobthebuilder
Hazed
Posts: 76
Joined: Sat Jan 28, 2006 7:21 am

Post by bobthebuilder »

There is a tutorial here

http://www.trendmicro.com/vinfo/virusen ... C&VSect=Sn

and here

http://www.bleepingcomputer.com/startup ... 12770.html

P.S. The overview states it is sent as a e-mail w/ Kangen.exe
Post Reply