I'm being attacked by a sneaky bug!

Miscellaneous Forums/General Discussion/I'm being attacked by a sneaky bug!

Help! I've just come home from Malaysia, and my PC has been
hit by a v1rus! This thing is crazy. If I run msconfig,
regedit or open the ctrl-alt-delete window, they get closed
automatically. It keeps changing itself and asking again
and again for permission to access the internet. My
Zonealarm keeps blocking it though. If I type the word
v1rus anywhere, all open programs close (That's why I'm
spelling it with a 1). If I click on any of my ant1-v1rus
bookmarks, my programs also close.

This is insane. I don't run Ant1-v1rus on this machine. I
just use the free ones online. In the 4 years I've been
using this machine though, I've never had problems - because
I know how to avoid the bastards. My new roommate must've
openned something while I was gone.

What do I do? Wiping the drive is either complicated and/or
expensive for me to do. Is there any other option?

When it asks for permission - what exactly is asking for permission? What is the 'Application Name' and the 'Destination IP'? Both of those should be displayed.

If you have XP, use System Restore to set your machine back before you went away!

If not, start Windows in safe mode, this boots essential drivers and nothing else, so hopefully, you can weed the rodent out!

Dabz

Aside from the obvious like getting a recently updated virus program, which I assume you can't do.

You'll have to go into safemode and alter your MSCONFIG and take out any suspicous startup programs...clear out your temporary internet files..clear out every 'temp' directory in your 'documents&settings' folders...then go into your windows directory and check your system, or system 32 folders for any new small programs (view by date is a good way of isolating recent odd exes and dos like programs)..check the basic C & D etc. hardrives too. Hope your folder settings are set to "view all files" - if not , set it on your folder options.

Oh yes - then do a system restore to get your old registry settings back as your current one will obviously be nobbled.

Looks like your room-mate has been doing some nasty internet viewing while you've not been there!

locate regedit.exe

and copy it, calling the new one regedit.com

then run regedit.com

does this allow the registry editor to open?

You could hook up the drive to another machine via IDE or USB and clean it from there. You could also install a clean copy of 2k or XP to a new partition and scan from there.

Most viruses today are smart enough to lock the user out of safe mode, but it's worth a try.

I would try to get AVG anti-virus running on the machine if at all possible before resorting to the former options.

"drew", I would recommend you try identifying the virus before taking any action - there might be complications.

Puki, what they are doing is trying to access the internet
(probably to turn my machine into a zombie), so when they do
for the first time, Zonealarm stops them and waits for the
user's permission first.

The two programs that are trying to get access are csrss.exe
and lsass.exe. For some reason, I didn't pay attention to
where they were trying to access. Whoops.

Well, those are two official Windows' processes. Which complicates things.

Retry and post the 'Destination IPs' - this will help identify whether they are calling to their offical home or not.

EDIT: bare in mind that they may not be the 'real' versions of the processes.

For some reason, they've stopped trying to call anywhere. Not
sure why. I managed to find an old version of Ad-Aware on my
machine. I updated and ran it. Got rid of 106 "critical
objects". Didn't get these guys though. Hmph.

Chris-M, here's something crazy. The bug has hidden my file
extensions. And if I click "Tools/Folder Options" to
reveal them again, the window gets closed automatically.
So, renaming "regedit" to "regedit.com" actually doesn't
change the way it's openned; it's just "regedit.com.exe"
now.

I open it and it says "Registry editing has been disabled by
your administrator" - argh! I'M the administrator!

Both files are located in system32. The crc's for them on XP Pro SP2 are as follows:

csrss.exe = 0EA5C1B0 = 6,144 bytes
lsass.exe = A12136B5 = 13,312 bytes

as reported by WinRAR. This should help eliminate whether they've been infected.

Hope this helps.

They both just tried to phone in - one after the other.

193.252.158.200:DNS


Whois gave me this information:

Record Type: IP Address

OrgName: RIPE Network Coordination Centre
OrgID: RIPE
Address: P.O. Box 10096
City: Amsterdam
StateProv:
PostalCode: 1001EB
Country: NL

ReferralServer: whois://whois.ripe.net:43

NetRange: 193.0.0.0 - 193.255.255.255
CIDR: 193.0.0.0/8
NetName: RIPE-CBLK
NetHandle: NET-193-0-0-0-1
Parent:
NetType: Allocated to RIPE NCC
NameServer: NS-PRI.RIPE.NET
NameServer: NS3.NIC.FR
NameServer: SUNIC.SUNET.SE
NameServer: NS-EXT.ISC.ORG
NameServer: SEC1.APNIC.NET
NameServer: SEC3.APNIC.NET
NameServer: TINNIE.ARIN.NET
Comment: These addresses have been further assigned to users in
Comment: the RIPE NCC region. Contact information can be found in
Comment: the RIPE database at http://www.ripe.net/whois
RegDate: 1992-08-12
Updated: 2005-08-03

Can you do the regedit rename using a command prompt?

That seems a bit fishy - I'm taking a look.

EDIT: does not seem to be Microsoft.

http://www.dnsstuff.com/tools/whois.ch?ip=193.252.158.200

Seems to be going here:

http://mysite.wanadoo-members.co.uk/public/divers/404.html

http://www.orange.co.uk/sitebuilder/mysite.htm

Kenshin, I was able to rename using the command prompt, thanks.
Sadly, I still get shut down.

I'm trying the system restore, then I'm going to try the safe mode.

See you all on the other side.

Whatever it was, it seems to have disappeared in April 2005. Not sure why the hell your computer wants to connect there.

It's over!

System restore did it. Now I've got to give my newbie
roommate a little talk about proper surfing habits!

Thank you, everyone for your help.

Don't speak too soon - if it's smart it'll be back.

DTaskManager is a great tool to locate anything running,
it shows all ongoing processes with path !

http://dimio.altervista.org/eng/

That is one nice little app!
The link is wrong though - I think it really needs that forward slash on the end.

http://dimio.altervista.org/eng/

All's still well.

well... i'm glad you appear to have solved this problem... but if you had paid attention to the medical officers briefing before going in country, this might not have ever happened in the first place...

when in malaysia, or for that fact, anywhere in that region, all personel should be very carefull where they stick their modem cables...

if i remember right, i heard that there was an island somewhere over there (or was it off the coast of Thailand) where computers that stuck their cables in the wrong places, and wound up with uncurable viruses, were sent... not a pretty sight...

you were lucky... this time...

:)

--Mike

I'm being attacked by a sneaky bug!

Me too. I wrote a letter to my landlord requesting an exterminator be sent asap.

That is one nice little app!
The link is wrong though - I think it really needs that forward slash on the end.
Fixed :o)

Not to throw a bug in the ointment... many smart viri attach themselves to the system restore files... Download AVAST now! It is free and updates itself very well... Don't depend on your "skill" to avoid a virus. I picked up TINYTROJAN when all I did was go to a Realestate site and the banner ad (which my AV told me had bad bits and blocked...) still managed to load the program into my computer.

Merry Hell removing it!

I mean if AdAware found all those items... you maybe are not as "skillful" at avoiding these things as you think...

And FYI The newest thing in MALware is the ROOTkit. You may still have problems... :)

I am really not trying to sound harsh OR superior... as I read this it sounds like that. I am just presenting info. Please take it as that. I hate MALware in all its forms.

I mean if AdAware found all those items... you maybe are not as "skillful" at avoiding these things as you think...


I was gone for two months. That was just me cleaning up
after my messy roommates. And my way of surfing has
kept me out of trouble for over 3 years on the same machine.
I'd say it works.

But anyway...

L O L

So...*ahem* ... I gave myself this virus. Here's how it happened:

- I get home, everyone's happy to see me again, yada yada. I go to show them some
of the pictures I took. They were sitting on burned cds.

- I was browsing through the folders on one cd, showing my friends the wonders of
Malaysia.

- I notice a folder called "100KM003" - the name of the default folder my
camera saves to. I click it. A dos prompt opens and shuts immediately. I
pause to think for a minute what that could've been, but ignore it and
continue to browse the disc. (Hmm!)

- I later begin to notice that a little bit of Hell has broken loose on my machine.

- So when I mention these strange new behaviours my machine has adopted, my roommate
seemed to be playing dumb. I got the obligatory "It wasn't doing that when I was
using it!" - I instantly judged that to be a lie!

- Then you guys helped me fix it.

- So now I was burning some more cds from my CF card and that same folder was
on the card! And like a moron, I opened it again! lsass.exe was back
on a rampage! That's how I found out.

It turns out that when I plugged my camera into one of the PCs at one of the
internet cafes in Kuala Lumpur, a virus executable, disguised as a
folder, would be transferred onto it, ready to be opened by me. So, naturally
every cd I burned at that cafe had the bug burned on! So Now I have a nice
little virus alongside my photos on the cds. Careful!

- Anyway, Roommate got an apology (Though I didn't really get angry)

Watch out for those publicly-used machines! (duh)

I sit corrected! Yap I had a similar situation when my wifes younger brother decided to install Kazaa on my computer and "allegedly" inflate his MP3 collection.

After I kicked his behind I passworded the box. No one knows the PW but me and no one else can get on!

I am happy you figgered out the cause... hope you saved a copy of the bug for the folks in the AV bidness!!!

I still reccomend AVAST though... free and good! :)

Wow, this is the very first time I hear of a camera that is used to transfer malware to a PC! And people say I'm paranoid when I ask myself why the floppy drive is acting strangely (eg: no error alert when I try to create a new file on a write-protected floppy...)
Mankind is evil, and so are Cameras! From now on I got to scan my cameras SanDisk as well. I only hope my coffee machine is still clean.

Wedoe - thanks for the link, this Dimio dude has some very nice utilities!

i hope what YOU ARE not infected jfk ;)