Windows = fail, Virus = Win

Discussion and support for the Windows family of operating systems.
Post Reply
UrBaN
Registered User
Posts: 12811
Joined: 02 Feb 2005, 02:00
Location: JHB East
Contact:

Windows = fail, Virus = Win

Post by UrBaN »

So I got a popup randomly, asking me whether I would like to replace my original Windows files with the new ones.

Image

Windows WTF = Fail.
After trying the CD thing to no avail, I realised my options were YES and YES. After phoning a friend, I decided to go with YES.

I then got these two beauties.
Image

Windows WTF = Fail again.
I denied, chose no callback and told it to never ever ever ask me that ever ever again. Ever.

Nod32 then turned red in the system tray, so I clicked it to see what that was about.

Image

Nod32 WTF = Fail.

At this point I lost all network connectivity, so tried disabling/enabling the LAN, as well as a repair.
Image

Repair LAN WTF = Fail.

After this, I managed to get the LAN working again - a simple restart - but everytime I tried to connect to ADSL to come here for help, the modem would connect, verify username/password and then fail.

Luckily I had a system restore point from 12pm this afternoon so I was able to restore prior to the balls up and everything is working properly...

Now to find the cause...

Incidentally, rapimgr.exe was utilising 99% of the CPU (it's used for MS Activesync, which wasn't even running at the time).

Anyone seen this?
Image
to ápeiro anima
Hex_Rated
Registered User
Posts: 3679
Joined: 19 Jan 2006, 02:00
Contact:

Post by Hex_Rated »

So I got a popup randomly, asking me whether I would like to replace my original Windows files with the new ones.
Downloaded any keygens lately?
DFI LanParty X48 LT-2TR
Intel Q9450 @ 3.2Ghz
Dell 24" 2408WFP | Phillips 37" 1080p
Sapphire HD4870 X2 2GB
4GB Corsair DDR-2 1066 | Thermalrite 120 Ultra Extreme | G9 Mouse | G15 Keyboard
Vista Ultimate x64
UrBaN
Registered User
Posts: 12811
Joined: 02 Feb 2005, 02:00
Location: JHB East
Contact:

Post by UrBaN »

Nope, don't use/need them.

Only recent addition to my PC is Open DNS, reviewed in the mag.
Image
to ápeiro anima
Screeper
Registered User
Posts: 3692
Joined: 04 Apr 2003, 02:00
Contact:

Post by Screeper »

/me runs and uninstalls Open DNS

I'm surprised Nod didn't catch it, it is usually very good in the 'finding baddies' department.

Interesting, let us know how you sorted it out if you find a solution.
There are 10 types of people in this world.
Those who understand binary and those who do not.
Hex_Rated
Registered User
Posts: 3679
Joined: 19 Jan 2006, 02:00
Contact:

Post by Hex_Rated »

It's obviously a virus. And it's probably raped your entire system by now after it replaced your windows network drivers with its own files. Format and reinstall.

What is OpenDNS? Dynamic DNS software? What is opendns.marc-hoersken.de? Sounds like that address could be hacking your PC.
DFI LanParty X48 LT-2TR
Intel Q9450 @ 3.2Ghz
Dell 24" 2408WFP | Phillips 37" 1080p
Sapphire HD4870 X2 2GB
4GB Corsair DDR-2 1066 | Thermalrite 120 Ultra Extreme | G9 Mouse | G15 Keyboard
Vista Ultimate x64
UrBaN
Registered User
Posts: 12811
Joined: 02 Feb 2005, 02:00
Location: JHB East
Contact:

Post by UrBaN »

I have also uninstalled - if you look at pic #2, it's OpenDNS trying to call out..

May or may not be related, but I noticed no improvement with openDNS so no point using it.

Thus far that is the only difference I am aware of in terms of system state, other that emails (no attachments) and a potentially dodgy driver for a USB to RS-232 adaptor...I have since deleted the install file.

If I do come across anything I'll post it.
Hex_Rated wrote:It's obviously a virus. And it's probably raped your entire system by now after it replaced your windows network drivers with its own files. Format and reinstall.

What is OpenDNS? Dynamic DNS software? What is opendns.marc-hoersken.de? Sounds like that address could be hacking your PC.
A system restore handled it, so no need to format and reinstall.

Just noticed, my PC bluescreens whenever I do a full system scan with NOD32. It was scheduled to do one everyday but the log says it hasnt successfully completed in ages...dodgy HDD?
Last edited by UrBaN on 03 Jun 2008, 17:30, edited 1 time in total.
Image
to ápeiro anima
Anthro
Moderator Emeritus
Posts: 5547
Joined: 21 Dec 2002, 02:00
Processor: i7 3770k
Motherboard: ASUS P8P67-Pro
Graphics card: 2xNvidia GTX670
Memory: 16 GB Gskill Sniper
Location: In SQL Space inserting 'null' on purpose
Contact:

Post by Anthro »

Open DNS is alternative DNS servers..
Can I recommend you Use AnalogueX fast Cache rather ??
pok
Registered User
Posts: 9639
Joined: 25 Oct 2006, 02:00
Location: sitting in my chair & having a cuppa java

Post by pok »

Also try Spybot - Search & Destroy, its freeware & work like a charm for me with NOD32 (ironically)
Ironman SA 2011 Finisher - 15h10min
3.8km swim, 180km cycle & 42.2km run

Got the shirt to prove it.....
UrBaN
Registered User
Posts: 12811
Joined: 02 Feb 2005, 02:00
Location: JHB East
Contact:

Post by UrBaN »

Ya I used to use it, it's good.

Will try it.
Image
to ápeiro anima
Hex_Rated
Registered User
Posts: 3679
Joined: 19 Jan 2006, 02:00
Contact:

Post by Hex_Rated »

A system restore handled it, so no need to format and reinstall.
If I were you I'd keep an eye on my outgoing bytes just to be safe. Some viruses can definitely survive system restores.
DFI LanParty X48 LT-2TR
Intel Q9450 @ 3.2Ghz
Dell 24" 2408WFP | Phillips 37" 1080p
Sapphire HD4870 X2 2GB
4GB Corsair DDR-2 1066 | Thermalrite 120 Ultra Extreme | G9 Mouse | G15 Keyboard
Vista Ultimate x64
Anakha56
Forum Administrator
Posts: 22136
Joined: 14 Jun 2004, 02:00
Processor: Ryzen 1700K
Motherboard: Asus X370
Graphics card: Asus 1060 Strix
Memory: 16GB RAM
Location: Where Google says

Post by Anakha56 »

it was not me i promise!

/refers to name in pic...

What Hex re last comment, watch your system...
JUSTICE, n A commodity which is a more or less adulterated condition the State sells to the citizen as a reward for his allegiance, taxes and personal service.
WAJeff
Registered User
Posts: 28011
Joined: 30 Jun 2006, 02:00
Location: /dev/sda1/home
Contact:

Post by WAJeff »

I see you running Pidgin as your IM
Its a start towards Linux dude :wink:
ADV4NCED
Registered User
Posts: 2164
Joined: 07 Nov 2004, 02:00
Location: KZN
Contact:

Post by ADV4NCED »

Hex_Rated wrote:
A system restore handled it, so no need to format and reinstall.
If I were you I'd keep an eye on my outgoing bytes just to be safe. Some viruses can definitely survive system restores.
Yeah alot of viruses place themselves in the system restore folder too...
Image
I am 63% addicted to Counterstrike. What about you?
Post Reply