Annoying virus/bug/spyware problem

sram

[H]ard|Gawd
Joined
Jul 30, 2007
Messages
1,699
We have this annoying virus at one of the computers at work that is not supposed to be connected to the internet. It must have gotten it from a flash drive. It has symantec security installed, but it is not updated of course. I disabled the antivirus and installed Avira thinking that it might catch something. I couldn't update it of course because I can't connect to the internet. It did actually find some infections and I deleted them, but the problem remained. I also installed the latest version of Advanced system care, and it did its things but still. I then installed Malwarebytes and did find some infections as well but it also didn't help with the problem.

The symptoms are like this:

It makes infected folders hidden and label them all as system files, which means I won't see them unless show hidden files is checked and hide protected system files is unchecked. And even if I do this, it will go back to the original settings meaning settings in folder options doesn't remain to what I set them. OS is xp.

The thing is that I can't connect to the internet in this specific pc because it has sensitive info. But, as far as I know, some antivirus programs can be updated via loading an update file that can be downloaded off the internet from another pc.

What do you suggest I do ? The flash I used to transport files into the pc became infected as well and i tried to clean it with another pc having avira and malwarebytes updated but it didn't get removed. !

Do you know a virus with these kind of symptoms ? If I know it, i'm sure I can find a removal tool for it. I'll keep trying to remove the virus from my flash to see which program can get rid of it and see if I can get its name.

I did a quick google search and it sounds like this is related:

http://answers.yahoo.com/question/index?qid=20080527074654AAHNpBX

What do you think? and how do I clean a pc that can't be connected to the internet from all possible infections?

Thanks.
 
I'd forgo booting into Safe Mode and just burn a bootable ISO with a virus scanner built in - that way you can update the definitions on a internet connected PC if need be and you can also be sure that no programs, virii, etc. are actively running on the potentially infected machine.

Links to some of the ISO's from Kapersky, Avira, etc. can be found here:
http://www.techmixer.com/free-bootable-antivirus-rescue-cds-download-list/

An alternative would be to make sure another internet workstation is up-to-date on definitions, disconnect it from the network, and then pop the drive from the infected PC as a slave drive and scan it.
 
Problem fixed. I used a combination of the suggestions here and the link I myself provided. But,how do I ensure the iso's are up to date? I want to create a cd from an iso file that has been updated.

Thanks.
 
But,how do I ensure the iso's are up to date?
AVG seems to update theirs the most often (last updated 8/31/2010) so that you don't have to - though they do have a page (https://share.avg.com/arl/) where you can download the newest definition. Would assume you could use something like MagicISO to just slip in the newest file. Couldn't find much on most the other folks pages (Kapersky, etc.)
 
Problem fixed. I used a combination of the suggestions here and the link I myself provided. But,how do I ensure the iso's are up to date? I want to create a cd from an iso file that has been updated.

Thanks.

I hope you fan ComboFix, since it sounds like you might have had a rootkit.
 
In the network and security forum there's a stickied thread about cleaning Malware, a lot of people put a lot of time in effort in building that thread with all the useful tools and info you need.
 
In the network and security forum there's a stickied thread about cleaning Malware, a lot of people put a lot of time in effort in building that thread with all the useful tools and info you need.

Yeah thanks. I forgot to look there. If after applying all what is that thread:

http://hardforum.com/showthread.php?t=1426658

you still have infections, you sure are unlucky.

Thanks to you all.
 
Back
Top