Windows Security Center virus

andyman
Posts: 11198
Joined: Wed Feb 09, 2005 8:20 pm

Windows Security Center virus

Post by andyman »

can someone explain to me how this can be on a freshly formatted computer that has only been online for maybe 2 hours???? wtf is this and how do I make it go away permanantly?? It's been plaguing my two computers for the last 3 days!! no matter how many times i reformat this machine it still comes back nearly right away!!
andyman
Posts: 11198
Joined: Wed Feb 09, 2005 8:20 pm

Re: Windows Security Center virus

Post by andyman »

trying to work this solution... http://forums.techguy.org/malware-remov ... virus.html

we'll see.
User avatar
Foo
Posts: 13840
Joined: Thu Aug 03, 2000 7:00 am
Location: New Zealand

Re: Windows Security Center virus

Post by Foo »

Well it could have infected your HD boot sector, or one of the CD or other media you're using to load things back on.

It could also be spreading on your local LAN from another infected machine.
andyman
Posts: 11198
Joined: Wed Feb 09, 2005 8:20 pm

Re: Windows Security Center virus

Post by andyman »

man no matter what i do this shit comes back withing seconds. I don't understand how a completely formatted drive with a fresh install of windows can get a fucking virus just about instantly.
It must be deeply embedded into something... what, i'll never know but for now this computer is pretty much fucked forever.
Peenyuh
Posts: 3783
Joined: Thu Jan 03, 2008 3:46 am

Re: Windows Security Center virus

Post by Peenyuh »

Foo wrote:Well it could have infected your HD boot sector, or one of the CD or other media you're using to load things back on.

It could also be spreading on your local LAN from another infected machine.
[color=#00FF00][b]"How do you keep the natives off the booze long enough to pass the test?" Asked of a Scottish driving instructor in 1995.[/b][/color]
§ìgñå
Posts: 210
Joined: Sat Jan 01, 2000 8:00 am

Re: Windows Security Center virus

Post by §ìgñå »

Does the XP your installing have at least SP1? If it doesn't and your installing while connected to the net and not behind a firewall your xp will be infected in only a few minutes.
make sure to install while not connected to the internet, and download service packs before you begin.
andyman
Posts: 11198
Joined: Wed Feb 09, 2005 8:20 pm

Re: Windows Security Center virus

Post by andyman »

It's xp pro sp3
User avatar
Captain
Posts: 20410
Joined: Thu Jan 05, 2006 2:50 am

Re: Windows Security Center virus

Post by Captain »

As Foo said, your boot sector might be infected. Try a new install with a fresh HDD.

Where'd you get the install disc from?
andyman
Posts: 11198
Joined: Wed Feb 09, 2005 8:20 pm

Re: Windows Security Center virus

Post by andyman »

Captain Mazda wrote:As Foo said, your boot sector might be infected. Try a new install with a fresh HDD.

Where'd you get the install disc from?
That was the very first thing i did, new hard drive and OS copy.
AmIdYfReAk
Posts: 6926
Joined: Thu Feb 10, 2000 8:00 am

Re: Windows Security Center virus

Post by AmIdYfReAk »

OS copy, install or ghost?
andyman
Posts: 11198
Joined: Wed Feb 09, 2005 8:20 pm

Re: Windows Security Center virus

Post by andyman »

Went to comp usa and got a new hard drive and os disk... even if i were to get another hard drive, whats to say that one wont get the virus instantly? would a new motherboard be a better option?
AmIdYfReAk
Posts: 6926
Joined: Thu Feb 10, 2000 8:00 am

Re: Windows Security Center virus

Post by AmIdYfReAk »

on another computer, Download a live OS on a USB key.. boot off of that and Format the disk and distroy all file systems.

if you REALLY want to be paranoid then you can do a low level format/Zero fill of the harddrive and see how that works out for ya

Also, is there any software that you are installing after said formats?
andyman
Posts: 11198
Joined: Wed Feb 09, 2005 8:20 pm

Re: Windows Security Center virus

Post by andyman »

AmIdYfReAk wrote:on another computer, Download a live OS on a USB key.. boot off of that and Format the disk and distroy all file systems.

if you REALLY want to be paranoid then you can do a low level format/Zero fill of the harddrive and see how that works out for ya

Also, is there any software that you are installing after said formats?
I don't know how to do any of that but it is definitely worth a try. The only program I'm installing is firefox right after a format.
obsidian
Posts: 10970
Joined: Mon Feb 04, 2002 8:00 am

Re: Windows Security Center virus

Post by obsidian »

Download Ubuntu. Stick it in your drive and boot off of that using default settings. Use Ubuntu's built in file manager to zap the file system and then create a new NTFS partition.
[size=85][url=http://gtkradiant.com]GtkRadiant[/url] | [url=http://q3map2.robotrenegade.com]Q3Map2[/url] | [url=http://q3map2.robotrenegade.com/docs/shader_manual/]Shader Manual[/url][/size]
AmIdYfReAk
Posts: 6926
Joined: Thu Feb 10, 2000 8:00 am

Re: Windows Security Center virus

Post by AmIdYfReAk »

Ubuntu live CD ^^^^ :)
andyman
Posts: 11198
Joined: Wed Feb 09, 2005 8:20 pm

Re: Windows Security Center virus

Post by andyman »

Installed ubuntu, and the computer wont startup with that os. It starts to, then it says "MP-BIOS Bug: 8254 Self TImer not connected" then it goes to the splash screen, loads the bar all the way up, then it's just a black screen and nothing happens.


so scratch that unless i'm doing it wrong.
AmIdYfReAk
Posts: 6926
Joined: Thu Feb 10, 2000 8:00 am

Re: Windows Security Center virus

Post by AmIdYfReAk »

is that on the live CD? or did you actually download and install it?
Deathshroud
Posts: 2103
Joined: Tue Feb 22, 2005 6:22 pm

Re: Windows Security Center virus

Post by Deathshroud »

You might have a rootkit embedded in the BIOS. You could attempt to update the BIOS to see if that takes care of it.

EDIT: Actually, there might be a way to reset the BIOS, check the motherboard manual to see if its possible. This thing sounds like a pretty potent worm, I would cut off the infected computers from network access until you have fixed them both.
Last edited by Deathshroud on Sat Jun 27, 2009 5:15 am, edited 1 time in total.
obsidian
Posts: 10970
Joined: Mon Feb 04, 2002 8:00 am

Re: Windows Security Center virus

Post by obsidian »

When you download the normal Ubuntu CD, you should have the option to install it, or load it as a Live CD (the default), as well as a few other things like memtest, etc. You want to load it up as a Live CD, this doesn't actually install anything to your hard drive, it just reads the OS off of the disc and loads everything to memory. You will be presented with the Ubuntu GUI where you should be able to find the disc manager (system > administration, I think) from which you should be able to wipe out the existing partitions and create a new one, then format it.
[size=85][url=http://gtkradiant.com]GtkRadiant[/url] | [url=http://q3map2.robotrenegade.com]Q3Map2[/url] | [url=http://q3map2.robotrenegade.com/docs/shader_manual/]Shader Manual[/url][/size]
andyman
Posts: 11198
Joined: Wed Feb 09, 2005 8:20 pm

Re: Windows Security Center virus

Post by andyman »

obsidian wrote:When you download the normal Ubuntu CD, you should have the option to install it, or load it as a Live CD (the default), as well as a few other things like memtest, etc. You want to load it up as a Live CD, this doesn't actually install anything to your hard drive, it just reads the OS off of the disc and loads everything to memory. You will be presented with the Ubuntu GUI where you should be able to find the disc manager (system > administration, I think) from which you should be able to wipe out the existing partitions and create a new one, then format it.

That was the first way I tried it, and it did the same thing so i thought maybe installing it would yield different results but no dice.
obsidian
Posts: 10970
Joined: Mon Feb 04, 2002 8:00 am

Re: Windows Security Center virus

Post by obsidian »

Well that's shitty. I've been using Ubuntu for a number of years now and I haven't been able to find a computer that Ubuntu won't start up on. Problems hunting for drivers... sure, but it should at least boot. :shrug:
[size=85][url=http://gtkradiant.com]GtkRadiant[/url] | [url=http://q3map2.robotrenegade.com]Q3Map2[/url] | [url=http://q3map2.robotrenegade.com/docs/shader_manual/]Shader Manual[/url][/size]
andyman
Posts: 11198
Joined: Wed Feb 09, 2005 8:20 pm

Re: Windows Security Center virus

Post by andyman »

I have tried the power off way many times, no worky.

Ubuntu started up after I went into the pre-startup menu and selected 'Safe with graphic line'. I think I was just supposed to wait a long long time for the regular first startup. Either way, when it finally loaded the system, it asked for a username and password but never asked me for one. Now I can't log in.
Deathshroud
Posts: 2103
Joined: Tue Feb 22, 2005 6:22 pm

Re: Windows Security Center virus

Post by Deathshroud »

Did you try resetting or updating the BIOS yet?
andyman
Posts: 11198
Joined: Wed Feb 09, 2005 8:20 pm

Re: Windows Security Center virus

Post by andyman »

Deathshroud wrote:Did you try resetting or updating the BIOS yet?

Not yet. I could do that tonight... I'll try the update.

My roommate wanted some media files from the laptop so i plugged in his external hard drive and gave them to him, now his laptop is infected lol
andyman
Posts: 11198
Joined: Wed Feb 09, 2005 8:20 pm

Re: Windows Security Center virus

Post by andyman »

Updated the BIOS on the desktop, now it won't even begin to turn on. The read lights for the cd drives just flicker and that's it. FUCK THIS SHIT. Now i have to get a new motherboard.
Locked