Antivirus Protection
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationAntivirus Protection
Receive the tools necessary to be the rock star of your field. Our 12-month program teaches you the evolving world of multi-channel marketing as well as the complex issues and opportunities found in the industry.

ASP Free and Iron Speed Designer are giving away $5,500+ in FREE licenses. Iron Speed's RAD CASE toolset can save up to 80% of your coding time. One free license per week, one perpetual license per month!
Download and Activate to enter!

Web development can be a daunting task, even for specialists. There is a lot of information to absorb and a lot of technologies to learn in order to manage a superior website. When trying to learn the ropes, developers need a reliable source to introduce new ideas that can be easily implemented. When working on large projects, even web veterans may run into a technology or an aspect of a technology that they are unfamiliar with.

Learn More!


Download to Enter
| Contest Rules

Tutorials | Forums

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old January 26th, 2012, 11:52 AM
WrinkledCheese's Avatar
WrinkledCheese WrinkledCheese is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jun 2011
Posts: 122 WrinkledCheese User rank is Sergeant Major (2000 - 5000 Reputation Level)WrinkledCheese User rank is Sergeant Major (2000 - 5000 Reputation Level)WrinkledCheese User rank is Sergeant Major (2000 - 5000 Reputation Level)WrinkledCheese User rank is Sergeant Major (2000 - 5000 Reputation Level)WrinkledCheese User rank is Sergeant Major (2000 - 5000 Reputation Level)WrinkledCheese User rank is Sergeant Major (2000 - 5000 Reputation Level) 
Time spent in forums: 1 Day 12 h 55 m 23 sec
Reputation Power: 37
Odd behaviour, can't find a virus though

Hello everyone,

Let me describe the behaviour, what I've done, what has worked, what hasn't and why I think there is still something there.

SYMPTOMS

Normal Boot:
The behaviour is extremely odd. When booting normally, the system ALWAYS tries a chkdsk. I skip it when I catch it. Upon entering, regardless of whether or not chkdsk ran or was skipped. The system will reboot after a few seconds to a few minutes with a BSOD/Stop error 0x8e 0x5 - hardware issue - and some other hex's that I haven't deemed ultra important but I can get them if you want. This happens whether or not you log in.

Safe Mode:
When I boot into safe mode, the first time I try it takes about 20 minutes after the last driver has been listed on screen. After this the system reboots from the driver display screen. If I go into safe mode a second time, I can get it and it doesn't take 20 minutes. Safe Mode is stable as a computer should be. I left it sit over night and it didn't reboot.

Common Symptoms:
Windows is hidden. There is a winnt_ folder but I suspect this is remnants of a virus. If you manually enter the Windows directory, System32 is hidden. It doesn't seem like I can get any administrator access, even after logging in with Administrator after issuing the command net user administrator /active:yes. There doesn't seem to be any performance degradation.

WHAT I'VE DONE

I tried virus scans, I've tried uninstalling EVERY driver while in safe mode. I tried a root kit scan using gmer and I tried using various hard disk checks(SpinRite) and RAM swaps.

WHAT WORKED
Using Falcon4's utilities disc, I use the Microsoft's Standalone Virus scanner which is run from a build of recovery console on the Falcon4 disc with MS DaRT. This scan revealed hundreds of trojans, keyloggers, etc. They were all cleaned although a couple were quarantined. I"m going to do another scan to see what it picks up, it just sucks cause the damn thing takes 4 hours to run.

WHAT DIDN'T WORK
Panda Safe CD virus scan. Found nothing.

Trend Micro's House Call virus scan and Hijack This scan. Fount Nothing.

SpinRite - no defects detected.

RAM Swap - no difference. Memory works in another system no problem.

GMER scan. It detected a root kit, said it had to reboot and then it doesn't pick anything up anymore but nothing has changed in the slightest.

Registry scans don't show anything.

The command attrib -s -h c: /d /s basically everything comes up as access denied even when I run the command prompt as administrator logged in as administrator.

Uninstalling all drivers. I mean everything in the device manager that allowed me to uninstall it was uninstalled. When I rebooted, nothing changed except regular user mode is using a basic video driver now.

exeHelper.com didn't seem to detect anything wrong with exe associations

ComboFix - detected a root kit and required a reboot but didn't find anything on subsequent scans. This led me to running GMER, which found a root kit after ComboFix did. They both don't give me enough time to read all the information. The system just reboots after about 2 seconds of detection, which I find suspicious.

WHY I BELIEVE IT'S MORE THAN A HARDWARE ISSUE
I can use the system for hours, running all the tests I want in Safe Mode but I can't get more than a minute of usage out of regular boot mode. I have resulted into having the boot configuration to boot into minimal Safe Mode except when I do something and want to test regular mode again. If I get into Safe Mode and reboot, I have no problems getting back in. It's when I go into regular boot mode that I have to wait 20 minutes after all the drivers list and have the system automatically reboot to get into safe mode by pressing f8 for two sequential boots.

[EDIT]
I should probably mention it's Windows Vista Home Premium installed on a HP G60 laptop.

[EDIT2]
I read the "Read this first" thread after posting...

I will run and post the requested logs.

[EDIT3]
I tried to run the Standalone System Sweeper but it would not update. I think it's time to plug the HDD into another system, backup files and re install the operating system.

Last edited by WrinkledCheese : January 27th, 2012 at 11:00 AM.

Reply With Quote
  #2  
Old January 27th, 2012, 05:55 PM
E-Oreo's Avatar
E-Oreo E-Oreo is offline
Moderator
Click here for more information.
 
Join Date: Dec 2004
Posts: 6,410 E-Oreo User rank is General 77th Grade (Above 100000 Reputation Level)E-Oreo User rank is General 77th Grade (Above 100000 Reputation Level)E-Oreo User rank is General 77th Grade (Above 100000 Reputation Level)E-Oreo User rank is General 77th Grade (Above 100000 Reputation Level)E-Oreo User rank is General 77th Grade (Above 100000 Reputation Level)E-Oreo User rank is General 77th Grade (Above 100000 Reputation Level)E-Oreo User rank is General 77th Grade (Above 100000 Reputation Level)E-Oreo User rank is General 77th Grade (Above 100000 Reputation Level)E-Oreo User rank is General 77th Grade (Above 100000 Reputation Level)E-Oreo User rank is General 77th Grade (Above 100000 Reputation Level)E-Oreo User rank is General 77th Grade (Above 100000 Reputation Level)E-Oreo User rank is General 77th Grade (Above 100000 Reputation Level)E-Oreo User rank is General 77th Grade (Above 100000 Reputation Level)E-Oreo User rank is General 77th Grade (Above 100000 Reputation Level)E-Oreo User rank is General 77th Grade (Above 100000 Reputation Level)E-Oreo User rank is General 77th Grade (Above 100000 Reputation Level)  Folding Points: 945 Folding Title: Novice Folder
Time spent in forums: 1 Month 2 Weeks 3 Days 18 h 27 m 22 sec
Reputation Power: 6142
Quote:
I think it's time to plug the HDD into another system, backup files and re install the operating system.

Yes. You either have a serious hardware failure or a serious virus infection. In either case, it sounds like your system is so damaged at this point that it is beyond repair. If it is a serious hardware issue then it will certainly happen again at some point.

It is possible that the problems only occur when booting into regular mode because the drivers for the failing piece of hardware are not activated when booting in safe mode.
__________________
How to program a basic, secure login system using PHP

Quote:
Originally Posted by Spad
Ah USB, the only rectangular connector where you have to make 3 attempts before you get it the right way around

Reply With Quote
  #3  
Old January 27th, 2012, 06:32 PM
Doug G Doug G is offline
Grumpier Old Moderator
Dev Shed God 18th Plane (13500 - 13999 posts)
 
Join Date: Jun 2003
Posts: 13,894 Doug G User rank is General 49th Grade (Above 100000 Reputation Level)Doug G User rank is General 49th Grade (Above 100000 Reputation Level)Doug G User rank is General 49th Grade (Above 100000 Reputation Level)Doug G User rank is General 49th Grade (Above 100000 Reputation Level)Doug G User rank is General 49th Grade (Above 100000 Reputation Level)Doug G User rank is General 49th Grade (Above 100000 Reputation Level)Doug G User rank is General 49th Grade (Above 100000 Reputation Level)Doug G User rank is General 49th Grade (Above 100000 Reputation Level)Doug G User rank is General 49th Grade (Above 100000 Reputation Level)Doug G User rank is General 49th Grade (Above 100000 Reputation Level)Doug G User rank is General 49th Grade (Above 100000 Reputation Level)Doug G User rank is General 49th Grade (Above 100000 Reputation Level)Doug G User rank is General 49th Grade (Above 100000 Reputation Level)Doug G User rank is General 49th Grade (Above 100000 Reputation Level)Doug G User rank is General 49th Grade (Above 100000 Reputation Level)Doug G User rank is General 49th Grade (Above 100000 Reputation Level) 
Time spent in forums: 1 Month 3 Weeks 4 Days 15 h 10 m 20 sec
Reputation Power: 4227
I agree with E-Oreo. Did you ever run chkdsk /f ? If yes and it found problems more than once I'd be inclined to replace the hard drive.
__________________
======
Doug G
======
It is a truism of American politics that no man who can win an election deserves to. --Trevanian, from the novel Shibumi

Reply With Quote
  #4  
Old January 30th, 2012, 07:11 AM
WrinkledCheese's Avatar
WrinkledCheese WrinkledCheese is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jun 2011
Posts: 122 WrinkledCheese User rank is Sergeant Major (2000 - 5000 Reputation Level)WrinkledCheese User rank is Sergeant Major (2000 - 5000 Reputation Level)WrinkledCheese User rank is Sergeant Major (2000 - 5000 Reputation Level)WrinkledCheese User rank is Sergeant Major (2000 - 5000 Reputation Level)WrinkledCheese User rank is Sergeant Major (2000 - 5000 Reputation Level)WrinkledCheese User rank is Sergeant Major (2000 - 5000 Reputation Level) 
Time spent in forums: 1 Day 12 h 55 m 23 sec
Reputation Power: 37
Thanks for the insights.

Quote:
Originally Posted by E-Oreo
You either have a serious hardware failure or a serious virus infection


There were 100s of viruses found with Microsoft's Standalone System Scanner, part of the MS Diagnostic and Recovery Toolkit available for Recovery Console. As well, ComboFix AND GMER detected a RootKit on their first runs and required a reboot but failed to detect anything on subsequent scans.

Quote:
Originally Posted by E-Oreo
In either case, it sounds like your system is so damaged at this point that it is beyond repair.
I know... It COULD be fixed but I think it's faster to just wipe and reinstall. Hopefully the virus has been removed from the non-filesystem locations such as MBR.

Quote:
Originally Posted by E-Oreo
if it is a serious hardware issue then it will certainly happen again at some point.
We shall see.

Quote:
Originally Posted by E-Oreo
It is possible that the problems only occur when booting into regular mode because the drivers for the failing piece of hardware are not activated when booting in safe mode.
I have a sneaking suspicion that this is not the case as the failure can happen anytime in the boot process - during regular boot - from the Windows loading splash to post login and launching IE. Please note that DHCP does not work, I have to statically set an IP address in order to get network functionality. This is true for both Safe Mode with Networking and regular boot....if I manage to get it running long enough to change it.

All of the items in Administrative Tools are also missing. Some programs are also disabled from running, IE Event Viewer and Services. Event Viewer gives an invalid IP error when ran manually from the command line.

I think it's safe to say it's time to give up cleaning this system and to just format and reinstall.

Oh well, I'll beat the next one.

Thanks very much for the input! Greatly appreciated.

Last edited by WrinkledCheese : January 30th, 2012 at 07:19 AM.

Reply With Quote
  #5  
Old February 13th, 2012, 02:33 AM
Habbakuk Habbakuk is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Feb 2012
Posts: 33 Habbakuk User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 3 h 54 m 51 sec
Reputation Power: 1
When a computer looks like that, it's time to re-install Windows. If you found hundreds of trojans and other malware, you never know, there could be more you didn't find, and it's best to re-install to be sure.

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationAntivirus Protection > Odd behaviour, can't find a virus though


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump

Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 


Powered by: vBulletin Version 3.0.5
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.

© 2003-2012 by Developer Shed. All rights reserved. DS Cluster 7 - Follow our Sitemap