Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Hello all,


  • Please log in to reply
1 reply to this topic

#1 j@y15

j@y15

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:22 PM

Posted 28 May 2015 - 11:46 AM

Hello,

I just signed up today after reading many posts from this forum and trying to clean a virus from my home computers that has been giving me fits.  I have been trying to clean this from two Win 8.1 machines but I belive that every other computer on my home network also has the same virus and it has even infected the two android tablets that we have.

My background is I am a Senior IT engineer and have been working in IT for over 25 years. I have done everything from programming, middleware configuration, Windows and Unix administration, telecom, security and internet setup for small businesses to major corporations.  My first PC was a Commodore 64 with two floppy disks (which really dates me) and currently I have two Win81 and two Win7 machines along with two android tablets on my home network that I believe all have been infected with this virus.

I consider myself very competent in all things IT and after over a month of trying to clean my machines of this virus have learned quite a bit about how it works.  Whoever wrote this is a genius and it has its own form of artificial intelligence aided by the remote access that whoever is behind this has set up to the various devices on my home network.  I have gotten to the point that I have watched how the virus is loaded and what changes it makes to get control and bypass being discovered by all the normal virus software. I am equally impressed and annoyed at the amount logic put into this virus and need the help of the experts on this site to get rid of it for good.   

I have already loaded most of the big Security/Virus software packages and have tried many of the standalone tools recommended on this site and no matter what I load it rarely can even detect and cannot clean this virus.  I know that part of it is a rootkit and have wiped both Win81 computers more than once.  From a freshly wiped (with Disk Kill) and formatted disk with Win8.1 installed from clean DVDs and all the SMB/file sharing and security holes of Win8.1 disabled and all other machines turned off, within 10 minutes of being on the network it will get re-infected.  I also found out that one of my android tablets was never actually turning off (even though is showed powered off but still had a charged battery) and it was connecting over bluetooth to transfer the initial files to the clean machine to kick off the virus.  After that initial bluetooth connection it opens a port to the internet and modifies many of the protocols to allow it to connect and change hundreds of files.  Those modified and resigned Microsoft files show up as clean on VirusTotal or by all the checkers that supposedly will prevent this from happening.

I have found a few posts on this site that match the symptoms of what has infected my machines and I will post the normal required log files and see where this goes.  I have tried almost everything to block and clean this and one way or another it always comes back so any help on how to clear it and prevent any future attacks will be welcomed.

Thanks.

 

Jay



BC AdBot (Login to Remove)

 


#2 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,490 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:08:22 PM

Posted 08 June 2015 - 07:44 PM

:welcome: to Bleeping Computer.

As a new member be sure to read the Welcome to Bleeping Computer! Guide and the following...

 

If you need individual assistance with malware infection, you should start a new topic in the Am I infected? What do I do? forum

OR follow the instructions provided in the Malware Removal and Log Section Preparation Guide starting at Step 6.

  • If you cannot complete a step, then skip it and continue with the next.
  • In Step 6 there are instructions for downloading and running FRST which will create two logs.

When you have done that, post your logs in the Virus, Trojan, Spyware, and Malware Removal Logs forum, NOT here, for assistance by the Malware Response Team.


.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users