![]() |
|
Post Reply ![]() |
Page 12> |
Author | ||||
chopper ![]() Special Collaborator ![]() ![]() Honorary Collaborator Joined: July 13 2005 Location: Essex, UK Status: Offline Points: 20032 |
![]() Posted: May 27 2010 at 08:48 |
|||
A number of services have recently started timing out when my PC is booting up - the main ones are DHCP, Windows Audio and Themes. I've just run a full malware scan and removed a few things but it's still happening. The services start fine when you start them up manually but this is an inconvenience.
Anyone else had this problem? Could it be related to profile size (i.e. taking too long to load)?
|
||||
![]() |
||||
Dean ![]() Special Collaborator ![]() ![]() Retired Admin and Amateur Layabout Joined: May 13 2007 Location: Europe Status: Offline Points: 37575 |
![]() |
|||
It's possibly a rootkit (virus) that's attempting to take over those services. If it is, then you're stuffed - lots of apps claim to remove rootkits, but none of them do. You can try doing a system restore but that's unlikely to work either. |
||||
What?
|
||||
![]() |
||||
Epignosis ![]() Special Collaborator ![]() ![]() Honorary Collaborator Joined: December 30 2007 Location: Raeford, NC Status: Offline Points: 32552 |
![]() |
|||
You may recall I had a rootkit issue about six months ago.
It was a nightmare. I even fell into the trap of forcing my PC to start in safe mode- this particular virus had disabled safe mode altogether, which meant my computer wouldn't boot up at all. I wound up having to boot from my Windows XP disc and do all manner of ![]() It took three days, ten different programs, and some intensive manual tweaking to get things back to normal. ![]() Edited by Epignosis - May 27 2010 at 12:37 |
||||
![]() |
||||
jampa17 ![]() Prog Reviewer ![]() ![]() Joined: July 04 2009 Location: Guatemala Status: Offline Points: 6802 |
![]() |
|||
Seems like a virus... if you have partitions in your disk, or if you have different sessions profiles, you should try to get in through a different profile and make a scan but with one good antivirus... I use Kadpedsky and it get actualized every day... so it's powerful enough to clean anything... but I don't know if it will run to install it... seems like a huge problem...
|
||||
|
||||
![]() |
||||
chopper ![]() Special Collaborator ![]() ![]() Honorary Collaborator Joined: July 13 2005 Location: Essex, UK Status: Offline Points: 20032 |
![]() |
|||
Thanks for breaking it to me gently Dean.
![]() I've removed some more malware but still have the problem. Don't think I'll go for the system restore at the moment as it's an inconvenience rather than a major problem. I'm wondering why a rootkit type virus would want to take over my Themes service. DHCP I can maybe understand.
|
||||
![]() |
||||
Falx ![]() Forum Senior Member ![]() ![]() Joined: May 05 2010 Location: New Zealand Status: Offline Points: 859 |
![]() |
|||
Or you pay someone like me to fix it... I removed a pretty nice rootkit from one computer this week, AVG Free (!) was the only antivirus that picked it up ![]() =F= |
||||
"You must go beyond the limit of the limit of your limits!" - Mr. Doctor
"It is our duty as men and women to proceed as though the limits of our abilities do not exist." - Pierre Teilhard de Chardin |
||||
![]() |
||||
chopper ![]() Special Collaborator ![]() ![]() Honorary Collaborator Joined: July 13 2005 Location: Essex, UK Status: Offline Points: 20032 |
![]() |
|||
Thanks, I've just read that thread, you mentioned "I ran a program that took over seven hours just to scan both drives, and it caught myriad things I wouldn't have thought of" - what program was that?
|
||||
![]() |
||||
Epignosis ![]() Special Collaborator ![]() ![]() Honorary Collaborator Joined: December 30 2007 Location: Raeford, NC Status: Offline Points: 32552 |
![]() |
|||
I'm pretty sure that was drweb-cureit. No guarantees of course, but this one and Malwarebytes Anti-malware proved to be the most effective. |
||||
![]() |
||||
Falx ![]() Forum Senior Member ![]() ![]() Joined: May 05 2010 Location: New Zealand Status: Offline Points: 859 |
![]() |
|||
Doctor Web just takes forever because it's slow, its detection rate isn't that great¹. But it's useful to have, and is the only effective way of removing the Mebroot trojan (nasty lil' bugger) I've found. ¹ http://www.virus.gr/portal/en/content/2009-08%2C-10-august-05-september =F= Edited by Falx - May 28 2010 at 07:41 |
||||
"You must go beyond the limit of the limit of your limits!" - Mr. Doctor
"It is our duty as men and women to proceed as though the limits of our abilities do not exist." - Pierre Teilhard de Chardin |
||||
![]() |
||||
chopper ![]() Special Collaborator ![]() ![]() Honorary Collaborator Joined: July 13 2005 Location: Essex, UK Status: Offline Points: 20032 |
![]() |
|||
Thanks for the advise everyone. I'm going to try Dr Web at least (speed isn't really an issue, I'll just leave it running overnight if I have to). Something else is also redirecting some of my web searches to another search engine so I need to get rid of that as well.
Quite why anyone thinks this is going to benefit them I don't know. If I want to go to a site for a reason and they divert elsewhere, I'm not going to think "Oh ok, I'll have a look here instead". Just
![]() Rant over.
|
||||
![]() |
||||
Dean ![]() Special Collaborator ![]() ![]() Retired Admin and Amateur Layabout Joined: May 13 2007 Location: Europe Status: Offline Points: 37575 |
![]() |
|||
![]() This is what rootkits do! You are definitely infected and anything you send or recieve is suspect. The reasonn it shows on Themes and DHCP is because it patches itself into whatever is in your boot sequence (msconfig ->startup) - those fail because the patch failed, but other processes were patched and didn't fail,which is why your search is being redirected.
I don't trust av software to 100% remove a rootkit - most just remove the symptoms, which will return again sometime in the future - the only guaranteed safe recovery is reformat your harddrive and reinstall XP.
![]() |
||||
What?
|
||||
![]() |
||||
Epignosis ![]() Special Collaborator ![]() ![]() Honorary Collaborator Joined: December 30 2007 Location: Raeford, NC Status: Offline Points: 32552 |
![]() |
|||
You may be right Dean, but I've not had a single problem since November. Granted it took three days, ten different programs, and screwing around in the registry among other things. Assuming there is still a rootkit problem somewhere on my hard drive, what would cause it to "return in force?" |
||||
![]() |
||||
Dean ![]() Special Collaborator ![]() ![]() Retired Admin and Amateur Layabout Joined: May 13 2007 Location: Europe Status: Offline Points: 37575 |
![]() |
|||
You've been okay for 7 months, you're probably safe.
I have to admit that for an Admin looking after a dozen desktop PC's three days and ten programs is far to time consuming for me - it takes me a hour to reinstall XP and Office and another hour to restore any data files from backups - I could ghost them, but that's impractical. If the user has lost anything, it's not my problem - they should have backed it up. (yeah, I'm Mr Hard Nose)
|
||||
What?
|
||||
![]() |
||||
Epignosis ![]() Special Collaborator ![]() ![]() Honorary Collaborator Joined: December 30 2007 Location: Raeford, NC Status: Offline Points: 32552 |
![]() |
|||
I'm just really stubborn, I guess. ![]() ![]() |
||||
![]() |
||||
Slartibartfast ![]() Collaborator ![]() ![]() Honorary Collaborator / In Memoriam Joined: April 29 2006 Location: Atlantais Status: Offline Points: 29630 |
![]() |
|||
Bill Gates is evil and must be destroyed.
![]() |
||||
Released date are often when it it impacted you but recorded dates are when it really happened...
![]() |
||||
![]() |
||||
VanderGraafKommandöh ![]() Prog Reviewer ![]() ![]() Joined: July 04 2005 Location: Malaria Status: Offline Points: 89372 |
![]() |
|||
Have you got a HijackThis log? I'm not sure if RootKits will show up on there though.
I often use CCleaner to clear my Registry. Of course, that won't really help your situation but it's a useful bit of software. |
||||
![]() ![]() ![]() |
||||
![]() |
||||
chopper ![]() Special Collaborator ![]() ![]() Honorary Collaborator Joined: July 13 2005 Location: Essex, UK Status: Offline Points: 20032 |
![]() |
|||
Running Dr Web now, it's found another bit of the TDSS virus I thought I'd cleared.
|
||||
![]() |
||||
Falx ![]() Forum Senior Member ![]() ![]() Joined: May 05 2010 Location: New Zealand Status: Offline Points: 859 |
![]() |
|||
If Bill Gates is the Emperor, then Steve Jobs is Darth Vader ![]() |
||||
"You must go beyond the limit of the limit of your limits!" - Mr. Doctor
"It is our duty as men and women to proceed as though the limits of our abilities do not exist." - Pierre Teilhard de Chardin |
||||
![]() |
||||
Falx ![]() Forum Senior Member ![]() ![]() Joined: May 05 2010 Location: New Zealand Status: Offline Points: 859 |
![]() |
|||
Rootkits are way over HijackThis's head, they normally live in c:\windows\system32\drivers and are loaded while the OS is booting. The only way to get rid of them is to pull the hard disk and scan it in another computer, or boot off a live CD (e.g. ERD Commander) and remove the file yourself, if you know where it is. =F= |
||||
"You must go beyond the limit of the limit of your limits!" - Mr. Doctor
"It is our duty as men and women to proceed as though the limits of our abilities do not exist." - Pierre Teilhard de Chardin |
||||
![]() |
||||
VanderGraafKommandöh ![]() Prog Reviewer ![]() ![]() Joined: July 04 2005 Location: Malaria Status: Offline Points: 89372 |
![]() |
|||
Damn, I might have one without realising it then... or would it be obvious if I did?
However, I use Firefox with AdBlock + and I am usually very careful. Of course, that doesn't mean I could not still get one, of course. Edited by James - May 28 2010 at 22:09 |
||||
![]() ![]() ![]() |
||||
![]() |
Post Reply ![]() |
Page 12> |
Forum Jump | Forum Permissions ![]() You cannot post new topics in this forum You cannot reply to topics in this forum You cannot delete your posts in this forum You cannot edit your posts in this forum You cannot create polls in this forum You cannot vote in polls in this forum |