The new forums will be named Coin Return (based on the most recent vote)! You can check on the status and timeline of the transition to the new forums here.
The Guiding Principles and New Rules document is now in effect.

Virus?

CasualCasual Wiggle Wiggle Wiggle Flap Flap Flap Registered User regular
edited April 2010 in Help / Advice Forum
I just started getting this warning flashing up every ten seconds. Is it false positive or something more serious? I can't get the warnings to stop.

f9o4ms.jpg

Casual on

Posts

  • TychoCelchuuuTychoCelchuuu PIGEON Registered User regular
    edited April 2010
    Did you download crypt_new_uk44.exe recently?

    TychoCelchuuu on
  • CasualCasual Wiggle Wiggle Wiggle Flap Flap Flap Registered User regular
    edited April 2010
    Uhhh, not to my knowledge but I was at a LAN last weekend and some stuff was shared.

    Casual on
  • TychoCelchuuuTychoCelchuuu PIGEON Registered User regular
    edited April 2010
    So maybe it's a trojan. Delete it and Avast! will shut up. If you ran it, though, you might be infected, at which point it's 5+ virus scanners time or reformat time or something.

    TychoCelchuuu on
  • CasualCasual Wiggle Wiggle Wiggle Flap Flap Flap Registered User regular
    edited April 2010
    I've deleted it but Avast still flags it every ten seconds. D:

    Casual on
  • matt has a problemmatt has a problem Points to 'off' Points to 'on'Registered User regular
    edited April 2010
    In that case crypt_new_uk44.exe is being created by something that's hidden somewhere else on your computer, most likely another program dialing home to download it. Run a regular virus scan, run malwarebytes, see what happens.

    matt has a problem on
    nibXTE7.png
  • TychoCelchuuuTychoCelchuuu PIGEON Registered User regular
    edited April 2010
    It says it's a rootkit so it's quite possibly a rootkit. At this point I'd nuke from orbit. It's the only way to be sure.

    TychoCelchuuu on
  • CasualCasual Wiggle Wiggle Wiggle Flap Flap Flap Registered User regular
    edited April 2010
    I was hoping to avoid a format. Running malwarebytes now.

    Casual on
  • 3drage3drage Registered User regular
    edited April 2010
    Once your system has been compromised no other method but a complete format is recommended.

    3drage on
  • CasualCasual Wiggle Wiggle Wiggle Flap Flap Flap Registered User regular
    edited April 2010
    3drage wrote: »
    Once your system has been compromised no other method but a complete format is recommended.

    You format every time you get a bit of malware? It's using a hammer to crack a nut.


    I downloaded and used malwarebytes and it seems to have gotten rid of it. Avast! has stopped popping up every ten seconds anyway.

    Casual on
  • GrimReaperGrimReaper Registered User regular
    edited April 2010
    Casual wrote: »
    3drage wrote: »
    Once your system has been compromised no other method but a complete format is recommended.

    You format every time you get a bit of malware? It's using a hammer to crack a nut.


    I downloaded and used malwarebytes and it seems to have gotten rid of it. Avast! has stopped popping up every ten seconds anyway.

    If you're unfamiliar with using boot cd's like bartpe then yeah, nuking it from orbit is the best way to go.

    If however you're pretty confident then you can create a bartpe boot cd and edit the registry, delete files etc. This all assumes you know what you are doing. I use a custom bartpe cd at work for when an outside contractor inevitably brings in a virus on a flash drive or on their laptop.

    GrimReaper on
    PSN | Steam
    ---
    I've got a spare copy of Portal, if anyone wants it message me.
  • 3drage3drage Registered User regular
    edited April 2010
    Casual wrote: »
    3drage wrote: »
    Once your system has been compromised no other method but a complete format is recommended.

    You format every time you get a bit of malware? It's using a hammer to crack a nut.


    I downloaded and used malwarebytes and it seems to have gotten rid of it. Avast! has stopped popping up every ten seconds anyway.

    Have fun, hopefully you don't get your accounts hacked by a key logger running via a rootkit that software won't pick up. If your ID is stolen it's your nuts that will be cracked.

    3drage on
  • TychoCelchuuuTychoCelchuuu PIGEON Registered User regular
    edited April 2010
    Casual wrote: »
    3drage wrote: »
    Once your system has been compromised no other method but a complete format is recommended.

    You format every time you get a bit of malware? It's using a hammer to crack a nut.


    I downloaded and used malwarebytes and it seems to have gotten rid of it. Avast! has stopped popping up every ten seconds anyway.

    A rootkit is not "a bit of malware." It's basically the toughest thing to remove, and it's even harder to know that you've removed it vs. just killed it enough to keep from noticing that it's logging all of your keystrokes.

    TychoCelchuuu on
  • TelMarineTelMarine Registered User regular
    edited April 2010
    I agree with you Casual, you shouldn't have to reformat. Formatting everytime something like this happens is a waste of time imo and people here always say that is what you should do (which you shouldn't really). There was another thread with something similar and recommended using rkill and TDSSKiller (http://support.kaspersky.com/viruses/solutions?qid=208280684) which worked very well and could be useful to you.

    TelMarine on
    3ds: 4983-4935-4575
Sign In or Register to comment.