WORM has me hogtied and bellywhupped

Sorry, I lost the post, but every computer anywhere with wireless or radio signal gets infected. Another apology as to not having the 3 post for you, but there is good reason.

I have been trying to track this sucker down for a month, but it moves, rewrites the registry and changes it’s ID process number right in front of your eyes. It takes control of all files, and places a hook everywhere. It covers all drives, inputs and ports, so if you try to install anything it injects its code an nullifies whatever you are trying to do to kill it. It creates its own (or has a library) of fake and useless help files, reroutes your internet connection and you really can’t believe if you are even on a good sight or not. Online scanners are no good since it occupies the RAM and every port. I have ran Housecall, F-Secure and Panda. They only found tracking cookies. I have AVG on this computer here, but this baby blocks all downloads and error messages and deletes all the DB’s for all antivirus. It even acts like it is scanning when it isn’t, Every file regardless of size 18k – 550k all showed the exact same result. 92 files checked and change dll shell32.dll.

It already had me so worked up that I destroyed my new HP laptop. It penetrates the the partition so there is no clean formating. It rewrites the boot function so it boots to its memory spot. I am pretty sure it has created 20 different shadow drives all the way to Z. It takes control of the Admin rights an assigns you as child. It creates miniports, faxlines any type of data out it can with the resources your computer has, it creates remote access. I blocked 4 computers at the very first, but I think it has place for 6. So, I think this is some sort of MOD where you are having to fight the system and physical remote monitors. If you halt the RPC so whoever cannot get in, then it shuts you down so you can’t get out. Not even with a pc card or usb card from AT & UNOWHO.

I think it is coming in 3 ways, via Synaptic Pointing Device, Real Tek Azalia Audio, and Nvdia Drivers. This is what I figure and very well could be wrong, maybe those where just he first to be exploited. The Real Tek has like some blue crabs, and when they moving on my other computer, I was deleting then but it was replicating them faster than I could delete. On the HP I smashed on the ground and happily jumped on, Spybot Secure Shredder would shred on full function and no sooner that that was done, the files would reappear with different names and extentions.

Sorry to be so long in this post, but every computer on my network out here in the field is infected. I bought a brand new one and was setting it up before I got to location and didn’t have a chance to load Kapersky Full Version I bought with it. An emergency on location cause me to just shut the lid of my new laptop, and not shutting it off, and when I went to open it up, this baby was installing itself all over my new computer. Tried system restore, no good it was there. I really do not know what to do.

I have 1 computer I was able to force to load in safe mode. It creates a bootloop with endpoint to where it will alway boot to itself. I need help because I cannot shut down these others.computers, but will have to work them 1 by 1 and purge this or jump on these too like my others. Thanks in advance.

This entry was posted on Saturday, December 20th, 2008 at 11:38 pm and is filed under Hi-Tech blog. You can follow any responses to this entry through the RSS 2.0 feed. Both comments and pings are currently closed.

Comments are closed.