FRIHOST FORUMS SEARCH FAQ TOS BLOGS COMPETITIONS
You are invited to Log in or Register a free Frihost Account!


Virus that create false windows services





iyepes
Definitely I'm out of shape, since I've tryining to remove a virus which creates false windows services and I haven't been able to.

My result was a out of service Domain controller, luckyly not a production one, just one in my class, but my students aren't happy of the info lost during the issue. I did it the old way, finding the registry entries and deleting them, but I did something wrong since the server never booted again. It's really rare that I can't boot the server. It's like virus let something into the MBR.

I also give sporadic support to some companies, and I have a server with similar symptoms. I don't want to cause the same damage that kicked out the domain controller. So I want to hear some suggestions about which virus it could be. I was told it could be conficker, but I haven't read that it create false windows services.
sonam
Did you try F8 (sometimes F12) and bring back your computer in prevous state. When you start computer just press F8 as long is not comming out list of solutuons. Then go down on "Last good known configuration" (or something like that) and press enter. This will bring your computer in time before virus comming. Of course in some situation this is not work.

Sonam
sanalskumar
sonam wrote:
Did you try F8 (sometimes F12) and bring back your computer in prevous state. When you start computer just press F8 as long is not comming out list of solutuons. Then go down on "Last good known configuration" (or something like that) and press enter. This will bring your computer in time before virus comming. Of course in some situation this is not work.

Sonam

What simply happens out here is that your system keeps track of the current settings and configuration details on each successful login. If your system is infected with conficker, this option will not bless you.

Guess what, the conficker(or any same kind of wares) creates false windows services. This not only make your system weak, but also creates conflicts between processes. Resulting in an absolute OS crash.

If you have any rootkit scanner CDs (for example, Trinity rescue kit) try that first because we can not straight away judge that this is conficker.

I strongly recommend you to copy critical data to some other storage media using any live CDs(ubuntu for example). Sticking only to windows causes all the problems....

And for the other windows machine, you do not need to delete registry entries and all. First install Service Pack 3 on the machine. This will help you a lot. Then google for tools for the removal of conficker. I bet you can find hundreds of tools over there....
iyepes
Hi.

Windows 2003 server doesn't have a Service Pack 3. I'm not talking about XP. I give server support, not for PCs. (I let PC support to people with more daily time).

Last good known configuration isn't a good idea in most server cases either.

It seems not to be the conficker.

I had recently an experience with virus in a laptop (my parents, the only case I offer PC support), and it was hidden into system volume. The only way to remove it was using the tool to free disk space (included in windows) and selecting delete previos states except the last one (it free lots of disk space and removed the virus). But that virus didn't create services with strange names.

Thanks for the feedback. I'm getting in shape again.
sanalskumar
I agree that Win 2k3 server OS doesnt have a Service Pack 3. But i think the people who are handling server class machines, are very carefull about backups. If you have the backup of the system state and data, just restore it in the domain contrller and let the virus say, Bye bye...

I am not sure what you meant by system volume, but i think, for removing the viruses, no matter wherever it may be in the hard disk, antivirus programs are available. If you mean system volume information, that is also in hard disk only, right?
Pepperfan
iyepes,

What Anti virus are you using and is it a free or paid version? If you have a paid version you can call in for support. Their techs can walk you through getting fixed up.

Also many anti viruses have the ability to create a boot disk that you can use to scan your system before the operating system loads. If you didn't create one you may be able to get your Anti virus company send you one.


Charles
Diablosblizz
I have my own bootable antivirus CD. It comes in handy if I am going out to fix somebodies computer. It is a bit slow to startup, but it does the job because there is nothing loaded into memory to stop the detection. There is a handy, very handy, Youtube videos (there is about 4)

http://www.youtube.com/watch?v=OYIktyeIKqI&feature=channel_page&fmt=18 (first video)
http://www.youtube.com/watch?v=OIqNawcQFDs&feature=related&fmt=18 (second video)
http://www.youtube.com/watch?v=_589Mx21guc&feature=related&fmt=18 (third video)
http://www.youtube.com/watch?v=QiGnVZlfDag&feature=related&fmt=18 (fourth video)

You must watch the first three videos to learn how to do it, the fourth it just him scanning his system. You need a CD, 2 GB of space, a copy of XP and the service pack. XP can be on a CD if need be. Not sure about this, but you maybe can also use a Server CD instead of a XP one.

If you don't have a copy of Windows XP, then download and install Avast and run a boot-time scanner. It scans the system for malware before the system boots the operating system. It's a really really good free antivirus and I'd recommend it to anybody.
Jamestf347
Honestly, The best way would be is to format your hard-drive, but you could scan... If it's not truly a virus, your anti-virus software won't be able to remove it. You'd need anti-malware. I also suggest you make back ups after you get rid of this worm/virus.
aningbo
i would suggest you to back up and format instead of spending days trying to figure it out what went wrong.

how about the system restore? it always comes in handy. good luck finding your virus.
Related topics
A "small" list of free apps
Windows Vista Official Thread
Fake Windows Update
Best Freeware
10 Reasons why PC's crash
Nyxem virus set to strike tonight
My Favorite Portable Applications
VIRUS??? XP gets hunged? OMG...
Windows XP vs Mac OS X
problem z services.exe
What Are Viruses
Looking for: On-Access virusscan, BSD compatible
Why people hate Windows?
Any Free Virus Scanner for Windows Server 2003
Reply to topic    Frihost Forum Index -> Computers -> Computer Problems and Support

FRIHOST HOME | FAQ | TOS | ABOUT US | CONTACT US | SITE MAP
© 2005-2011 Frihost, forums powered by phpBB.