• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

The baddest skype virus got me !

Joined
May 4, 2009
Messages
69 (0.01/day)
Location
Kardzhali
System Name The Pacificator :D
Processor Athlon64x2 @ 3,05 ghz
Motherboard Gigabyte
Cooling DIY
Memory Corsair Xms2 800mhz 2gb
Video Card(s) Gigabyte 9600GT Zalman
Storage 40gb ATA + 320gb SATA
Case DIY
Power Supply sucky 400W
The baddest skype virus | KILLED

:twitch:

Yesterday a trusted friend started writing some idiotic stuff, not having sense at all (i'm sure it was him... he laughs like that "HahAHAhahaaHAHA" or he writes "o" with a "0" for ex.), i asked him "Are you high?" and then he posted me an IP that looks something like that: 22..22.22..2. (ip)/"my skype name" "my country" and some other stuff... i clicked it and it downloaded a file... i didn't even open it because it looked fishy... "myskypename.scr (screensaver)... i right clicked the file then properties and it suddenly closed, then i deleted the file with shift+delete...

Then anomalies started happening... 10 minutes later my pc froze for 3 seconds, i knew something was wrong, i went to task manager and found 2 new .exe files: sffsafuiagsifgasf.exe and another one... every time i killed it, new exe's were running with random character names...
I tried to locate the .exe's (in hidden files too) and i saw nothing... i knew the path of the exe but it wasn't there... i searched it with the windows7 search engine and didn't find it... i pasted its name in the start menu search box and it found it but when i deleted it nothing happened... it just popped up again

I knew the precise time when the first file was created and i searched for files created at the same time and deleted all that windows found... but it didnt found the file in task maneger (from witch i saw the creation time)

I went to C:/ where i keep all installations for AV's and important programs, and went in folder NOD32 Antivirus then the folder closed suddenly like the properties window earlier, i navigated there again but it was empty (it deleted all files)... then i googled "skype virus changing name" and the browser closed like the folder, and the properties window... Same thing with, another NOD, spyware remover, adware remover... Everywhere it found an antivirus-related name it closed the program or deleted a file...

I booted up in safe mode, i was disappointed i cant install an antivirus in safemode...
I deleted files with funny names and whatever created in the same day after 7:22 (the precise time it got on my pc) i opened regedit and pasted exe file names from the task maneger in the search box, and deleted the registrities-nothing happened...

I found a program called "PC Tools Spyware Doctor" and im scaning at the moment... if someone had the same problem or a suggestion feel free to post... :respect:
 
Last edited:

crazyeyesreaper

Not a Moderator
Staff member
Joined
Mar 25, 2009
Messages
9,763 (1.77/day)
Location
04578
System Name Old reliable
Processor Intel 8700K @ 4.8 GHz
Motherboard MSI Z370 Gaming Pro Carbon AC
Cooling Custom Water
Memory 32 GB Crucial Ballistix 3666 MHz
Video Card(s) MSI GTX 1080 Ti Gaming X
Storage 3x SSDs 2x HDDs
Display(s) Dell U2412M + Samsung TA350
Case Thermaltake Core P3 TG
Audio Device(s) Samson Meteor Mic / Generic 2.1 / KRK KNS 6400 headset
Power Supply Zalman EBT-1000
Mouse Mionix NAOS 7000
Keyboard Mionix
good example to never click a suspect file not much ican say to help best bet here is malwarebytes

http://www.malwarebytes.org/

but i would suggest a full system reinstall i dont mess with virus wipe the drive reformat reinstall and dont fall for it again :toast:

also another example of why ppl shouldn't text like idiots
 
I

InTeL-iNsIdE

Guest
Nasty lil bugger.

Either get a few different av programs and anti spyware ( I reccommend spybot s+d) loaded onto a USB stick then try running all of them in safe mode, or whip your hdd out and throw it in another pc and boot from the other pc's OS and again scan with multiple av and spyware programs.


Failing that perhaps you might have to format if its a nasty one and has buggered the registry etc
 
Joined
May 4, 2009
Messages
69 (0.01/day)
Location
Kardzhali
System Name The Pacificator :D
Processor Athlon64x2 @ 3,05 ghz
Motherboard Gigabyte
Cooling DIY
Memory Corsair Xms2 800mhz 2gb
Video Card(s) Gigabyte 9600GT Zalman
Storage 40gb ATA + 320gb SATA
Case DIY
Power Supply sucky 400W
crasyeyesreaper it shows an error when i install it... probably because im in safe mode
 

crazyeyesreaper

Not a Moderator
Staff member
Joined
Mar 25, 2009
Messages
9,763 (1.77/day)
Location
04578
System Name Old reliable
Processor Intel 8700K @ 4.8 GHz
Motherboard MSI Z370 Gaming Pro Carbon AC
Cooling Custom Water
Memory 32 GB Crucial Ballistix 3666 MHz
Video Card(s) MSI GTX 1080 Ti Gaming X
Storage 3x SSDs 2x HDDs
Display(s) Dell U2412M + Samsung TA350
Case Thermaltake Core P3 TG
Audio Device(s) Samson Meteor Mic / Generic 2.1 / KRK KNS 6400 headset
Power Supply Zalman EBT-1000
Mouse Mionix NAOS 7000
Keyboard Mionix
then i suggest a full install ive only had 3 virus in my lifetime and all 3 times i just said screw it and reinstalled problem solved :toast:

either that or do as InTeL-iNsIdE suggested pull the hdd out put it in another machine boot and scan it from that machine
 

Mussels

Freshwater Moderator
Staff member
Joined
Oct 6, 2004
Messages
58,413 (8.19/day)
Location
Oystralia
System Name Rainbow Sparkles (Power efficient, <350W gaming load)
Processor Ryzen R7 5800x3D (Undervolted, 4.45GHz all core)
Motherboard Asus x570-F (BIOS Modded)
Cooling Alphacool Apex UV - Alphacool Eisblock XPX Aurora + EK Quantum ARGB 3090 w/ active backplate
Memory 2x32GB DDR4 3600 Corsair Vengeance RGB @3866 C18-22-22-22-42 TRFC704 (1.4V Hynix MJR - SoC 1.15V)
Video Card(s) Galax RTX 3090 SG 24GB: Underclocked to 1700Mhz 0.750v (375W down to 250W))
Storage 2TB WD SN850 NVME + 1TB Sasmsung 970 Pro NVME + 1TB Intel 6000P NVME USB 3.2
Display(s) Phillips 32 32M1N5800A (4k144), LG 32" (4K60) | Gigabyte G32QC (2k165) | Phillips 328m6fjrmb (2K144)
Case Fractal Design R6
Audio Device(s) Logitech G560 | Corsair Void pro RGB |Blue Yeti mic
Power Supply Fractal Ion+ 2 860W (Platinum) (This thing is God-tier. Silent and TINY)
Mouse Logitech G Pro wireless + Steelseries Prisma XL
Keyboard Razer Huntsman TE ( Sexy white keycaps)
VR HMD Oculus Rift S + Quest 2
Software Windows 11 pro x64 (Yes, it's genuinely a good OS) OpenRGB - ditch the branded bloatware!
Benchmark Scores Nyooom.
sounds nasty


try looking in MSconfig, its got to start with windows somehow
 
Joined
Apr 14, 2008
Messages
1,777 (0.30/day)
Location
South Australia
System Name QUACK
Processor Intel i7 2600K (3.4 GHz, 8 threads)
Motherboard Asus P67P8-V3
Cooling Xigmatek Balder 120mm (4x120,1x140mm case)
Memory Patriot 2 Viper Sector 5, 8GB DDR3 1600 MHz
Video Card(s) Gigabyte GeForce GTX 960 G1 4GB
Storage 1x Samsung EVO 850 (500GB) SSD, 1x Fujitsu 256GB SSD
Display(s) Dell Ultrasharp U2311h 23" (so sexy)
Case CoolerMaster Gladiator RC-600
Audio Device(s) Onboard 5.1
Power Supply Antec 850w with yellow racing stripes
Software Windows 7 HP 64 bit
sounds nasty


try looking in MSconfig, its got to start with windows somehow

Agreed, I had a program that was legit, uninstalled it, and then suddenly next reboot after about 3-4 minutes explorer would freeze, completely.
I went into safe mode, had a look at the services in msconfig, and it was the service with no description next to it. I also found the file and deleted it (shift+delete, none of that recycle bin shiz).
Avast! is able to do a pre-boot scan as well, which means it could find the virus before it starts in windows.
 

crazyeyesreaper

Not a Moderator
Staff member
Joined
Mar 25, 2009
Messages
9,763 (1.77/day)
Location
04578
System Name Old reliable
Processor Intel 8700K @ 4.8 GHz
Motherboard MSI Z370 Gaming Pro Carbon AC
Cooling Custom Water
Memory 32 GB Crucial Ballistix 3666 MHz
Video Card(s) MSI GTX 1080 Ti Gaming X
Storage 3x SSDs 2x HDDs
Display(s) Dell U2412M + Samsung TA350
Case Thermaltake Core P3 TG
Audio Device(s) Samson Meteor Mic / Generic 2.1 / KRK KNS 6400 headset
Power Supply Zalman EBT-1000
Mouse Mionix NAOS 7000
Keyboard Mionix
i still suggest a reinstall kill it 100% every time ;)
 

DrPepper

The Doctor is in the house
Joined
Jan 16, 2008
Messages
7,482 (1.26/day)
Location
Scotland (It rains alot)
System Name Rusky
Processor Intel Core i7 D0 3.8Ghz
Motherboard Asus P6T
Cooling Thermaltake Dark Knight
Memory 12GB Patriot Viper's 1866mhz 9-9-9-24
Video Card(s) GTX470 1280MB
Storage OCZ Summit 60GB + Samsung 1TB + Samsung 2TB
Display(s) Sharp Aquos L32X20E 1920 x 1080
Case Silverstone Raven RV01
Power Supply Corsair 650 Watt
Software Windows 7 x64
Benchmark Scores 3DMark06 - 18064 http://img.techpowerup.org/090720/Capture002.jpg
Joined
May 4, 2009
Messages
69 (0.01/day)
Location
Kardzhali
System Name The Pacificator :D
Processor Athlon64x2 @ 3,05 ghz
Motherboard Gigabyte
Cooling DIY
Memory Corsair Xms2 800mhz 2gb
Video Card(s) Gigabyte 9600GT Zalman
Storage 40gb ATA + 320gb SATA
Case DIY
Power Supply sucky 400W
Thank you all for your help, i installed XP on my other hard drive to get an AV program and kill it... xp got infected too, when i clicked "end procces tree" in Taskmaneger it killed it( in Win7 it didnt happen)

now im safe, it shows up again when you doubleclick a hard drive in my computer, but thats not a problem... the NOD32 is scaning at the moment.... i got the "Regedit has been disabled by your administrator" error , but i think i fixed it >>> GPEDIT.MSX; user config; administr. templates; system; prevent acces to registrity tools - disabled it and ill restart after the scan is over

I also removed the startup exe's from msconfig but nothing changed, new ones appeared
 

Mussels

Freshwater Moderator
Staff member
Joined
Oct 6, 2004
Messages
58,413 (8.19/day)
Location
Oystralia
System Name Rainbow Sparkles (Power efficient, <350W gaming load)
Processor Ryzen R7 5800x3D (Undervolted, 4.45GHz all core)
Motherboard Asus x570-F (BIOS Modded)
Cooling Alphacool Apex UV - Alphacool Eisblock XPX Aurora + EK Quantum ARGB 3090 w/ active backplate
Memory 2x32GB DDR4 3600 Corsair Vengeance RGB @3866 C18-22-22-22-42 TRFC704 (1.4V Hynix MJR - SoC 1.15V)
Video Card(s) Galax RTX 3090 SG 24GB: Underclocked to 1700Mhz 0.750v (375W down to 250W))
Storage 2TB WD SN850 NVME + 1TB Sasmsung 970 Pro NVME + 1TB Intel 6000P NVME USB 3.2
Display(s) Phillips 32 32M1N5800A (4k144), LG 32" (4K60) | Gigabyte G32QC (2k165) | Phillips 328m6fjrmb (2K144)
Case Fractal Design R6
Audio Device(s) Logitech G560 | Corsair Void pro RGB |Blue Yeti mic
Power Supply Fractal Ion+ 2 860W (Platinum) (This thing is God-tier. Silent and TINY)
Mouse Logitech G Pro wireless + Steelseries Prisma XL
Keyboard Razer Huntsman TE ( Sexy white keycaps)
VR HMD Oculus Rift S + Quest 2
Software Windows 11 pro x64 (Yes, it's genuinely a good OS) OpenRGB - ditch the branded bloatware!
Benchmark Scores Nyooom.
honestly, back up data and format. this sounds like one nasty virus.

the fact that it somehow spread to the new OS is rather worrying.
 
Joined
Feb 10, 2008
Messages
3,393 (0.57/day)
Location
BC.CAN
Processor 2700x under H100i progeebee
Motherboard ASUS x470 prime
Cooling Fans
Memory gskill ripjaw 3200
Video Card(s) MSi Vega 64 ref
Storage 120Gb OCZ Vertex 2E SSD - 500Gb Games - 1.5tb Storage and Media
Case CM HAF 932
Power Supply Corsair TX750
Software Win 10
Disconnect the PC from your network and format it. If that thing jumped from on HDD and infected another OS then it's pretty lethal.
 
Joined
May 4, 2009
Messages
69 (0.01/day)
Location
Kardzhali
System Name The Pacificator :D
Processor Athlon64x2 @ 3,05 ghz
Motherboard Gigabyte
Cooling DIY
Memory Corsair Xms2 800mhz 2gb
Video Card(s) Gigabyte 9600GT Zalman
Storage 40gb ATA + 320gb SATA
Case DIY
Power Supply sucky 400W
honestly, back up data and format. this sounds like one nasty virus.

the fact that it somehow spread to the new OS is rather worrying.

The nastiest thing is the way it spreads... it records random chat from your friend (you) and pastes it, you think that its some kind of a joke, and then he posts a link with your name, country, some IP and other characters, and because the stuff he is saying are actualy his words you think that your friend is just an idiot, and you think that its not spam and get interested and click on the link... i didnt even open the file, i dont know how it spreaded all over the pc...

I usualy eat for breakfast some viruses, but this one :twitch:

If NOD32 doesnt find anything, ill scan with Kaspersky and if nothing happens - full format
 
Joined
Feb 10, 2008
Messages
3,393 (0.57/day)
Location
BC.CAN
Processor 2700x under H100i progeebee
Motherboard ASUS x470 prime
Cooling Fans
Memory gskill ripjaw 3200
Video Card(s) MSi Vega 64 ref
Storage 120Gb OCZ Vertex 2E SSD - 500Gb Games - 1.5tb Storage and Media
Case CM HAF 932
Power Supply Corsair TX750
Software Win 10
Give Malwarebytes a shot too if you feel like testing.
 
Joined
Jan 17, 2009
Messages
2,143 (0.38/day)
System Name THE MAD BEAST!!!
Processor Tinfoil rapper with some coathangers
Motherboard Graham cracker with with frosting
Cooling A shovel full of snow
Memory Grey matter out of a corpse
Video Card(s) Cat eyes
Storage A whales brain
Display(s) Cyclops eyeball
Case Inside a yetis hollowed out corpse
Audio Device(s) howling banchee
Power Supply 32 hamster on a massive wheel
Software WHo needs software when you have a box of kittens
Benchmark Scores IS gatrillions a number?
you can run kaspery in safe mode, you have to go into the program files and start its safe mode scanner, it works quite well actually
 
Joined
May 5, 2009
Messages
2,270 (0.42/day)
Location
the uk that's all you need to know ;)
System Name not very good (wants throwing out window most of time)
Processor xp3000@ 2.17ghz pile of sh** /i7 920 DO on air for now
Motherboard msi kt6 delta oap /gigabyte x58 ud7 (rev1.0)
Cooling 1 green akasa 8cm(rear) 1 multicoloured akasa(hd) 1 12 cm (intake) 1 9cm with circuit from old psu
Memory 1.25 gb kingston hyperx @333mhz/ 3gb corsair dominator xmp 1600mhz
Video Card(s) (agp) hd3850 not bad not really suitable for mobo n processor/ gb hd5870
Storage wd 320gb + samsung 320 gig + wd 1tb 6gb/s
Display(s) compaq mv720
Case thermaltake XaserIII skull / coolermaster cm 690II
Audio Device(s) onboard
Power Supply corsair hx 650 w which solved many problems (blew up) /850w corsair
Software xp pro sp3/ ? win 7 ultimate (32 bit)
Benchmark Scores 6543 3d mark05 ye ye not good but look at the processor /uknown as still not benched
i used malwarebytes (from here) on someone elses machine but had to go into the system
( whilst in safe mode )then delete the threads it created by using regedit but that's not recomended unless you know what your doing ,and what your looking for:rolleyes:

edit
i got the "Regedit has been disabled by your administrator" error
wo didn't see that, sounds a bad un, never had malware do that before and i've had to deal with a few :eek:
 
Last edited:
Joined
Mar 9, 2006
Messages
1,203 (0.18/day)
Location
FL
System Name Iam-a-computah
Processor i9 9900k @5 Ghz
Motherboard Gigabyte Auros z390x
Cooling Custom water loop, x2 280 radiators
Memory 16gb Corsair Dominator
Video Card(s) MSI 1080 TI FE 11gb WC
Storage SSD: 256gb Samsung 840pro & HHD: WD black 2T
Display(s) LG 34" UW screen
Case EVGA DG-86
Audio Device(s) Creative x-FI
Power Supply EVGA super NOVA 1300wtt
Keyboard G710
Software W 10
Jesus that's one bad virus, It reminds me when i got something similar years ago on my XP PC. I noticed when you deleted some of the virus's file and then they just re-appear is because there's another file somewhere, creating them. Finding that sucker is hard but not impossible. I eventually did and got rid of the whole thing without never using an anti virus, well i did but just to scan.

hmmm i have an extra machine that i wouldnt mind getting infected by your virus, and then try to kill it.......yeah i have fun doing that (im pc sadistic >=]) but i guess that's just my crazy side talking =P.
 
Joined
May 4, 2009
Messages
69 (0.01/day)
Location
Kardzhali
System Name The Pacificator :D
Processor Athlon64x2 @ 3,05 ghz
Motherboard Gigabyte
Cooling DIY
Memory Corsair Xms2 800mhz 2gb
Video Card(s) Gigabyte 9600GT Zalman
Storage 40gb ATA + 320gb SATA
Case DIY
Power Supply sucky 400W
Give Malwarebytes a shot too if you feel like testing.

I will, after nod finishes scaning. :rockout:

you can run kaspery in safe mode, you have to go into the program files and start its safe mode scanner, it works quite well actually

I know i can, but i cant install it in safe mode :S

unless you know what your doing ,and what your looking for:rolleyes:

I think i know what im doing... if i don't, at least ill learn what not to do next time..
 
Last edited:

MK4512

New Member
Joined
Aug 26, 2009
Messages
222 (0.04/day)
Location
Toronto, Canada
System Name MK4512's Computer
Processor Phenom II X3 720 @3.4GHz
Motherboard ASRock AOD790GX
Cooling Artic Cooling Freezer 64 Pro
Memory 4 GB GSkill DDR2 800 RAM @4-4-4-12
Video Card(s) Sapphire Radeon 4890
Storage 500GB Seagate
Display(s) 22" Philips 1920x1080
Case Antec 300 (w/ New LED Fans!)
Power Supply 600w OCZ XStream Modular PSU
Software Windows 7
Well, if it's stopping you from opening things, I recommend Unlocker Assistant, and an anti-virus I personally use is Avast. Check out Avast if you are looking to install a new anti-virus to get this thing.
 
Joined
May 4, 2009
Messages
69 (0.01/day)
Location
Kardzhali
System Name The Pacificator :D
Processor Athlon64x2 @ 3,05 ghz
Motherboard Gigabyte
Cooling DIY
Memory Corsair Xms2 800mhz 2gb
Video Card(s) Gigabyte 9600GT Zalman
Storage 40gb ATA + 320gb SATA
Case DIY
Power Supply sucky 400W
99 infiltrations found / 99 files deleted (main hdd)
scanning current HD - 1 infiltration found for now
 
Joined
May 4, 2009
Messages
69 (0.01/day)
Location
Kardzhali
System Name The Pacificator :D
Processor Athlon64x2 @ 3,05 ghz
Motherboard Gigabyte
Cooling DIY
Memory Corsair Xms2 800mhz 2gb
Video Card(s) Gigabyte 9600GT Zalman
Storage 40gb ATA + 320gb SATA
Case DIY
Power Supply sucky 400W
malwarebytes did an awesome job on the smaller hd where i installed XP

37 infiltrations found and they all were viruses of the kind that bothers me :rockout:

its now scaning the win7 hdd its 320 gb so lets wait :respect:
 

crazyeyesreaper

Not a Moderator
Staff member
Joined
Mar 25, 2009
Messages
9,763 (1.77/day)
Location
04578
System Name Old reliable
Processor Intel 8700K @ 4.8 GHz
Motherboard MSI Z370 Gaming Pro Carbon AC
Cooling Custom Water
Memory 32 GB Crucial Ballistix 3666 MHz
Video Card(s) MSI GTX 1080 Ti Gaming X
Storage 3x SSDs 2x HDDs
Display(s) Dell U2412M + Samsung TA350
Case Thermaltake Core P3 TG
Audio Device(s) Samson Meteor Mic / Generic 2.1 / KRK KNS 6400 headset
Power Supply Zalman EBT-1000
Mouse Mionix NAOS 7000
Keyboard Mionix
good malwarebytes is doing its job then glad you decided to try it
 
Joined
Jun 2, 2007
Messages
5,106 (0.83/day)
Location
Kansas
Processor Core i5 3570K
Motherboard AsRock z77 Pro4
Cooling Zalman CNPS10X Extreme
Memory 2x4GB GSkill Sniper
Video Card(s) MSI GTX970 Gaming
Storage 240GB OCZ ARC 100, Samsung Spinpoint F3 1TB
Display(s) LG 23" 1920x1080
Case Antec P100
Audio Device(s) Onboard
Power Supply Antec Edge 750W
Software Windows 8.1 Pro 64
Malwarebytes rules, and it can be installed in safe mode.

If you get an error or the virus won't let you install, try renaming the .exe. Sometimes the virus recognizes it by name and blocks it. I call mine by my favorite whiskey. :D
 
Joined
Jan 17, 2009
Messages
2,143 (0.38/day)
System Name THE MAD BEAST!!!
Processor Tinfoil rapper with some coathangers
Motherboard Graham cracker with with frosting
Cooling A shovel full of snow
Memory Grey matter out of a corpse
Video Card(s) Cat eyes
Storage A whales brain
Display(s) Cyclops eyeball
Case Inside a yetis hollowed out corpse
Audio Device(s) howling banchee
Power Supply 32 hamster on a massive wheel
Software WHo needs software when you have a box of kittens
Benchmark Scores IS gatrillions a number?
I will, after nod finishes scaning. :rockout:



I know i can, but i cant install it in safe mode :S



I think i know what im doing... if i don't, at least ill learn what not to do next time..

thats what i keep a installed version on a jump drive, or have a secondary harddrive with it on there i can make a primary incase some bad shit goes down, switch harddrive boot up scan the other and kilL KILL KILL!!!!
 

Espera

New Member
Joined
Nov 23, 2009
Messages
46 (0.01/day)
Not sure if this effects internal HDD connections but did you have AUTORUN disabled before you connected the HDD internally or externally?
 
Top