Pages: [1]   Go Down
  Print  
Author Topic: SDRA64 Trojan  (Read 95 times)
0 Members and 1 Guest are viewing this topic.
Splinter
Pub regular
*******

Good Guy/Gal Points. 64
Online Online

Posts: 3818


Climbing back on


WWW
« on: August 18, 2010, 08:20:59 PM »

I found this a bugger to remove, including the ending processes (svchost....) when you then get 60 secs to countdown and click to accept the registry change between second 1 and 0 remaining, which didn't work.
Booting to Ubuntu was the only solution that worked.
Logged



Phenom II X4 965 8Gb Ram Sapphire HD5770 !Gb Win7 Pro x64
Wooster
Wall Eyed Wanker
Administrator
Drinking problem
*

Good Guy/Gal Points. -520
Online Online

Posts: 4877


'An how faust kin it ging?'


« Reply #1 on: August 18, 2010, 11:00:41 PM »

Svchost covers a pile of different services under different Process ID's

I.E. svchost PID 408



I.E. svchost PID 752



I'd guess you used Task Manager to shut down the svchost entries and accidentally killed Remote Procedure Call...which forces the system to shut down.  Wink

You can get around this by using Procexp and either killing the svchost entry the rogue service is running under, or suspending it (hopefully stalling the shutdown procedure). smile
http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx

Btw, this comes in well handy for those Viruses that just pop up under a different name while you're trying to remove them. If you suspend them, you can get to work removing the bastards while they think they're still working. smile
« Last Edit: August 18, 2010, 11:02:43 PM by Wooster » Logged

Splinter
Pub regular
*******

Good Guy/Gal Points. 64
Online Online

Posts: 3818


Climbing back on


WWW
« Reply #2 on: August 19, 2010, 12:40:30 AM »

Nice one mate, I'll try that.
Was extremely tempted to zap the drive (client said nothing worth keeping), but I was determined to find a way and actually enjoyed it. scratchhead
Will take you up on that procexp though.
Cheers
Logged



Phenom II X4 965 8Gb Ram Sapphire HD5770 !Gb Win7 Pro x64
Pages: [1]   Go Up
  Print  
 
Jump to: