Strange malware

Can you post a list of installed programs?

i have no vga drver at all, i reinstalled it several times, the fresh driver install works until the first restart, but after the second restart the problem appears again.
Have you tried installing the vga driver in "windows safe mode" ????

Panda seems to be buggy on some computers.

Guys you should read previous posts fully, so you can see that my driver get loaded now at startup, although it works interesitng somtimes( but i dont have HW problems, i have absolutely no problem with the driver on win7, the only problem with that OS install is that its slow as hell, and it wasnt previously )

I continued scanning the system with “noname” AV-s, i had a lot of F/P-s but found some hidden trojans. I think my porrtble apps are not clean, or something made them infected. I downloaded most of them from the official site, if they had the binaries on it, but others are “handmade”. No they are not illegal, they are freewares or sharwares, what are either way free, i just dont like to mess up the registry, and i also can share the files between the two OS-es, so i dont have to install them twice, and i also spare some space on my hdd-s.

My favourite benchmark has been also alerted several times by more AV-s, and i uploaded it to virustotal too.:

http://www.virustotal.com/analisis/73dee42b4624b30c6d02ff53a03d4817cd48ac3c1eda91597e3f22a831a0f225-1262644350

I dont know if its a false positive, but i have now Norman Antimalware installed, and it deleted immediately it during the scan, so i downloaded it again, because i thought it was a false positive, and after i extracted the zip, the guard of this norman ■■■■ alerted immediately, and deleted my poor hyper pi without asking it. But ist interesting, becasue the scanner wasnt running, what should mean that its a trojan in deed, i just cant believe it, because i downloaded it right from the developers site.

Could someone tell me for sure if its a trojan or not? You can dowload it from here:

Its a FP guaranteed.

I would say set CIS to safe mode and submit any file as suspicious that tries to automatically start a process. In this way you should be able to identify the problem.

This may be stupid advice, but I am assuming that there will not be that many alerts on your computer from legitimate applications if you are not installing something.

I am now upset as hell… i have finished scanning with the n-th antivirus, and have bulldozed almost all files from the machine, thus things getting worse and worse. Currently i cant enter Xp, i get blue screen at startup, even in safe mode. I installed an antivirus called Blue Atom, but now i cant decide if its and antivirus or a virus. Everytime i started it on Xp, it made the system lag so much, that i had to reset the machine. Then i installed Remove it pro, and it found 5 detections:

http://img99.imageshack.us/img99/8924/removeit.jpg

isatoor, and pnkbstr are my SATA driver and the punkbuster service fro Crysis Wars, what are surely FP-s so i uncheked them, the others were deleted.

There were 2 suspicious temp file, becasue it was unable to open them, i wanted to upload them to virustotal, but every time i was trying it, i got this :

http://img37.imageshack.us/img37/6711/virustotal.jpg

I could upload any other files without problem at the same time…

I also made a scan ith dr web, found only one thing:

http://img189.imageshack.us/img189/2458/drweb.jpg

This says that a so called “HOST” file is modified, what has something to do with storing the mcahines IP address, and it could mean that a malware has modified it to track the machines IP. I fixed this too.

Everything was fine, until i booted Win7. Then - again - comodo detected 3 things on the D partition, what is the partition of the Xp, and there shouldnt have been any running processes, because i used win7, but there was, namely that Blue Atom shit, so i pwnd it:

http://img301.imageshack.us/img301/442/ba3k.jpg

http://img301.imageshack.us/img301/2465/ba2c.jpg

http://img98.imageshack.us/img98/6686/ba1x.jpg

I downloaded this thing from softpedia…

No there could be two things:

  1. It got infected after i downloaded it ( could explain why Hyper Pi was infected too )
  2. Its a trojan horse itself.

I will try to fix Xp from the CD, but now ive got my mind made up that i will dozer the whole system and reinstall everything one by one, and watch after which install the system gets infected. I have no other idea how else could i find out, how the malware infiltrates into the system.

Damm, that’s one hell of a rootkit

Have you tried running the anti-virus programs in (windows safe mode)??? This generally stops the infection from coming back. You might want to go to “system restore” and delete everything because it will probably be infected <----if you have already done this, then read below

When rebooting the computer, quickly keep hitting the “F8” Key until new screen comes up. PICK THIS ONE-----> windows safe with networking (with internet)

This is the last program you should try, it (requires internet to use it) and uses cloud ( there is no need to update anti-virus defenitions

it has G-Data, Avira, Nod32, Asquared, and prevx all in one <—you Don’t need to download updates, just download the program

It’s a bad idea to randomly start downloading AVs to try to solve the problem. Believe me, I’ve been there before. Why don’t you try a few of the programs off of this guide:
What You Need To Know About Removing Infections and Securing Your Computer

Chances are you’ve already tried them all, but I can at least guarantee you that all of these programs are legitimate. :wink:

Now ive got a totally new install( onyl Xp yet ) and it seems to be ok so far, but i have not installed all of the programs what were on the previous system. What i noticed, that MBR was messed up, i had a ~40K Tera(!!) unpartitioned area displayed in the install, and the installer could not found the disk, until i made this issue disappeare. But anyhow, the system seems to be clean so far. I installed comodo immediately after the OS install had been finished, and let the scanner run on the whole system, found nothing, and i also installed avast, and checked the drives with a bootime scan. I dont know whether it has found something or not, because i was away, and when i arrived home i then the scan was already finished, without displaying the results :confused:

I am gonna add the other apps to the system on by one, and i will check after each if there will be som malfunction or suspicious thing.