HELP!! Infected by CIA Trojan!!

Problems? Post here...
Post Reply
eppik
Fame ! Where are the chicks?!
Fame ! Where are the chicks?!
Posts: 212
Joined: 26 Mar 2006, 16:00
18
Location: Infinite Loop
Contact:

HELP!! Infected by CIA Trojan!!

Post by eppik »

I've been infected by CIA trojan. I blocks the Task MAnager, windows recovery, registry editing, etc..!!!!

I have kaspersky anti vir and i deleted all threaths also i instale a trojan remover but it didnt work!!


Plz HELP ME!!

Chaos1986
Fame ! Where are the chicks?!
Fame ! Where are the chicks?!
Posts: 412
Joined: 03 May 2006, 16:00
17
Location: United States Of America
Contact:

Post by Chaos1986 »

If You Can Some How Get To Your Task Manager http://www.spywaredb.com/remove-cia/
You Can Also Try http://security.symantec.com/sscv6/defa ... &venid=sym
And Click GO
Or Try http://www.ccleaner.com/
I Use It To Keep My Registry Clean.
Good Luck :twisted: :evil:
If Man Made It Man Can Crack Or Hack It & If You Want To Be A True Hacker You Need To Keep Your Mind Open And Always Be Willing To Learn
[img]http://img384.imageshack.us/img384/9996/chaos19862ub.png[/img]

eppik
Fame ! Where are the chicks?!
Fame ! Where are the chicks?!
Posts: 212
Joined: 26 Mar 2006, 16:00
18
Location: Infinite Loop
Contact:

Post by eppik »

i didnt help much cuz i cant acess task manager

isnt there a software to remove it?

I really need to acess task manager


PS i've gained acess to regedit now but stll need tsk manager to kill it

User avatar
zer0Dose
Newbie
Newbie
Posts: 9
Joined: 10 Feb 2007, 17:00
17

Post by zer0Dose »

try using a differnt connection, the noob might disable task when ur online, but differnt IP, he wont know, unless he set it to disable task as soon as u opened the exe :? google? :lol:

User avatar
Gogeta70
^_^
^_^
Posts: 3275
Joined: 25 Jun 2005, 16:00
18

Post by Gogeta70 »

This is simple. Boot up in safe mode, and follow the proper steps to move it. It may be preferrable to start in safe mode with networking. This way, you can come back here and look at the useful information given by Chaos1986.
¯\_(ツ)_/¯ It works on my machine...

eppik
Fame ! Where are the chicks?!
Fame ! Where are the chicks?!
Posts: 212
Joined: 26 Mar 2006, 16:00
18
Location: Infinite Loop
Contact:

Post by eppik »

The n00b set it do kill AV and firewall as whell as Task MNG and Regedit and windows recovery....



Damn even in safe mode i cant acess Task manager to kill the processes so i cant follow Chaos' advice on how to remove it.....


If i find the noobs IP ill kill him...

eppik
Fame ! Where are the chicks?!
Fame ! Where are the chicks?!
Posts: 212
Joined: 26 Mar 2006, 16:00
18
Location: Infinite Loop
Contact:

Post by eppik »

New update:

I CANT ACESS cmd.exe!!!

eppik
Fame ! Where are the chicks?!
Fame ! Where are the chicks?!
Posts: 212
Joined: 26 Mar 2006, 16:00
18
Location: Infinite Loop
Contact:

Post by eppik »

It was one of my friends he doesnt know english so he just checked every box in the server builder so now:

It hides from task manager
it hides from windows explorer
it hides from AV
it kills Firewall and AV


Advances:

I now get acess to task manager and cmd in networking safe mode, but the processes are hidden!

I really need to get rid of this plz

User avatar
Gogeta70
^_^
^_^
Posts: 3275
Joined: 25 Jun 2005, 16:00
18

Post by Gogeta70 »

Seems like it did some registry edits. Boot up in safe mode again, and do a system restore. Also, in safe mode, watch it boot up and at the bottom if it says it's loading some file and that you can cancel it, DO IT. It's probably that trojan integrating itself into safe mode. Anyway, once you've done system restore, try doing the things chaos recommended.
¯\_(ツ)_/¯ It works on my machine...

eppik
Fame ! Where are the chicks?!
Fame ! Where are the chicks?!
Posts: 212
Joined: 26 Mar 2006, 16:00
18
Location: Infinite Loop
Contact:

Post by eppik »

ill trie and update this post

it disabled sys restore in safe mode but i will do as you say:

press ESC when files are loading



UPDATE: When i press escape, the computer reeboots, and the system restore says that has been disabled by some thing called the Group policie or something like that

User avatar
knightm4r3
suck-o-fied!
suck-o-fied!
Posts: 74
Joined: 28 Dec 2006, 17:00
17

Post by knightm4r3 »

Can you use BART cd?

Also, try to use a knoppix disk.

If you use the Knoppix disk, you'll have to just sat all permissions to admin and you should be able to access the windows partition. It is what I use anytime my windows dies.

eppik
Fame ! Where are the chicks?!
Fame ! Where are the chicks?!
Posts: 212
Joined: 26 Mar 2006, 16:00
18
Location: Infinite Loop
Contact:

Post by eppik »

yes i've got the Knoppix STD version (live cd)

How do i acess teh HD, and what do i do?

User avatar
Pathogenic_Linx
Newbie
Newbie
Posts: 1
Joined: 10 Mar 2007, 17:00
17

Post by Pathogenic_Linx »

Sounds more like a root kit than anything else. :?

User avatar
bad_brain
Site Owner
Site Owner
Posts: 11636
Joined: 06 Apr 2005, 16:00
19
Location: In your eye floaters.
Contact:

Post by bad_brain »

Pathogenic_Linx wrote:Sounds more like a root kit than anything else. :?
not exactly...a rootkit can't usually be found in the list of running tasks or opened ports, but on the other side a rootkit doesn't need to kill the AV or firewall. the AV usually can't detect it anyway because the rootkit is running on system level and not on application level, and because it binds to other services it doesn't need to open a own port.
but well, it's like viruses and worms, there is no "pure" malware around anymore, just mixes of different malware categories....so a RAT can partitially behave like a rootkit too...
:wink:

Post Reply