Computer Repair

CRMC - 5 Day Trial
 
Security and Malware Issues A place to talk about System Security and Malware removal.

Reply
  #1  
Old 07-18-2012, 02:52 PM
sandra's Avatar
sandra sandra is offline
Forum Member
 
Join Date: Apr 2012
Location: Scotland
Posts: 616
Default Graftor 36517

I've ran rkill around 5 times now, and this baby is still showing up - should I just go on to combofix or malwarebytes?


Reply With Quote
  #2  
Old 07-18-2012, 07:57 PM
popeye67's Avatar
popeye67 popeye67 is offline
Moderator
 
Join Date: Apr 2009
Location: North west England, just follow the smell of curry.
Posts: 6,038
Default

You need to run rkill and combofix straight after, rkill on its own will only stop things running not get rid, you would probably get away with using malwarebytes or an avast boot scan


__________________
Q6600-P5K Premium+Alphacool w/blocks
EVGA 8800gt+Koolance w/block
Samsung f1 raid0 +f2 hard drives
Enermax infinity 650w

Popeye67's Blog
Reply With Quote
  #3  
Old 07-18-2012, 08:20 PM
sandra's Avatar
sandra sandra is offline
Forum Member
 
Join Date: Apr 2012
Location: Scotland
Posts: 616
Default

Think I've finally got rid of it with the malwarebytes.


Reply With Quote
  #4  
Old 07-18-2012, 08:29 PM
sandra's Avatar
sandra sandra is offline
Forum Member
 
Join Date: Apr 2012
Location: Scotland
Posts: 616
Default

Spoke too soon, it's showing up again...


Reply With Quote
  #5  
Old 07-18-2012, 08:38 PM
ernie ernie is offline
Forum Member
 
Join Date: Aug 2011
Location: Ohio,U.S.A
Posts: 168
Default

boot time virus scanning works if virus has frozen your os so it wont open

start in safe mode
rkill to stop running programs
then use like 3-4 different software to get rid of it but make sure there up to date
might have to use a rootkit for stuff hidden in lock files
or If its to nasty you might have to wipe and reload



Last edited by ernie; 07-18-2012 at 08:42 PM.
Reply With Quote
  #6  
Old 07-18-2012, 10:11 PM
sandra's Avatar
sandra sandra is offline
Forum Member
 
Join Date: Apr 2012
Location: Scotland
Posts: 616
Default

rkill, combofix, avast, malwarebytes, and superantispyware haven't gotten rid of this one.

Looks like it's going to be a full re-install - unless anyone can suggest something else????

I haven't tried hijackthis... Does anyone know how to read hijackthis reports? I certainly don't...



Last edited by sandra; 07-19-2012 at 12:12 AM. Reason: thought about hijackthis...
Reply With Quote
  #7  
Old 07-19-2012, 12:08 AM
ernie ernie is offline
Forum Member
 
Join Date: Aug 2011
Location: Ohio,U.S.A
Posts: 168
Default

if you can you can try to identify the virus and the program the virus is infecting and delete the infected program you can also google the removal of the virus if you know the name


Reply With Quote
  #8  
Old 07-19-2012, 12:15 AM
daisymae70's Avatar
daisymae70 daisymae70 is offline
Moderator
 
Join Date: Jan 2010
Location: IOWA
Posts: 2,249
Default

Graftor 36517 This is a strain I have never even heard of. Doesn't appear to be much out there on it that I could see. Always makes me wonder how someone picks these up on their computer. You have your work cut out for you Sandra.


__________________
The Truth is the Truth whether you believe it or not.


READ YOUR COMPUTER'S WARRANTY BEFORE ATTEMPTING TO DO ANY OF THE REPAIRS YOURSELF.
Reply With Quote
  #9  
Old 07-19-2012, 12:19 AM
sandra's Avatar
sandra sandra is offline
Forum Member
 
Join Date: Apr 2012
Location: Scotland
Posts: 616
Default

Quote:
Originally Posted by ernie View Post
if you can you can try to identify the virus and the program the virus is infecting and delete the infected program you can also google the removal of the virus if you know the name
It's a trojan gen.variant Graftor.36517. Googled it straight off, but couldn't find this one.

Even if I can't get rid of this and need to do a full re-install, I'll still have to scan the backup files. The customer is a graphic designer, so this isn't just Joe Bloggs machine, it's the guy's livelihood that's at stake.


Reply With Quote
  #10  
Old 07-19-2012, 12:24 AM
sandra's Avatar
sandra sandra is offline
Forum Member
 
Join Date: Apr 2012
Location: Scotland
Posts: 616
Default

Quote:
Originally Posted by daisymae70 View Post
Graftor 36517 This is a strain I have never even heard of. Doesn't appear to be much out there on it that I could see. Always makes me wonder how someone picks these up on their computer. You have your work cut out for you Sandra.
From the malwarebytes report, it appears this trojan was downloaded within clipart, and there were hundreds of them...


Reply With Quote
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search



All times are GMT. The time now is 07:40 PM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2013, vBulletin Solutions, Inc.
CRMC
SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.