Registry Virus!?

Author
soens
Max Output Level: -23.5 dBFS
  • Total Posts : 5154
  • Joined: 2005/09/16 03:19:55
  • Location: Location: Location
  • Status: offline
2012/05/10 04:47:17 (permalink)

Registry Virus!?

It appears my non-internet/non-AntiVirus computer has picked up a registry virus.
When I launch Sonar the registry window opens with the serial and registry entries blank.
When I search Windows registry for the Sonar entries there's nothing there, not even the Cakewalk Software section. It's like it's been completely deleted.
 
Last time this happened I did a System Restore To An Earlier Date which solved it.
 
This time there are absolutely no Restore Points available to do this.
 
Something has definitely attacked my system. I am currently running a full Norton scan on the drive. If nothing shows up I will be facing a complete format/install of everything.
 
This drive is a Paragon image of an earlier drive which I still have. Maybe somethings wrong with the image or else the original drive had a dormant virus... At any rate, Sonar is the only program so far affected this way.
#1

7 Replies Related Threads

    JonD
    Max Output Level: -39 dBFS
    • Total Posts : 3617
    • Joined: 2003/12/09 11:09:10
    • Location: East of Santa Monica
    • Status: offline
    Re:Registry Virus!? 2012/05/10 06:35:01 (permalink)
    soens


     
    Last time this happened I did a System Restore To An Earlier Date which solved it. 
     
    Despite your statement that the system is not on the internet, unless you can rule out the possibility of a virus 100%, this does seem to suggest a dormant virus -- one that's likely to be resident on your current Paragon image as well.
     
    And if it is a virus, my guess is it's a Rootkit or boot-sector type... which means that Norton (or most any other mainstream commercial antivirus app) will not be able to detect or clean it.  Nowadays, you need at least 3 or 4 different cleaner apps to have a decent chance against some of the more sophisticated viruses.
     
    For starters, Kaspersky has a free Rootkit cleaner you can download from their site.  Easy to install and run...
     
    If it were me, I'd restore from the image, and then before doing anything else:
     
    -- Wipe and recreate the master boot record, using either a dedicated utility, or FIXMBR command.
     
    -- Scan the C: partition with at least two good anti-malware apps, in addition to a dedicated rootkit scanner.
     
    Assuming it's a virus, the above should give you a fighting chance.  And even if it's not, these steps won't hurt anything (other than being time-consuming).
     
    Good luck.
     
     
     

    SonarPlat/CWbBL, Win 10 Pro, i7 2600K, Asus P8Z68 Deluxe, 16GB DDR3, Radeon HD5450, TC Electronic Impact Twin, Kawai MP11 Piano, Event ALP Monitors, Beyerdynamic DT770 Pro, Too Many Plugins, My lucky hat.
    #2
    Zo
    Max Output Level: -25 dBFS
    • Total Posts : 5036
    • Joined: 2008/01/25 20:49:55
    • Status: offline
    Re:Registry Virus!? 2012/05/10 07:08:22 (permalink)
    Hijack this + Combo fix

    For sale  (PM me) : transfert ilok included
    Eventide Ultrachannel make offers
    Softube Summit EQ
    IK Neve 1081 , Neve precision Comp/Lim
    EastWest Goshtwriter
    Soundforge Pro 12
     
    #3
    MarioD
    Max Output Level: -72 dBFS
    • Total Posts : 901
    • Joined: 2006/04/15 15:59:50
    • Status: offline
    Re:Registry Virus!? 2012/05/10 09:28:47 (permalink)
    I know that a couple of computer stores around here use the Security Tango [color=#810081 font="comic sans ms"]http://securitytango.com/#
    to eliminate problems like this. Go to "Let’s Dance" and follow the instructions to a T. I have used this many times on really badly infected computers and it worked every time. Note all of the programs used here are free ones.
    I hope this helps and good luck.
    #4
    soens
    Max Output Level: -23.5 dBFS
    • Total Posts : 5154
    • Joined: 2005/09/16 03:19:55
    • Location: Location: Location
    • Status: offline
    Re:Registry Virus!? 2012/05/10 21:50:03 (permalink)
    WOW! I honestly figured I'd get no response to this so thanks guys! Though it's not on the internet it has been connected a time or two and I transfer files from system to system, so anything's possible.
     
    As we all thought, Norton found nothing so it's likely pretty deep and dormant. I'll try some of your suggestions. Panda is another company that does pretty good here.
     
    I may just take it to a local shop since I don't have a lot of time to invest right now. Do you think it would be on the HDD or somehow in BIOS, memory, or some other location on the MB? This would matter so I knew to take the whole thing down or just the HDD.
     
     
    Steve
    #5
    Michael Five
    Max Output Level: -83 dBFS
    • Total Posts : 366
    • Joined: 2008/01/18 00:43:06
    • Status: offline
    Re:Registry Virus!? 2012/05/11 00:12:14 (permalink)
    definitely try kaspersky.  it is also possible that this is not a virus, rather application or sector-local corruption.  If it's  malware, you'll see more than just Sonar being jerked about....

    _______________________________________________
    X1c, p35 6600 Quad OC@3Ghz, FF400, Saffire 6, IBM T42, UAD-1, Superior 2.0
    #6
    chuckebaby
    Max Output Level: 0 dBFS
    • Total Posts : 13146
    • Joined: 2011/01/04 14:55:28
    • Status: offline
    Re:Registry Virus!? 2012/05/11 01:52:17 (permalink)
    most common way to get a virus is through a usb thunb drive or a network(if your a daw offliner.)
    could have been an update for a program?
    or something that caught on to your network.
    did you just install norton?
    because if not,im trying to figure out why you have norton installed on an offline daw?
    before anything i would try a reboot,sometimes a simple power down/up will restet alot of values in the regestry,so if you havent done that,
    do it now !!!

    Windows 8.1 X64 Sonar Platinum x64
    Custom built: Asrock z97 1150 - Intel I7 4790k - 16GB corsair DDR3 1600 - PNY SSD 220GB
    Focusrite Saffire 18I8 - Mackie Control
       
    #7
    soens
    Max Output Level: -23.5 dBFS
    • Total Posts : 5154
    • Joined: 2005/09/16 03:19:55
    • Location: Location: Location
    • Status: offline
    Re:Registry Virus!? 2012/05/11 02:00:46 (permalink)
    I removed the HDD and USBed it to the laptop and ran the scan. For this reason I may install antivirus on the desktop to keep it safe(r). I'm currently running a deep scan on it and will try your approach when it's done.
     
    This whole thing started after reinstalling the soundblaster & drivers.
     
    #8
    Jump to:
    © 2025 APG vNext Commercial Version 5.1