Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Help, I'm being attacked!

Thread Tools
 
Search this Thread
 
Old 25 January 2005, 09:10 PM
  #1  
Jiggerypokery
Scooby Regular
Thread Starter
 
Jiggerypokery's Avatar
 
Join Date: Apr 2003
Location: Location: Location:
Posts: 1,097
Likes: 0
Received 0 Likes on 0 Posts
Red face Help, I'm being attacked!

Hello boffins,

For some reason, a file keeps getting copied / installed to this location on my Win2000 machine.

C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\683e8586.exe

It also finds its way into the registry under HKLM/blah blah/RUN_ONCE under the value name sys1612188 and command line
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\683e8586.exe


Microsoft's antispyware blocks this registry key, but it also appears in HKEY_CURRENT_USER and runs! It can be stopped using the task manager. I've looked in the file using a hex editor, it's only 8k but there's a print, SOCK, RasEnum and MSVCRT.dll all mentioned in there.

When it runs, there is initial network activity, and it seems to start up ntvdm.dll (and wowexec.dll).

NAV is up to date and shows everything is clean.

Any thoughts? The only thing I installed recently was a shareware/demo version of a winRAR unzipper. It has since been uninstalled.
Old 25 January 2005, 09:24 PM
  #2  
Milamber
Scooby Senior
iTrader: (2)
 
Milamber's Avatar
 
Join Date: Jan 2004
Location: England
Posts: 18,358
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by Jiggerypokery
Hello boffins,

For some reason, a file keeps getting copied / installed to this location on my Win2000 machine.

C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\683e8586.exe

When it runs, there is initial network activity, and it seems to start up ntvdm.dll (and wowexec.dll).
Can't find anything on 683e8586.exe but there is this from the microsoft knwledgebase http://support.microsoft.com/kb/q196453/ doesnt seem to be on all fours with your problem though. Also it states that it applies to win2000 servers.

Have you tried to "roll back"?
Old 25 January 2005, 09:32 PM
  #3  
Milamber
Scooby Senior
iTrader: (2)
 
Milamber's Avatar
 
Join Date: Jan 2004
Location: England
Posts: 18,358
Likes: 0
Received 0 Likes on 0 Posts
Default

Actually it looks worse than I thought....

The mere mention of RasEnum and MSVCRT.dll scream out to me that you have a virus infection. The .dll is a visual basic entry and rasenum collects data from your address book. Hhhhmmmmm.

Opened any strange emails about Anna Kournikova recently?

I just don't get why your AV program doesn't pick up on it.
Old 25 January 2005, 09:48 PM
  #4  
Jiggerypokery
Scooby Regular
Thread Starter
 
Jiggerypokery's Avatar
 
Join Date: Apr 2003
Location: Location: Location:
Posts: 1,097
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by Milamber
Actually it looks worse than I thought....

The mere mention of RasEnum and MSVCRT.dll scream out to me that you have a virus infection. The .dll is a visual basic entry and rasenum collects data from your address book. Hhhhmmmmm.

Opened any strange emails about Anna Kournikova recently?

I just don't get why your AV program doesn't pick up on it.
I haven't opened any dodgy emails, but I'm now installing sygate's personal firewall in the hope that it may close any backdoors I may have.
I might try copying the file to another machine with WinXP and McAfee to see if it picks it up.
I'm also running ad-aware which shows nothing out of the ordinary.
Old 25 January 2005, 10:05 PM
  #5  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Default

Go here www.webimmune.net and submit the file.
Old 25 January 2005, 10:05 PM
  #6  
Jiggerypokery
Scooby Regular
Thread Starter
 
Jiggerypokery's Avatar
 
Join Date: Apr 2003
Location: Location: Location:
Posts: 1,097
Likes: 0
Received 0 Likes on 0 Posts
Default

McAfee doesn't detect it either
Hopefully it won't come back with the firewall installed.
Old 25 January 2005, 10:29 PM
  #7  
Jiggerypokery
Scooby Regular
Thread Starter
 
Jiggerypokery's Avatar
 
Join Date: Apr 2003
Location: Location: Location:
Posts: 1,097
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by JackClark
Go here www.webimmune.net and submit the file.
Done.
Will they get back to me, or is it a black hole?
Old 25 January 2005, 11:35 PM
  #8  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Default

They'll get back to you.
Old 26 January 2005, 09:18 PM
  #9  
Jiggerypokery
Scooby Regular
Thread Starter
 
Jiggerypokery's Avatar
 
Join Date: Apr 2003
Location: Location: Location:
Posts: 1,097
Likes: 0
Received 0 Likes on 0 Posts
Default

Hello Jack,

I received an update for McAfee in the form of a dat file, which detects this file, but, I can't use McAfee on my main machine as it interferes with another program which needs to access a remote network.

Sygate firewall tells me the file is trying to access www.google.com (216.239.59.104) using remote port 80.

Any thoughts on why it would want to do this? Thanks.
Old 26 January 2005, 09:52 PM
  #10  
Nicks VR4
Scooby Regular
 
Nicks VR4's Avatar
 
Join Date: May 2003
Posts: 1,165
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by Jiggerypokery
Hello Jack,

I received an update for McAfee in the form of a dat file, which detects this file, but, I can't use McAfee on my main machine as it interferes with another program which needs to access a remote network.

Sygate firewall tells me the file is trying to access www.google.com (216.239.59.104) using remote port 80.

Any thoughts on why it would want to do this? Thanks.
What does McAfee report is as ???
Old 26 January 2005, 09:53 PM
  #11  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Default

Probably searching for new addresses to infect from your machine.
Old 26 January 2005, 10:37 PM
  #12  
Jiggerypokery
Scooby Regular
Thread Starter
 
Jiggerypokery's Avatar
 
Join Date: Apr 2003
Location: Location: Location:
Posts: 1,097
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by Nicks VR4
What does McAfee report is as ???
Proxy-Agent
Old 26 January 2005, 11:06 PM
  #13  
Nicks VR4
Scooby Regular
 
Nicks VR4's Avatar
 
Join Date: May 2003
Posts: 1,165
Likes: 0
Received 0 Likes on 0 Posts
Default

Proxy-Agent is very old so cant see why ????????????
Old 26 January 2005, 11:36 PM
  #14  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Default

Depends on the variant Nick, .e was last week.
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
LSherratt
Non Scooby Related
104
27 September 2015 03:25 PM
yabbadoo4
General Technical
10
24 September 2015 11:10 PM
jayallen
Was it you?
4
19 September 2015 07:42 PM



Quick Reply: Help, I'm being attacked!



All times are GMT +1. The time now is 12:21 PM.