ScoobyNet.com - Subaru Enthusiast Forum

ScoobyNet.com - Subaru Enthusiast Forum (https://www.scoobynet.com/)
-   Computer & Technology Related (https://www.scoobynet.com/computer-and-technology-related-34/)
-   -   Help, I'm being attacked! (https://www.scoobynet.com/computer-and-technology-related-34/397768-help-im-being-attacked.html)

Jiggerypokery 25 January 2005 09:10 PM

Help, I'm being attacked!
 
Hello boffins,

For some reason, a file keeps getting copied / installed to this location on my Win2000 machine.

C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\683e8586.exe

It also finds its way into the registry under HKLM/blah blah/RUN_ONCE under the value name sys1612188 and command line
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\683e8586.exe


Microsoft's antispyware blocks this registry key, but it also appears in HKEY_CURRENT_USER and runs! It can be stopped using the task manager. I've looked in the file using a hex editor, it's only 8k but there's a print, SOCK, RasEnum and MSVCRT.dll all mentioned in there.

When it runs, there is initial network activity, and it seems to start up ntvdm.dll (and wowexec.dll).

NAV is up to date and shows everything is clean.

Any thoughts? The only thing I installed recently was a shareware/demo version of a winRAR unzipper. It has since been uninstalled.

Milamber 25 January 2005 09:24 PM


Originally Posted by Jiggerypokery
Hello boffins,

For some reason, a file keeps getting copied / installed to this location on my Win2000 machine.

C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\683e8586.exe

When it runs, there is initial network activity, and it seems to start up ntvdm.dll (and wowexec.dll).

Can't find anything on 683e8586.exe but there is this from the microsoft knwledgebase http://support.microsoft.com/kb/q196453/ doesnt seem to be on all fours with your problem though. Also it states that it applies to win2000 servers.

Have you tried to "roll back"?

Milamber 25 January 2005 09:32 PM

Actually it looks worse than I thought....

The mere mention of RasEnum and MSVCRT.dll scream out to me that you have a virus infection. The .dll is a visual basic entry and rasenum collects data from your address book. Hhhhmmmmm.

Opened any strange emails about Anna Kournikova recently?

I just don't get why your AV program doesn't pick up on it.

Jiggerypokery 25 January 2005 09:48 PM


Originally Posted by Milamber
Actually it looks worse than I thought....

The mere mention of RasEnum and MSVCRT.dll scream out to me that you have a virus infection. The .dll is a visual basic entry and rasenum collects data from your address book. Hhhhmmmmm.

Opened any strange emails about Anna Kournikova recently?

I just don't get why your AV program doesn't pick up on it.

I haven't opened any dodgy emails, but I'm now installing sygate's personal firewall in the hope that it may close any backdoors I may have.
I might try copying the file to another machine with WinXP and McAfee to see if it picks it up.
I'm also running ad-aware which shows nothing out of the ordinary.

JackClark 25 January 2005 10:05 PM

Go here www.webimmune.net and submit the file.

Jiggerypokery 25 January 2005 10:05 PM

McAfee doesn't detect it either :(
Hopefully it won't come back with the firewall installed.

Jiggerypokery 25 January 2005 10:29 PM


Originally Posted by JackClark
Go here www.webimmune.net and submit the file.

Done. :)
Will they get back to me, or is it a black hole?

JackClark 25 January 2005 11:35 PM

They'll get back to you.

Jiggerypokery 26 January 2005 09:18 PM

Hello Jack,

I received an update for McAfee in the form of a dat file, which detects this file, but, I can't use McAfee on my main machine as it interferes with another program which needs to access a remote network.

Sygate firewall tells me the file is trying to access www.google.com (216.239.59.104) using remote port 80.

Any thoughts on why it would want to do this? Thanks.

Nicks VR4 26 January 2005 09:52 PM


Originally Posted by Jiggerypokery
Hello Jack,

I received an update for McAfee in the form of a dat file, which detects this file, but, I can't use McAfee on my main machine as it interferes with another program which needs to access a remote network.

Sygate firewall tells me the file is trying to access www.google.com (216.239.59.104) using remote port 80.

Any thoughts on why it would want to do this? Thanks.

What does McAfee report is as ???

JackClark 26 January 2005 09:53 PM

Probably searching for new addresses to infect from your machine.

Jiggerypokery 26 January 2005 10:37 PM


Originally Posted by Nicks VR4
What does McAfee report is as ???

Proxy-Agent

Nicks VR4 26 January 2005 11:06 PM

Proxy-Agent is very old so cant see why ????????????

JackClark 26 January 2005 11:36 PM

Depends on the variant Nick, .e was last week.


All times are GMT +1. The time now is 06:44 AM.


© 2024 MH Sub I, LLC dba Internet Brands