New User? Need help? Click here to register for free! Registering removes the advertisements.

Computer Cops
image image image image image image image image
Donations
If you found this site helpful, please donate to help keep it online.
image
Prime Choice
· Head Lines
· Advisories (All)
· Dnld of the Week!
· CCSP News Ltrs
· Find a Cure!

· Ian T's (AR 20)
· Marcia's (QA2)
· Bill G's (CO8)
· Paul's (AR 5)

· Ian T's Archive
· Marcia's Archive
· Bill G's Archive
· Paul's Archive
image
Security Central
· Home
· Wireless
· Bookmarks
· CLSID
· Columbia
· Community
· Downloads
· Encyclopedia
· Feedback (send)
· Forums
· Gallery
· Giveaways
· HijackThis
· Journal
· Members List
· My Downloads
· PremChat
· Premium
· Private Messages
· Proxomitron
· Quizz
· Recommend Us
· RegChat
· Reviews
· Search (Topics)
· Sections
· Software
· Statistics
· Stories Archive
· Submit News
· Surveys
· Top
· Topics
· Web Links
· Your Account
image
CCSP Toolkit
· Email Virus Scan
· UDP Port Scanner
· TCP Port Scanner
· Trojan TCP Scan
· Reveal Your IP
· Algorithms
· Whois
· nmap port scanner
· IPs Banned [?]
image
Survey
How much can you give to keep Computer Cops online?

$10 up to $25 per year?
$25 up to $50 per year?
$10 up to $25 per month?
$25 up to $50 per month?
More than $50 per year?
More than $50 per month?
One time only?
Other (please comment)



Results
Polls

Votes: 369
Comments: 9
image
Translate
English German French
Italian Portuguese Spanish
Chinese Greek Russian
image
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Login to check your private messagesLogin to check your private messages   LoginLogin 

a new virus? need your assistance

 
Post new topic   This topic is locked you cannot edit posts or make replies       Computer Cops Forum Index -> Virus - Prevention
View previous topic :: View next topic  
Author Message
oren100

Cadet
Cadet



Joined: Apr 04, 2004
Posts: 3
Location: USA

PostPosted: Sun Apr 04, 2004 7:30 pm    Post subject: a new virus? need your assistance
Reply with quote

Hello guys. Great forum!
Here is my problem: I think I have a virus that I cannot remove:
Every few hours, the Norton is Disabled and gone from the shortcut bar. When manually opening it, the email protection is disabled and the email scanning shows error.

I cannot surf to certain websites, such as Norton, MacAfee etc.
When running HijackThis.exe the program shuts itself down after few seconds.

When trying to solve the problem, I noticed few things:
New registry entries are created in "RUN" and RUN SERVICES" named " Video Device Loader" and two files, named "testfile" and "MSDTC32.EXE" appears on the D root. When deleting the services and the file the problem ends, but happens again after few hours.


Any suggestions?
Back to top
View users profile Send private message
Marianna

1st Responder
1st Responder
Premium Member
Premium Member


Joined: Nov 05, 2003
Posts: 1071
Location: Canada

PostPosted: Wed Apr 07, 2004 7:01 pm    Post subject:
Reply with quote

Hi,

Yep, I just found it:

A variant of the Gaobot worm appeared at Yale over the weekend. This worm strongly resembles the W32.Gaobot.UM strain, but there are differences in the filenames. It spreads through administrative shares with weak passwords, and can affect W2000 and Windows XP machines that are fully patched and have up-to-date NAV definitions.

Infections have included servers throughout the Academic and Administrative departments, in addition to the original outbreak at CLS.

Characteristics of the Worm

1. The worm copies and executes itself as %Systemroot%\msdtc32.exe.

2. It installs a value called "Video Device Loader" to the
following registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices


3. The worm ends any antivirus or firewall software. and attempts to kill processes associated with other worms. It will interfere with the Task Manager.

http://216.239.53.104/search?q=cache:TQ...n&ie=UTF-8

Scroll down - there you will see instructions to remove.
Back to top
View users profile Send private message
oren100

Cadet
Cadet



Joined: Apr 04, 2004
Posts: 3
Location: USA

PostPosted: Fri Apr 09, 2004 1:01 am    Post subject:
Reply with quote

Dear Marianna, Thanks a lot.
Back to top
View users profile Send private message
Marianna

1st Responder
1st Responder
Premium Member
Premium Member


Joined: Nov 05, 2003
Posts: 1071
Location: Canada

PostPosted: Fri Apr 09, 2004 11:31 am    Post subject:
Reply with quote

Hi oren100

You're Welcome Smile

Happy Safe Computing !
Back to top
View users profile Send private message
Acheton

Forums Admin
Forums Admin
Premium Member
Premium Member


Joined: Sep 04, 2003
Posts: 2555
Location: Uk

PostPosted: Fri Apr 23, 2004 1:10 pm    Post subject:
Reply with quote

I've locked this thread since the issue is resolved Smile Please pm a mod if you want it reopened for any reason.
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   This topic is locked you cannot edit posts or make replies       Computer Cops Forum Index -> Virus - Prevention All times are GMT - 5 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB 2.0.8a © 2001 phpBB Group

Version 2.0.6 of PHP-Nuke Port by Tom Nitzschner © 2002 www.toms-home.com
Version 2.2 by Paul Laudanski © 2003-2004 Computer Cops