PC Review


Reply
Thread Tools Rate Thread

possible virus???

 
 
Mr. F.
Guest
Posts: n/a
 
      10th Jan 2004
I think I got a virus but I can't find it. I downloaded one of those
newsgroup files about some hot chick nude. I didn't open the file because I
knew it was a virus. The file was a .pif file. All I did was right click
on the file to look at its properties and when I did that Explorer crasher
and now I don't have administrator privileges and scanning for the visus
finds nothing. I use AVG antivirus (up to date), tried nortons online scan
as well as another with no success. Could someone help me out. Thanks.
Scott


 
Reply With Quote
 
 
 
 
taff
Guest
Posts: n/a
 
      10th Jan 2004
On Sat, 10 Jan 2004 03:53:28 GMT, "Mr. F." <(E-Mail Removed)>
wrote:

>I think I got a virus but I can't find it. I downloaded one of those
>newsgroup files about some hot chick nude. I didn't open the file because I
>knew it was a virus. The file was a .pif file. All I did was right click
>on the file to look at its properties and when I did that Explorer crasher
>and now I don't have administrator privileges and scanning for the visus
>finds nothing. I use AVG antivirus (up to date), tried nortons online scan
>as well as another with no success. Could someone help me out. Thanks.
>Scott
>


Possibly a trojan. Try
Spybot http://www.safer-networking.org/index.php?page=mirrors
CWShredder http://www.merijn.org/files/cwshredder.zip

If that does not work, call back with as much information as possible.

Taff..........



www.sounds-pa.com | www.thecomputerworkshop.com
 
Reply With Quote
 
Ben Myers
Guest
Posts: n/a
 
      11th Jan 2004
Please repost with more information, including why you think you no
longer have "administrator" privileges.

Ben

"Mr. F." <(E-Mail Removed)> wrote in message news:YGKLb.110034$(E-Mail Removed)...
> I think I got a virus but I can't find it. I downloaded one of those
> newsgroup files about some hot chick nude. I didn't open the file because I
> knew it was a virus. The file was a .pif file. All I did was right click
> on the file to look at its properties and when I did that Explorer crasher
> and now I don't have administrator privileges and scanning for the visus
> finds nothing. I use AVG antivirus (up to date), tried nortons online scan
> as well as another with no success. Could someone help me out. Thanks.
> Scott
>
>

 
Reply With Quote
 
Ian Kenefick
Guest
Posts: n/a
 
      11th Feb 2004
Mr. F. wrote:
> I think I got a virus but I can't find it. I downloaded one of those
> newsgroup files about some hot chick nude. I didn't open the file because I
> knew it was a virus. The file was a .pif file. All I did was right click
> on the file to look at its properties and when I did that Explorer crasher
> and now I don't have administrator privileges and scanning for the visus
> finds nothing. I use AVG antivirus (up to date), tried nortons online scan
> as well as another with no success. Could someone help me out. Thanks.
> Scott
>
>


I believe it is the new Dumaru varient,

According to SARC,

W32.Dumaru.AH@mm has a polymorphic dropper, which drops and runs the
file C:\nload.exe when running. The dropped file nload.exe is 28,020
bytes in size and is compressed with FSG. This file contains the worm's
email routine. When nload.exe runs, it does the following,

1. Creates a file %Windir%\TEMP\photo.jpg, and launches explorer.exe
to load this file, which is a graphic. (the "hot chick" you speak of)

Regards, Ian Kenefick


 
Reply With Quote
 
MickKi
Guest
Posts: n/a
 
      11th Feb 2004
On Wed, 11 Feb 2004 19:33:05 +0000, Ian Kenefick
<virus-(E-Mail Removed)> wrote:

> Mr. F. wrote:
>> I think I got a virus but I can't find it. I downloaded one of those
>> newsgroup files about some hot chick nude. I didn't open the file
>> because I
>> knew it was a virus. The file was a .pif file. All I did was right
>> click
>> on the file to look at its properties and when I did that Explorer
>> crasher
>> and now I don't have administrator privileges and scanning for the visus
>> finds nothing. I use AVG antivirus (up to date), tried nortons online
>> scan
>> as well as another with no success. Could someone help me out. Thanks.
>> Scott
>>
>>

>
> I believe it is the new Dumaru varient,
>
> According to SARC,
>
> W32.Dumaru.AH@mm has a polymorphic dropper, which drops and runs the
> file C:\nload.exe when running. The dropped file nload.exe is 28,020
> bytes in size and is compressed with FSG. This file contains the worm's
> email routine. When nload.exe runs, it does the following,
>
> 1. Creates a file %Windir%\TEMP\photo.jpg, and launches explorer.exe
> to load this file, which is a graphic. (the "hot chick" you speak of)
>
> Regards, Ian Kenefick


Do a search in your Windows directory (& subdirectories) for:

dllreg.exe"
load32.exe"
Vxdmgr32.exe"

If you find them lurking in there, you're infected with W32.Dumaru@mm

If so, try downloading this the removal tool from here:

http://securityresponse.symantec.com...oval.tool.html

and do as the instructions recommend.

Regards,

Mick
--
Using M2, Opera's revolutionary e-mail client: http://www.opera.com/m2/
 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Re: Use this important VIRUS ALERT - VIRUS ALERT - W32.Swen.A@mm Worm - VIRUS ALERT - VIRUS ALERT - VIRUS ALERT - VIRUS ALERT nemo Microsoft VC .NET 0 3rd Nov 2003 09:34 PM
Re: See update - VIRUS ALERT - VIRUS ALERT - W32.Swen.A@mm Worm - VIRUS ALERT - VIRUS ALERT - VIRUS ALERT - VIRUS ALERT nemo Microsoft Dot NET Framework 0 12th Oct 2003 02:29 PM
Re: See update - VIRUS ALERT - VIRUS ALERT - W32.Swen.A@mm Worm - VIRUS ALERT - VIRUS ALERT - VIRUS ALERT - VIRUS ALERT nemo Microsoft Outlook Contacts 0 12th Oct 2003 02:29 PM
Re: See update - VIRUS ALERT - VIRUS ALERT - W32.Swen.A@mm Worm - VIRUS ALERT - VIRUS ALERT - VIRUS ALERT - VIRUS ALERT nemo Windows XP Print / Fax 0 12th Oct 2003 02:29 PM
New Virus detected as of yet unknown to Anti-Virus companied (Virus Name: MSBLAST.EXE) . Anti-Virus 6 12th Aug 2003 07:06 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 09:34 PM.