Unrecoginized virus from pop up window

Y

yootzee

Greetings all,

I am trying to help a family member (sis-n-law) who has apparently received
a virus, which I have yet to identify, and am hoping someone has seen this.
Here are the details:

I have their winXP system running with an account using standard privileges
(I'll just call it "user"), and the virus hasn't affected the administered
account, only user.

She indicated to me that no email attachments had been opened recently, they
rarely get any attachments, and when they do, it is from trusted sources,
and they know that the attachments are coming prior, so for now, I'm ruling
email infection out.

The problem seems to have originated via a pop up add clicked on using IE
6.x. What she says happened is that she was browsing, came to an unknown
site (she can't remember the url) and a pop up window appeared indicating
that "you may have a virus" or something similar (these seem to be
prevalent), and she clicked somewhere on the window trying to close it.
Upon clicking on the window, the harddrive starts going crazy, and the
system locks up.

When I examine it, and log into the user account, the cpu is maxed out. I
look in the task manager, and the cpu is maxed out because roughly 200+
*.exe's are running. The files are garbage names, all starting with the
letter 'a' followed by a sequence of random letters i.e. aBuqRretzr.exe. If
one is killed via task manager, it appears that 5 or 10 more will be
generated.

After some searching, I located these EXE's in the system32 directory. All
are 54kb in size. I've googled some of the file names just for the heck of
it, and havn't found anything. I've thrown Trend Micro, Symantec, AdAware,
Spybot, and HiJackThis at this, and none have found anything. I've also
been checking the registry, primarily
HKLM/software/ms/windows/currentversion/run and runonce, and don't see
anything in there that shouldn't be.

Anyone have any ideas, cause I have run out of 'em.

Thanks in advance,
yootzee
 
N

null

Greetings all,

I am trying to help a family member (sis-n-law) who has apparently received
a virus, which I have yet to identify,

The Escan AV Toolkit Utility available through my web site is
exceptionally good at detecting malware. You should also run AdAware
and Spybot.


Art
http://www.epix.net/~artnpeg
 
Y

yootzee

Thanks for the reply Art, but as I mentioned, neither AdAwar nor Spybot
cought this. Neither did HiJack, Trend Micro, Symantec, or NOD.

I finally went into the user account under safe mode, and the exe's didn't
start up. So, I dug down into the reg key
HKCU/software/microsoft/windows/currentversion/run, and there I found about
50 values with the random names that I hand mentioned in my first post,
along with two exe's that I saw starting up and closing in the task manager
as well. The files were 76_150_noinst.exe and 77_150_noinst.exe. Anyone
recognize these by chance? I then went into the system32 directory, and
found about 250 exe's with the random name and deleted them.

After removing these values from the run key and the exe's from the system32
dir, I did a restart, and the problem seems to be solved. I've restarted a
few times ran IE, and kept an eye on the task list, and alls seems to be ok.
But, if anyone can identify these files, or what the heck this was, I would
greatly appreciate it.

Thanks,
yootzee
 
A

AkHibby

yootzee said:
Thanks for the reply Art, but as I mentioned, neither AdAwar nor Spybot
cought this. Neither did HiJack, Trend Micro, Symantec, or NOD.

I finally went into the user account under safe mode, and the exe's didn't
start up. So, I dug down into the reg key
HKCU/software/microsoft/windows/currentversion/run, and there I found
about
50 values with the random names that I hand mentioned in my first post,
along with two exe's that I saw starting up and closing in the task
manager
as well. The files were 76_150_noinst.exe and 77_150_noinst.exe. Anyone
recognize these by chance? I then went into the system32 directory, and
found about 250 exe's with the random name and deleted them.

After removing these values from the run key and the exe's from the
system32
dir, I did a restart, and the problem seems to be solved. I've restarted
a
few times ran IE, and kept an eye on the task list, and alls seems to be
ok.
But, if anyone can identify these files, or what the heck this was, I
would
greatly appreciate it.

Thanks,
yootzee
If you still have any of the EXE's you can submit them to your favourite AV
company; I'm not sure how up to date this list is, it's old - that I
know...

Zip them and password protect them first. Most recently I've been
submitting suspicious files to McAfee via http://www.webimmune.net.

Ian

Command Software <[email protected]>
Computer Associates (US) <[email protected]>
Computer Associates (Vet/EZ) <[email protected]>
DialogueScience (Dr. Web) <[email protected]>
Eset (NOD32) <[email protected]>
F-Secure Corp. <[email protected]>
Frisk Software (F-PROT) <[email protected]>
Grisoft (AVG) <[email protected]>
Kaspersky Labs <[email protected]>
Network Associates (McAfee) <[email protected]>
Norman (NVC) <[email protected]>
Sophos Plc. <[email protected]>
Symantec (Norton) <[email protected]>
Trend Micro (PC-cillin) <[email protected]>
 
Y

yootzee

Yep, I saved a copy of them before deleting them from the system, and also
exported the registry keys/values that I killed. I'll give it a shot and
see if they can come up with anything. Thanks for the reply.

yootzee
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top