Virus on my computer?

dfi

Golden Member
Apr 20, 2001
1,213
0
0
I just scanned my computer with a squared, antivir, spybot, adaware, and a rootkit detector. Nothing came up. But then I noticed that run -> "regedit" did nothing, but "regedit.exe" works. Then, even worse, I noticed I couldn't see system32, even though hidden files were displayed.

A quick searched on the net, and it seemed like I had worm alcan a/b and its variants. Apparently it hides system32 and various .com files, such as regedit.com, etc. So I removed attributes on system32 and the files it was suppose to create, and found the following:

regedit.com
cmd.com
tasklist.com
ping.com
tracert.com

As well as 2 registry entries for regedit.com and cmd.com. All these files were created on the same date, same time. A search for all files created on this date yielded only these files.

However, these files are only 2kb. Also, I don't have any of the other symptoms or files of the worm described. Now I don't know what to think. Supposedly this worm is associated with p2p programs, such as limewire. I do have limewire installed but I rarely use it. I do't know if these files came in with it somehow, but I don't have any of the other symptoms described. Also, my computer and router are blocking all ping requests and only necessary ports are open. I use a separate, limited privilege account for every day use as well. Somehow this thing still got through. And none of my antivirus or spyware tools found it. What the heck is going on? Is this a virus, worm, or something else?
 

Creig

Diamond Member
Oct 9, 1999
5,171
13
81
Maybe the following will help. You might want to read through the entire thread I've linked to at the bottom of this post before doing anything to make sure it applies to your situation. But it appears to be related.


The reason you can't open regedit by typing "regedit.exe" and not regedit alone, is because some worms create a new file called "regedit.com" in your system (this will execute first than the .exe). Follow this instructions to remove all this files.

- Click here to download Killbox by Option^Explicit.
- Extract the program to your desktop and double-click on its folder, then double-click on Killbox.exe to start the program.
- In the killbox program, select the Delete on Reboot option.
- Copy the file names below to the clipboard by highlighting them and pressing Control-C:
Code:
C:\Program Files\MsConfigs\MsConfigs.exe
C:\WINDOWS\system32\p2pnetwork.exe
C:\WINDOWS\system32\CMD.COM
C:\WINDOWS\system32\netstat.com
C:\WINDOWS\system32\ping.com
C:\WINDOWS\system32\regedit.com
C:\WINDOWS\system32\tasklist.com
C:\WINDOWS\system32\taskkill.com
C:\WINDOWS\system32\taskmgr.com
C:\WINDOWS\system32\tracert.com
- Return to Killbox, go to the File menu, and choose "Paste from Clipboard".
- Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.

After the reboot regedit should work again.


http://www.ozzu.com/ftopic44857.html
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
I use a separate, limited privilege account for every day use as well. Somehow this thing still got through.

...

I do have limewire installed
There's one possible "somehow." Limited accounts don't stop you from elevating to Admin and installing stuff that might be packing a malicious payload.

If it were me, I'd burn the whole hard drive to the ground with DBAN, then reinstall Windows, set it up securely, and not break the "chain of trust" anywhere. No re-using any executables, drivers, programs, utiliities that the old Windows installation ever touched.

If that sounds too drastic, download a 30-day trial version of Kaspersky Antivirus Personal 6 and install it. Go into its Settings panel and max out all the settings, including Riskware, and max out all the sliders to HIGH in the Protection and Scan panels. Now run an update, reboot into Safe Mode, and launch Kaspersky from the Start > All Programs menu and run a full Scan My Computer while you're in Safe Mode.
 

beggerking

Golden Member
Jan 15, 2006
1,703
0
0
Originally posted by: Creig
Maybe the following will help. You might want to read through the entire thread I've linked to at the bottom of this post before doing anything to make sure it applies to your situation. But it appears to be related.


The reason you can't open regedit by typing "regedit.exe" and not regedit alone, is because some worms create a new file called "regedit.com" in your system (this will execute first than the .exe). Follow this instructions to remove all this files.

- Click here to download Killbox by Option^Explicit.
- Extract the program to your desktop and double-click on its folder, then double-click on Killbox.exe to start the program.
- In the killbox program, select the Delete on Reboot option.
- Copy the file names below to the clipboard by highlighting them and pressing Control-C:
Code:
C:\Program Files\MsConfigs\MsConfigs.exe
C:\WINDOWS\system32\p2pnetwork.exe
C:\WINDOWS\system32\CMD.COM
C:\WINDOWS\system32\netstat.com
C:\WINDOWS\system32\ping.com
C:\WINDOWS\system32\regedit.com
C:\WINDOWS\system32\tasklist.com
C:\WINDOWS\system32\taskkill.com
C:\WINDOWS\system32\taskmgr.com
C:\WINDOWS\system32\tracert.com
- Return to Killbox, go to the File menu, and choose "Paste from Clipboard".
- Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.

After the reboot regedit should work again.


http://www.ozzu.com/ftopic44857.html

:thumbsup:
 

dfi

Golden Member
Apr 20, 2001
1,213
0
0
Originally posted by: Creig
Maybe the following will help. You might want to read through the entire thread I've linked to at the bottom of this post before doing anything to make sure it applies to your situation. But it appears to be related.


The reason you can't open regedit by typing "regedit.exe" and not regedit alone, is because some worms create a new file called "regedit.com" in your system (this will execute first than the .exe). Follow this instructions to remove all this files.

- Click here to download Killbox by Option^Explicit.
- Extract the program to your desktop and double-click on its folder, then double-click on Killbox.exe to start the program.
- In the killbox program, select the Delete on Reboot option.
- Copy the file names below to the clipboard by highlighting them and pressing Control-C:
Code:
C:\Program Files\MsConfigs\MsConfigs.exe
C:\WINDOWS\system32\p2pnetwork.exe
C:\WINDOWS\system32\CMD.COM
C:\WINDOWS\system32\netstat.com
C:\WINDOWS\system32\ping.com
C:\WINDOWS\system32\regedit.com
C:\WINDOWS\system32\tasklist.com
C:\WINDOWS\system32\taskkill.com
C:\WINDOWS\system32\taskmgr.com
C:\WINDOWS\system32\tracert.com
- Return to Killbox, go to the File menu, and choose "Paste from Clipboard".
- Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.

After the reboot regedit should work again.


http://www.ozzu.com/ftopic44857.html

I guess I wasn't specific enough. I've already done a search, as well as attrib -a -r -s -h, on the list of files you have identified above. Of all the ones you have identified, the five that existed were cmd.com, regedit.com, tasklist.com, tracert.com, and ping.com. So I've already been able to isolate those files, as well as remove the two registry settings. So my regedit, cmd, etc, all work again without needing the .exe extension.

The thing that I'm concerned about is that there's something I haven't caught. I'm not sure if there's anything else that is still around. I'm not even sure how those files got into the system folder. Only thing I can think of is that I may have ran limewire once or twice as admin.

I don't know if I will completely reformat over this. Kasperasky, at highest scan level, found nothing. Nod32 is scanning right now and has found nothing so far. I don't know what I'm going to do if four virus scanners, two spyware detector, and a rootkit detector comes up with nothing.
 

beggerking

Golden Member
Jan 15, 2006
1,703
0
0
the worm may have created these files, and your antivirus software may have "cured" them.. you should be fine..
 

dfi

Golden Member
Apr 20, 2001
1,213
0
0
Well, long story short, I decided to reformat. Burn it all down and start from scratch. It was probably nothing but I'm paranoid.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |