Author Topic: Viruses found  (Read 7138 times)

0 Members and 1 Guest are viewing this topic.

spg SCOTT

  • Guest
Viruses found
« on: January 03, 2009, 11:15:37 PM »
Currently doing a standard  scan with avast and it found these, all are safely within the chest, so no problems:


03/01/2009 19:49:48   xxxxxxxxx   3060   Sign of "Win32:VB-IE [Wrm]" has been found in "C:\Documents and Settings\xxxxxxxxx\Shared\PDF-File PDF Converter 1.zip\Setup.exe" file. 

03/01/2009 20:58:06   xxxxxxxxx   3060   Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Qoobox\Quarantine\[4]-Submit_2008-10-13@17.56.zip\hojyr.exe" file. 

03/01/2009 21:00:37   xxxxxxxxx   3060   Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Qoobox\Quarantine\[4]-Submit_2008-10-13@17.56.zip\luconnuj.exe" file. 


The xxxxxxxx refers to the user name, it is not mine but the previous owner of the computer, (I don't think that they want their name on the internet, go figure) which is odd because I have changed that previously but all of the documents and settings still bear the original name, but the user name at the welcome screen is mine.

The last two, from what i can gather on the internet are from the quarantine folder of ComboFix, I used this to eradicate these files previously when infected, this has, for some time been gone from my system

The first one though, is confusing, because I have never even looked in that folder, or been in there until now and I don't know what it is from.

I will submit the files to Alwil, but I think that they have already had the last two, and I'm pretty sure a I'm clean now

The odd thing with this scan is that the scanner has reached 39% and has been there for some time now but is still scanning and has scanned nearly 450 000 files, is this right?


One last thing, I don't know whether this is relevant, but my computer always turns back on when I shut down or even Hibernate, which is a pain, but hey gotta live with it...



Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Viruses found
« Reply #1 on: January 03, 2009, 11:23:52 PM »
The odd thing with this scan is that the scanner has reached 39% and has been there for some time now but is still scanning and has scanned nearly 450 000 files, is this right?
If the scanning is not frozen, it's right...

One last thing, I don't know whether this is relevant, but my computer always turns back on when I shut down or even Hibernate, which is a pain, but hey gotta live with it...
Do you mean the computer restart instead of shutting down or hibernate? ???
The best things in life are free.

spg SCOTT

  • Guest
Re: Viruses found
« Reply #2 on: January 03, 2009, 11:31:17 PM »
Do you mean the computer restart instead of shutting down or hibernate? ???

When I tell it to shut down it restarts... and even if I hold the power button it still does it, and I have to do it again, so yes

It's a fairly old computer that is just about surviving, could be something to do with the electrics failing after so long, I mean I had to disconnect two usb ports earlier because I discovered a broken one was shorting out something and the computer was turning off

what do you think about the user name issue though?

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Viruses found
« Reply #3 on: January 03, 2009, 11:57:47 PM »
The name inicates it is a worm. Worms replicate and spread usually via Network protcocols, email, Peer-2-Peer (P2P) software and a few other methods.

I suggest using the following tool to scan your computer.


Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to allow it to download the needed AV vendor related files.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the PC.

You can choose to go to each menu item and just download the needed files or you can
download the files and perform a scan in Normal Mode. Once you have downloaded the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
during boot] and re-run the menu again and choose which scanner you want to run in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
file. http://www.ik-cs.com/multi-av.htm

Additional Instructions:
http://pcdid.com/Multi_AV.htm

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

spg SCOTT

  • Guest
Re: Viruses found
« Reply #4 on: January 04, 2009, 12:15:39 AM »
Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

It's probably me but I cannot find the file you suggest to download,

Additional Instructions:
http://pcdid.com/Multi_AV.htm

This link doesn't work, I get a "DNS error - cannot find server."



Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Viruses found
« Reply #5 on: January 04, 2009, 12:42:54 AM »
I checked the first link: Checking: http://www.ik-cs.com/programs/virtools/Multi_AV.exe
Engine version: 4.44.0.9170
File size: 452 bytes

http://www.ik-cs.com/programs/virtools/Multi_AV.exe - Ok

Checking: http://www.kolmic.com/?dn=ik-cs.com&pid=2PON5G6BT
File size: 27.48 KB

http://www.kolmic.com/?dn=ik-cs.com&pid=2PON5G6BT - archive HTML
>http://www.kolmic.com/?dn=ik-cs.com&pid=2PON5G6BT/Script.0 - Ok
>http://www.kolmic.com/?dn=ik-cs.com&pid=2PON5G6BT/Script.1 - Ok
http://www.kolmic.com/?dn=ik-cs.com&pid=2PON5G6BT - Script - OK

I can give you another download link and explanation:
Download MULTI_AV.EXE from the URL --
http://www.pctipp.ch/index.cfm?pid=1411&pk=28470

It is a self-extracting ZIP file that contains the Kixtart Script Interpreter
{ http://kixtart.org - Kixtart is CareWare } 4 batch files, 6 Kixtart scripts, one Link
(.LNK) file, a PDF instruction file and two utilities; UNZIP.EXE and WGET.EXE. It will
simplify the process of using; Sophos, Trend, Kaspersky and McAfee Anti Virus Command
Line Scanners to remove viruses, Trojans and various other malware.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal Mode.
This way all the components can be downloaded from each AV vendor’s web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the PC.

You can choose to go to each menu item and just download the needed files or you can
download the files and perform a scan in Normal Mode. Once you have downloaded the
files needed for each scanner you want to use, you should reboot the PC into Safe Mode
[F8 key during boot] and re-run the menu again and choose which scanner you want to
run in Safe Mode. It is suggested to run the scanners in both Safe Mode and Normal
Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF
help file.

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through
your FireWall to allow it to download the needed AV vendor related files.

End of Procedure, link scanned:
Checking: http://www.pctipp.ch/index.cfm?pid=1411&pk=28470
Engine version: 4.44.0.9170
File size: 32.11 KB

http://www.pctipp.ch/index.cfm?pid=1411&pk=28470 - archive HTML
>http://www.pctipp.ch/index.cfm?pid=1411&pk=28470/JavaScript.0 - Ok
>http://www.pctipp.ch/index.cfm?pid=1411&pk=28470/JavaScript.1 - Ok
>http://www.pctipp.ch/index.cfm?pid=1411&pk=28470/Script.2 - Ok
>http://www.pctipp.ch/index.cfm?pid=1411&pk=28470/Script.3 - Ok
>http://www.pctipp.ch/index.cfm?pid=1411&pk=28470/Script.4 - Ok
http://www.pctipp.ch/index.cfm?pid=1411&pk=28470 - Ok

Checking: http://www.pctipp.ch/index.cfm//js/sky_scroll.js?pid=1411&pk=28470
File size: 32.11 KB

http://www.pctipp.ch/index.cfm//js/sky_scroll.js?pid=1411&pk=28470 - archive HTML
>http://www.pctipp.ch/index.cfm//js/sky_scroll.js?pid=1411&pk=28470/JavaScript.0 - Ok
>http://www.pctipp.ch/index.cfm//js/sky_scroll.js?pid=1411&pk=28470/JavaScript.1 - Ok
>http://www.pctipp.ch/index.cfm//js/sky_scroll.js?pid=1411&pk=28470/Script.2 - Ok
>http://www.pctipp.ch/index.cfm//js/sky_scroll.js?pid=1411&pk=28470/Script.3 - Ok
>http://www.pctipp.ch/index.cfm//js/sky_scroll.js?pid=1411&pk=28470/Script.4 - Ok
http://www.pctipp.ch/index.cfm//js/sky_scroll.js?pid=1411&pk=28470 - Ok

Checking: http://www.pctipp.ch/index.cfm//js/domtab.js?pid=1411&pk=28470
File size: 32.11 KB

http://www.pctipp.ch/index.cfm//js/domtab.js?pid=1411&pk=28470 - archive HTML
>http://www.pctipp.ch/index.cfm//js/domtab.js?pid=1411&pk=28470/JavaScript.0 - Ok
>http://www.pctipp.ch/index.cfm//js/domtab.js?pid=1411&pk=28470/JavaScript.1 - Ok
>http://www.pctipp.ch/index.cfm//js/domtab.js?pid=1411&pk=28470/Script.2 - Ok
>http://www.pctipp.ch/index.cfm//js/domtab.js?pid=1411&pk=28470/Script.3 - Ok
>http://www.pctipp.ch/index.cfm//js/domtab.js?pid=1411&pk=28470/Script.4 - Ok
http://www.pctipp.ch/index.cfm//js/domtab.js?pid=1411&pk=28470 - Ok

Checking: http://www.pctipp.ch/index.cfm//js/default.js?pid=1411&pk=28470
File size: 32.11 KB

http://www.pctipp.ch/index.cfm//js/default.js?pid=1411&pk=28470 - archive HTML
>http://www.pctipp.ch/index.cfm//js/default.js?pid=1411&pk=28470/JavaScript.0 - Ok
>http://www.pctipp.ch/index.cfm//js/default.js?pid=1411&pk=28470/JavaScript.1 - Ok
>http://www.pctipp.ch/index.cfm//js/default.js?pid=1411&pk=28470/Script.2 - Ok
>http://www.pctipp.ch/index.cfm//js/default.js?pid=1411&pk=28470/Script.3 - Ok
>http://www.pctipp.ch/index.cfm//js/default.js?pid=1411&pk=28470/Script.4 - Ok
http://www.pctipp.ch/index.cfm//js/default.js?pid=1411&pk=28470 - Ok

Checking: http://www.pctipp.ch/index.cfm//js/whoson_pctipp.ch_trackingonly.js?pid=1411&pk=28470
File size: 32.11 KB

http://www.pctipp.ch/index.cfm//js/whoson_pctipp.ch_trackingonly.js?pid=1411&pk=28470 - archive HTML
>http://www.pctipp.ch/index.cfm//js/whoson_pctipp.ch_trackingonly.js?pid=1411&pk=28470/JavaScript.0 - Ok
>http://www.pctipp.ch/index.cfm//js/whoson_pctipp.ch_trackingonly.js?pid=1411&pk=28470/JavaScript.1 - Ok
>http://www.pctipp.ch/index.cfm//js/whoson_pctipp.ch_trackingonly.js?pid=1411&pk=28470/Script.2 - Ok
>http://www.pctipp.ch/index.cfm//js/whoson_pctipp.ch_trackingonly.js?pid=1411&pk=28470/Script.3 - Ok
>http://www.pctipp.ch/index.cfm//js/whoson_pctipp.ch_trackingonly.js?pid=1411&pk=28470/Script.4 - Ok
http://www.pctipp.ch/index.cfm//js/whoson_pctipp.ch_trackingonly.js?pid=1411&pk=28470 - Ok

Checking: http://www.pctipp.ch/index.cfm//js/search.js?pid=1411&pk=28470
File size: 32.11 KB

http://www.pctipp.ch/index.cfm//js/search.js?pid=1411&pk=28470 - archive HTML
>http://www.pctipp.ch/index.cfm//js/search.js?pid=1411&pk=28470/JavaScript.0 - Ok
>http://www.pctipp.ch/index.cfm//js/search.js?pid=1411&pk=28470/JavaScript.1 - Ok
>http://www.pctipp.ch/index.cfm//js/search.js?pid=1411&pk=28470/Script.2 - Ok
>http://www.pctipp.ch/index.cfm//js/search.js?pid=1411&pk=28470/Script.3 - Ok
>http://www.pctipp.ch/index.cfm//js/search.js?pid=1411&pk=28470/Script.4 - Ok
http://www.pctipp.ch/index.cfm//js/search.js?pid=1411&pk=28470 - Ok

polonus


Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89033
  • No support PMs thanks
Re: Viruses found
« Reply #6 on: January 04, 2009, 12:45:20 AM »
1. I think the setup.exe might be an FP, so you should check it, see below.

2. This is the ComboFix's Quarantine area, C:\Qoobox\Quarantine\
However, it does surprise me that the quarantine area isn't protected encrypted, etc. so other scanners don't detect what effectively has been dealt with. So I would suggest you clear the quarantine area as basically a) they are old and b) avast is also confirming the original combofix detection.

So the only file that should be sent to avast is setup.exe if it is confirmed an FP.
You could also check the offending/suspect file at: VirusTotal - Multi engine on-line virus scanner and report the findings here the URL in the Address bar of the VT results page. You can't do this with the file securely in the chest, you need to extract it to a temporary (not original) location first, see below.

Create a folder called Suspect in the C:\ drive, e.g. C:\Suspect. Now exclude that folder in the Standard Shield, Customize, Advanced, Add, type (or copy and paste) C:\Suspect\* That will stop the standard shield scanning any file you put in that folder. You should now be able to export any file in the chest to this folder and upload it to VirusTotal without avast alerting.

If it is indeed a false positive, see http://forum.avast.com/index.php?topic=34950.msg293451#msg293451, how to report it to avast! and what to do to exclude them until the problem is corrected.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

spg SCOTT

  • Guest
Re: Viruses found
« Reply #7 on: January 04, 2009, 01:04:43 AM »
DavidR, thanks for confirming

1. I think the setup.exe might be an FP, so you should check it, see below.

2. This is the ComboFix's Quarantine area, C:\Qoobox\Quarantine\
However, it does surprise me that the quarantine area isn't protected encrypted, etc. so other scanners don't detect what effectively has been dealt with. So I would suggest you clear the quarantine area as basically a) they are old and b) avast is also confirming the original combofix detection.


1. Avast still is scanning but once it is done I will check it at VT
2. That's one of the reasons why I posted, I thought that it would have been encrypted but, as they are in the chest, does that mean that they are not in the quarantine folder anymore?

Polonus, Thanks for the reply.
The second link you gave me worked and I have It downloaded and when avast is finished, or maybe tomorrow, I will have a look at it

spg SCOTT

  • Guest
Re: Viruses found
« Reply #8 on: January 04, 2009, 12:13:32 PM »
I have uploaded the file to VT

http://www.virustotal.com/analisis/e9eb1d17f565d51a886972658928a560

12 of 38


AntiVir   7.9.0.45   2009.01.04   Worm/Rbot.174080

Authentium   5.1.0.4   2009.01.03   W32/CodeCru-based!Maximus

Avast   4.8.1281.0   2009.01.03   Win32:VB-IE

eTrust-Vet   31.6.6289   2009.01.02   Win32/Alcan.I!ZIP

F-Prot   4.4.4.56   2009.01.03   W32/CodeCru-based!Maximus

Fortinet   3.117.0.0   2009.01.04   W32/VB.DW!p2p

GData   19   2009.01.04   Win32:VB-IE

Norman   5.80.02   2009.01.02   W32/Solo.A

PCTools   4.4.2.0   2009.01.03   Backdoor.IRCBot.DD

SecureWeb-Gateway   6.7.6   2009.01.04   Worm.Rbot.174080

Sophos   4.37.0   2009.01.04   Mal/HckPk-A

VirusBuster   4.5.11.0   2009.01.03   Worm.P2P.VB.CIY


I don't think it is an FP

EDIT:
Polonus,
Have tried the program you suggested but can't download the files from it
I get the error:  bad file descriptor, on all of the options

« Last Edit: January 04, 2009, 01:29:21 PM by spg SCOTT »

GrizeBar

  • Guest
Re: Viruses found
« Reply #9 on: January 04, 2009, 03:09:41 PM »
Run Combofix, then upload the Log file text to this thread for analysis and recommendation.

Download: http://www.combofix.org/download.php

Tutorial: http://www.bleepingcomputer.com/combofix/how-to-use-combofix


Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89033
  • No support PMs thanks
Re: Viruses found
« Reply #10 on: January 04, 2009, 04:55:09 PM »
I have uploaded the file to VT

http://www.virustotal.com/analisis/e9eb1d17f565d51a886972658928a560

12 of 38
<snip>
I don't think it is an FP

Nor do I it appears to be a good detection, on occasion setup files get pinged because of what they do, that is however more commonly by the generic signatures like win32:trojan-gen, which wasn't the case here. So it looks like there were some unwelcome gifts in this PDF Converter.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security