Avast WEBforum

Other => Viruses and worms => Topic started by: SPACEY on April 08, 2009, 12:57:43 AM

Title: WORM? WHAT'S HAPPENED & WHAT NEXT?
Post by: SPACEY on April 08, 2009, 12:57:43 AM
Any advice would be much appreciated...
Downloading some programmes from limewire  p2p & avast picked up the following baddies;

06/04/2009 10:05:23   Owner   1676   Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\Owner\Desktop\MUSIC\ONLINE\sketchup pro + serial by ROR.zip\keymaker_by_CORE\CORE10k.EXE" file. 

06/04/2009 09:54:02   Owner   1676   Sign of "Win32:VB-FXE [trj]" has been found in "C:\Documents and Settings\Owner\Desktop\MUSIC\ONLINE\Google SketchUp Pro v6.0.1099.zip\Setup.exe" file. 

06/04/2009 09:53:55   Owner   1676   Sign of "Win32:Agent-AAKK [trj]" has been found in "C:\Documents and Settings\Owner\Desktop\MUSIC\ONLINE\Google SketchUp Pro v6.0.1099.zip\Crack.exe" file. 

06/04/2009 09:53:05   Owner   1676   Sign of "Win32:Wegit-C [Adw]" has been found in "C:\Documents and Settings\Owner\Desktop\MUSIC\ONLINE\sketchup



I ran ad-aware & c-cleaner programmes, deleted all cookies etc
Searched all computer activity at the time of infection, deleted all temporary files as I went.

Tried to open a couple of programmes - autocad & google sketchup and got error messages; 'can't open,files missing, moved....' , but autocad did open at the second attempt. Sketchup is now disabled. Downloaded a new copy but still can't open it. Firefox is hijacked intermittently too with MS iexplorer pop-ups to various ad sites. Ad-aware has also been disabled. Downloaded & installed current ad-aware but it wont open, not responding to double click or open.

It's all way more aggressive than any previous trouble.

So, what's happening people?  Any ideas

Title: Re: WORM? WHAT'S HAPPENED & WHAT NEXT?
Post by: Confused Computer User on April 08, 2009, 01:10:58 AM
just a though but this is odd

Downloading some programmes from limewire  p2p & avast picked up the following baddies;

06/04/2009 10:05:23   Owner   1676   Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\Owner\Desktop\MUSIC\ONLINE\sketchup pro + serial by ROR.zip\keymaker_by_CORE\CORE10k.EXE" file. 
 

sketchup pro + serial by ROR.zip\keymaker_by_CORE\CORE10k.EXE" file

This would be IMHO a crak or serial generator. The thing is that most this things are sometimes infected. In your case, by the sound of it the infection has spread far and wide. Did you try to do a boot time Scan?
Title: Re: WORM? WHAT'S HAPPENED & WHAT NEXT?
Post by: DavidR on April 08, 2009, 02:29:44 AM
So your surprised when downloading a program with a crack, etc. that avast would find an unwelcome trojan.

Cracks and key-gens, etc. apart from any legal or moral issue are high risk and frequently come with Trojans, I mean who are you going to complain to.

Based on the other problems you are experiencing you may have other hidden or undetected malware.

If you haven't already got this software (freeware), download, install, update and run it, preferably in safe mode and report the findings (it should product a log file).

AdAware really is a waste of space and hasn't kept pace with the development of spyware, etc.

I can't recall who said it (I don't use P2P at all), but by all accounts the Limewire network is infected with malware.
Title: Re: WORM? WHAT'S HAPPENED & WHAT NEXT?
Post by: Lisandro on April 08, 2009, 02:37:42 AM
I suggest:

1. Clean your temporary files.
2. Schedule a boot time scanning with avast with archive scanning turned on. If avast does not detect it, you can try DrWeb CureIT! (http://www.freedrweb.com/cureit/) instead.
3. Use SUPERantispyware (http://www.superantispyware.com), MBAM (http://malwarebytes.org/mbam.php) or Spyware Terminator (http://www.spywareterminator.com/) to scan for spywares and trojans. If any infection is detected, better and safer is send the file to Quarantine than to simple delete them.
4. Test your machine with anti-rootkit applications (http://www.antirootkit.com/software/index.htm). I suggest avast! antirootkit (http://files.avast.com/files/beta/aswar.exe) or Trend Micro RootkitBuster (http://www.trendmicro.com/download/rbuster.asp).
5. Make a HijackThis (http://www.bleepingcomputer.com/files/hijackthis.php) log to post here or this analysis site (http://www.hijackthis.de/#anl). Or even submit the RunScanner (http://www.runscanner.net/) log to to on-line analysis.
6. Disable System Restore and then reenable it again.
7. Immunize your system with SpywareBlaster (http://www.javacoolsoftware.com/spywareblaster.html).
8. Check if you have insecure applications with Secunia Software Inspector (http://secunia.com/software_inspector/).
Title: Re: WORM? WHAT'S HAPPENED & WHAT NEXT?
Post by: SPACEY on April 08, 2009, 10:52:08 AM
Thanks all Confused/David/Tech,

Have installed Superspyware but it won't open, like the others, Just installed CureIt and the basic scans picked up the following and has deleted it;

ieencode32.dll in c:\windows\system32 Trojan download 33662

Set it off on a complete scan now, waiting...

Is it likely the one found so far is the one responsible?

I knew there were risks with p2p, usually only use it for music, first time seeking a programme so have been burned & lessons learned. What are the golden rules with p2p then, never trust an exe file I guess?
Title: Re: WORM? WHAT'S HAPPENED & WHAT NEXT?
Post by: SPACEY on April 08, 2009, 10:58:55 AM
Ran a thorough avast! overnight as well with no results
Title: Re: WORM? WHAT'S HAPPENED & WHAT NEXT?
Post by: SPACEY on April 08, 2009, 12:15:11 PM
Cureit's found some things;

can't copy cureit's log so I'll summarise the messgaes;

ieencode32.dll in c:\windows\system32   Trojan.download.33662 -  this 33662 trojan also detected in A0108873.exe and A0110141.dll in c:\system volume information\restore

A0106411.exe in c:\system volume information\restore  Trojan.download.15184 - this 15184 trojan also detected in another exe file from a plug-in that was downloaded probably two years ago.

That's seven objects the scan picked up.

Does this mean I should be regulary running two different AV softwares?


Title: Re: WORM? WHAT'S HAPPENED & WHAT NEXT?
Post by: Mr.Agent on April 08, 2009, 01:00:28 PM
I didnt like Limewire for a reason because its got full virus !!! If you wanna download game you should try isohunt for torrent and blubster for music :) its more safe and less virus ! I never taked any virus from torrent in isohunt or blubster maybe there none or few :)
Title: Re: WORM? WHAT'S HAPPENED & WHAT NEXT?
Post by: SPACEY on April 08, 2009, 01:02:03 PM
....or three?
superantispyware now installed and has detected 8 items;
1 tracking cookie and
a registry cleaner trial;
HKCR\.03
HKCR\03_auto_file
HKCR\03_auto_file\shell
HKCR\03_auto_file\shell\open
HKCR\03_auto_file\shell\open\command
HKCR\03_auto_file\shell\print
HKCR\03_auto_file\shell\print\command

all quarantined

I'll see what happens...
Title: Re: WORM? WHAT'S HAPPENED & WHAT NEXT?
Post by: Confused Computer User on April 08, 2009, 02:04:27 PM
Does this mean I should be regulary running two different AV softwares?

Well we have to be careful with this. It is always counter indicated to run 2 or more AV on the same computer. If you look at my signature at the bottom of each of my posts I have one AV (avast) and 2 anti spyware (Super Anti-Sapyware and Malware Bytes Anti-Malware)

Now the theory behind not having two AV on one comp is that if they are both Scaning the system at the same time it can create conflicts which lead to instability in your system.What happens, and what is recomended by most Avast forum members is to keep one active AV porgram (Avast of course) and a couple of secondary Anti-spyware programs that you scan your system with once a week or more.

Title: Re: WORM? WHAT'S HAPPENED & WHAT NEXT?
Post by: DavidR on April 08, 2009, 03:08:14 PM
You should now run MBAM from safe mode, this program can also be installed from safe mode too, so it can avoid some to the malware that targets security applications.
Title: Re: WORM? WHAT'S HAPPENED & WHAT NEXT?
Post by: CharleyO on April 08, 2009, 05:16:43 PM
***

My golden rule for P2P programs ... never use them!


***