Author Topic: Unknown Virus  (Read 8928 times)

0 Members and 1 Guest are viewing this topic.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: Unknown Virus
« Reply #15 on: May 21, 2007, 02:54:24 PM »
No problem, glad we could help.

A belated welcome to the forums.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

an0nymous

  • Guest
Re: Unknown Virus
« Reply #16 on: May 22, 2007, 03:26:59 AM »
hello, eventhough avast deletes it, it keeps coming back. attacks stopped for a week and now its on the rampage again.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: Unknown Virus
« Reply #17 on: May 22, 2007, 03:51:38 AM »
Well there could either by another element downloading the malware again (you have to find that) or you keep visiting the same site that infected the system to start with. Or it could be being re-infected via your network, other systems not clean.

What is your firewall ?

You might also consider proactive protection (if this is possible on your network), in order to place files in the system folders and create registry entries you need permission. Prevention is much better and theoretically easier than cure.

Whilst browsing or collecting email, etc. if you get infected then the malware by default inherits the same permissions that you have for your user account. So if the user account has administrator rights, the malware has administrator rights and can reap havoc. With limited rights the malware can't put files in the system folders, create registry entries, etc. This greatly reduces the potential harm that can be done by an undetected or first day virus, etc.

Check out the link to DropMyRights (in my signature below) - Browsing the Web and Reading E-mail Safely as an Administrator. This obviously applies to those NT based OSes that have administrator settings, winNT, win2k, winXP.

If you haven't already got this software (freeware) to try and find any other elements of this infection, download, install, update and run it, preferably in safe mode.
1. AVG anti-spyware (formerly Ewido) If using winXP. or a-Squared free if using win98/ME.
« Last Edit: May 22, 2007, 03:54:00 AM by DavidR »
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

an0nymous

  • Guest
Re: Unknown Virus
« Reply #18 on: May 22, 2007, 04:13:16 AM »
I've noticed that it's attacking servers with SQL server installed. It copies itself from temporary internet files of another user account and writes itself to drive C:\ with x.exe.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: Unknown Virus
« Reply #19 on: May 22, 2007, 04:25:02 AM »
I don't know enough about networks to be of much help, but you are battling to keep systems clean when the server needs to protected with it's own AV solution.

Is x.exe being detected by avast ?
If not send the sample to avast and upload it to VirusToial or Jotti.

hello, eventhough avast deletes it, it keeps coming back. attacks stopped for a week and now its on the rampage again.

Are you saying that the winpatch.exe is coming back (as that seems a little removed from x.exe?) if so what location is it going to ?
You never mentioned what the location was in your original post.

Sorry I'm calling it a late nigh now, 3:25 am here.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security