Results 1 to 6 of 6

Thread: Getting Hammered by a Virus

  1. #1
    Administrator
    August Knights
    Assistant Recruiter

    [AK]Clay's Avatar
    Join Date
    Nov 2003
    Posts
    3,004

    Getting Hammered by a Virus

    I got hit by something tenatious in the last couple days that's giving me a tough time of it. I'm posting this because it may get some others here too - particulaly those using MYIE2 and IE

    Source:
    Unknown - but suspect related to MYIE2 usage. Using Firefox now with reliable performance.

    Name:
    Downloader.agent.BF (or something similar to that). I see that troj_Agent.AC is currently the number 1 virus out there - so it's probably some form of it.

    Description:
    This is a tenatious little bastard that AVG (my virus scanner) pops up and starts saying files in the Windows directory are infected with. The more you move around, the more it starts infecting files. So far, AVG has identified the following files as infected:

    C:\Windows\:
    iesw.exe
    d3cd32.exe
    addgo32.exe

    \System32\:
    crne.exe
    bzndo.dll
    notqf32
    ulgpr.dll (this one's annoying, because this is somehow involved in hijacking IE - had to use regedit to kill this one out)
    javadav32.exe
    javaave32.exe
    iditk.dll
    sysuv32.exe
    rraag.dll

    I don't know how many of the above are legit windows files that are infected - or are complete viruses.

    The good news is AVG finds these and fixes them. The bad news is that AVG does not appear to be able to eliminate the virus, becuase it keeps coming back. Particulaly when you launch IE.

    Behavior:
    For now, it looks like it's staying within the Windows and Windows\System32 directories, infecting dll's and exe's only. I haven't discovered any data corruption, key logger evidence, or other particularly nasty behavior. But it is fast. The more you let it build in your system, the faster it starts infecting. I've been running AVG and adware ALOT today. It doesn't appear to have seriously damaged anything, but panic'd behavior can do that for you!

    Fix:
    Not sure. Adaware 6.0 JUST came out with a patch late this evening that found a bunch of new registry hacks that it fixed. But the problem came back for me. AVG finds and fixes infected files, but the problem came back for me. I updated Windows today - there were 2 new critical updates (you'd think they would have found most of the holes by now) and installed. The good news is some of the damage I did by panic deleting files I probably shouldn't have appeared to be repaired by the updates, because Windows stopped whinning on boot-up. The bad news is, the problem came back. It's buried in here somewhere.

    My current status:
    Oddly, I can't get the virus to act up anymore and AVG and Adaware are no longer finding anything. I'm not sure why this is - I haven't done anything seriously new.

    There is one item that I'm suspect about. in my Task manager there is something called d3cn32.exe running. I don't know what this is, and can't find anything on it on a google search. I've ended the execution, and like I said, it's all quiet now - pretty suspicious. Before I nuke this file from my Windows directory, do any of you know what this might be?

    Here's a handy link - you may need this. There is a fix program in it. I just ran it while typing this. It may help - may not. Needless to say, I'm not entering anything into MSMoney right now. Thank goodness I don't have any sensative financial info stored on my PC - and I keep my simple MSMoney checkbook registry is passworded and without account numbers.

    http://www.trendmicro.com/vinfo/default.asp?sect=TT
    Last edited by [AK]Clay; 06-26-2004 at 09:39 PM.

  2. #2
    August Knights
    Undersecretary of War


    Long Live Reaganomics!
    [AK]Hylander's Avatar
    Join Date
    Sep 2001
    Location
    Bethlehem, PA
    Posts
    5,497
    If you are running XP, the chances are the reason it keeps coming back is that the infected files are backed up in a restore point somewhere. If you have restore on, what you need to do is turn off system restore, boot into safe mode, and then run AVG in safe mode.
    "The inherent vice of capitalism is the unequal sharing of blessings; the inherent virtue of socialism is the equal sharing of miseries." - Winston Churchill

    ---
    Hustedia.com | Husted Visuals | The Racing Historian


  3. #3
    Administrator
    August Knights
    Assistant Recruiter

    [AK]Clay's Avatar
    Join Date
    Nov 2003
    Posts
    3,004
    Thanks Hylander. Restore is turned off for all my drives and has been for awhile. Interesting note though, AVG updated today and found a corrupt .dat file and a corrupt executable. Interestingly, that executable was the teh d3cd32.exe process (also called DC23.exe), which was a file I was suspect of and moved to my recycle bin (where the scanner found it). AVG never found this before, so the update must be to take into account this virus.

    I'm feeling pretty good about that now - I cautiously optimistic that I may have finally nixed it. I hope so, I was about 15 minutes from just reformating yesterday.

  4. #4
    Token Commie [AK]Sonic Boom's Avatar
    Join Date
    Oct 2002
    Location
    Seattle
    Posts
    1,125
    Okay, this is a rookie question but, what the hell is AVG?
    Hasta,
    Boom

  5. #5
    August Knights
    Undersecretary of War


    Long Live Reaganomics!
    [AK]Hylander's Avatar
    Join Date
    Sep 2001
    Location
    Bethlehem, PA
    Posts
    5,497
    AVG is a free anti-virus software package. It is VERY good. I'd probably switch over to it if I didn't have *clears throat* a perpetual Norton subscription.
    "The inherent vice of capitalism is the unequal sharing of blessings; the inherent virtue of socialism is the equal sharing of miseries." - Winston Churchill

    ---
    Hustedia.com | Husted Visuals | The Racing Historian


  6. #6
    Lurking Moar Slaughter's Avatar
    Join Date
    Apr 2001
    Location
    Cincinnati, OH
    Posts
    4,389
    Perpetual Norton license?!? dude, hook me up.

    I got Perpetual McAffe on my Laptop.. but that is no where near as good as Norton.
    lol, <3

    Retired EQ, WoW Player.

Similar Threads

  1. Anti-Virus and other security software
    By [AK]Clay in forum Operating Systems & Applications
    Replies: 11
    Last Post: 02-07-2008, 09:55 AM
  2. New Virus Alert -- Mugly
    By [AK]Choozoo in forum Operating Systems & Applications
    Replies: 0
    Last Post: 11-30-2004, 05:27 AM
  3. Virus Attack
    By [AK]Clay in forum August Knights Round Table
    Replies: 7
    Last Post: 04-22-2004, 03:40 AM
  4. Virus problems
    By [AK]Abaddon in forum August Knights Round Table
    Replies: 7
    Last Post: 11-13-2001, 03:46 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •