Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

elaborate unknown virus?

Status
Not open for further replies.

413345

Technical User
Mar 8, 2005
17
NO
came across a really elaborate virus or trojan the problems began after booting and receiving a message from windows that the system had had to restore several files (unfortunately I didn't note which)

the malicious little creep has performed the following on my system:


1. denies access to internet through IE (attempts to download files to the temporary internet folder, which doesn't exist so it fail (* astonished)
2. alters NAV and any other AV program files
3. blocks windows help (as if that would really do any good :)) (again attempting to download files in place of opening the progam)
4. deletes the "run" button in the start menu
5. disables the possibility of entering programs through start menu

Have run HJT etc and gone through registry without detecting any conspicious new commands or files.
Have searched and googled for three days without coming across a virus that excactly matches the description.

So, a plead for help here...
 
Deleting the run button is certainly new to me. I've seen a couple of virus advisories this week, but haven't seen the actual virus yet. I assume you have checked the websites for the latest viruses. Perhaps try the latest version of McAfee's stinger? I assume its been updated this week.
 
Hi
thanks for your replies

It is not the atak I think, as there is not svrhost.exe file to be found

I can't get access to the net at all, in reply to your other Q...

 
In the registry I found a

nodrivetypeautorun

entry in the HKCU register

may this be of help to identify the bleep?
 
Do me a favor and check your hosts file

C:\WINDOWS\system32\drivers\etc\hosts

And make certain that there are no entries, other than 127.0.0.1

As to the virus, I'm hoping that someone else can recall what the recent attack was (I believe it was only a few months ago)...and speaking of which...I found it.

Check for


Or one of its several variants.

It doesn't remove the run function, but let's focus on getting you back to the web before we move onto that specific problem.
 
Thanks again...

The host file hasn't been changed since 2003 so I think it is ok...

also, in reference to the virus you suggested, there is no winupd.exe file on my harddisk afaik...
 
413345,

Have you tried to put a copy with updated virus defs from AVG on the machine and do a full scan? That could solve your issue.

Go to and download it and the definitions (make sure they are the newest) from a different PC and burn a CD or transfer it with a Pen Drive or something to that effect. Then, try and hammer the virus.

Hope that helps,

Erik
 
thanks for your reply mate, but have done and failed miserably :) avg did not detect any virus...
 
You mentioned the host file, did you search for duplicates, or actually look inside? Sometimes in situations like this a program called Winsockfix has helped restore web access. I dont' remember where I got it, but can email you a copy.
 
Have you tried spyware issues and used Microsoft Antispyware and Spybot. I would recommend giving them a go also, make sure you have the updated defs...

We will figure it out.

Erik
 
Also, what does your host file say? What is in it besides
127.0.0.1

Thanks,

Erik
 
host file has nothing besides 127.0.0.1
have tried spybot,etc...
 
I'm leaning towards bill with this. Download two programs...

LSPFix and the Winsock Fix.

Run the LSPFix, if that doesn't work then move on and run the Winsock fix.
 
thanks will give it a go and reply about the results tomorrow!
 
Thankie Erik! But Billcmh was the one that mentioned, it just looks like I'm a touch louder about it ;-)
 
Links would be nice, eh?"

Thanks Aquias, I am unfamiliar with LSPfix, I will check the link.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top