|
|||||||
|
Possible new virus variant *updated post 30*
Preface: We are primarily in an XP environment and use IE to access most of our internal processes. We have a corporate firewall and Symantec Endpoint Protection Enterprise anti-virus on our computers.We have had a rash of reports of slow computers. I did some investigation and discovered a common thread. They each had a program that launches at start-up located at C:\Documents and Settings\[username]\Application Data\[directory] that is about 200kb in size. The directory name matched the file name. The file names have been one of three names: AdVantage.exe googletalk.exe Skype.exe The DOS FC command indicate all three files are identical. I found them initially by using the MSCONFIG utility and clicking on the Startup tab. Unchecking the box and rebooting seemed to fix the issue of the computers being slow. AV scans of the systems came back clean. Symantec identifies a similar virus called Trojan.Gatak [symantec.com] but the files are not being flagged. Of course the first ones I found were the AdVantage.exe file that is NOT listed in the virus description. ![]() As a test, I emailed one of the files to myself via Yahoo Mail. No viruses were detected. I uploaded the file to a place that uses multiple anti-virus products to check for viruses [garyshood.com]. It came back clean. I have submitted the files to Symantec and will report back when I hear something. Have I mentioned that I just LOVE job security?
Last edited by marg_fan; 05-14-2012 at 09:11 AM.. |
| 03-28-2012, 07:01 AM | |
|
|
|
Any virus that doesn't kill msconfig, or running any and all programs, safe mode, or accessing files is no good virus in my books.
I've only seen one really really bad one that did all of the above as well as spread across a network of 5000 computers in less than 20 minutes while being undetected by all antivirus and malware programs. Any computer that was connected to the subnet was immediately infected. Feds even got involved after it resulted in 250k in money being stolen. Symantec paid for several drives to be sent in for analysis. It was a good 4 months later that a new definition was created for it. Thank got that was early on in my career and I was not the guy in charge
|
|
Not new "could be a virus" .... Run Malwarebytes
http://www.prevx.com/filenames/X3...K.EXE.html File Behavior GOOGLETALK.EXE has been seen to perform the following behavior: The Process is packed and/or encrypted using a software packing process This Process is a file infector which modifies program files to include a copy of the infection This process creates other processes on disk Copies files This Process Deletes Other Processes From Disk Looks at the contents of the autoexec.bat file Includes file creation code which could be used to test for interception by security products Uses DNS to retrieve the IP address for web sites Writes to another Process's Virtual Memory (Process Hijacking) Executes a Process GOOGLETALK.EXE has been the subject of the following behavior: Created as a process on disk Added as a Registry auto start to load Program on Boot up Created by processes which appear to be checking for interception by security products Executed as a Process Has code inserted into its Virtual Memory space by other programs Last edited by boltman2007; 03-28-2012 at 09:14 AM.. |
|
|
||
|
Hitman Pro identified Skype.exe as a possible threat (the only one of the three on the computer) and I uploaded it to their cloud. I think the only reason it flagged it was the file name being the same as a previous threat rather than actually finding something.
|
|
~~~~~~~~~~~ Check out my Youtube [youtube.com] ~~~~~~~~~~~
~~ Corsair Carbide 500R | ASUS Maximus IV Gene-Z | Intel i5-2500k 4.7GHz [canardpc.com] | Cooler Master Hyper 212 | 2x MSI GTX 460 Hawks in SLI | 4x4GB G.Skill Ripjaws X 1600MHz | Seasonic X650 PSU | Corsair Force 3 120GB SSD 2TB HDD 1x750GB HDD 1x640GB HDD| Saitek Eclipse II | Logitech MX-518 | ASUS VS247H-P 23.6" Monitor x2 | Windows 7 Pro 64-bit~~ XBox Live Gametag - Reflection X13 Steam - jhu' X13_Y [steamcommunity.com] |
|
|
I would not consider "emailing to my self via yahoo" a great test, but If I was you I would looking in to making sure that your computers are patched (including flash, java, office, etc). The virus has to get on the computer somehow as I doubt its a zero day exploit.
|
|
![]() Our WSUS does push out OS and Office updates. Java is/was a version behind because it hadn't passed our validity testing yet (not within my scope). I'm not sure about the Flash version. I will check on that. |
|
|
|
|
|
Additionally, we have replaced the msgina.dll with our own logon processing program that adds the ability to clock in before signing onto the computer (no physical time clocks). Combofix automatically deleted our replacement for msgina.dll and restored the default logon user interface. Until we have more information, we will me removing the infection the old fashioned way. Thanks for all the help. |
||
|
|
|
|
|
|
| Thread Tools | Search this Thread |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Create Recovery/Boot Partition? Is it possible? | kpatel1 | Tech Support | 7 | 04-05-2012 12:56 AM |
| Look out for a new virus email!!!!!!!!!!!!!! | -Shadow | Tech Support | 7 | 02-22-2012 08:48 AM |
| Norton disables itself completely after one year | boltman2007 | Tech Support | 21 | 04-13-2011 03:58 PM |
| Use an old HDD as primary on a new PC, possible? | slimwantsfat | Tech Support | 37 | 03-18-2011 09:52 AM |
| Removing viruses tip | callpocket | Tech Support | 3 | 10-24-2010 06:37 PM |