Re: Please Help with WINCFG.SCR Infection !

From: Andrew (andrew_at_fried.us)
Date: 07/29/03

  • Next message: Samui: "Re: How Java work with PKCS12?"
    Date: 28 Jul 2003 21:36:56 -0700
    
    

    cathexis@erols.com (Reticulum) wrote in message news:<3f240136.1283637@localhost>...
    > Greetings,
    >
    > I hope this is the right group to ask for help. My ancient PC is
    > infected by WINCFG.SCR and removal as per on-line help available
    > at places like Symantec are not working.
    >
    > All instructions say to run Regedit -- it turns itself off whether
    > accessed by Run command or Explorer. The wincfg.scr file is plainly
    > visible in windows but neither Eraser nor BC Wipe will remove it. When
    > I go to run Regedit then regedit will appear for no more than 1 second
    > and then shut itself off. A search was made for any *.el-type file. One
    > was found and deleted (gnugo.el in a directory of Go-games I have).
    >
    > If there's anything "saving" me it is that my system is so ancient
    > and I use a dial-up and DONT save the password ( to control kid's access)
    > so as soon as I log off the Connection Screen will keep popping up. I was
    > hit by some trojan once before and this was the give-away I was infected.
    >
    > System Info:
    >
    > Pitiful P-166 running Win95 thru dial-up to Internet.
    > Agnitum Outpost Firewall that *appears* to be blocking. It lists WINCFG as
    > blocked but oddly it comes up under allowed as well despite multiple attempts
    > at rule setting. Also, AVG 6.0 Virus Scan which is seeing NADA despite updates
    > and re-tries.
    >
    > Please help me with this infection. It has stumped anything I can think
    > of to eliminate it.
    >
    > Accept my Thank in Advance,
    >
    > Andrew
    > Reticulum
    >
    > Remove "your.hat" when replying via e-mail

    The file should be located in c:\windows\system32\WINCFG.SCR. Reboot
    your system in safe mode and delete the file. I just found this same
    file earlier this afternoon, and if you're running any kind of
    firewall you'll find that it's attempting to contact an IRC server is
    the Netherlands... My file, in particular, was attempting to contact
    ip address 194.134.7.194.

    It looks like the file hit the net on or about July 26th. I've sent
    copies of the program to Symantec and TrendMicro for further analysis.

    Also, check and make sure you don't have another infection that might
    account for the strangeness you're experiencing with programs closing.
     I also found the file c:\windows\lan32c.exe on my system, and that
    was attempting to contact ip address 81.135.78.76, port 17773. The
    interesting thing about that file is that it's less than 300 bytes and
    if moved and executed, it will relocate itself right back to
    c:\windows again. Based on my firewall logs, I seems to have picked
    that one up on July 28th.

    None of the anti-virus or spyware programs detected either of these
    files.

    Good luck....


  • Next message: Samui: "Re: How Java work with PKCS12?"

    Relevant Pages

    • RE: New IRC Trojan -Symantec and Trend Micro Unable To Stop Infection
      ... about a new malware of some sort, that was not being detected by Symantec AV ... 13/06/2004 rev. 17, still NO detection, no action). ... and that was spreading fast through IRC (IRC is very popular here ... ] (ps links are broken with - intentionally to prevent infection) ...
      (Bugtraq)
    • [Full-Disclosure] Analysis of a Spam Trojan
      ... We found a couple of suspicious files that Symantec AntiVirus CE ... I soon discovered that audio.exe was indeed the infection ... In the GET request, it identified the host as ...
      (Full-Disclosure)
    • Re: VIRUSES HELP! W32SWEN.A@mm and W32KLEZ.H@mm
      ... > files that the Symantec cleaner won't get because it runs in Windows ... The first Klez infected Byf.exe, a TMP file of 90.6 KB. ...
      (microsoft.public.windowsxp.general)
    • Re: Windows XP Pro client wont shut down
      ... except lots of virus's picked up by Symantec (she seems to get a few every ... "Mike Webb" wrote: ... First thing is to check for Error in the Event Viewer and see if it is ... machines and the server for infection. ...
      (microsoft.public.windowsxp.help_and_support)
    • Re: Firewall wont stay enabled
      ... Maybe I missed something somewhere to get the infection. ... But perhaps it's just a new enough critter that Symantec hasn't gotten to isolate it yet. ...
      (microsoft.public.windowsxp.security_admin)