Re: Found a virus undetected - any thoughts ?



If you would allow it sir, you can contribute to the general community by
calling
Microsoft Security at 866 727 2338 should you deem this file is a new virus
undetected. The support team can delete it for you and ask for some sample to
to be added to Microsoft security apps to better protect other people who
would get same instances as you have

thanks
--
Milo
MSPSS


"David H. Lipman" wrote:

From: "Daniel" <Daniel@xxxxxxxxxxxxxxxxxxxxxxxxx>

| Last night I discoved a virus on my XP machine. The strange thing is none of
| my virus or anti-spyware software packages picked it up. I noticed over the
| last few days that my page file would grow over 3 gigs (it never does) and I
| started recieving 'low on virtual memory errors', so I started digging (keep
| in mind i was never low in physical memory and nothing was running in task
| manager). I found a file via msconfig - startup called 70hasd1.exe (which is
| telling) so I disabled it and deleted the file from the windows\system32
| folder and rebooted the machine. After a reboot the file reappeared as
| 812332.exe (seems like random names each time), but the file always had the
| same modifed date and size - 12 KB. I removed the file and searched my
| machine eventually locating the source (I am hopeful anyways). This morning
| when I looked at the event logs I noticed a ton of Scheduler errors - it
| seems this virus had placed itself into Schedular using a different name and
| time to run each day. So far my machine seems fine, the pagefile is back to
| normal and there are no other items in msconfig or suspects that I can see.
| I have never seen a virus use windows scheduler before and I have never seen
| one that grows the page file to an enormous size - does anyone know what it
| was doing and is this unusual or the norm ?

You are being presumptuous in calling this a "virus". It may be a Trojan but I don't think
you are infected with a virus.


Download MULTI_AV.EXE from the URL --
http://www.pctipp.ch/downloads/dl/35905.asp

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to allow it to download the needed AV vendor related files.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the PC.

You can choose to go to each menu item and just download the needed files or you can
download the files and perform a scan in Normal Mode. Once you have downloaded the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
during boot] and re-run the menu again and choose which scanner you want to run in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
file.

Additional Instructions:
http://pcdid.com/Multi_AV.htm


* * * Please report back your results * * *


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



.



Relevant Pages

  • Re: I-Worm/Bagle.J
    ... > | I have a Bagle virus. ... > FireWall to allow it to download the needed AV vendor related files. ... > This will bring up the initial menu of choices and should be executed in Normal Mode. ... Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the PC. ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: alcan A or a dropper?
    ... I've never had a virus this bad. ... Download Adware-Virtumundo Removal Tool -- ... It would be best to scan in both Safe Mode and in Normal Mode and save a copy of the HTML ...
    (microsoft.public.windowsxp.general)
  • Re: Detecting unauthorized upload
    ... Is there a virus trying to upload my data? ... not infected with a virus or Trojan that AVG might be missing... ... This will bring up the initial menu of choices and should be executed in Normal Mode. ... You can choose to go to each menu item and just download the needed files or you can ...
    (alt.comp.anti-virus)
  • Re: JAVA BYTEVER.A
    ... | I have a question regarding this virus, which was found during a recent scan ... This will bring up the initial menu of choices and should be executed in Normal Mode. ... Trend, McAfee, Exit the menu and Reboot the PC ... You can choose to go to each menu item and just download the needed files or you can ...
    (microsoft.public.security.virus)
  • Re: URGENT- VIRUS
    ... has gotten the MSN block checker Virus. ... | blockers cant get rid of, and it has disabled the 'enter' button on my ... This will bring up the initial menu of choices and should be executed in Normal Mode. ... You can choose to go to each menu item and just download the needed files or you can ...
    (microsoft.public.windowsxp.general)