Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old March 27th, 2005, 04:50 AM
ddd ddd is offline
Infrequent Poster
 
Join Date: Jun 2004
Posts: 20
Exclamation got this new virus!

here's the problem. nod32 finds new kind of virus, but it cannot be removed since is the new kind of virus. it runs in c:\windows\winrun.exe
i can't open taskmanager, so i really don't know what to do!
please help!!!!
  #2  
Old March 27th, 2005, 05:26 AM
Blackspear's Avatar
Blackspear Blackspear is offline
Global Moderator
 
Join Date: Dec 2002
Location: Gold Coast, Queensland, Australia
Posts: 15,114
Default Re: got this new virus!

Have you tried rebooting into Safe Mode and running a scan that way?

Just make sure Nod32 is set up as per instructions mentioned in post number 2 HERE.

Hope this helps...

Let us know how you go.

Cheers
__________________
"Illegitimis non carborundum"
translation:
"Don't let the bastards grind you down"
U.S. General Joseph W. "Vinegar Joe" Stilwell (1883-1946)
Two Photographers

Last edited by Blackspear : March 27th, 2005 at 05:40 AM. Reason: Spelling and Grammer, just the usual... ;)
  #3  
Old March 27th, 2005, 06:02 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,194
Default Re: got this new virus!

Whenever NOD32 finds a probable unknown NewHeur_PE virus, tick the Quarantine check-box before deleting the file. It should be possible to delete even viruses detected by heuristics. After the scan completes, reboot the machine and send the content of the program files\eset\infected folder to sample@eset.com. Should there be a problem deleting the file, boot to safe mode first as suggested by Blackspear.
  #4  
Old March 27th, 2005, 06:21 AM
Happy Bytes
 
Posts: n/a
Default Re: got this new virus!

If you stuck somewhere then download ProcessExplorer from www.sysinternals.com

Rename the executable to hahayes.exe (that it cannot be terminated within process name) and kill the process During kill process maybe you hear this bugger crying, but dont spend attention to that
  #5  
Old March 27th, 2005, 07:32 AM
ddd ddd is offline
Infrequent Poster
 
Join Date: Jun 2004
Posts: 20
Default Re: got this new virus!

well my nod32 can't delete the selectede virus not even put in quarantine!
  #6  
Old March 27th, 2005, 07:36 AM
Blackspear's Avatar
Blackspear Blackspear is offline
Global Moderator
 
Join Date: Dec 2002
Location: Gold Coast, Queensland, Australia
Posts: 15,114
Default Re: got this new virus!

Quote:
Originally Posted by ddd
well my nod32 can't delete the selectede virus not even put in quarantine!
Have you tried it in Safe Mode?
__________________
"Illegitimis non carborundum"
translation:
"Don't let the bastards grind you down"
U.S. General Joseph W. "Vinegar Joe" Stilwell (1883-1946)
Two Photographers
  #7  
Old March 27th, 2005, 10:03 AM
ddd ddd is offline
Infrequent Poster
 
Join Date: Jun 2004
Posts: 20
Default Re: got this new virus!

yes, now it seems that the virus is deleted but i still can't open task manager?!
  #8  
Old March 27th, 2005, 06:00 PM
Blackspear's Avatar
Blackspear Blackspear is offline
Global Moderator
 
Join Date: Dec 2002
Location: Gold Coast, Queensland, Australia
Posts: 15,114
Default Re: got this new virus!

Quote:
Originally Posted by ddd
yes, now it seems that the virus is deleted but i still can't open task manager?!
Can you please send the quarantined file found in C Drive> Program files> Eset> Infected to sample@eset.com

If you find Windows system files affected, you can place your Windows CD in the drive, click start> run type in CMD, when the black window opens type in "sfc /scannow" SFC (System File Checker, a part of Windows File Protection) will replace any changed/damaged system files with a clean copy. SFC may not solve every problem, but it's a good start that anyone can do.

Hope this helps...

Let us know how you go.

Cheers
__________________
"Illegitimis non carborundum"
translation:
"Don't let the bastards grind you down"
U.S. General Joseph W. "Vinegar Joe" Stilwell (1883-1946)
Two Photographers
  #9  
Old March 28th, 2005, 02:00 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,194
Default Re: got this new virus!

What about changing the appropriate registry value?

User Key: [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\
System]
Value Name: DisableTaskMgr
Data Type: REG_DWORD (DWORD Value)
Value Data: (0 = default, 1 = disable Task Manager)

WARNING: If you use Registry Editor incorrectly, you may cause serious problems that may require you to reinstall your operating system.

Last edited by Marcos : March 28th, 2005 at 02:13 AM.
  #10  
Old March 28th, 2005, 03:18 AM
ddd ddd is offline
Infrequent Poster
 
Join Date: Jun 2004
Posts: 20
Default Re: got this new virus!

i've checked in the registry, but the tskmanager is not disabled. when i try to open tskmanager i get the message ''the tskmanager was disabled by your administrator''??
  #11  
Old March 28th, 2005, 03:37 AM
Happy Bytes
 
Posts: n/a
Default Re: got this new virus!

http://www.dougknox.com/xp/utils/xp_taskmgrenab.zip
  #12  
Old March 28th, 2005, 06:25 AM
ddd ddd is offline
Infrequent Poster
 
Join Date: Jun 2004
Posts: 20
Default Re: got this new virus!

thx a lot Happy Bytes!
  #13  
Old March 28th, 2005, 06:26 AM
ddd ddd is offline
Infrequent Poster
 
Join Date: Jun 2004
Posts: 20
Default Re: got this new virus!

there is another thing: when i try to open my dvd rom i get no result; if i try this with another account on win xp i have no problems. any idea why is this happening.
  #14  
Old March 28th, 2005, 08:26 AM
Happy Bytes
 
Posts: n/a
Default Re: got this new virus!

Open the CDRom how ?
Via right click and eject media or pressing the button directly on the drive?
  #15  
Old March 28th, 2005, 04:37 PM
alglove alglove is offline
Frequent Poster
 
Join Date: Jan 2005
Location: Houston, Texas, USA
Posts: 904
Default Re: got this new virus!

Quote:
Originally Posted by ddd
i've checked in the registry, but the tskmanager is not disabled. when i try to open tskmanager i get the message ''the tskmanager was disabled by your administrator''??
The Task Manager can be disabled with a registry entry or group policy. Once way to reenable it is to go to HKEY_CURENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System . On the right side, look for DisableTaskMgr , which should be of type REG_DWORD. If it is not there, create it. DisableTaskMgr should have a value of 0 (zero, not the letter O).
  #16  
Old March 28th, 2005, 04:39 PM
alglove alglove is offline
Frequent Poster
 
Join Date: Jan 2005
Location: Houston, Texas, USA
Posts: 904
Default Re: got this new virus!

Quote:
Originally Posted by ddd
there is another thing: when i try to open my dvd rom i get no result; if i try this with another account on win xp i have no problems. any idea why is this happening.
It sounds like something in that login is accessing the DVD-ROM drive, or at least keeping it locked. Try looking in the HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run... entries for something that should not be there.
  #17  
Old March 29th, 2005, 12:41 PM
ddd ddd is offline
Infrequent Poster
 
Join Date: Jun 2004
Posts: 20
Default Re: got this new virus!

i can't open dvd in my explorer (only when i use my account!). otherwise i can open it with other accounts on my comp.
i've checked HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, but nothing weird was there!
  #18  
Old March 29th, 2005, 02:57 PM
alglove alglove is offline
Frequent Poster
 
Join Date: Jan 2005
Location: Houston, Texas, USA
Posts: 904
Default Re: got this new virus!

Any CD/DVD burning applications on your computer, like Nero, Roxio, etc.?
  #19  
Old March 29th, 2005, 07:58 PM
NOD32 user's Avatar
NOD32 user NOD32 user is offline
Very Frequent Poster
 
Join Date: Jan 2005
Location: Australia
Posts: 1,766
Default Re: got this new virus!

Hi ddd,
Nothing to add with regards to the exact cause but its highly likely your issues are indirectly the result of using KaZaA or WinMX. Do you use either of these?
I am a bit curious today but I'm wondering also if you've got Advanced Heuristics turned on and all the other bells and whistles - I can't see if you said it is or not? Apart from the link above Blackspear also has an excellent config guide for NOD32 somewhere.
__________________
1. What is right is always The Truth.
2. Every Truth is supported in agreement by every Truth.
3. If the facts would persuade you otherwise, see 1.

ESET Reseller (Australia)
  #20  
Old March 30th, 2005, 09:20 AM
ddd ddd is offline
Infrequent Poster
 
Join Date: Jun 2004
Posts: 20
Default Re: got this new virus!

well i don't use kazaa or winmx nad YES i have turned on advanced heuristic,...
i reinstalled SP2 and now it's seems ok.
the weird thing was that i couldn't quarantine the winrun.exe, nod32 just deleted it?!
  #21  
Old March 30th, 2005, 03:14 PM
ShunterAlhena's Avatar
ShunterAlhena ShunterAlhena is offline
Regular Poster
 
Join Date: Aug 2004
Location: Szigethalom, Hungary
Posts: 134
Default Re: got this new virus!

Quote:
Originally Posted by ddd
the weird thing was that i couldn't quarantine the winrun.exe, nod32 just deleted it?!

Quarantine in NOD32 doesn't work like in other AV products like in Norton. Here it means that before deleting, cleaning etc. the infected file, NOD32 creates a secure copy of it in the 'infected' folder contained where NOD32 was installed to. So it's not a separate action. If you ticked the checkbox, the copy should be made and accessible via "NOD32 System Tools \ Quarantine".
__________________
"Look at you hacker...
a petty creature of meat and bone...
panting and sweating as you run through my corridors...
How can you challenge a perfect, immortal machine?"
SHODAN, System Shock
best game ever
  #22  
Old April 13th, 2005, 05:40 AM
ddd ddd is offline
Infrequent Poster
 
Join Date: Jun 2004
Posts: 20
Default Re: got this new virus!

hm, it's been more than two weeks now that i got rid of that virus (?), but i have another problem. i kinda lost my administrative rights on my winxp pro sp2. i tried everything, but still i cannot delete some files from partition d: and even on c:
is it normal that some viruses mess up your registry?
  #23  
Old April 13th, 2005, 05:46 AM
Blackspear's Avatar
Blackspear Blackspear is offline
Global Moderator
 
Join Date: Dec 2002
Location: Gold Coast, Queensland, Australia
Posts: 15,114
Default Re: got this new virus!

Quote:
Originally Posted by ddd
is it normal that some viruses mess up your registry?
Indeed, have you tried what I posted above?

If you find Windows system files affected, you can place your Windows CD in the drive, click start> run type in CMD, when the black window opens type in "sfc /scannow" SFC (System File Checker, a part of Windows File Protection) will replace any changed/damaged system files with a clean copy. SFC may not solve every problem, but it's a good start that anyone can do.

Cheers
__________________
"Illegitimis non carborundum"
translation:
"Don't let the bastards grind you down"
U.S. General Joseph W. "Vinegar Joe" Stilwell (1883-1946)
Two Photographers
  #24  
Old April 13th, 2005, 03:27 PM
alglove alglove is offline
Frequent Poster
 
Join Date: Jan 2005
Location: Houston, Texas, USA
Posts: 904
Default Re: got this new virus!

Quote:
Originally Posted by ddd
hm, it's been more than two weeks now that i got rid of that virus (?), but i have another problem. i kinda lost my administrative rights on my winxp pro sp2. i tried everything, but still i cannot delete some files from partition d: and even on c:
is it normal that some viruses mess up your registry?
How do you know that the registry is the problem? It could be something else preventing you from deleting these files, like NTFS ownership/permissions. What kind of error messages do you get when you try to delete these files? File locked or in use? Insufficient privilege? Something else?
  #25  
Old April 14th, 2005, 03:47 AM
ddd ddd is offline
Infrequent Poster
 
Join Date: Jun 2004
Posts: 20
Default Re: got this new virus!

Blackspear i've tried what you proposed but it stopped during the process (i think it was the problem with SP2, because my WIN XP has on CD SP1).
when i try to delete certain files i get the message i don't have permission for deleting files (it's strange cause i'm the administrator for my account). i even can't install some programs on partition d:
i've looked on internet and some had the same problem-virus, messed up registry,...
so my guess is that i got messed up registry so i don't have permission for some thing. strange it seems that always bad things happen to me!
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:48 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums