Caught a Virus: Virus:Trj/Shutdown.Z -- need advice

Caught a Virus: Virus:Trj/Shutdown.Z -- need advice

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Caught a Virus: Virus:Trj/Shutdown.Z -- need advice Lady Dungeness 06-13-2007
Posted by Lady Dungeness on June 13, 2007, 12:59 am
If you were  Registered and logged in, you could reply and use other advanced thread options

Windows MCE 2005 SP2 & patched here --

I just used Panda Online to scan my computer -- and it turned up a
malware. I looked in the WINDOWS directory and saw a couple of other
entries I don't recognize:

C:\WINDOWS
* catchme.exe (with the default blank-window icon)
AWuninstall.exe (with the international red-circle-slash for "NO"
icon). The name sounds suspicious.
* iminst2.exe (with the default blank window icon)
movexe.exe (with the default blank window icon)
* ExpressPlayer.iso & ExpressPlayer.txt (says only "1.0.023-204782")

PANDA RESULTS:
* Potentially unwanted tool:Application/NirCmd.A; Not disinfected;
C:\WINDOWS\nircmd.exe

* Potentially unwanted tool:Application/Processor        ; Not
disinfected; C:\WINDOWS\system32\process.exe
        The PROPERTIES on this file say it comes from www beyondlogic org
and uses Australian English. I use US English, and don't recall using
any problem from Australia.

* Virus:Trj/Shutdown.Z; Disinfected; C:\WINDOWS\system32\restart.exe.
I could not find this file, so I guess Panda did its job! But I have
no way of checking the dates to see when I might have gotten this
virus.

HOW TO BETTER PROTECT MYSELF?
        I've had to kill off a couple of viruses in the last month. This
after years of computing virus-free. I went to online cable six
months ago; I don't visit dangerous websites, and have Google
configured to warn me if a redirect tries to take me to one.
        I have been going through some old CD's with programs (4-5 years
old), and copying the ones I wnat to keep onto an external hard-drive.
About 70% of the programs are going into the trash.
        I use AVG, Spybot S&D, Ad-Aware regularly and keep them updated.
I run a full AVG virus check weekly, and use online Panda, Trend
Micro, and Kaspersky monthly.
        WHAT computing behaviors should I change?
        WHAT programs, controls, configurations, etc should I change?

Lady Dungeness
Crabby, but the Legs are Delicious!



Posted by David H. Lipman on June 13, 2007, 7:29 am
If you were  Registered and logged in, you could reply and use other advanced thread options


| Windows MCE 2005 SP2 & patched here --

| I just used Panda Online to scan my computer -- and it turned up a
| malware. I looked in the WINDOWS directory and saw a couple of other
| entries I don't recognize:

| C:\WINDOWS
| * catchme.exe (with the default blank-window icon)
| AWuninstall.exe (with the international red-circle-slash for "NO"
| icon). The name sounds suspicious.
| * iminst2.exe (with the default blank window icon)
| movexe.exe (with the default blank window icon)
| * ExpressPlayer.iso & ExpressPlayer.txt (says only "1.0.023-204782")

| PANDA RESULTS:
| * Potentially unwanted tool:Application/NirCmd.A; Not disinfected;
| C:\WINDOWS\nircmd.exe

| * Potentially unwanted tool:Application/Processor ; Not
| disinfected; C:\WINDOWS\system32\process.exe
| The PROPERTIES on this file say it comes from www beyondlogic org
| and uses Australian English. I use US English, and don't recall using
| any problem from Australia.

| * Virus:Trj/Shutdown.Z; Disinfected; C:\WINDOWS\system32\restart.exe.
| I could not find this file, so I guess Panda did its job! But I have
| no way of checking the dates to see when I might have gotten this
| virus.

| HOW TO BETTER PROTECT MYSELF?
| I've had to kill off a couple of viruses in the last month. This
| after years of computing virus-free. I went to online cable six
| months ago; I don't visit dangerous websites, and have Google
| configured to warn me if a redirect tries to take me to one.
| I have been going through some old CD's with programs (4-5 years
| old), and copying the ones I wnat to keep onto an external hard-drive.
| About 70% of the programs are going into the trash.
| I use AVG, Spybot S&D, Ad-Aware regularly and keep them updated.
| I run a full AVG virus check weekly, and use online Panda, Trend
| Micro, and Kaspersky monthly.
| WHAT computing behaviors should I change?
| WHAT programs, controls, configurations, etc should I change?

| Lady Dungeness
| Crabby, but the Legs are Delicious!



Lady:

Catchme.exe -- Did you get this from Gmer ?
process.exe -- Not a proble and is not malware. It is a tool that in itself is
NOt
malicious but can be used maliciously. I believe although restart.exe is
called a rojan
it too falls under the same banner.

.ISO files are not malicious. They are CD/DVD image files.

However, "PANDA RESULTS: * Potentially unwanted tool:Application/NirCmd.A; Not
disinfected; C:\WINDOWS\nircmd.exe
I'm not sure what that is. This needs more research. Maybe submit it to Virus
Total.

Overall, I'd say that you really do NOT have a problem.


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by Nick Goetz on June 14, 2007, 6:00 am
If you were  Registered and logged in, you could reply and use other advanced thread options

>
>
>| Windows MCE 2005 SP2 & patched here --
>
>| I just used Panda Online to scan my computer -- and it turned up a
>| malware. I looked in the WINDOWS directory and saw a couple of other
>| entries I don't recognize:
>
>| C:\WINDOWS
>| * catchme.exe (with the default blank-window icon)
>| AWuninstall.exe (with the international red-circle-slash for "NO"
>| icon). The name sounds suspicious.
>| * iminst2.exe (with the default blank window icon)
>| movexe.exe (with the default blank window icon)
>| * ExpressPlayer.iso & ExpressPlayer.txt (says only "1.0.023-204782")
>
>| PANDA RESULTS:
>| * Potentially unwanted tool:Application/NirCmd.A; Not disinfected;
>| C:\WINDOWS\nircmd.exe
>
>| * Potentially unwanted tool:Application/Processor ; Not
>| disinfected; C:\WINDOWS\system32\process.exe
>| The PROPERTIES on this file say it comes from www beyondlogic org
>| and uses Australian English. I use US English, and don't recall
>| using any problem from Australia.
>
>| * Virus:Trj/Shutdown.Z; Disinfected;
>| C:\WINDOWS\system32\restart.exe.
>| I could not find this file, so I guess Panda did its job! But I have
>| no way of checking the dates to see when I might have gotten this
>| virus.
>
>| HOW TO BETTER PROTECT MYSELF?
>| I've had to kill off a couple of viruses in the last month. This
>| after years of computing virus-free. I went to online cable six
>| months ago; I don't visit dangerous websites, and have Google
>| configured to warn me if a redirect tries to take me to one.
>| I have been going through some old CD's with programs (4-5 years
>| old), and copying the ones I wnat to keep onto an external
>| hard-drive. About 70% of the programs are going into the trash.
>| I use AVG, Spybot S&D, Ad-Aware regularly and keep them updated.
>| I run a full AVG virus check weekly, and use online Panda, Trend
>| Micro, and Kaspersky monthly.
>| WHAT computing behaviors should I change?
>| WHAT programs, controls, configurations, etc should I change?
>
>| Lady Dungeness
>| Crabby, but the Legs are Delicious!
>
>
>
> Lady:
>
> Catchme.exe -- Did you get this from Gmer ?
> process.exe -- Not a proble and is not malware. It is a tool that in
> itself is NOt malicious but can be used maliciously. I believe
> although restart.exe is called a rojan it too falls under the same
> banner.
>
> .ISO files are not malicious. They are CD/DVD image files.
>
> However, "PANDA RESULTS: * Potentially unwanted
> tool:Application/NirCmd.A; Not disinfected; C:\WINDOWS\nircmd.exe
> I'm not sure what that is. This needs more research. Maybe submit it
> to Virus Total.
>
> Overall, I'd say that you really do NOT have a problem.
>
>

David:

I think "nircmd" is probably the "command line tool" from Nirsoft.
The instalation has an option to place "nircmd.exe" in the Windows
directory.

Nick Goetz

Posted by Lady Dungeness on June 14, 2007, 1:44 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
These files were not there two days ago. Where could they have come
from? That's why I'm worried about virus ...

Lady D


On Wed, 13 Jun 2007 07:29:03 -0400, "David H. Lipman"

>
>
>| Windows MCE 2005 SP2 & patched here --
>
>| I just used Panda Online to scan my computer -- and it turned up a
>| malware. I looked in the WINDOWS directory and saw a couple of other
>| entries I don't recognize:
>
>| C:\WINDOWS
>| * catchme.exe (with the default blank-window icon)
>| AWuninstall.exe (with the international red-circle-slash for "NO"
>| icon). The name sounds suspicious.
>| * iminst2.exe (with the default blank window icon)
>| movexe.exe (with the default blank window icon)
>| * ExpressPlayer.iso & ExpressPlayer.txt (says only "1.0.023-204782")
>
>| PANDA RESULTS:
>| * Potentially unwanted tool:Application/NirCmd.A; Not disinfected;
>| C:\WINDOWS\nircmd.exe
>
>| * Potentially unwanted tool:Application/Processor ; Not
>| disinfected; C:\WINDOWS\system32\process.exe
>| The PROPERTIES on this file say it comes from www beyondlogic org
>| and uses Australian English. I use US English, and don't recall using
>| any problem from Australia.
>
>| * Virus:Trj/Shutdown.Z; Disinfected; C:\WINDOWS\system32\restart.exe.
>| I could not find this file, so I guess Panda did its job! But I have
>| no way of checking the dates to see when I might have gotten this
>| virus.
>
>| HOW TO BETTER PROTECT MYSELF?
>| I've had to kill off a couple of viruses in the last month. This
>| after years of computing virus-free. I went to online cable six
>| months ago; I don't visit dangerous websites, and have Google
>| configured to warn me if a redirect tries to take me to one.
>| I have been going through some old CD's with programs (4-5 years
>| old), and copying the ones I wnat to keep onto an external hard-drive.
>| About 70% of the programs are going into the trash.
>| I use AVG, Spybot S&D, Ad-Aware regularly and keep them updated.
>| I run a full AVG virus check weekly, and use online Panda, Trend
>| Micro, and Kaspersky monthly.
>| WHAT computing behaviors should I change?
>| WHAT programs, controls, configurations, etc should I change?
>
>| Lady Dungeness
>| Crabby, but the Legs are Delicious!
>
>
>
>Lady:
>
>Catchme.exe -- Did you get this from Gmer ?
>process.exe -- Not a proble and is not malware. It is a tool that in itself is
NOt
>malicious but can be used maliciously. I believe although restart.exe is
called a rojan
>it too falls under the same banner.
>
>.ISO files are not malicious. They are CD/DVD image files.
>
>However, "PANDA RESULTS: * Potentially unwanted tool:Application/NirCmd.A; Not
>disinfected; C:\WINDOWS\nircmd.exe
>I'm not sure what that is. This needs more research. Maybe submit it to Virus
Total.
>
>Overall, I'd say that you really do NOT have a problem.

Posted by David H. Lipman on June 14, 2007, 4:42 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| These files were not there two days ago. Where could they have come
| from? That's why I'm worried about virus ...
|
| Lady D

Maybe they were but you were not aware of their presence.

I also agree with Nick G's. assertion. No mlware found, only admini. type tools.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Similar ThreadsPosted
Anti-Virus on Server - Advice September 8, 2005, 7:33 am
Virus removed webpages still restricted. Advice please October 7, 2005, 8:03 am
advice on anti-virus, anti-trojan software May 12, 2008, 7:35 am
help please. malware removal advice October 3, 2005, 7:57 pm
low on virtual memory advice October 30, 2005, 5:00 am
OEM AntiVirus Software Advice January 31, 2006, 10:41 am
Advice Sought re Norton Replacements August 29, 2006, 9:03 am
HELP: Virus is preventing me from installing anti virus software!! January 11, 2007, 2:17 am
I have a virus that uses "anti virus software" downloads as a cover up March 24, 2007, 1:40 pm
I have a worm or virus that does not allow me to go to ANY anti-virus website January 28, 2006, 10:29 pm

The site map in XML format XML site map

Contact Us | Privacy Policy