|
Posted by =?Utf-8?B?TWlsbyAoTVNQU1Mp?= on July 2, 2007, 10:46 pm
If you were Registered and logged in, you could reply and use other advanced thread options If you would allow it sir, you can contribute to the general community by
calling
Microsoft Security at 866 727 2338 should you deem this file is a new virus
undetected. The support team can delete it for you and ask for some sample to
to be added to Microsoft security apps to better protect other people who
would get same instances as you have
thanks
--
Milo
MSPSS
"David H. Lipman" wrote:
>
> | Last night I discoved a virus on my XP machine. The strange thing is none of
> | my virus or anti-spyware software packages picked it up. I noticed over the
> | last few days that my page file would grow over 3 gigs (it never does) and I
> | started recieving 'low on virtual memory errors', so I started digging (keep
> | in mind i was never low in physical memory and nothing was running in task
> | manager). I found a file via msconfig - startup called 70hasd1.exe (which is
> | telling) so I disabled it and deleted the file from the windows\system32
> | folder and rebooted the machine. After a reboot the file reappeared as
> | 812332.exe (seems like random names each time), but the file always had the
> | same modifed date and size - 12 KB. I removed the file and searched my
> | machine eventually locating the source (I am hopeful anyways). This morning
> | when I looked at the event logs I noticed a ton of Scheduler errors - it
> | seems this virus had placed itself into Schedular using a different name and
> | time to run each day. So far my machine seems fine, the pagefile is back to
> | normal and there are no other items in msconfig or suspects that I can see.
> | I have never seen a virus use windows scheduler before and I have never seen
> | one that grows the page file to an enormous size - does anyone know what it
> | was doing and is this unusual or the norm ?
>
> You are being presumptuous in calling this a "virus". It may be a Trojan but
I don't think
> you are infected with a virus.
>
>
> Download MULTI_AV.EXE from the URL --
> http://www.pctipp.ch/downloads/dl/35905.asp
>
> To use this utility, perform the following...
> Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
> Choose; Unzip
> Choose; Close
>
> Execute; C:\AV-CLS\StartMenu.BAT
> { or Double-click on 'Start Menu' in C:\AV-CLS }
>
> NOTE: You may have to disable your software FireWall or allow WGET.EXE to go
through your
> FireWall to allow it to download the needed AV vendor related files.
>
> C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
> This will bring up the initial menu of choices and should be executed in
Normal Mode.
> This way all the components can be downloaded from each AV vendor's web site.
> The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot
the PC.
>
> You can choose to go to each menu item and just download the needed files or
you can
> download the files and perform a scan in Normal Mode. Once you have downloaded
the files
> needed for each scanner you want to use, you should reboot the PC into Safe
Mode [F8 key
> during boot] and re-run the menu again and choose which scanner you want to
run in Safe
> Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.
>
> When the menu is displayed hitting 'H' or 'h' will bring up a more
comprehensive PDF help
> file.
>
> Additional Instructions:
> http://pcdid.com/Multi_AV.htm
>
>
> * * * Please report back your results * * *
>
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>
>
|