Found a virus undetected - any thoughts ?

Found a virus undetected - any thoughts ?

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Found a virus undetected - any thoughts ? =?Utf-8?B?RGFuaWVs?= 06-28-2007
Posted by =?Utf-8?B?RGFuaWVs?= on June 28, 2007, 8:08 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Last night I discoved a virus on my XP machine. The strange thing is none of
my virus or anti-spyware software packages picked it up. I noticed over the
last few days that my page file would grow over 3 gigs (it never does) and I
started recieving 'low on virtual memory errors', so I started digging (keep
in mind i was never low in physical memory and nothing was running in task
manager). I found a file via msconfig - startup called 70hasd1.exe (which is
telling) so I disabled it and deleted the file from the windows\system32
folder and rebooted the machine. After a reboot the file reappeared as
812332.exe (seems like random names each time), but the file always had the
same modifed date and size - 12 KB. I removed the file and searched my
machine eventually locating the source (I am hopeful anyways). This morning
when I looked at the event logs I noticed a ton of Scheduler errors - it
seems this virus had placed itself into Schedular using a different name and
time to run each day. So far my machine seems fine, the pagefile is back to
normal and there are no other items in msconfig or suspects that I can see.
I have never seen a virus use windows scheduler before and I have never seen
one that grows the page file to an enormous size - does anyone know what it
was doing and is this unusual or the norm ?

Posted by C J. on June 28, 2007, 1:04 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
> Last night I discoved a virus on my XP machine. The strange thing is
> none of my virus or anti-spyware software packages picked it up. I
> noticed over the last few days that my page file would grow over 3 gigs
> (it never does) and I started recieving 'low on virtual memory errors',
> so I started digging (keep in mind i was never low in physical memory and
> nothing was running in task manager). I found a file via msconfig -
> startup called 70hasd1.exe (which is telling) so I disabled it and
> deleted the file from the windows\system32 folder and rebooted the
> machine. After a reboot the file reappeared as 812332.exe (seems like
> random names each time), but the file always had the same modifed date
> and size - 12 KB. I removed the file and searched my machine eventually
> locating the source (I am hopeful anyways). This morning when I looked
> at the event logs I noticed a ton of Scheduler errors - it seems this
> virus had placed itself into Schedular using a different name and time to
> run each day. So far my machine seems fine, the pagefile is back to
> normal and there are no other items in msconfig or suspects that I can
> see. I have never seen a virus use windows scheduler before and I have
> never seen one that grows the page file to an enormous size - does anyone
> know what it was doing and is this unusual or the norm ?



Posted by David H. Lipman on June 28, 2007, 9:12 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| Last night I discoved a virus on my XP machine. The strange thing is none of
| my virus or anti-spyware software packages picked it up. I noticed over the
| last few days that my page file would grow over 3 gigs (it never does) and I
| started recieving 'low on virtual memory errors', so I started digging (keep
| in mind i was never low in physical memory and nothing was running in task
| manager). I found a file via msconfig - startup called 70hasd1.exe (which is
| telling) so I disabled it and deleted the file from the windows\system32
| folder and rebooted the machine. After a reboot the file reappeared as
| 812332.exe (seems like random names each time), but the file always had the
| same modifed date and size - 12 KB. I removed the file and searched my
| machine eventually locating the source (I am hopeful anyways). This morning
| when I looked at the event logs I noticed a ton of Scheduler errors - it
| seems this virus had placed itself into Schedular using a different name and
| time to run each day. So far my machine seems fine, the pagefile is back to
| normal and there are no other items in msconfig or suspects that I can see.
| I have never seen a virus use windows scheduler before and I have never seen
| one that grows the page file to an enormous size - does anyone know what it
| was doing and is this unusual or the norm ?

You are being presumptuous in calling this a "virus". It may be a Trojan but I
don't think
you are infected with a virus.


Download MULTI_AV.EXE from the URL --
http://www.pctipp.ch/downloads/dl/35905.asp

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go
through your
FireWall to allow it to download the needed AV vendor related files.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal
Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the
PC.

You can choose to go to each menu item and just download the needed files or you
can
download the files and perform a scan in Normal Mode. Once you have downloaded
the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode
[F8 key
during boot] and re-run the menu again and choose which scanner you want to run
in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive
PDF help
file.

Additional Instructions:
http://pcdid.com/Multi_AV.htm


* * * Please report back your results * * *


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by =?Utf-8?B?TWlsbyAoTVNQU1Mp?= on July 2, 2007, 10:46 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
If you would allow it sir, you can contribute to the general community by
calling
Microsoft Security at 866 727 2338 should you deem this file is a new virus
undetected. The support team can delete it for you and ask for some sample to
to be added to Microsoft security apps to better protect other people who
would get same instances as you have

thanks
--
Milo
MSPSS


"David H. Lipman" wrote:

>
> | Last night I discoved a virus on my XP machine. The strange thing is none of
> | my virus or anti-spyware software packages picked it up. I noticed over the
> | last few days that my page file would grow over 3 gigs (it never does) and I
> | started recieving 'low on virtual memory errors', so I started digging (keep
> | in mind i was never low in physical memory and nothing was running in task
> | manager). I found a file via msconfig - startup called 70hasd1.exe (which is
> | telling) so I disabled it and deleted the file from the windows\system32
> | folder and rebooted the machine. After a reboot the file reappeared as
> | 812332.exe (seems like random names each time), but the file always had the
> | same modifed date and size - 12 KB. I removed the file and searched my
> | machine eventually locating the source (I am hopeful anyways). This morning
> | when I looked at the event logs I noticed a ton of Scheduler errors - it
> | seems this virus had placed itself into Schedular using a different name and
> | time to run each day. So far my machine seems fine, the pagefile is back to
> | normal and there are no other items in msconfig or suspects that I can see.
> | I have never seen a virus use windows scheduler before and I have never seen
> | one that grows the page file to an enormous size - does anyone know what it
> | was doing and is this unusual or the norm ?
>
> You are being presumptuous in calling this a "virus". It may be a Trojan but
I don't think
> you are infected with a virus.
>
>
> Download MULTI_AV.EXE from the URL --
> http://www.pctipp.ch/downloads/dl/35905.asp
>
> To use this utility, perform the following...
> Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
> Choose; Unzip
> Choose; Close
>
> Execute; C:\AV-CLS\StartMenu.BAT
> { or Double-click on 'Start Menu' in C:\AV-CLS }
>
> NOTE: You may have to disable your software FireWall or allow WGET.EXE to go
through your
> FireWall to allow it to download the needed AV vendor related files.
>
> C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
> This will bring up the initial menu of choices and should be executed in
Normal Mode.
> This way all the components can be downloaded from each AV vendor's web site.
> The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot
the PC.
>
> You can choose to go to each menu item and just download the needed files or
you can
> download the files and perform a scan in Normal Mode. Once you have downloaded
the files
> needed for each scanner you want to use, you should reboot the PC into Safe
Mode [F8 key
> during boot] and re-run the menu again and choose which scanner you want to
run in Safe
> Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.
>
> When the menu is displayed hitting 'H' or 'h' will bring up a more
comprehensive PDF help
> file.
>
> Additional Instructions:
> http://pcdid.com/Multi_AV.htm
>
>
> * * * Please report back your results * * *
>
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>
>

Posted by Phil Weldon on July 2, 2007, 11:36 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
'Milo' wrote:
| If you would allow it sir, you can contribute to the general community by
| calling
| Microsoft Security at 866 727 2338 should you deem this file is a new
virus
| undetected. The support team can delete it for you and ask for some sample
to
| to be added to Microsoft security apps to better protect other people who
| would get same instances as you have
_____

I think 'David H. Lipman' knows that, and that it is not relevant to his
post.

Perhaps you meant to post in reply to the message from 'Daniel', or perhaps
the Microsoft discussion web interface makes proper posting difficult? If
you must stick with Microsoft, perhaps Outlook Express is indicated.

Phil Weldon

| If you would allow it sir, you can contribute to the general community by
| calling
| Microsoft Security at 866 727 2338 should you deem this file is a new
virus
| undetected. The support team can delete it for you and ask for some sample
to
| to be added to Microsoft security apps to better protect other people who
| would get same instances as you have
|
| thanks
| --
| Milo
| MSPSS
|
|
| "David H. Lipman" wrote:
|
| >
| > | Last night I discoved a virus on my XP machine. The strange thing is
none of
| > | my virus or anti-spyware software packages picked it up. I noticed
over the
| > | last few days that my page file would grow over 3 gigs (it never does)
and I
| > | started recieving 'low on virtual memory errors', so I started digging
(keep
| > | in mind i was never low in physical memory and nothing was running in
task
| > | manager). I found a file via msconfig - startup called 70hasd1.exe
(which is
| > | telling) so I disabled it and deleted the file from the
windows\system32
| > | folder and rebooted the machine. After a reboot the file reappeared
as
| > | 812332.exe (seems like random names each time), but the file always
had the
| > | same modifed date and size - 12 KB. I removed the file and searched
my
| > | machine eventually locating the source (I am hopeful anyways). This
morning
| > | when I looked at the event logs I noticed a ton of Scheduler errors -
it
| > | seems this virus had placed itself into Schedular using a different
name and
| > | time to run each day. So far my machine seems fine, the pagefile is
back to
| > | normal and there are no other items in msconfig or suspects that I can
see.
| > | I have never seen a virus use windows scheduler before and I have
never seen
| > | one that grows the page file to an enormous size - does anyone know
what it
| > | was doing and is this unusual or the norm ?
| >
| > You are being presumptuous in calling this a "virus". It may be a
Trojan but I don't think
| > you are infected with a virus.
| >
| >
| > Download MULTI_AV.EXE from the URL --
| > http://www.pctipp.ch/downloads/dl/35905.asp
| >
| > To use this utility, perform the following...
| > Execute; Multi_AV.exe { Note: You must use the default folder
C:\AV-CLS }
| > Choose; Unzip
| > Choose; Close
| >
| > Execute; C:\AV-CLS\StartMenu.BAT
| > { or Double-click on 'Start Menu' in C:\AV-CLS }
| >
| > NOTE: You may have to disable your software FireWall or allow WGET.EXE
to go through your
| > FireWall to allow it to download the needed AV vendor related files.
| >
| > C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in
C:\AV-CLS}
| > This will bring up the initial menu of choices and should be executed in
Normal Mode.
| > This way all the components can be downloaded from each AV vendor's web
site.
| > The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and
Reboot the PC.
| >
| > You can choose to go to each menu item and just download the needed
files or you can
| > download the files and perform a scan in Normal Mode. Once you have
downloaded the files
| > needed for each scanner you want to use, you should reboot the PC into
Safe Mode [F8 key
| > during boot] and re-run the menu again and choose which scanner you want
to run in Safe
| > Mode. It is suggested to run the scanners in both Safe Mode and Normal
Mode.
| >
| > When the menu is displayed hitting 'H' or 'h' will bring up a more
comprehensive PDF help
| > file.
| >
| > Additional Instructions:
| > http://pcdid.com/Multi_AV.htm
| >
| >
| > * * * Please report back your results * * *
| >
| >
| > --
| > Dave
| > http://www.claymania.com/removal-trojan-adware.html
| > http://www.ik-cs.com/got-a-virus.htm
| >
| >
| >



Similar ThreadsPosted
I think I've found a virus.... September 7, 2007, 3:35 pm
virus found April 6, 2008, 5:34 pm
Virus found: IRC/Backdoor.flood February 5, 2007, 7:10 pm
avg found a virus called downloader.tibs October 4, 2006, 5:06 pm
RE: annoynmous virus found in Win2K3 and also spread to memory flash d May 1, 2007, 2:11 pm
SOPHOS found... September 27, 2006, 6:01 pm
vius found on computer February 15, 2007, 10:55 am
Adaware critical object found May 17, 2006, 8:07 am
RE: Adaware critical object found May 17, 2006, 11:19 pm
Infection found: Win32/Parasitic-gen February 5, 2007, 7:23 pm

The site map in XML format XML site map

Contact Us | Privacy Policy