home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Security and Privacy Issues
Join TechIMO for Free!
Register Blogs FAQ Members List Calendar Search Today's Posts Mark Forums Read
Reply Get bargains at  »  Dealighted.com
 
Thread Tools
Currently Active Users: 1963
Discussions: 186,591, Posts: 2,226,905, Members: 230,218
Free Scan: Update Your PC's Outdated Drivers to Optimize Performance
Old April 27th, 2007, 01:05 PM   Digg it!   #1 (permalink)
Ultimate Member
 
blubomber's Avatar
 
Join Date: Oct 2001
Location: Reno, NV
Posts: 1,598
Send a message via MSN to blubomber Send a message via Yahoo to blubomber
Help Needed indentifying Virus or Trojan

Hello,

I have a system that i am working on. It is a windows 2000 server with SP4 and it has been infected by something.

Symptoms.... upon booting the computer and having it disconnected from the network, the computer runs fine but there is a rogue process in the task manager. It is a six alpha numeric .exe file. but i changes every time the computer is restarted. Also, when doing a search, the file shows up in the temp directory on the C: drive. Once the computer is plugged into the network, after about 5 minutes or so it becomes slow and eventually locksup and only a hard reboot gets it back.

The computer does have the Trend Micro antivirus enterprise software on it but it cant find anything when doing a scan with updated virus definitions. I have also run Adaware, Spybot and hijackthis but they did not get rid of it. I have been able to do some research but i just cant pinpoint which virus or trojan it is. I believe very strongly that it is taking advantage of a DCOM vulnerability in windows 2000 that has gone unpatched.

So, has anyone run into these symptoms before and know what virus this is?

Oh, one more thing. The file in the temp folder that is created has an icon that looks like a scottish terrior.

Thanks for any help.
__________________
"Life moves pretty fast, if you dont stop to look around once in a while, you could miss it." -FB

blubomber is offline   Reply With Quote
TechIMO.com Ads - Login or register for less ads.
How many errors does your computer have?

You no longer need to guess! This free stability scan and registry cleaner download will give you a complete diagnosis of your Windows registry, identifying errors and conflicts.

FREE instant scan


Guest, Register Free! to remove this ad and get your tech support questions answered in minutes!
Old April 27th, 2007, 02:15 PM     #2 (permalink)
Ultimate Member
 
PoonDoggy's Avatar
 
Join Date: Oct 2001
Location: Texas
Posts: 1,102
Send a message via Yahoo to PoonDoggy
Quote:
Oh, one more thing. The file in the temp folder that is created has an icon that looks like a scottish terrior.
Do you have Win patrol on this computer?

http://answers.google.com/answers/threadview?id=568868

Quote:
- WinPatrol

"WinPatrol uses a heuristic approach to detecting attacks
and violations of your computing environment. Traditional
security programs scan your hard drive searching for
previously identified threats. WinPatrol takes snapshot
of your critical system resources and alerts you to any
changes that may occur without your knowledge."
http://www.winpatrol.com/

This program loads with Windows and sits in the system
tray, offering many features. The most noticeable are
when Scotty, the Scottish Terrier, barks to alert you
that a new program has been added to the Windows Startup
sequence, either in the registry or the Startup Folder.

Since one of the ways that viruses multiply themselves
is to add an entry to Windows Startup, this is a very
valuable program. You can immediately deny any program
from placing a startup entry.

You can also use the program by double-clicking on the
tray icon. Scotty will bark in response, and you'll
have access to several tabs of options, including
viewing Startup Programs, Active Tasks, IE Helpers,
Cookies, and much, much more.

Scotty can also be set to monitor any changes made to
your HOSTS file. Much more on this later.
__________________
Don't let your head get cut off unless you know what you are doing.

http://www.ninja.co.uk/manar/pics/Vectra/vectra6.html

PoonDoggy is offline   Reply With Quote
Old April 27th, 2007, 03:05 PM     #3 (permalink)
Ultimate Member
 
blubomber's Avatar
 
Join Date: Oct 2001
Location: Reno, NV
Posts: 1,598
Send a message via MSN to blubomber Send a message via Yahoo to blubomber
No, winpatrol is not loaded on the computer.

Thanks for the reply.

blubomber is offline   Reply With Quote
Old April 27th, 2007, 03:58 PM     #4 (permalink)
Mean Moderator
 
EvilRick's Avatar
 
Join Date: Oct 2001
Location: N of Music City, USA
Posts: 7,791
You may need to try another scanner like McAfee Stinger since you're software may have been disabled by the virus.

You might also want to try Spy Sweeper

Make sure 'System Restore' is disabled before running either of these. Hell, I'd just turn it off for good really.
__________________
This signature intentionally left blank.
EvilRick is offline   Reply With Quote
Old April 28th, 2007, 03:07 AM     #5 (permalink)
Ultimate Member
 
blubomber's Avatar
 
Join Date: Oct 2001
Location: Reno, NV
Posts: 1,598
Send a message via MSN to blubomber Send a message via Yahoo to blubomber
Thanks for the replies. I found out that the little file i was worried about is actually part of the TrendMicro anti virus app. But, it seems the problems i was having have gone away. I ran wireshark for a bit and saw that the server was trying to get to a website. After doing some research i found out that it was a trojan and how to get rid of it. The trojan was a process called w2symtec.exe. So, all is well.
blubomber is offline   Reply With Quote
Old October 3rd, 2008, 09:50 PM     #6 (permalink)
Junior Member
 
Join Date: Oct 2008
Posts: 1
Talking
Help

I have that on several of my servers, I have done an extensive search on w2symtec.exe and could not find any info on how to fix it.

Can you please post a little more info on how you fixed it
seatac is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may post new threads
You may post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
is it a virus or trojan ??? celticman Technical Support 10 June 28th, 2006 12:08 PM
Trojan Virus yochanda Security and Privacy Issues 6 October 27th, 2004 09:33 PM
Anti trojan virus protect your PC from trojan virus and shulippsl Security and Privacy Issues 3 August 21st, 2003 12:21 AM
Anti trojan virus protect your PC from trojan virus and worm gavinpeng Security and Privacy Issues 1 May 20th, 2003 02:59 AM
about the trojan virus krazy4purple2 Technical Support 5 October 2nd, 2002 09:23 AM

Most Active Discussions
Is It Just Me? (495)
heatsink issue (8)
Word Association!! (1655)
SSD's, RAID, and External Backup (6)
New Mobo (16)
1 internet. 1 house. 3 computer. ho.. (12)
UPGRADING C/D DRIVE TO 250GB & .. (10)
Is This A Compatible Gaming PC? (16)
Connected to LAN but unable to use .. (5)
Recent Discussions
Which applications are the best.. (3)
1 internet. 1 house. 3 computer.. (12)
Hard Core Overclock (10)
C++ compiler suggestions (2)
Letter Count Array (3)
SSD's, RAID, and External Backu.. (6)
Folderchat: The Holiday thread (113)
heatsink issue (8)
FS: New Benny Hill Megaset DVD .. (6)
Computer won't start (2)
FS: Dell 6000 laptop, modded 36.. (2)
Apple iPod touch 16 GB $200 (4)


All times are GMT -4. The time now is 01:20 AM.
TechIMO Copyright 2008 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28