home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Technical Support
Ask a Tech Support Question (free)!

Weird ZIP files all over

Reply
Get bargains at  »  Dealighted.com
 
Thread Tools Search this Thread
Currently Active Users: 1944
Discussions: 200,992, Posts: 2,379,903, Members: 246,360
Old March 12th, 2004, 06:01 PM   Digg it!   #1 (permalink)
Ultimate Member
 
implexant's Avatar
 
Join Date: Jun 2002
Location: Vancouver, WA, USA
Posts: 2,696
Send a message via ICQ to implexant Send a message via AIM to implexant Send a message via MSN to implexant Send a message via Yahoo to implexant
Weird ZIP files all over

Hi there,

I have a client who just called, two of their eight computers have these weird zip files all over the place. They are named things like asdikljsda.zip, 390asdljk892.zip, asdjklsadklj.zip. Just odd random names. On the root of C:\, desktop, my documents, program files, you name it, there's at least one zip file around. They have a fairly secure network, with a router/firewall and Symantec Corporate Virus Scan running constantly. A win2k domain controller exists and controls everything.

One of the computers is also missing some files in My Documents.

I'm scanning it for viruses as we speak, but I can't believe anything would have gotten through.

Any ideas on how to get her files back? And how they went away?

TIA

-Chris
implexant is offline   Reply With Quote
Old March 12th, 2004, 06:02 PM     #2 (permalink)
Mean Moderator
 
EvilRick's Avatar
 
Join Date: Oct 2001
Location: N of Music City, USA
Posts: 7,791
Sounds like a "worm". I just had somebody with the same thing. Norton removed it, but don't remember exactly which "worm" it was.
__________________
This signature intentionally left blank.
EvilRick is offline   Reply With Quote
Old March 12th, 2004, 06:06 PM     #3 (permalink)
Ultimate Member
 
implexant's Avatar
 
Join Date: Jun 2002
Location: Vancouver, WA, USA
Posts: 2,696
Send a message via ICQ to implexant Send a message via AIM to implexant Send a message via MSN to implexant Send a message via Yahoo to implexant
I see, well SAV isn't recognizing it, even with today's definition. I've also noticed alot of oddly and randomly named .exe files all over the place. It has spread to networked drives, but of course unless the exe is run on the other computers, it still only effects one computer.

Odd, wish I had the name of the worm.

Thanks ER!

-Chris
implexant is offline   Reply With Quote
Old March 12th, 2004, 06:10 PM     #4 (permalink)
Mean Moderator
 
EvilRick's Avatar
 
Join Date: Oct 2001
Location: N of Music City, USA
Posts: 7,791
I'm looking.

I think it was Beagle or a variant of it.
EvilRick is offline   Reply With Quote
Old March 12th, 2004, 09:29 PM     #5 (permalink)
Ultimate Member
 
implexant's Avatar
 
Join Date: Jun 2002
Location: Vancouver, WA, USA
Posts: 2,696
Send a message via ICQ to implexant Send a message via AIM to implexant Send a message via MSN to implexant Send a message via Yahoo to implexant
Got the latest def file and it's detecting as MyDoom

Go figure.

-Chris
__________________
http://www.implexant.com
implexant is offline   Reply With Quote
Old March 14th, 2004, 07:20 PM     #6 (permalink)
I'm silently judging you
 
ArcticFox's Avatar
 
Join Date: Jan 2003
Location: Lincoln City, OR
Posts: 5,379
Send a message via AIM to ArcticFox Send a message via MSN to ArcticFox Send a message via Yahoo to ArcticFox
How big are the random EXE and ZIP files?
ArcticFox is offline   Reply With Quote
Old March 14th, 2004, 10:00 PM     #7 (permalink)
Ultimate Member
 
implexant's Avatar
 
Join Date: Jun 2002
Location: Vancouver, WA, USA
Posts: 2,696
Send a message via ICQ to implexant Send a message via AIM to implexant Send a message via MSN to implexant Send a message via Yahoo to implexant
Didn't check, and VNC isn't working on her workstation for whatever reason. I'm going to have to wait until Monday to finish this up.

-Chris
implexant is offline   Reply With Quote
Old March 17th, 2004, 08:55 PM     #8 (permalink)
Member
 
Join Date: Oct 2003
Posts: 60
The latest variant was around for 1-2 days before it was added to the AV data files, so that would explain why it wasn't caught by the AV software. The real question in my mind is how did those files get onto her hard drive without user intervention? One can receive these as e-mail attachments and simply delete the e-mails. So I'm guessing she saved them onto the hard drive herself?

Hedda Lora
HeddaLora is offline   Reply With Quote
Old March 17th, 2004, 10:38 PM     #9 (permalink)
Ultimate Member
 
implexant's Avatar
 
Join Date: Jun 2002
Location: Vancouver, WA, USA
Posts: 2,696
Send a message via ICQ to implexant Send a message via AIM to implexant Send a message via MSN to implexant Send a message via Yahoo to implexant
Quote:
Originally posted by HeddaLora
The latest variant was around for 1-2 days before it was added to the AV data files, so that would explain why it wasn't caught by the AV software. The real question in my mind is how did those files get onto her hard drive without user intervention? One can receive these as e-mail attachments and simply delete the e-mails. So I'm guessing she saved them onto the hard drive herself?

Hedda Lora

Turns out that she did open it, but thought she didn't. Got an email from me (spoofed of course) and opened it. Ended up being the virus.

The spoofers are using my address alot. Irritates me.



-Chris
implexant is offline   Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Most Active Discussions
Is It Just Me? (3083)
Charges against non-tippers dropped.. (20)
Health Care Rationing (13)
Delete an OS (17)
Nvidia GTX 260 problem (10)
Laptop with wireless problem. (12)
Wireless Televisions. (12)
windows vista security holes (19)
CPU fan stops spinning randomly (11)
Regular Build (11)
[F@H SPAM 11/16/09] ! 1/2 months to.. (41)
Point and Shoot Camera Suggestions. (8)
windows 7 problem (7)
Internet Lost (5)
Recent Discussions
[F@H SPAM 11/16/09] ! 1/2 months to r.. (41)
Print spooler problem (17)
Foxconn Blackops x48 MoBo (3)
Q9650 vs. Q9550 (2)
Desktop Calendar Application (2)
Looking for new motherboard (1)
soundmon.exe (8)
Jedi Academy Problem (3)
Can a page file be "too big".. (1)
Nvidia GTX 260 problem (10)
Point and Shoot Camera Suggestions. (8)
Size after cutting 700Mb file is 2.5 .. (0)
Delete an OS (17)
windows vista security holes (19)
updating BIOS via winflash, claims fi.. (1)
New Server Configuration Suggestions (0)
cheap gaming laptop? (12)
Unallocated Space (2)
help me pls laptop just stopped worki.. (1)
C# + LINQ Help (7)
Dynex DX E-402 (3)
EVGA 9800 gtx help with finding a goo.. (12)
Multiple Restarts Required at Boot (5)
cell phone won't work (0)
Is the PSU I received dead? (15)


All times are GMT -4. The time now is 09:51 AM.
TechIMO Copyright 2009 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28