»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Tech Support

Reply
 
LinkBack Thread Tools Display Modes
Old 03-12-2004, 03:01 PM   #1 (permalink)
Registered User
 
implexant's Avatar
 
Join Date: Jun 2002
Location: USA
Posts: 1,991
implexant is on a distinguished road
Send a message via ICQ to implexant Send a message via AIM to implexant Send a message via Yahoo to implexant Send a message via Skype™ to implexant
Weird ZIP files all over

Hi there,

I have a client who just called, two of their eight computers have these weird zip files all over the place. They are named things like asdikljsda.zip, 390asdljk892.zip, asdjklsadklj.zip. Just odd random names. On the root of C:\, desktop, my documents, program files, you name it, there's at least one zip file around. They have a fairly secure network, with a router/firewall and Symantec Corporate Virus Scan running constantly. A win2k domain controller exists and controls everything.

One of the computers is also missing some files in My Documents.

I'm scanning it for viruses as we speak, but I can't believe anything would have gotten through.

Any ideas on how to get her files back? And how they went away?

TIA

-Chris

implexant is offline   Reply With Quote
Old 03-12-2004, 03:02 PM   #2 (permalink)
Guest
Guest
 
Posts: n/a
Sounds like a "worm". I just had somebody with the same thing. Norton removed it, but don't remember exactly which "worm" it was.
  Reply With Quote
Old 03-12-2004, 03:06 PM   #3 (permalink)
Registered User
 
implexant's Avatar
 
Join Date: Jun 2002
Location: USA
Posts: 1,991
implexant is on a distinguished road
Send a message via ICQ to implexant Send a message via AIM to implexant Send a message via Yahoo to implexant Send a message via Skype™ to implexant
I see, well SAV isn't recognizing it, even with today's definition. I've also noticed alot of oddly and randomly named .exe files all over the place. It has spread to networked drives, but of course unless the exe is run on the other computers, it still only effects one computer.

Odd, wish I had the name of the worm.

Thanks ER!

-Chris
implexant is offline   Reply With Quote
Old 03-12-2004, 03:10 PM   #4 (permalink)
Guest
Guest
 
Posts: n/a
I'm looking.

I think it was Beagle or a variant of it.
  Reply With Quote
Old 03-12-2004, 06:29 PM   #5 (permalink)
Registered User
 
implexant's Avatar
 
Join Date: Jun 2002
Location: USA
Posts: 1,991
implexant is on a distinguished road
Send a message via ICQ to implexant Send a message via AIM to implexant Send a message via Yahoo to implexant Send a message via Skype™ to implexant
Got the latest def file and it's detecting as MyDoom

Go figure.

-Chris
implexant is offline   Reply With Quote
Old 03-14-2004, 04:20 PM   #6 (permalink)
Registered User
 
ArcticFox's Avatar
 
Join Date: Jan 2003
Location: Wilsonville, OR
Posts: 2,220
ArcticFox is on a distinguished road
Send a message via AIM to ArcticFox Send a message via MSN to ArcticFox Send a message via Yahoo to ArcticFox Send a message via Skype™ to ArcticFox
How big are the random EXE and ZIP files?
ArcticFox is offline   Reply With Quote
Old 03-14-2004, 07:00 PM   #7 (permalink)
Registered User
 
implexant's Avatar
 
Join Date: Jun 2002
Location: USA
Posts: 1,991
implexant is on a distinguished road
Send a message via ICQ to implexant Send a message via AIM to implexant Send a message via Yahoo to implexant Send a message via Skype™ to implexant
Didn't check, and VNC isn't working on her workstation for whatever reason. I'm going to have to wait until Monday to finish this up.

-Chris
implexant is offline   Reply With Quote
Old 03-17-2004, 05:55 PM   #8 (permalink)
Registered User
 
Join Date: Oct 2003
Posts: 31
HeddaLora is on a distinguished road
The latest variant was around for 1-2 days before it was added to the AV data files, so that would explain why it wasn't caught by the AV software. The real question in my mind is how did those files get onto her hard drive without user intervention? One can receive these as e-mail attachments and simply delete the e-mails. So I'm guessing she saved them onto the hard drive herself?

Hedda Lora
HeddaLora is offline   Reply With Quote
Old 03-17-2004, 07:38 PM   #9 (permalink)
Registered User
 
implexant's Avatar
 
Join Date: Jun 2002
Location: USA
Posts: 1,991
implexant is on a distinguished road
Send a message via ICQ to implexant Send a message via AIM to implexant Send a message via Yahoo to implexant Send a message via Skype™ to implexant
Quote:
Originally posted by HeddaLora
The latest variant was around for 1-2 days before it was added to the AV data files, so that would explain why it wasn't caught by the AV software. The real question in my mind is how did those files get onto her hard drive without user intervention? One can receive these as e-mail attachments and simply delete the e-mails. So I'm guessing she saved them onto the hard drive herself?

Hedda Lora
Turns out that she did open it, but thought she didn't. Got an email from me (spoofed of course) and opened it. Ended up being the virus.

The spoofers are using my address alot. Irritates me.



-Chris
implexant is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 02:05 PM.