richuu
09-23-04, 11:06
I have some weird stuff going on with a couple of W2K machines at work... both pointing at the same kind of infection. I noticed the first after OfficeScan Corp Ed found the spyw_firstlook.a virus/spyware. This was cleaned up no problem, but since I removed some of the files manually, I lost the network connection on the PC due to a damaged LSP stack (used LSPfix to repair).
After this, all was well, but I noticed a process running in Task Manager which I know shouldn't be there. I don't still have the filename, but it was a random 6 character name, both numbers & letters. (others on second PC are NJ7793.exe, CB9E7F, FVE3EB, YX23D0, ZT6255......) I couldn't terminate the process, and couldn't delete the file from C:\winnt\temp. If I rebooted to safe mode, neither instances exist. If I reboot normally, it will come back with a different name. In all cases, the file is 1,928k in size. The source file in the Temp dir, with the same name as the running process is always 169Kb.
I've been through all the 'fix' processes - online scans, HJT, etc. (I'm very confident with HJT and know what should and shouldn't be there!) and I've also manually checked the HKLM/Software/Microsoft/Windows/Current Version/Run and similar keys. None of these showed up anything.
The whole affair is very similar to CoolWebSearch or HomeShopping or whatever, but I can't find the companion DLL's as was the case with those. Ans as said, using all the named tools in both safe and normal mode come up with nothing.
Any ideas folks?
After this, all was well, but I noticed a process running in Task Manager which I know shouldn't be there. I don't still have the filename, but it was a random 6 character name, both numbers & letters. (others on second PC are NJ7793.exe, CB9E7F, FVE3EB, YX23D0, ZT6255......) I couldn't terminate the process, and couldn't delete the file from C:\winnt\temp. If I rebooted to safe mode, neither instances exist. If I reboot normally, it will come back with a different name. In all cases, the file is 1,928k in size. The source file in the Temp dir, with the same name as the running process is always 169Kb.
I've been through all the 'fix' processes - online scans, HJT, etc. (I'm very confident with HJT and know what should and shouldn't be there!) and I've also manually checked the HKLM/Software/Microsoft/Windows/Current Version/Run and similar keys. None of these showed up anything.
The whole affair is very similar to CoolWebSearch or HomeShopping or whatever, but I can't find the companion DLL's as was the case with those. Ans as said, using all the named tools in both safe and normal mode come up with nothing.
Any ideas folks?