Win32.Worm.Viking.BU removal help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by molexus, Feb 26, 2008.

  1. molexus

    molexus Private E-2

    Hello,

    I am using Bitdefender Antivirus Plus v10 wich keeps on detecting files getting created and infected with the virus name Win32.Worm.Viking.BU. I have searched on google about removal guides but in vain. I now hope that you guys could assist me in this.

    What happened was that i tried to save some information from a dieing hard drive wich seemed to be infected with this worm. Now i can't get rid of it. It creates copies of allready existing exe files and tries to infect them. For example if i have foo.exe the worm creates foo.exe.exe and tries to inject it with the worm code. Bitdefender seems to block all of these attempts but is unable to find the host program that does this, so i am beeing nagged with the worm detection window over and over.

    I have run the "READ & RUN ME FIRST Before Asking for Support" testing phases and will attach the logs i gained.

    Please let me know if you need anything else from me in order to help me remove this nagger from my system.

    thank you very much.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!
    Common names for this infection are:
    Win32/Looked.FY
    W32.Downloader (Symantec)
    W32/HLLP.Philis.dll (McAfee)
    W32/HLLP.Philis.fw (McAfee)
    W32.Looked.BK (Symantec)
    W32/Viking.BU (F-Secure)
    W32.Virus:Win32/Viking.EO (MS OneCare)
    Worm.Win32.Viking.dx (Kaspersky)
    W32/Agent.GA@adw (exact) (F-Secure)
    W32/Adware.GUK (exact) (F-Secure)

    Do you have a BitDefender log that you can attach that shows what it is finding and where it is finding it?
     
  3. molexus

    molexus Private E-2

    The BitDefender log is pretty much useless, it doesn't detect anything. Only when the host program becomes active and tries to infect files it blocks the infection. And it only infects unused executables. I haven't had any warnings of infections on the system partition ( C: ), only where i keep my junk ( D: ) Might it be a partition unaware worm? Don't know ... it's still active in the background, so it probably hides somewhere in the registry or is started by a system process. or maybe a hidden scheduled task. Anyways ... just thoughts.

    I'll attach the Bitdefender scan log to this message, maybe i'm missing something. I scanned all drives with all the options, if there is a scan that can find something it's this one.

    Regards.

    P.S. Ignore the Keylogger "infections", and the Viking infection stated there is when bitdefenders active protection was disabled. Usually there is nothing found since every infection attempt is blocked
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    BitDefender obviously does not like the Taskinfo program you have installed.
    The detection will continue unless you delete this file and uninstall the program that I see running in your HijackThis log. The choice is yours. Live with the detections, uninstall the program and delete files, get and update for BitDefender that does not detect this program if you believe it is safe, or get a different antivirus.
     
    Last edited: Feb 28, 2008
  5. molexus

    molexus Private E-2

    The problem is not the taskinfo program. It's a harmless process manager. I had it instaled long before the virus came up. And that exe is the installation kit from it that got infected while bitdefender was inactive.

    Sometimes bitdefender acts very weird and i can't see the buttons correctly anymore and i have to kill the process and start it over again. During that time i'm vulnerable to infections ... that's when the taskinfo installation file got infected. But as you can see it has been disinfected. I will attach a new scan log so you can see that this time there are no infections, however from time to time the bitdefender alert keeps popping up about blocking the viking worm. So the host program is still in there and i don't know witch one it is...

    You can check on taskinfo just to be on the safe side: http://www.iarsn.com/taskinfo.html
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are missing the point. I did not say it was malware. This is what BitDefender is now detecting as a problem. It does not matter how long you had the file. BitDefender updates all the time and a new update may now be what is causing the detection. That was the only file that you are showing me as being infected. Delete it and the detection will go away. Otherwise scan the file with other scanneres (like these: http://virusscan.jotti.org/ ) to see if they detect anything. Or as I stated, ask the people at SOFTWIN why BitDefender is detecting a file you believe to be clean.

    Reinstall it or also ask SOFTWIN about this problem.

    You will need to provide more proof and show me a log that is showing BitDefender detecting something other then TaskInfo. If it is saying that it is something in memory, that also could be TaskInfo since you have it running at startup and is running as a service.

    Your logs were all basically clean. All I noticed is:

    C:\Program Files\BearShare <--- this folder should be deleted if it still exists.

    Java(TM) 6 Update 3 <--- you need to uninstall this old version and update as instructed in the READ ME.
     
  7. molexus

    molexus Private E-2

    If you look carefully at the first bitdefender log you will see that the taskinfo got disinfected, hence, in the second log there is no more infection so no need to delete the kit.

    I will attach some screenshots to show you what the active monitor of bitdefender is picking up.

    All these *.exe.exe files are blocked so the infection isn't actually spreading. I am also attaching a print screen with total commander showing that these files have 0 bytes.

    So the only conclusion i can come up with is that there's a "mother" process that spreads the worm witch is really really well hidden.

    ............... I just had a crazy idea. I read somewhere while googling that this worm can spread over network shares as well. So might it be that the "mother" process isn't actually on my computer but on my parents one? It is pretty plausible since only files from partition D: (witch is shared) get infected.

    I will make a test by putting some executables into a folder on drive c and share it. if those start getting attacked as well i think it's obvious isn't it?
     

    Attached Files:

  8. molexus

    molexus Private E-2

    and two other screens
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All that is obvious is that the files you created (I'm assuming you created them) that have multiple .exe extensions are falsely detected as a problem. The files have 0 bytes in size so how could they be infected. Or did they become 0 bytes after BitDefender cleaned the infection? Did you create fake files with multiple .exe extensions? Did you copy these files the other PC to this PC? Or did you just create them on this PC.

    But yes you are correct in assume that you can get infected from shared drives/folders. Read the info Symantec for W32.Looked.BK which is their name for this trojan. I gave you these other names for the trojan in message # 2.


    Have you run a full scan of drive D?
     
  10. molexus

    molexus Private E-2

    I did not create those exe files. This is what i've been talking about the whole time. There is a process that creates these files, witch are copies of the original exe files, then probably tries to infect them with the Looked trojan, delete the original then rename the copy to the original name, however since Bitdefender detects the infection process it denies access to the file and it remains with a size of 0 bytes.

    I ran a full system scan, (C and D) and Bitdefender couldn't detect anything (except the keylogger).

    I also copied some executables into a folder on my desktop to test the network shares infection theory and it seems correct. Suddenly i get infection attempts on those executables as well. In consequence i will attach to this post the logs gathered during the "READ & RUN ME FIRST Before Asking for Support" tests on my parents computer. Maybe the host program is over there (allthough i scanned it with Bitdefender and i still get no results).

    I also checked for the specific filenames in that report from symantec however i didn't find them either on my, nor on my parents computer. I'm totally in the dark of what's going on
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is nothing of interest in these new logs either.

    Does your version of BitDefender being used on both PCs have a firewall? I thought it would have one but I don't see anything in your logs that looks like a firewall.

    I'm going to give you a few scans to run on both PCs. The last ones will be online scanners and one of these online scanners will be from BitDefender. When you run these online scans, you may want to do it late at night when no one is going to need the PCs. They can take a long time to run and for the best and fastest results you really should not have anything else running or any other process open while doing the scans.

    First run this Using Sophos Anti-Rootkit on both PCs. Attach the logs when you come back. Be sure to label them so I can tell the difference between your PC and your parents.

    Now run this online scan on both Using BitDefender Online Scan and attach the log when you come back.

    Then just as an additional backup, it would be a good idea to run the below on both PCs too:

    Trend Micro Housecall

    Save and attach logs from this too.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds