Win32.Novarg.A@mm in dbx files

Discussion in 'Malware Help (A Specialist Will Reply)' started by abri, Aug 21, 2006.

  1. abri

    abri MajorGeek

    Old problem, no solution. My only concern at the moment is whether any of these are for breakins? Otherwise this is NOT pressing.

    Bitdefender continues to come up with the same infected files in my dbx inbox files for Outlook Express. I haven't yet been able to get rid of these files and I wondered if the find files program would help or if there is some dbx translation software, that might put the dbx files into a form to where I could find the contaminated files. Searches inside of Outlook Express and inside of Win Explorer don't work, including system searches, searches of words within texts, date searches, any searches I've been able to think of. I'm out of ideas, except perhaps to change to a different e-mail client. If it's not possible for me to clean these files out, can someone recommend a better e-mail client? That would also work, except that I would like to keep my Outlook Express files of the last years.

    I'm running XPhomeSp2, P-IV, 1.8 Ghz. My computer is running well. I will read up on Novarg to see what it does. Since I don't have computer problems that I can notice, I wondered if these things Bitdefender is finding might be in attachments and not loose and active?

    Sorry, to keep coming back with the same things. I'll post my logs, but will tell you in advance, I ran them CC, AdAware, & Spybot yesterday, Windows Defender 2 days ago, then Bitdefender & Panda last night and then runkeys and then show-new and then CC again and then Hijack This. If I don't have to do them over again in the right order, I would be grateful. I didn't run windows Malicious, but will. I can also try running Trend Micro or Kaspersky online if this would help. My computer's been coming up pretty clean except for these repeat offenders. There must be a way to clean up these dbx files or maybe just get another client.

    Thanks so much.
    abri
     

    Attached Files:

  2. abri

    abri MajorGeek

    the other two
     

    Attached Files:

  3. abri

    abri MajorGeek

    I went to a Bitdefender site and downloaded Antinovarg-de.exe and will try running that.
    abri
     
  4. abri

    abri MajorGeek

    oh, and one last question: why doesn't avg pick up on this one if it's a mydoom variant?
    abri
     
  5. abri

    abri MajorGeek

    I have this in my registry so I think it must be running.

    HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32

    thanks for help.
    abri
     
  6. abri

    abri MajorGeek

    Okay, I did a Kaspersky online scan and it gave the following log which identifies the same viruses, but can't remove them because they're locked.
    Thanks for reading this thread. If the viruses are active, I'd like to get them out of there.
    abri
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to run Outlook Express and delete these file manually.

    I assume that Posteingang in english is equal to Inbox

    Thus go to your Inbox (which shows under M:\Outlook\original\default ) and delete the messages that Bitdefender indicates. They appear to be messages number 11, 153, & 154. If this is not an active user account, you will have to just delete the old folder.

    The messages appear to have the below in them:

    # 11 - text.htm .pif
    #153 - Subject: Hello,abridge,the Garden of Eden
    #154 - Subject: Hello,abridge,the Garden of Eden

    Note you are using an outdated version of ShowNew
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is drive M where you currently store all of your Outlook email? If not, is drive M just an old backup?
     
  9. abri

    abri MajorGeek

    Hi Chas,
    Drive M is where I store all my current OE dbx files. They're not old files and they're not from a different user name. I can't delete the things BitDefender finds, because I can't find them. As I mentioned with an earlier thread, I've actually searched the entire computer for the words and dates that BitDefender indicates, not just the dbx files. That's why I was wondering if there is a way to translate dbx files into something that I can open and look at. I don't have any numbers attached to the dbx files. I don't even know what the numbers refer to.
    From within OE, no search (I've tried every search I can think of) comes up with any of the information I'm getting from BitDefender, but I'm more worried at what Kaspersky came up with. I don't know how to tell if the files are active. I do have a change in the registry as indicated in my 5th post which looks like the virus is at least in the registry. When Kaspersky writes that it can't fix the viruses because it is blocked, what is it referring to? I don't like having icky stuff on my computer without knowing if it's doing icky stuff or just sitting there.
    Thanks so much.
    abri
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If both Bitdefender and Kaspersky are finding these problems in your Posteingang.dbx file then the messages do exist. Perhaps you have some kind of filter setup that is hiding things from your view. Perhaps they are even semi-deleted and your Outlook email database is corrupted and not showing them. But the text for them is in the dbx file. You could probably even load it into a binary editor or maybe even into Wordpad and see the info yourself. BUT DO NOT EDIT THEM AT ALL. If you do, you will corrupt the file.

    I'm not sure what you are trying to tell me about the 5th post. The below is a valid registry key and should exist:

    HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32

    It will contain things like:
    LastVisitedMRU
    OpenSaveMRU
     
  11. abri

    abri MajorGeek

    Oh, what I was trying to tell you about the 5th post is that I went to a website to read about Novarg and one of the things it said was if this ComDlg32 was in the registry either under the HKCU path or the HKLM path, then it was an indication the virus was there. I was looking for information that would help me figure out the viruses are active or not. Your comment about this being a legit file is why I don't like just hunting around the internet for information.

    Word Pad is not an option in my list of opening devises (??wondering why ... maybe I don't have WordPad at the moment), but I opened it in Editor and as a text it looks like this (as an example):

    wDpps/gr0231C0vIfNt5d6SfP8AaI6+dxOG9mfRYPE/YJo5PMPmx/3P9ZUkcfmJ
    J0euM9QI/OkXzfk/dv8AJRHHL/qo/wDlp9/y6mYIP+viL+PZ5dJH5Un7qSX/AFf/AJEqgGxyfJ9l
    +d0/g/jqKSOXZ5Ucu87/APlpQA2T7/m/fNNuI5f+B/8APSOpgDG+XIUSKSJH8z/lpUL/ALz/AFkT
    7/8AnpH/AMtKk0HZ/wCenzvUcsnmJ5UnT7lHxkaDZI​

    I didn't understand in my Kaspersky log why it says "object is locked". It said this for everything it found. Could that mean that it was locked by a previous antivirus program? Or do you think it might be locked by the virus itself? Or, possibly by Outlook Express? In the last year I've used Nortons, Kaspersky 6 and AVG free, and so it surprises me the viruses are still showing up in the scans. In the Kaspersky log file, it lists 13 infected objects. One is:

    C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Microsoft\Crypto\DSS\MachineKeys\92c65e2e2ccb44dd6aef001d65c0e1ab_ca37b8bb-ea16-4c0c-b2f7-5dba26e15d13 Object is locked skipped

    I don't know what the MachineKeys in the above pathway refers to. It sounds important. Dokumente und Einstellungen is Documents and Settings. Anwendungsdaten is maybe Applications or ApplicationsData in English. I'll check that when I'm on an English computer.

    I've been thinking about this problem for some months, and the problem about my changing to another e-mail client is that I would need to import my working files from Outlook Express. I imagine as soon as I import anything, I would simply take the viruses with me.

    There's a tool called AntiMyDoom-DE.exe that I can try running, but I don't recognize any of the websites that are recommending it. I found the Engllish version called AntiMyDoom-EN.exe at this site: http://www.pro-support.de/antivirus.shtml
    One of the tools at the German site is called Antisober-DE.exe which is in a simple listing of removal tools at http://sicherheit.altmuehlnet.de/sw/removals.htm

    Generally, I can only run the -DE versions of programs. (I wonder who had the bright idea of coming up with a German-language microsoft computer, German referring to something in the programs itself, not just the interface.)

    Should I try running this?
    Sorry, I'm running out of ideas.
    abri
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not true (as you now know). As I said that is a valid registry key the will be in all PCs and you are right.....you cannot always believe everything you read. There may be more details to it than being mentioned.

    You have to add it yourself to the SendTo folder or you could just run Wordpad and navigate to the file to open it. A binary editor is still a better choice but I knew you would have Wordpad.

    That's because it is in binary. You have to search for the text strings that the virus scanners are giving you to find the area of the file that they are telling you about.


    No it did not say that for eveything found. It said it for all files that were locked. For files where it actually scanned and found an infection, it said skipped. It skips because it is not a removal tool unless you buy it.

    A file can be locked for many reasons and it is perfectly normal. Many files are protected by the OS, or if an application that is running is using the file it is also locked. Without reading every single line in your log right now, a brief scan just reveals that most things that were locked should be locked.

    The only files on your PC that were flagged as infected are these two:
    It did not find 13 infected files! It found 13 infected objects and some were in the same file! There were 9 objects found in your Posteingang.dbx file and 4 in the WinBORGXPV4.0.ISO file (which by were not true infections - it said they were not-a-virus:RiskTool )


    Kaspersky did not say it was infected. It said it was locked. This is valid Windows system folder which should be locked.

    I don't know anything about those tools and have never used them so I cannot in good conscience recommend them. It's your choice. Just be aware that no program can always fix everything. Also no program can fix something if the file is in use or locked. So you have to be sure that you are not running anything that could interfere with any scan/removal tool. That is one reason we boot in safe mode. Less runs by default in safe mode. But it still could be necessary to shut other processes down. Even then, there will still be files locked by the OS.
     
    Last edited: Aug 24, 2006
  13. abri

    abri MajorGeek

    Thanks Chas! That was a very long post and I appreciate all the details!
    I know this has been simmering quite awhile on the back burner while I was away. My son suggested I switch to Thunderbird, which I would like to do. I foresee the obvious problem, that if I import the e-mails from Outlook Express, the viruses will still be there. Is there any chance that I will have better luck locating them in Thunderbird than I had in Outlook Express, since I wasn't able to translate the dbx files in Outlook Express? Will that be the same problem in Thunderbird?
    Thanks!
    abri
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I cannot answer that question! If you cannot see the infected messages yourself then I would doubt you can even import them into Thunderbird!
     
  15. abri

    abri MajorGeek

    oh..
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds