Computing.Net > Forums > Security and Virus > Anyone know this virus?

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Anyone know this virus?

Reply to Message Icon

Name: namsupo
Date: January 22, 2009 at 03:29:16 Pacific
OS: Windows XP
CPU/Ram: n/a
Product: N/a / N/A
Subcategory: Viruses
Comment:

Hi people, am hoping someone might recognise these symptoms as a virus and know what to do! Friend of mine's business has just been hit by something but I can't work out what it is. Symptoms are:

- Periodically (every 30-60 minutes or so), around 40 pages are sent to every printer on every computer on the network (even shared printers). The printed pages are related to porno sites. The print jobs are listed as both "Remote Downlevel Document" owned by the Guest account, and "Local Downlevel Document" which is owned by the local user.

- Some computers (but not all) on the network have multiple directories created (in C: and in C:\ sub directories and possibly other locations), all called "-= Porn Collection =-" which contain screenshots and links to porno websites.

I've done lots of googling and I can't find any reference to what this virus might be. The only reference to a virus that submits print jobs I can find is BugBear but it doesn't seem to have the porn collection and that was around about 5 years ago so you'd think modern AV software would pick it up (all these computers have updated AV software on them btw!)

Can anyone help???
Thanks!



Sponsored Link
Ads by Google

Response Number 1
Name: amvinfe
Date: January 23, 2009 at 09:09:04 Pacific
Reply:

Hi,
download to your desktop
http://www.suspectfile.com/systemscan
open it and make sure that all options are checked, click on "Scan Now" at the end of the scan will be released (always on your desktop inside the folder suspectfile) two files.
Go to office http://www.freefilehosting.net the zip file and write in your next reply URL where I can get it.

Remember the scan with no connection with the antivirus disabled unless then resume scanning finished.

SystemScan is recognized, mistake, by some antivirus as infected.

Ciao,
Marco


0

Response Number 2
Name: namsupo
Date: January 26, 2009 at 03:45:24 Pacific
Reply:

Thanks a lot for your help. The report is here:

http://freefilehosting.net/download...

If you have any ideas please let me know! Thanks!


0

Response Number 3
Name: amvinfe
Date: January 27, 2009 at 16:29:07 Pacific
Reply:

Hi
There are many values infected, for example
C:\WINDOWS\system32\drivers\lsass.exe
C:\WINDOWS\system32\icondrv.exe
and many others.

The problem now is that we must work in the system registry to restore the two values in
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon

[Winlogon]
"Shell"
and
"Userinit"

We can do even using HijackThis, so we do it automatically.

So please, download HijackThis
http://www.trendsecure.com/portal/e...

Install HijackThis, go to the folder and run the program Hijackthis.exe
select the button "Do a system scan and save a logfile."

Now brought into the program folder and copy and paste the log.

Thank you


0

Response Number 4
Name: virus-problem
Date: March 11, 2009 at 04:01:05 Pacific
Reply:

Hi.
I am having the same problem so I was very interested in the dialog going on about this issue. However, it seems like it was never completed.
So if anyone has the time to take a look at my logfile I would be glad to post it.
Thanks.


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Anyone know this virus?

Virus causes dirt on screen www.computing.net/answers/security/virus-causes-dirt-on-screen/934.html

Does anyone know anything about thi www.computing.net/answers/security/does-anyone-know-anything-about-thi/2969.html

Has anyone else seen this? virus? www.computing.net/answers/security/has-anyone-else-seen-this-virus-/6376.html