Computing.Net > Forums > Security and Virus > win.exe.virus!

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

win.exe.virus!

Reply to Message Icon

Original Message
Name: Matthew Ebien-Pesa
Date: June 23, 2002 at 11:33:03 Pacific
Subject: win.exe.virus!
Comment:

According to my Virus-scanner,I have two(2) infected files,with the Win.exe.virus.Those files are: C:\cpqs\quicksr\PQFF\PQFFIN9X.EXE and,D:\CPQDRV\156376\B2A\022\156376.ZIP:CPQ...
According to the scan,they are probably infected with said virus,because it could not "read"them,because they are corrupted.Appreciated it very much,if somebody advises me what to do!
I thank you very much in advance!
Matthew.


Report Offensive Message For Removal


Response Number 1
Name: Tank863
Date: June 23, 2002 at 11:45:09 Pacific
Reply: (edit)

Matthew:

W32/Maldal-G is a worm which spreads as an email attachment.

The subject of the email is "ZaCker".
The name of the attachment is ZaCker.exe.

The email message text is chosen randomly from the following list :

Test this game
I wish u like it
I have got this file for you
Surprise !!!
download this game & have fun ;)
desktop maker ,you may need it ;)
have you ever got a gift !?
What women wants !
Don't waste any time ,Subscribe now
Make your pc funny !
new program from my fun groups
Map of the world
Create your Ecard
looooooooooooooooool
Send it to everybody you love
Its made by me ;)
Our symbol
If you have an elegant taste
Test your mind
1 + 1 = 3 !!!
See this file
Singer , searsh for any song and sing ;)
For everybody wants to marry a woman that he doesn't love !
nowadays , there is no womanhood !! :P
Just Try to fix it
Keep these advertisements run and earn 0.25 $ per 10 minute ;)

When the worm is run it will display a fake error message.

The message title is :
Project1

The fake message is :
Run time error '71'
Object required

The worm will then create a copy of itself named win.exe in the Windows system folder and add the registry value

HKLM\Software\Microsoft\Windows\
CurrentVersion\run\System

which contains the name of the copy.

The worm will also attempt to delete files used by anti-virus and other security software from the following directories :

Program Files\Zone Labs
Program Files\AntiViral Toolkit Pro
Program Files\Command Software\F-PROT95
eSafe\Protect
PC-Cillin 95
PC-Cillin 97
Program Files\Quick Heal
Program Files\FWIN32
Program Files\FindVirus
Toolkit\FindVirus
f-macro
Program Files\McAfeeVirusScan95
Program Files\Norton AntiVirus
TBAVW95
VS95
rescue

It will also delete files which have the following extensions

HTM
PHP
HTML
COM
BAT
MDB
XLS
DOC
LNK
PPS
PPT
JPG
MPEG
INI
DAT
ZIP
TXT

Finally the worm will change the name of the infected computer to "ZaCker".

What you need to do is use one of the free online scanners to remove the virus....
also use a worm/trojan scanner.

goto:
Trend Micro House Call Free Virus Scanner"

Swat-it Trojan/Worm Scanner

hope this helps....

Tank863

Tank863



Report Offensive Follow Up For Removal

Response Number 2
Name: Matthew Ebien-Pesa
Date: June 24, 2002 at 11:28:58 Pacific
Reply: (edit)

Hi! Tank863,
Thanks for your quick and excellent response.Did what you told me to do.Swat it found 2 files that were infected(C:\Windows\Desktop\Downloads\P...and C:\Windows\Desktop\Programs\Text... with the Invite engine virus. I choose the option,"Clean all"(in Swat it).Did I do the right thing and are the files de-infected or did I loose both files?If so,how do I get them back.Could not find said virus in the Symantec virus encyclopedia.Your input is greatly appreciated.
Matthew.


Report Offensive Follow Up For Removal







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home








Do you have your own blog?

Yes
No
I did before
I will soon


View Results

Poll Finishes In 4 Days.
Discuss in The Lounge
Poll History




Data Recovery Software