Forum     

Go Back   Digit Technology Discussion Forum > Software > Software Q&A
Register FAQ Calendar Mark Forums Read

Software Q&A Having trouble with software? Find solutions here


Closed Thread
 
LinkBack Thread Tools Display Modes
Old 09-03-2007, 03:21 PM   #1 (permalink)
Right Off the Assembly Line
 
Join Date: Jan 2006
Location: Belgaum
Posts: 20
Unhappy A Virus tale


My system has been infected by some sort of Virus stuff. The problem is that
even after scanning with latest Norton Antivrus 2007, Avast 4 Professional.
The virus still exits and affects my Pen Drive by copying some DOS executable stuff. Other interesting thing is that even after terminating the process of the executable file it restarts itself. The process files are named as "Severe.exe", "Conime.exe" and "Jusdol.exe". So, could anyone help me out?
__________________
Nikhils
Nikhilsam is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 09-03-2007, 03:38 PM   #2 (permalink)
Right Off the Assembly Line
 
deadpulse's Avatar
 
Join Date: Feb 2007
Location: Sin City
Posts: 41
Default Re: A Virus tale

Use AVG Antivirus free edition and scan your system in DOS mode. Norton and other antivirus don't scan system is DOS mode. Also, you can try using NOD32 anti-virus its the best virus since 2006.
__________________
"Attitude is not walking like a King, it's walking like I don't care who the King is......"
deadpulse is offline  
Old 09-03-2007, 03:39 PM   #3 (permalink)
HELP AND SUPPORT
 
rakeshishere's Avatar
 
Join Date: Jun 2006
Posts: 1,603
Default Re: A Virus tale

Must be Spyware..Run any gud Antispyware like ewido or spybot...
rakeshishere is offline  
Old 09-03-2007, 03:47 PM   #4 (permalink)
Wise Old Owl
 
piyush gupta's Avatar
 
Join Date: Sep 2005
Location: never land
Posts: 1,284
Default Re: A Virus tale

Its a trojan
more details here

http://kr.ahnlab.com/SecuInfoVirusVi...hn?SEQ_NO=6907


Update your AV definations and scan
or use KAV or NOD32
piyush gupta is offline  
Old 09-03-2007, 04:07 PM   #5 (permalink)
Security Exp
 
47shailesh's Avatar
 
Join Date: Apr 2006
Posts: 734
Default Re: A Virus tale

Dropper/QQPass.48436 is a dropper. When the dropper is executed, it creates
- jusodl.dll (21,168 bytes)
- jusodl.exe (48,436 bytes)
- severe.exe (48,436 bytes)

It creates following file(s) in Windows system folder\drivers.

- conime.exe (48,436 bytes)
- pnvifj.exe (48,436 bytes)

It creates following file(s).

- autorun.inf (75 bytes)
- OSO.exe (48,436 bytes)


The dropper adds a Windows registry entry to run itself automatically whenever Windows starts.

SOURCE

REMOVAL
__________
Quote:
Originally Posted by piyush gupta
Its a trojan
more details here

http://kr.ahnlab.com/SecuInfoVirusVi...hn?SEQ_NO=6907


Update your AV definations and scan
or use KAV or NOD32
i think if he installs KAV on infectected mc it will not work..

It modifies HOSTS file to keep the user from connecting specifiec addresses. Generally, the addresses are homepages of Internet security sites and antivirus engine updates servers. So the infected system's user can't get information or engine updates to scan and remove the malicious code.

127.0.0.1 dnl-us1.kaspersky-labs.com
127.0.0.1 dnl-us2.kaspersky-labs.com
127.0.0.1 dnl-us3.kaspersky-labs.com
127.0.0.1 dnl-us4.kaspersky-labs.com
127.0.0.1 dnl-us5.kaspersky-labs.com
127.0.0.1 dnl-us6.kaspersky-labs.com
127.0.0.1 dnl-us7.kaspersky-labs.com
127.0.0.1 dnl-us8.kaspersky-labs.com
127.0.0.1 dnl-us9.kaspersky-labs.com
127.0.0.1 dnl-us10.kaspersky-labs.com
127.0.0.1 dnl-eu1.kaspersky-labs.com
127.0.0.1 dnl-eu2.kaspersky-labs.com
127.0.0.1 dnl-eu3.kaspersky-labs.com
127.0.0.1 dnl-eu4.kaspersky-labs.com
127.0.0.1 dnl-eu5.kaspersky-labs.com
127.0.0.1 dnl-eu6.kaspersky-labs.com
127.0.0.1 dnl-eu7.kaspersky-labs.com
127.0.0.1 dnl-eu8.kaspersky-labs.com
127.0.0.1 dnl-eu9.kaspersky-labs.com
127.0.0.1 dnl-eu10.kaspersky-labs.com


source
__________
@Nikhilsam

infect if u see the modified host file you'll yourself find the removals tools..

here host file
127.0.0.1 mmsk.cn
127.0.0.1 ikaka.com
127.0.0.1 safe.qq.com
127.0.0.1 360safe.com
127.0.0.1 www.mmsk.cn
127.0.0.1 www.ikaka.com
127.0.0.1 tool.ikaka.com
127.0.0.1 www.360safe.com
127.0.0.1 zs.kingsoft.com
127.0.0.1 forum.ikaka.com
127.0.0.1 up.rising.com.cn
127.0.0.1 scan.kingsoft.com
127.0.0.1 kvup.jiangmin.com
127.0.0.1 reg.rising.com.cn
127.0.0.1 update.rising.com.cn
127.0.0.1 update7.jiangmin.com
127.0.0.1 download.rising.com.cn

so use netcafe and get for ur system

360 security guards v3.1 from 360safe.com

or search in the above listed pages
__________________
We Love Once, And When We do We do it Well

Last edited by 47shailesh; 09-03-2007 at 04:07 PM. Reason: Automerged Doublepost
47shailesh is offline  
Old 09-03-2007, 04:16 PM   #6 (permalink)
Wise Old Owl
 
piyush gupta's Avatar
 
Join Date: Sep 2005
Location: never land
Posts: 1,284
Default Re: A Virus tale

U r right shailesh better he use some removal tools and after that update his AV
piyush gupta is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


 
Latest Threads
- by Sujeet
- by ico
- by Tenida
- by gohan89
- by clinton

Advertisement




All times are GMT +5.5. The time now is 10:30 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2