Z
Zantafio
For any reason, Zone Alarm didn't rename a .PIF file attached to a message.
Confusing it with a .TIF, and quite sure the work was correctly done by the
firewall, I confidently clicked on the attachment and within the following
microsecond I realized my mistake.
The result is that Zone Alarm went unloaded as well as The Cleaner Monitor
and TCActive.
All of them don't load again as well as VirusScan.
The first investigations gave the following:
The infected file name is "image023.pif" 54048 bytes long.
It created "mshxbh.com" also 54048 bytes long in the "windows\command"
directory with the attribute "system"
3 Run keys were created in HKCU, HKLM & HKUD with a name "COM Service" and a
value equal to "u:\windows\command\mshxbh.com"
Whatever I attempt to delete them from the registry or to disable them from
MSCONFIG - Start, they are self generating.
Removing "mshxbh.com" from DOS freshly booted from a safe protected diskette
doesn't solve the issue. The file appears to be deleted but it appears again
as soon as Windows is working. When deleted under DOS, It doesn't look to be
active during the DOS session. I mean, the file remains deleted.
I put the file on a floppy and scanned it in an NT protected system.
Virusscan doesn't find it except with the heuristics options. It says it
could be a variant of "New Backdoor 1".
For the moment, the virus looks not to have spreades over my network. It's
located on a client. The four PCs are protected by their own firewalls.
I fear to connect to Internet with the infected one.
I also scanned the client from the server with The Cleaner. It didn't find
anything.
I can't manage to find any clue through google or Yahoo since I don't know
what trojan or virus it is.
Shall I add that the rescue disk created with McAfee gives garbage when it
scans the FAT32 disks, rendering it completely unusable ?
Thanks to VirusScan !
Thanks for your help.
Confusing it with a .TIF, and quite sure the work was correctly done by the
firewall, I confidently clicked on the attachment and within the following
microsecond I realized my mistake.
The result is that Zone Alarm went unloaded as well as The Cleaner Monitor
and TCActive.
All of them don't load again as well as VirusScan.
The first investigations gave the following:
The infected file name is "image023.pif" 54048 bytes long.
It created "mshxbh.com" also 54048 bytes long in the "windows\command"
directory with the attribute "system"
3 Run keys were created in HKCU, HKLM & HKUD with a name "COM Service" and a
value equal to "u:\windows\command\mshxbh.com"
Whatever I attempt to delete them from the registry or to disable them from
MSCONFIG - Start, they are self generating.
Removing "mshxbh.com" from DOS freshly booted from a safe protected diskette
doesn't solve the issue. The file appears to be deleted but it appears again
as soon as Windows is working. When deleted under DOS, It doesn't look to be
active during the DOS session. I mean, the file remains deleted.
I put the file on a floppy and scanned it in an NT protected system.
Virusscan doesn't find it except with the heuristics options. It says it
could be a variant of "New Backdoor 1".
For the moment, the virus looks not to have spreades over my network. It's
located on a client. The four PCs are protected by their own firewalls.
I fear to connect to Internet with the infected one.
I also scanned the client from the server with The Cleaner. It didn't find
anything.
I can't manage to find any clue through google or Yahoo since I don't know
what trojan or virus it is.
Shall I add that the rescue disk created with McAfee gives garbage when it
scans the FAT32 disks, rendering it completely unusable ?
Thanks to VirusScan !
Thanks for your help.