Results 1 to 8 of 8

Thread: W32.Conycspa.G@mm

  1. #1
    Xcelsion... In Disguise. Xaneden's Avatar
    Join Date
    Nov 2004
    Location
    United Kingdom
    Posts
    1,699
    Thanks
    0
    Thanked
    0 times in 0 posts

    W32.Conycspa.G@mm

    Hey Guys,
    A few days back, I got an alert from Symantec Antivirus that I had a virus. It picked up 3 seperate things, all within 30 seconds.

    Initally, it picked up 2 instances of a generic trojan. Then it picks up "W32.Conycspa.G@mm". All 3 things can be quarentined/deleted without any errors. I then get IE loading, trying to connect me to a website. However, the site (which I'm sure is an IP) does not have any full stops. For instance, one of the addresses was http://20089/, so it obviously doesn't load; it just gives me a generic Page not found error. I also tried changing my generic browser to Firefox, but it opened up the address in that browser too

    This popup webpage usually occurs just before/after Symantec picks the virus up (so they're clearly connected), but the whole process repeats itself every hour or so. I've done full system scans using Symantec Antivirus, NOD32, BullGuard etc, and even an online scan. Symantec sometimes finds an instance of the viruses (usually within the 1 hour popup timeframe), but apart from that, it finds nothing (i.e. no regeneration files, which would be necessary for this to keep coming back). I have disabled system restore so those files can be scanned too.

    Does anyone have any advice for me? I am obviously concerned about this, and hope to clear it up asap. I have a lot of work to do over the weekend, so reinstallation is not plausible unfortunately.
    Last edited by Xaneden; 05-11-2005 at 12:06 AM.
    New Sig on the Way...

  2. #2
    Xcelsion... In Disguise. Xaneden's Avatar
    Join Date
    Nov 2004
    Location
    United Kingdom
    Posts
    1,699
    Thanks
    0
    Thanked
    0 times in 0 posts
    Forgot to mention, the main 'W32.Conycspa.G@mm' virus is found in 'C:\WINDOWS\inet20089\alg.exe' and the generic trojans are found in 'C:\WINDOWS\inet20089\skiller.exe'.
    New Sig on the Way...

  3. #3
    Bigger than Jesus Norky's Avatar
    Join Date
    Feb 2005
    Posts
    1,579
    Thanks
    1
    Thanked
    8 times in 8 posts
    http://securityresponse.symantec.com...cspa.g@mm.html

    Try reading that, hope this helps

  4. #4
    Xcelsion... In Disguise. Xaneden's Avatar
    Join Date
    Nov 2004
    Location
    United Kingdom
    Posts
    1,699
    Thanks
    0
    Thanked
    0 times in 0 posts
    Thanks for the link Norky, but I've desperately read that about 5 times already tonight

    I've tried doing what it says, but it comes to no avail. I also have a firewall etc so I don't see how this is getting through.

    Oh, and I didn't get this via an email.
    New Sig on the Way...

  5. #5
    Senior Trouble Maker muddyfox470's Avatar
    Join Date
    Jul 2004
    Location
    moving to Suffolk
    Posts
    3,103
    Thanks
    104
    Thanked
    46 times in 39 posts
    • muddyfox470's system
      • Motherboard:
      • Abit I-N73HD
      • CPU:
      • E4500
      • Memory:
      • 4Gb PC6400 Corsair ?
      • Storage:
      • 2 x Seagate 7200.12 500Gb and 1 x Hitachi 7k1000.b 750gb
      • Graphics card(s):
      • Powercolor 4850
      • PSU:
      • Corsair HX520W
      • Case:
      • Silverstone SG-01e
      • Monitor(s):
      • Fujitsu D22W-1
      • Internet:
      • BT Home
    try microsoft antispyware, it has a browser restore function, if and when the browser becomes hijacked.

    tho i dont know whether that will help you at all...

    ian
    Mac fancier > white macbook base spec .................. CS: muddyfirebang

  6. #6
    Xcelsion... In Disguise. Xaneden's Avatar
    Join Date
    Nov 2004
    Location
    United Kingdom
    Posts
    1,699
    Thanks
    0
    Thanked
    0 times in 0 posts
    Ok, I updated NOD32 this morning, and it located a 'services.exe' in the same directory as the other viruses, but stated it was an unknown virus

    Also, I am now getting Symantec picking up lots of seperate temporary files all seemingly infected with the Conycspa virus.
    Last edited by Xaneden; 05-11-2005 at 10:40 AM.
    New Sig on the Way...

  7. #7
    Ex-MSFT Paul Adams's Avatar
    Join Date
    Jul 2003
    Location
    %systemroot%
    Posts
    1,926
    Thanks
    29
    Thanked
    77 times in 59 posts
    • Paul Adams's system
      • Motherboard:
      • Asus Maximus VIII
      • CPU:
      • Intel Core i7-6700K
      • Memory:
      • 16GB
      • Storage:
      • 2x250GB SSD / 500GB SSD / 2TB HDD
      • Graphics card(s):
      • nVidia GeForce GTX1080
      • Operating System:
      • Windows 10 x64 Pro
      • Monitor(s):
      • Philips 40" 4K
      • Internet:
      • 500Mbps fiber
    I would start by backing up the entire registry and then booting into Safe Mode

    Run Autoruns to check what is starting up when I boot and logon.
    Delete all references to files in C:\Windows\inet20089 - that folder should not be there

    Then check the system with Rootkit Revealer to see if it shows you anything hidden on the system that AV may only pick up when it becomes a running process (read the page for "interpreting the output" as not everything it reports indicates a problem)

    Then a full AV scan of the system after a refresh of the virus definitions.

    If you really didn't get it via email then you ran an executable you downloaded or received via IM or something similar (AOL Instant Messenger apparently has some nasties running around in it at the moment).
    ~ I have CDO. It's like OCD except the letters are in alphabetical order, as they should be. ~
    PC: Win10 x64 | Asus Maximus VIII | Core i7-6700K | 16GB DDR3 | 2x250GB SSD | 500GB SSD | 2TB SATA-300 | GeForce GTX1080
    Camera: Canon 60D | Sigma 10-20/4.0-5.6 | Canon 100/2.8 | Tamron 18-270/3.5-6.3

  8. #8
    Xcelsion... In Disguise. Xaneden's Avatar
    Join Date
    Nov 2004
    Location
    United Kingdom
    Posts
    1,699
    Thanks
    0
    Thanked
    0 times in 0 posts
    Thanks for the advice, I'll try that stuff out now. And no, I didn't get any files over any IMs lately, or via a downloaded file. I was browsing through a widescreen wallpaper website, when I got a warning that the virus had infected, how though, I do not know, as I did not accept any ActiveX notifications etc.
    New Sig on the Way...

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •