Results 1 to 2 of 2

Thread: Virus on win2k and i cant track it down at all

  1. #1
    Senior Member
    Join Date
    Jul 2003
    Location
    Petersfield, UK
    Posts
    1,755
    Thanks
    0
    Thanked
    0 times in 0 posts

    Virus on win2k and i cant track it down at all

    Hi - sorry this is going to be long.

    A friend of mine was using her laptop earlier today, she was looking at her uni webmail when a webpage came up apparently from the system administrator (we are on a uni internet connection) saying that something had expired. This gave a zip file to download, called important-details.zip she opened it and ran it, the file in the zip was called important-details.zip .pif she was running a DOS program instead of a .txt file.

    I went round and had a look. I tried to look in the taskmanager, but it would load up then close very quickly, norton antivirus wouldnt load up either, neither would the regedit. I tried to search the hard drive for "important-details" but that came back empty.

    Finally i thought a reboot may be helpful in some way. So i hit reboot and an "end program" thing came up, it didnt say what program it was for. However i could use the regedit, task manager, and norton when the computer was in this state of near shut down; with very few (all windows) processes running. So i tried to hunt down the virus again, but failed as i couldnt find it anywhere!

    I then tried to open the .pif with notepad (as she was clearly infected), i managed to get mzkernel32.dll from it but nothing else - dont really know what i expecting to achieve, but you never know. There is only 1 result on google for this file (http://lists.gnetlibrary.org/piperma...ay/000420.html) i have no idea what is it talking about.

    Her access to the internet has been stopped, i think that maybe the administrator, as what would be the usefulness of a virus stopping the internet? surely they want the remote access?

    The Norton scan i ran also threw up these other files which i am just checking out on the net now:
    pingchek.exe
    crime[1].exe
    payload.dat
    rundll82.exe

    Sorry for the lengthy post, but does anyone have any idea what this virus is and how to remove it?

    Thanks very much guys
    Hope you can help
    Will.
    Last edited by blockers; 14-06-2005 at 07:30 PM.
    | XP1600-m | ASUS AN78X Deluxe | r9700 pro | 2x512mb pc37000 |

  2. #2
    Ah, Mrs. Peel! mike_w's Avatar
    Join Date
    Oct 2003
    Location
    Hertfordshire, England
    Posts
    3,326
    Thanks
    3
    Thanked
    9 times in 7 posts
    You could try running Stinger (http://vil.nai.com/vil/stinger/) to see if it can find anything - it'll fit on a floppy. You might also want to try running MSConfig to see if anything is starting up that shouldn't be.

    Sorry for not being much help, but I'm not really sure what else you could do if Norton can't do anything - as a last resort, you can always reformat, but you might lose some important data. If you do reformat, make sure you have backups of anything you might want beforehand!

    Edit: Sorry for the lengthy post? Longer posts are more useful than simple "Argh! Virus! Help!". Besides, gives me something to read
    "Well, there was your Uncle Tiberius who died wrapped in cabbage leaves but we assumed that was a freak accident."

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Win2k domain gubbins...
    By Neo_VR in forum Software
    Replies: 2
    Last Post: 13-03-2005, 03:41 AM
  2. Win2k: Which service pack?
    By eldren in forum Software
    Replies: 6
    Last Post: 07-03-2004, 10:36 PM
  3. Replies: 15
    Last Post: 14-01-2004, 10:49 PM
  4. networking win2k
    By blockers in forum Networking and Broadband
    Replies: 15
    Last Post: 25-11-2003, 12:00 AM
  5. loading win2k or win98 in DOS
    By blockers in forum Software
    Replies: 2
    Last Post: 08-11-2003, 10:10 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •