W00t! Found a new virus at work

Adul

Elite Member
Oct 9, 1999
32,999
44
91
danny.tangtam.com
Had a user who called in complain about very long load times and sluggish response from her PC. So i remote into the users PC and poke around
its riddle with spyware, adware, malware etc.

remove that stuff and have a look at her hkey_local machine and hope on over to run.

What I saw freaked me out.

hundreds of entries was in the run folder. I did am export to on the registry, file size was 647K for just the run folder!

turned out there was over 6k entries of random names all pointing to a file in the program files directory

c:\program files\suppsux\srvtorv.exe

and two processes that run and can not be end tasked as each one seems to support each other.

srvtorv and vrotvrs

turns out this is another mass emailing virus with no cure for it yet. This should b fun, I had the user disconnect from the network to be safe.

:)
 
Oct 9, 1999
15,216
3
81
i hate viruses.. i got to reinstall vanny's laptop cause she is getting hit by a trojan horse.. not sure how she got it..

rule #1: no use of any microsoft email and browsing products!
 

Adul

Elite Member
Oct 9, 1999
32,999
44
91
danny.tangtam.com
Originally posted by: TheGoodGuy
i hate viruses.. i got to reinstall vanny's laptop cause she is getting hit by a trojan horse.. not sure how she got it..

rule #1: no use of any microsoft email and browsing products!

indeed firefox and thunderbird :)

 

Merlyn3D

Platinum Member
Sep 15, 2001
2,148
0
0
On a side note, does anyone know of some sort of plugin to sync thunderbird with activesync?