Win32.TrojanRunner attack!! Help needed!

MIDIman

Diamond Member
Jan 14, 2000
3,594
0
0
Not sure if this is the place but...

As I was updating my virus checker (AVP), I got an error signifying Win32.TrojanRunner in C:\Windows\dsnekqg.exe. After some troubles with the updating process (it appears that AVP is getting rid of their old line of virus checking, and it didn't get all the files), I rebooted, uninstalled AVP, and installed a newer version.

It found the virus and could not "disinfect" and so opted to delete the exe, which I did, however it appears the attacker did something beforehand.

Long story short - Now, anytime I try to run ANY exe file (including all the bootup programs), I get the windows error "Couldn't find c:\Windows\dsnekqg.exe, please locate." Looking at the file associations list ("File Types"), .exe files are associated with dsnekqg.exe rather than the usual [Executable], with no option to remove or edit the association! I can't run any exe files, including regedit.exe, which is where I probably need to be.

Help Me! Feel free to reply to this, e-mail, or pm me.
 

StuckMojo

Golden Member
Oct 28, 1999
1,069
1
76

with NT you can run regedit on another machine and edit the registry (at least part of it) on a remote machine.

not sure if it works with 98 (probably not)


if you're running 98, you might want to try reinstalling overtop. but that might not fix it either.
 

MIDIman

Diamond Member
Jan 14, 2000
3,594
0
0
I'm on Win98, and currently backing up to reformat (was going to do it soon anyway, so this was just the extra needed incentive!)

Still curious how to fix this...funny, but if I copy another program, like Notepad.exe, then rename it to the original host trojan program (dsnekqg.exe), it will act like notepad any time I load an exe. Unfortunately, this still can't get me into regedit.exe, because even when an associated file with regedit is loaded, it acts as if it is adding to the registry...

Nonetheless, I am able to run programs by loading an associated file, such as a *.txt to load notepad, or for instance I created a new text document, labelled it as a fake *.cl4 file, and am using it to load Easy CD Creator to backup my needed files on CDR.

This sucks!!
 

StuckMojo

Golden Member
Oct 28, 1999
1,069
1
76

have you tried copying regedit.exe and renaming the copy to regedit.com? .com files are also executed i believe...

i just tried it, and it will work..assuming the virus writer wasnt smart enough to screw with the .com extension also.

maybe try .bat too.
 

StuckMojo

Golden Member
Oct 28, 1999
1,069
1
76

or couldnt you rename a copy of regedit.exe to dsnekqg.exe, then double click that to start regedit? (since the file that you double clicked, named dsnekqg.exe is really regedit anyway)
 

beamrider

Senior member
Oct 4, 2000
880
0
0
Can't remember correctly, but I believe that .scr ( screensaver) will also work as an executable.......
 

MIDIman

Diamond Member
Jan 14, 2000
3,594
0
0
Thx

Haven't tried trhe .com or .bat, but will ASAP.

I tried renaming regedit.exe to dsnekqg.exe, but when I did this, you get the usual reg extension popup: "Would you like to add *** to the registry?"

Quite annoying...another user in my other thread has said they have reg patches for this, so we'll see if that will fix it:
link to other thread