New Virus!""... not detected by Symantec!!! Pretends to be "Windows Security Centre"

Scrat

New Member
EVERYONE PLEASE READ THIS

Hi all, have just descovered a new virus on one of our Laptops at work.
The Laptop was originaly running WindowsXP Prof. SP1. I have now upgraded it to SP2 in attemtp to stop virus.

So far Symantec's Norton Antivirus Corp. Ed. does not detect it. And Trend Micro detects it as a Trojan but cant remove it.

The originaly displays a message box on the screen that mimics one exactly the same as Windows XP's "Windows Security Centre" however the 'close window cross' in top right corner is disabled. I haven't written down the message it displays yet, but it says something like "your computer might be at risk... do you want to install" and it has an 'Yes' & 'No' button.
If you Open Taskmanager and endtask this message under the aplications tab, you get a message saying that "nettm32.exe" has stoped responding do you want to endtask it.

Also, found that it later displayed an icon in the system tray the same as windows firewall (A red shield with white border and white cross in middle). If you endtask "nettm32.exe" then refresh, the icon disapears.

Task Manager shows it as "nettm32.exe" and also "crhj32.exe". These are in the Run entry in the registry and attempts by 'Microsoft's Antispyware" & "Spybot" fail to stop the virus from re-adding to registry and starting after you delete it.

The virus creates a directory in "C:\WINDOWS\" called "Prefetch" and copies vurtualy every setting on your PC into this folder and names them all with the extension .PF

It also sets the IE home page to "about:about" and attempts by Microsoft Antispyware & Spybot fail to stop it reaplying itself after i change it to google.

It keeps installing its files once you delete them... so far i've found the following virus files in C:\WINDOWS
nettm32.exe
javadb.exe
msmm32.exe
crea32.exe
crhj32.exe
There are many others and it also puts these in the SYSTEM32 folder.

If anyone knows how to fix this please let me know.... other that reinstalling windows.
 
Last edited:

Greg J.

VIP Member
Can you use System Restore in Windows XP to move it back to an earlier time when you didn't have the virus? if you do that, then re-install SP2.
 

NT61

banned
Norton AV sucks like you would not believe it. It does not protect you, takes a long time to load and sometimes, you need a NAV removal tool. Try AVG, Panda, F-Secure :cool:
 

Scrat

New Member
Greg J. said:
Can you use System Restore in Windows XP to move it back to an earlier time when you didn't have the virus? if you do that, then re-install SP2.

Unfortunatly have already disabled it to try using removal tools in safe mode, so no more system restore points.
 

Hellbreather

New Member
I have heard of this virus it is protected by Symantec so you need to update and try again. I will look for the virus on websites.
 

Scrat

New Member
Already have latest version of Symantec Antivirus corp ed. on it and latest virus def's.... even called symantec, they don't know what it is yet so had to send off some files to them. Have done all windows security updates. Have microsoft antispyware and Spybot's Search & Distroy running and with latest revs. So far nothing has been able to detect it and name it... nor stop it.
I will prob install some other anti virus progs next week and see how they go.

One good thing thou, is that it has been on our office network several times but no evidence of it spreading to any other PC's (win2k nor winXP)
 

Byteman

Malware Destroyer
YOU HAVE A VARIENT OF THE ABOUT:BLANK HIJACK. Symantec corp ONLY does viruses not spyware/hijacks. Please read the this thread through entirely to get rid of it. :)
 
Top