Well then Lucf, that proves McAffee and Norton are well over a week behind, right?
Will leave this up for a bit for others to see.
Main Topics
Browse All TopicsPosting this here too (at Callandor's suggestion), to alert everyone that I found a new virus last night that is not found by any of the latest virus updates of McAfee or Norton, and is not found by Ad-Aware6, with the latest update last night.
If people complain of their system running about HALF speed, it is due to the WMIPRVSE.EXE virus.
Normally, wmipvrse.exe is a valid windows/system32 file, and with SP1, it stays in the WDEM directory at about 199KB, and has the SP1 distribution date of 8/29/2002. But when you get the virus, you will find another file, of 38KB size in the Windows/Prefetch directory, with the same name, but a more recent date. Deleting that file and rebooting seems to fix the problem, the original MS file seems unharmed.
The way I found this is, as soon as the system booted fully, I did C-A-D to bring up Task Manager. A few seconds later, it popped into view, and the system process meter went to 100% immediately.
Tell people to check for it if they are experiencing slow systems in the next week or so. Good luck.
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
I must have got a variant or a crippled version, as none of what they describe on their site actually happened. IT IS EXACTLY AS I DESCRIBED ABOVE -- NONE OF THE FOLLOWING (from TM site) was found --
<<< Upon execution, this Trojan drops the following copies of itself in the Windows system folder:
* NTSVC.EXE
* WMIPRVSE.EXE
It also drops the following files in the Windows and Windows system folders, respectively:
* USERLOGON.EXE – another copy of itself
* RSASEC.DLL – a .DLL keylogger component >>>
I think it is the new "banking password theft" virus they are talking about on all the news sites in the past 2 days. It does not match any of those Trend Micro features, it just used the "Windows/Prefetch" to run from. If anyone wants to report my original post to one of the virus companies, please do so. I don't have time.
This is a virus and because of that it's not the job of Ad-Aware to detect it. But NAV and VirusScan have to.
You didn't find the files mentioned on the Trend Micro site on your computer but only WMIPRVSE.EXE. Have you checked the logfile of your antivirus software whether there is an item pointing to this virus? Maybe the virus was stopped and because of that not able to create the other files?!
> ...that proves McAffee and Norton are well over a week behind, right?
Maybe but not necessarily. It could also be new variant that is spammed now. And it's also possible that your antivirus software is not configured to scan all files or compressed files. This can also prevent to detect this (UPX packed) virus.
In addition to checking the antivirus configuration I would recommend to install the security patch MS04-013 (http://www.microsoft.com/
I covered all those bases and I did say I did the latest AV updates.
Read this latest article, the virus collects passwords into bank data, and is quite serious --
http://www.sfgate.com/cgi-
sciwriter, you are right: This is a serious problem and I got first reports about 36 hours ago. But this is another virus called Scob or Toofer (depending on the av vendor). As far as I know until now this virus does not contain a file named WMIPRVSE.EXE
Information about the virus you mentioned in the article at SFGate:
http://www3.ca.com/securit
http://vil.nai.com/vil/con
http://www.symantec.com/av
http://www.trendmicro.com/
Until now all URLs that were used by the virus to download the backdoor component should be offline. So even if webservers keep infected this won't result in any further infections on the computers while browsing on these servers.
Hi sciwriter,
Looks like my fellow Experts are giving you a great hand handling your problem. About reporting the new virus to the AV manufacturers, you have to do it yourself by submitting a sample of the infected file, we can't do it for you. Here's links to some AV vendor's instructions on submitting virus samples:
Symantec:
http://securityresponse.sy
McAfee:
http://us.mcafee.com/root/
http://us.mcafee.com/root/
CA (for users of ez-Trust, Vet, and Innoculate only):
http://www3.ca.com/securit
TrendMicro (for users of their products only):
http://subwiz.trendmicro.c
I have emailed other vendors and will try to put together a more comprehensive list for reference.
Good Vibes!
Lobo
Thanks LOBO, and good vibes to you too, friend!!
I am not interested in helping software vendors improve their products. That is THEIR job, not mine. After 20 years or more in this business, you realize how much software vendors suck off users to fix their coding problems --totally for free, and with no recompense for the effort people put in. Do I ask you to fix my car for nothing? No, well neither should they.
If these AV "experts" haven't yet figured out how to get ahead of virus writers, they are not doing their job, AFAIAMC. I have too much to do already helping people who appreciate the help, the software companies can just get better, or quit. Sorry, but trying to work with software companies for years before most of you were even in the business, has hardened me to their total ineptitude, and inability to think beyond their own narrow scope.
It's time I'm not prepared to waste. But thanks for your input, I like your style!!
Inside my Windows/Prefatch directory, I have this file: WMIPRVSE.EXE-28F301A9.pf
123kb, modidfied tonight at 3:03AM. (Um, that's the future, lol. And my system date/time is correct).
And are you guys meaning C:\Windows\System for all OS's? Or do you mean C:\WINNT\SYSTEM32 for NT/XP? Just trying to clarify :)
No, paths like c:\windows\system are never valid for all operating systems. More common we could say %SYSTEM% and this means the default installation location for the System directory. The default installation location for the System directory for Windows 2000 and NT is C:\Winnt\System32; for 95,98 and ME is C:\Windows\System; and for XP is C:\Windows\System32.
Business Accounts
Answer for Membership
by: LucFPosted on 2004-06-26 at 08:45:51ID: 11405954
It's this one: e.com/ente rprise/sec urity_info / ve_detail .php?id=59 656&VName= TROJ_GLETT A.A&VSect= T
http://nl.trendmicro-europ
Found 6/11/2004
Greetings,
LucF