troubleshooting Question

big infection?

Avatar of pzilioli
pzilioli asked on
Security
17 Comments1 Solution1166 ViewsLast Modified:
Hi guys,
I have a little big problem on many PC's of my office.
It's difficult to exactly explain what happens but I try to ask your help.
I find in winnt directory (windows 2000 professional) a file named as random sequence of characters .exe, that is started on windows boot.
Infact when I search in registry I find this exe, present in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
(example: hrzucas C:\WINNT\system32\ikrgyoe.exe r).
When I kill from taskmanager this file, at once it create a new one with a different name.
So, even if I remove the "infected" key from registry, when windows restarts, this key is created again and the "infected" process live.
- We have Symantec Antivirus running on all the PC's, daily updated.
- I analized and clean the PC's with hijackthis, RootkitRevealer, Prevx Gromozon Removal...
- I booted windows from setup CD and under C:\winnt I didn't find the "infected" executable.
I presume that this malware is created on windows startup but I'm not able to discover the creator.
Can Anyone help me?
Thanks in advance

PS. Sorry for my poor english

ASKER CERTIFIED SOLUTION
Join our community to see this answer!
Unlock 1 Answer and 17 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 17 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros