Solved

Problem with Chess.exe and Windows Vista

Posted on 2008-10-07
7
1,397 Views
Last Modified: 2013-11-22
Seem to be having a bit of a strange problem.  We have a network of about 15-20 desktops running a mixture of operating systems from 2000/XP and Vista.

Recently we have installed a Windows Server 2008 file server and moved our data over to this.  

Now on all of our Windows Vista computers show an option for chess everytime we right click on our mapped drive and we can't double click to open the drive.  We can get to the drive if we go through a unc path and we have checked permissions on the new server .  

If we search through the registry on a vista machine it refers to a program called chess.exe in the root of the mapped drive, however we can't find this file on either servers.

This only seems to be causing an issue with our windows vista computers, all of our other computers are working fine.

We can delete any registry keys that relate to chess.exe and the issue looks like it disappears but when you reboot the machine the issue comes back again.  We have ran malwarebytes on the computer but it doesn't detect anything.  We have anti virus running on all computers and both servers.

Any help would be much appreciated.
0
Comment
Question by:asp_indi
7 Comments
 

Expert Comment

by:dbhsupport
ID: 22660196
Sorry not a solution for you.

We have the same problem, chess.exe and autorun.inf showing on the root of shares on a windows 2003 server.

Fully updated Trend running on the Server and nothing reported.

 
0
 
LVL 1

Accepted Solution

by:
interactit earned 500 total points
ID: 22660202
Hi

We saw a similar, if not identical issue recently, we solved it by locating the following registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2

You should see 2 subkeys which are Autoru & Shell, delete them and restart the PC.

I would guess that the Malware product you have run was only able to part clean the registry of the chess worm (Vista's registry is more secure than XP).

Let me know how you get on?

0
 

Expert Comment

by:dbhsupport
ID: 22660272
Thanks for that had a look but do not see the subkeys :-(


0
Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

 
LVL 1

Expert Comment

by:interactit
ID: 22660296
dbhsupport, are you using Vista (if so what versuion) or XP?
0
 

Author Comment

by:asp_indi
ID: 22660507
Hi interactit

performed your fix and also noticed that the autorun.ini was still in the root of the of the drive and this so far has fixed my problems on the vista computers.  We have rebooted all of them and the issue hasn't come back.

I'll give it until tomorrow to see if the virus is regenerating itself.

0
 

Expert Comment

by:dbhsupport
ID: 22667038
It is on Windows 2003 server. Not done a reboot yet to see if it will come back.
thanks
0
 
LVL 1

Expert Comment

by:akg_exel
ID: 22830906
I have this also on a customer machine.

Noticed it on one laptop which was reinstalled and it came back today - deleted the keys of which one was..

C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL chess.exe e

which I assume is the culprit which is creating this file.

Really surprised there are no fixes from AV people.  Is it a virus or malware?
0

Featured Post

Backup Your Microsoft Windows Server®

Backup all your Microsoft Windows Server – on-premises, in remote locations, in private and hybrid clouds. Your entire Windows Server will be backed up in one easy step with patented, block-level disk imaging. We achieve RTOs (recovery time objectives) as low as 15 seconds.

Join & Write a Comment

Suggested Solutions

HOW TO REMOTELY CLEAN MEROND.O WITH ESET SILENTLY PROBLEM       If you have the fortunate luck to contract the Merond.O virus on your network, it can be quite troublesome to remove as it propagates to network shares on your network. In my case, the …
You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
This tutorial will show how to push an installation of Backup Exec to an additional server in both 2012 and 2014 versions of the software. Click on the Backup Exec button in the upper left corner. From here, select Installation and Licensing, then I…
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now