Avatar of hindsight
hindsightFlag for United States of America

asked on 

Chess.exe, autorun.inf virus/spyware

I've got a virus hopping all around my domain.  I'm still not sure where it's hiding, but any removable devices or mapped betwork shares will be infected by a chess.exe file and an autorun.inf file in their root directoies if they come in contact with an infected pc.  After this, two files appear in %windir%\system32: aj32.dll, and kcc1.dll.  Running avg in safe mode by the command line will seemingly remove the infections.  However, on reboot, when the profile is loading, the dcom dialog box pops up, and the message "aj32.dll could not be found.  Upon a nother reboot, this message goes away, but any new profile created will display this message.  After the profile is completely loaded, task manager and regedit will be disabled, and any install fails out since it cant access the reg.  This eventually spreads to all users, including the local administrator profile.  superantispyware's repair function will restore all rights, but any flash drive or network share will eventually become reinfected.  I've tried scanning with avg, malwarebytes, superantispyware, combodix, and trend micro...none of the seem to clear the cause of this infection.  Has anyone seen anything this.
Anti-Virus AppsAnti-SpywareMicrosoft Legacy OS

Avatar of undefined
Last Comment
rpggamergirl
Avatar of rionroc
rionroc
Flag of United States of America image

Hello

Surely its a worm virus.

Boot in safe-mode.
Delete autorun.inf, chess.exe.
Go to regedit, then aj32.dll string, delete it.


Great is our GOD.
:)
rionroc
Avatar of hindsight
hindsight
Flag of United States of America image

ASKER

Treid that already, it just keeps regenerating
Avatar of hindsight
hindsight
Flag of United States of America image

ASKER

And yes, I know it's worm...I'm leaning towards w32.ogid or w32.oror-B
Avatar of hindsight
hindsight
Flag of United States of America image

ASKER

autorun.inf and chess.exe are on the removable and shared drives, the files that are controlling the infection are somewhere on the local drive.
Avatar of chris_futron
chris_futron

Hi there,
Did you disable system restore for all the PCs? Else, the AV will regenerate itself most of the time... Try disable system restore for now... When everything is stable, then turn it back on...
Hope it helps...
Avatar of rpggamergirl
rpggamergirl
Flag of Australia image

Please attach the Combofix log so we can make a script for any bad files that weren't removed during CF first run.
Avatar of hindsight
hindsight
Flag of United States of America image

ASKER

Combofix log attached.  Thanks in advance to anyone who can shed some light on this issue.

I've also found the loader point in the reg.  However, even if I delete it, it regenerates on reboot.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{0EA88F0F-B698-4ab1-8DBC-EBE2CD00927F}]
@="DCOM service"
"Locale"="EN"
"StubPath"="rundll32 kcc1.dll,InitO"
"IsInstalled"=dword:00000001
"Version"="4,3,6,3"
combofix-log.txt
Avatar of Mizugori44
Mizugori44

First disable system restore as stated above. Then boot in safe mode with networking and download this tool, extract to C:\ drive so you have a C:\rogueremoval tool, then follow all the steps in the help file. It will clean your problem for sure.

http://www.elitekiller.com/files/rogueremoval.zip

Cheers
Avatar of hindsight
hindsight
Flag of United States of America image

ASKER

zip file is corrupted
ASKER CERTIFIED SOLUTION
Avatar of rpggamergirl
rpggamergirl
Flag of Australia image

Blurred text
THIS SOLUTION IS ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
Avatar of rpggamergirl
rpggamergirl
Flag of Australia image

Thanks!
To uninstall Combofix:
Go to Start > Run and 'copy and paste' next command in the field:

ComboFix /u
Microsoft Legacy OS
Microsoft Legacy OS

The Microsoft Legacy Operating System topic includes legacy versions of Microsoft operating systems prior to Windows 2000: All versions of MS-DOS and other versions developed for specific manufacturers and Windows 3/3.1, Windows 95 and Windows 98, plus any other Windows-related versions, and Windows Mobile.

55K
Questions
--
Followers
--
Top Experts
Get a personalized solution from industry experts
Ask the experts
Read over 600 more reviews

TRUSTED BY

IBM logoIntel logoMicrosoft logoUbisoft logoSAP logo
Qualcomm logoCitrix Systems logoWorkday logoErnst & Young logo
High performer badgeUsers love us badge
LinkedIn logoFacebook logoX logoInstagram logoTikTok logoYouTube logo