View Single Post
Old 06-15-2009, 03:04 PM   #1 (permalink)
ClancyDamon
Registered User
 
Join Date: Jun 2009
Posts: 2
OS: XP SP3


username.exe Virus?

Our entire company was hit early this morning with a slew of viruses. Don't know how, I figure someone opened up one of those damn chain-mails I keep telling them to delete. Most of these things were relatively easy to deal with, but I've been killing myself trying to figure out this one in particular.

Every machine has an executable named after the default user of the machine, located in their Documents and Settings folder.

Every machine runs Win XP with SP3. We have Symantec Corporate Antivirus 10.1.

To give this more detail, let's use Mike Fistell as an example. Each user has a first initial, last name scheme for logins. Mike's login is mfistell. His directory is "C:\Documents and Settings\mfistell\". Every time we login into his profile, there is an executable in there with his user name attached - "C:\Documents and Settings\mfistell\mfistell.exe". This executable starts running right at startup (in the process list) but only if the computer is connected to the net. I made sure to disconnect everyone before cleaning these out, and everything seemed fine until I reconnected the LAN cables for some of these. Suddenly those executables start coming back and running.

I've run HijackThis, but I'm not an expert in this area (read: novice) so that hasn't solved the issue. I can't even figure out what this virus (worm? trojan?) is supposed to be. The best I've found is W32.Gavgent.A, but that that only matches the [user name].exe aspect. Nothing else matches.

I'm going insane. Can anyone help?
ClancyDamon is offline   Reply With Quote
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here