Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > Virus/Trojan/Spyware Help
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Virus/Trojan/Spyware Help Get Rid Of Malware With Help From Our Analysts. Follow the "First Steps" link at the top right of each page before posting for help.

Reply
 
LinkBack Thread Tools
Old 06-15-2009, 03:04 PM   #1 (permalink)
Registered User
 
Join Date: Jun 2009
Posts: 2
OS: XP SP3


username.exe Virus?

Our entire company was hit early this morning with a slew of viruses. Don't know how, I figure someone opened up one of those damn chain-mails I keep telling them to delete. Most of these things were relatively easy to deal with, but I've been killing myself trying to figure out this one in particular.

Every machine has an executable named after the default user of the machine, located in their Documents and Settings folder.

Every machine runs Win XP with SP3. We have Symantec Corporate Antivirus 10.1.

To give this more detail, let's use Mike Fistell as an example. Each user has a first initial, last name scheme for logins. Mike's login is mfistell. His directory is "C:\Documents and Settings\mfistell\". Every time we login into his profile, there is an executable in there with his user name attached - "C:\Documents and Settings\mfistell\mfistell.exe". This executable starts running right at startup (in the process list) but only if the computer is connected to the net. I made sure to disconnect everyone before cleaning these out, and everything seemed fine until I reconnected the LAN cables for some of these. Suddenly those executables start coming back and running.

I've run HijackThis, but I'm not an expert in this area (read: novice) so that hasn't solved the issue. I can't even figure out what this virus (worm? trojan?) is supposed to be. The best I've found is W32.Gavgent.A, but that that only matches the [user name].exe aspect. Nothing else matches.

I'm going insane. Can anyone help?
ClancyDamon is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 06-15-2009, 05:04 PM   #2 (permalink)
Registered User
 
Join Date: Jun 2009
Posts: 2
OS: XP SP3


Re: username.exe Virus?

I found something out. If I shut down the server completely, and log into a client machine (using the domain login) then there isn't any problem. The files that I have deleted from the system stay deleted. If I turn the server back on and re-synchronize, then we still don't have any (noticeable) problems. It's only if the server is already turned on the and user logs into their profile on a client machine that we have problems.

Whatever this thing is, it's server based. In that case, I'd assume it has something to do with the Active Directory, seeing as these executables are tied to user names.

Has anyone seen anything like this before? Hell, if I just had a name of what this might be it'd help a lot.
ClancyDamon is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 06:37 AM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85