- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic to the Top
- Bookmark
- Subscribe
- Printer Friendly Page
bloodhound .pdf.10 with a.exe virus
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Email to a Friend
- Notify Moderator
04-25-2009 08:10 AM
Hello,
I just got my first virus on my pc yesterday. I went to a foxnews.com website that had a link to the SUN newspaper in England (fyi, if you want to reproduce this, go find the story about clown feet and shoes...really). When I loaded this page, there were many clicks (usually happens when pop-ups are downloaded which I block). In fact there were so many clicks I got concerned and disconnected from the ethernet. But it was too late. I saw in task manager the file a.exe running and then it tried to connect to the internet which my firewall blocked. I killed a.exe. It had been installed on my Desktop page. Norton identified a temp file in my LOCAL TEMP directory as bloodhound.pdf.10 but it never identified the a.exe file which was obviously bad. I deleted it. So what does a.exe do? Did it install anything on my system? I know it ran as I saw it in taskmanager. Sorry, the file a.exe is deleted.
David
Re: bloodhound .pdf.10 with a.exe virus
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Email to a Friend
- Notify Moderator
04-25-2009 08:15 AM
Hi Daspdasp:
Can you tell us your operating system and service packs? Also what version of Norton do you have? Look under Help & Support> about.
Have you updated and tried a full system scan? Disable system restore and disconnect from the net before the scan. Let us know if anything shows up. Did you get any warnings from Norton?
Mark Twain
Re: bloodhound .pdf.10 with a.exe virus
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Email to a Friend
- Notify Moderator
04-25-2009 09:28 AM
Hello,
I have XP with SP2 and am updated with all Microsoft service packs. My antivirus was all updated.
Norton showed the bloodhound.pdf.10 virus in a temp file in LOCAL. That was immediately detected when I went to the suspect website and before the scan. I quarantined it and deleted it and the FULL scan did not reveal anything even though a.exe was on the pc in the recycler bin (I had deleted it manually). I have looked around on the pc some more and at files modified at exactly that time. I did find a prefetch file called "a.exe-1c1f2ffb.pf". It does not seem like other files were downloaded. But a.exe did run and I am wondering if it did anything (but I cannot see any files it placed). Like I said before, it did not access the internet as my firewall blocked it and then I killed it in taskmgr.
d
Re: bloodhound .pdf.10 with a.exe virus
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Email to a Friend
- Notify Moderator
04-25-2009 11:11 AM
Mark Twain
Re: bloodhound .pdf.10 with a.exe virus
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Email to a Friend
- Notify Moderator
04-25-2009 11:28 AM
Hello,
I found the prefetch file today and deleted it. Is it really the same file as a.exe (ie, is this file malicious or is it only a pointer to the a.exe file?)
Again, I looked at all files modified for yesterday at the given time (11:48am) and found the prefetch file. I did not see any other files downloaded at this time.
After reading some correspondance about this possible virus, some people said it took advantage of a hole in Adobe Reader. Since I had v7 I downloaded the version 9. Had no problems but noticed that when I opened WORD, the Control Toolbox window was opened. Usually, it will not open a window like this unless I used it before. So I thought it had something to do with the Adobe install as the reader is listed in the Class files (active X or dll). Maybe a total coincidence. I was just worried that the a.exe program did something to this (added a ocx or dll file) but I cannot find anything.
As I said, I am sure the virus came about from clicking on that newstory in that paper. It could likely be repeated if someone or Norton wants to check it out.
Any suggestions as to how to determine if anything was done to my system?
d
Re: bloodhound .pdf.10 with a.exe virus
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Email to a Friend
- Notify Moderator
04-25-2009 11:39 AM
Foxnews.com has had some real issues with malware recently. I would stay away from that site. You were most likely infected through one of the ads. For a thorough (and long) discussion, check out this thread at DSL Reports:
http://www.dslreports.com/forum/r22225362-foxnewsc
Re: bloodhound .pdf.10 with a.exe virus
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Email to a Friend
- Notify Moderator
04-25-2009 01:36 PM
Hello,
good call. I did not know this. FoxNews had a link to the London SUN website (probably owned by the same company). When the page was loading, about 100 clicks were heard (seems like it clicks when it fetches something like popups). I got worried and disconnected but it was too late. The a.exe file was Russion as when I clicked properties, it was all in Russian. Something about version 5.xxx
Again if Norton wants to verify all of this and make a fix, do a search for "clown shoes" or something close to this (about a clown who wasn't allowed to wear his big shoes - hey I did not make this up).
d
Re: bloodhound .pdf.10 with a.exe virus
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Email to a Friend
- Notify Moderator
04-25-2009 03:04 PM
If you wanted to run another scan just to reassure yourself, you can download Malwarebytes, free version here:
http://www.malwarebytes.org/mbam.php
Install, update and run with log. You can post the log here if you wish and others will view it.
Mark Twain
Re: bloodhound .pdf.10 with a.exe virus
[ Edited ]
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Email to a Friend
- Notify Moderator
04-25-2009 03:11 PM - last edited on 04-25-2009 03:18 PM
Hi daspdasp,
I believe I found the page you were referring to, but I had no unusual events occur. My NIS2009 is fully up to date along with my Adobe Reader.
I don't see where you have noted which Norton product and version you are using, however in addition to what delphinium has suggested, I would also recommend performing a Norton Full System Scan in SAFE MODE while disconnected from the internet.
Your experience emphasizes the need to keep all programs updated, not just Windows and your security program.
There is a free online evaluation tool at Secunia that will examine your system to see if any other programs have vulnerabilities. If any are noted, you will be provided with a link to update them.
The Simple Scan should tell you all you need and no downloads are required.
Best Wishes.
[edit: grammar]
Phil_D
NIS 2010 • 360 v4 • Ghost 15.0
XP SP3 • Vista SP2 • Windows 7 Professional x64
Re: bloodhound .pdf.10 with a.exe virus
[ Edited ]
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Email to a Friend
- Notify Moderator
04-25-2009 03:23 PM - last edited on 04-25-2009 03:30 PM
daspdasp,
You said: "Again, I looked at all files modified for yesterday at the given time (11:48am) and found the prefetch file. I did not see any other files downloaded at this time."
Just to play it safe, do a search for all files created yesterday at the approximate time. See if a file looks suspicious, like another Russian one. The virus might be clever enough to use an older modified date to avoid detection.
Marty
NIS-09 Vista
