CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 937
Comments: 25
block bottom
spacer spacer

RBOT? mcafe32.exe, navprotect.exe
Goto page 1, 2  Next
 
Post new topic   This topic is locked you cannot edit posts or make replies       All -> FavForums -> Startup Programs [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Mere_Mortal

1st Responder


Joined: Apr 10, 2004
Posts: 4191
Location: Kidderminster
1st Responders Rootkit Responders

PostPosted: Fri Jan 21, 2005 4:18 pm    Post subject: RBOT? mcafe32.exe, navprotect.exe
Reply with quote

O4 - HKLM\..\Run: [Windows Media Player] mcafe32.exe
O4 - HKLM\..\Run: [NAV Auto Protect] navprotect.exe

I believe this one is RBOT...
O4 - HKLM\..\Run: [Windows Media Player] msams.exe

No information on them anywhere.


_________________
[Malware Removal and Prevention] [Malware Complaints]
Back to top
View users profile Send private message Visit posters website
Marianna

Security Expert
Premium Member

Joined: Nov 05, 2003
Posts: 11725

MVP Premium Rootkit Experts Security Experts

PostPosted: Fri Jan 21, 2005 10:43 pm    Post subject:
Reply with quote

Well, here is some info about:

Mcafe32

Windows Media Player

http://www.answersthatwork.com/Tasklist_pages/tasklist_m.htm

You have a Trojan virus which you picked up probably through the use of file sharing software like KaZaA, or through downloading and installing something from a malicious web page. At the time of writing, 16‑Jan‑2005, this Trojan is not picked up by the majority of antivirus programs.

Recommendation :
Get rid of this immediately
.....

MSAMS.EXE

WORM_RBOT.AHR

http://uk.trendmicro-europe.com/enterprise/security_info/ve_detail.php?Vname=WORM_RBOT.AHR
.........

O4 - HKLM\..\Run: [NAV Auto Protect] navprotect.exe

seems to be: "Backdoor.Win32.Rbot.gen" Virus.

HTH


_________________
"Wisdom is not a product of schooling but of the life-long attempt to acquire it."
- Albert Einstein (1879-1955)


Microsoft MVP - Consumer Security 2006 - 2008
Back to top
View users profile Send private message
Mere_Mortal

1st Responder


Joined: Apr 10, 2004
Posts: 4191
Location: Kidderminster
1st Responders Rootkit Responders

PostPosted: Fri Jan 21, 2005 10:57 pm    Post subject:
Reply with quote

Excellent, thanks for that Thumbs Up


_________________
[Malware Removal and Prevention] [Malware Complaints]
Back to top
View users profile Send private message Visit posters website
Marianna

Security Expert
Premium Member

Joined: Nov 05, 2003
Posts: 11725

MVP Premium Rootkit Experts Security Experts

PostPosted: Fri Jan 21, 2005 11:00 pm    Post subject:
Reply with quote

You're Welcome Very Happy


_________________
"Wisdom is not a product of schooling but of the life-long attempt to acquire it."
- Albert Einstein (1879-1955)


Microsoft MVP - Consumer Security 2006 - 2008
Back to top
View users profile Send private message
TonyKlein

Site Moderator
Microsoft MVP

Joined: Oct 15, 2002
Posts: 13113
Location: Netherlands
MIRT Moderators MVP Premium Security Experts

PostPosted: Mon Jan 24, 2005 2:37 pm    Post subject:
Reply with quote

Thanks for picking this up, Marianna.

And of course thank you for submitting these, Mere_Mortal Smile


Added to the List: CastleCops Link/s6981-mcafe32_exe.html and CastleCops Link/s6982-navprotect_exe.html


_________________
Tony image CLSID List
Back to top
View users profile Send private message
Marianna

Security Expert
Premium Member

Joined: Nov 05, 2003
Posts: 11725

MVP Premium Rootkit Experts Security Experts

PostPosted: Mon Jan 24, 2005 4:53 pm    Post subject:
Reply with quote

You're Welcome, Tony - Teamwork is everything Wink


_________________
"Wisdom is not a product of schooling but of the life-long attempt to acquire it."
- Albert Einstein (1879-1955)


Microsoft MVP - Consumer Security 2006 - 2008
Back to top
View users profile Send private message
Magic_Marker

Cadet
Cadet


Joined: Jan 24, 2005
Posts: 3
Location: USA

PostPosted: Mon Jan 24, 2005 5:53 pm    Post subject:
Reply with quote

Hello everyone,

Was wondering what people are using to remove mcafe32.exe? It doesn't seem to be stopped by Norton Antivirus (with dat files from the 20th)

I've attempted to remove the item from the registry but it appears to reinfect itself.

also has anyone had the problem with this causing a SYN FLOOD and crashing a wireless network?

Thanks!

Back to top
View users profile Send private message
Mere_Mortal

1st Responder


Joined: Apr 10, 2004
Posts: 4191
Location: Kidderminster
1st Responders Rootkit Responders

PostPosted: Mon Jan 24, 2005 6:18 pm    Post subject:
Reply with quote

You're welcome Tony Thumbs Up

Hi Magic_Marker, Welcome to CCSP Smile

Check the link for information...
http://uk.trendmicro-europe.com/enterprise/security_info/ve_detail.php?Vname=WORM_RBOT.AHR

You could by all means post a HijackThis Log to the main forum CastleCops Link/f67-Trend_Micro_HijackThis_Logs.html

Regards,
M_M


_________________
[Malware Removal and Prevention] [Malware Complaints]
Back to top
View users profile Send private message Visit posters website
Magic_Marker

Cadet
Cadet


Joined: Jan 24, 2005
Posts: 3
Location: USA

PostPosted: Mon Jan 24, 2005 8:18 pm    Post subject:
Reply with quote

M_M cool thanks!

Question. it doesn't seem to mention mcafe32.exe it points to different exe files. is this the same thing? sorry I don't have the machiene available right now but I may send a hijack log later to see what people think.

M

Back to top
View users profile Send private message
Mere_Mortal

1st Responder


Joined: Apr 10, 2004
Posts: 4191
Location: Kidderminster
1st Responders Rootkit Responders

PostPosted: Mon Jan 24, 2005 8:51 pm    Post subject:
Reply with quote

Well, it appears to be rather new, which is why it's in fact posted in here in the first place. There's not much mention of it anywhere, so consequentially, there'll be no specific fix for it. That's not to say a manual removal is out of the question though Wink

It is likely an updated version of the RBOT Worm.


_________________
[Malware Removal and Prevention] [Malware Complaints]
Back to top
View users profile Send private message Visit posters website
Magic_Marker

Cadet
Cadet


Joined: Jan 24, 2005
Posts: 3
Location: USA

PostPosted: Tue Jan 25, 2005 4:24 pm    Post subject:
Reply with quote

Just wanted to give an update.

In windows normal mode I just couldn't get things cleaned out completely and it kept reinfecting. was using spybot and microsoft anti-spy both indicated they removed everything but after a reboot they were always back or came back after a few minutes.

unplugged from network.

Disabled system restore.

I booted in safe mode, deleted any of the run keys that appeared to be related (I don't remember which ones but there were alot). rebooted and went back into safe mode.

I downloaded the latest antivirus .dat files from symantec and installed and did a full drive scan. (I saved the .dat to cd then installed from cd) Something in the antivirus was fixed when I ran the intelligent updater it indicated it had fixed some components. Had some files that didn't want to delete so I went into the c:\documents and settings\username\local settings\temporary internet files and deleted the directories that contained the virus files.

rebooted and ran both spy sweeper and microsoft anti spy. spy sweeper seemed to remove all other traces of adware / spyware. Rebooted and went into safe mode again. I ran spy sweeper again just to check then ran antispy for that extra measure. Just for grins I rebooted back into safe mode and ran antivirus again. no infected files found. i'm going to run a few more test on the machine but so far nothing has resurfaced. i'll keep you updated.


MM

Back to top
View users profile Send private message
BCG

Cadet
Cadet


Joined: Jan 26, 2005
Posts: 1
Location: USA

PostPosted: Wed Jan 26, 2005 9:40 pm    Post subject:
Reply with quote

according to symantec definitions 1/25/04 this is a variant of Spybot Worm
We have this all over our network, its bogging down LAN traffic pretty bad.

Back to top
View users profile Send private message
Mere_Mortal

1st Responder


Joined: Apr 10, 2004
Posts: 4191
Location: Kidderminster
1st Responders Rootkit Responders

PostPosted: Wed Jan 26, 2005 10:47 pm    Post subject:
Reply with quote

I believe they are the same problem Wink

IRC.Sdbot [McAfee]
WORM_RBOT [Trend Micro]
W32.Spybot.Worm [Symantec]
Backdoor.Win32.Rbot.gen [Kaspersky]

Trend have updated their listing to include WORM_RBOT.AIJ,
which mentions NAVPROTECT.EXE...

http://es.trendmicro-europe.com/enterprise/security_info/ve_detail.php?VName=WORM_RBOT.AIJ

Also check Pest Patrol's information...
http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39437


_________________
[Malware Removal and Prevention] [Malware Complaints]
Back to top
View users profile Send private message Visit posters website
Mere_Mortal

1st Responder


Joined: Apr 10, 2004
Posts: 4191
Location: Kidderminster
1st Responders Rootkit Responders

PostPosted: Wed Jan 26, 2005 11:39 pm    Post subject:
Reply with quote

I've just come across these removal tools...

ftp://ftp.f-secure.com/anti-virus/tools/f-bot.zip
ftp://ftp.f-secure.com/anti-virus/tools/f-sdbot.zip

Might be useful?


_________________
[Malware Removal and Prevention] [Malware Complaints]
Back to top
View users profile Send private message Visit posters website
lshy

Trooper
Trooper


Joined: Feb 02, 2005
Posts: 12
Location: USA

PostPosted: Wed Feb 02, 2005 3:04 pm    Post subject: Navprotect.exe == msfwe1.exe
Reply with quote

Hi all,
I'm new here...and new to WIN2000 as well. (I upgraded from ME which has been a PAINFUL process.) At any rate, Spysweeper keeps finding navprotect.exe trying to load upon startup. It's in the registry folder HKCU: Run and it's location is msfwe1.exe

I've googled msfwe1.exe and can't find anything on it. I thought someone here might know what it is and if it's even safe.

As a reference, I don't have NAV installed on my computer...and don't know why anything involving Navprotect would be popping up. Furthermore, I did try and remove it prior to the last reinstall of Win2000 and after removing it, the next day I was bombarded with like 700 spyware traces.

Help!
Thanks
Leah Question

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   This topic is locked you cannot edit posts or make replies       All -> FavForums -> Startup Programs All times are GMT
Goto page 1, 2  Next
Page 1 of 2

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer