PDA

View Full Version : Win32:Lovgate-E1-ASP [Wrm]


killercow
08-29-2004, 09:31 PM
:( :( :( :( :(

I opened an email attachment from a friend of mine (who until now I trusted) and it was supposed to have some html coding in it to help me out with my site... well I open the zip file he sent me and now I've got jipperish printing all the time and emails being forcefully sent through outlook express. I ran and am running again an avast scan. On the system boot scan it found 28 files infected and if they were in the windows folder i ignored them... if they weren't I deleted them. Some of the files I deleted were C:/command.exe and D:/command.exe and F:/command.exe and E:/command.exe (each of those are partitions on my 2 hard drives. I have no clue what some of them are I was just angry:mad:. Now I cannot access those drives in my computer and the file: C:\WINDOWS\System32\hxdef.exe cannot be quarintined, deleted, or fixed. None of them can be fixed so I just delete them. I do remember that C:/windows/system32/IEXPLOER.EXE was infected and against my better judgement I deleted it. Is there any way to fix this problem?????? He is going to get it from me when I see him at school tomorrow!:mad:

everything is infected and I'm getting virus warnings, outlookexpress warnings, printouts and everything every couple of minutes. Any help would be greatly appreciated.

thanks

Paul Komski
08-29-2004, 10:17 PM
If you are on a LAN pull the cable out of the NIC.

Try the removal tool from http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.lovgate.c@mm.html

killercow
08-30-2004, 07:40 PM
Thank you much Paul.

The removal tool changed multiple registry keys but found no traces of the worm. Avast Antivirus said differently and I am running another Avast scan now just to be sure.

But I have another problem:(

With most of the files I deleted on the initial Avast scan were the x:/command.exe files on all four of my virtual drives. Now if I open up my computer and double click on the drive I get this:

http://upload-patch.net/users/heinebro802/desktop.jpg

Is there any way to fix this?

Paul Komski
08-31-2004, 06:22 PM
Delete any autorun.inf (http://support.microsoft.com/default.aspx?scid=kb;EN-US;153981) files if they exist in any of your HDD partitions.

killercow
08-31-2004, 06:34 PM
:(

thanks, there are no aurorun.inf files on any of my drives. It's asking me for a command.exe I'm not sure if that's the same thing.

Paul Komski
09-01-2004, 04:29 PM
Something is "pointing to" command.exe. It looked as if this was an autorun.inf file and I cant think of another way that accessing a drive would sipmly just call another program. The other strange thing is to have what appently is a .file file extension though this had seemed to be addressed in the MS article.

Autorun.inf files do not normally autorun stuff from HDDs but from CDROMs. One can suppress them on CDROMs by holding down the shift key when the CD is inserted/accessed; perhaps depressing the shift key when accessing your partitions might have the same effect.