Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Possible Virus - QetqDB1E.exe


You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion

Possible Virus - QetqDB1E.exe
Reply
 
Thread Tools
Old 01-07-2010, 11:59   #16
Kymmy
Cable Forum Team
 
Kymmy's Avatar
 
Join Date: Dec 2007
Age: 43
Posts: 15,387
Kymmy has a pair of shiny starsKymmy has a pair of shiny stars
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Re: Possible Virus - QetqDB1E.exe

Sorry but that is rediculous and I'm totally astounded that they'd remove an AV and not replace it with a backup.. We always had a policy that no company laptops ever left the building without nav corp on it and because they all were NAV clients we could check to see exactly who updated when and who was getting security alerts..

As said before the machine looks clean.. You really should though contact the IT department and specify that you've got a problem even if it's more a case of covering your back..
Kymmy is online now   Reply With Quote
Old 01-07-2010, 12:01   #17
Keyz333
cf.addict
 
Keyz333's Avatar
 
Join Date: Oct 2007
Location: Yateley, Hampshire
Age: 21
Services: Virgin TV & Broadband
Posts: 261
Keyz333 will become famous soon enoughKeyz333 will become famous soon enoughKeyz333 will become famous soon enough
Send a message via AIM to Keyz333 Send a message via MSN to Keyz333 Send a message via Skype™ to Keyz333
Re: Possible Virus - QetqDB1E.exe

Just browsing the net when I get a chance - I have no idea how this got on here.

And wow, the closest recover point is feb.
Keyz333 is offline   Reply With Quote
Old 01-07-2010, 12:01   #18
zing_deleted
Guest
 
Posts: n/a
Re: Possible Virus - QetqDB1E.exe

is that your ITs fault also?
  Reply With Quote
Old 01-07-2010, 12:08   #19
Keyz333
cf.addict
 
Keyz333's Avatar
 
Join Date: Oct 2007
Location: Yateley, Hampshire
Age: 21
Services: Virgin TV & Broadband
Posts: 261
Keyz333 will become famous soon enoughKeyz333 will become famous soon enoughKeyz333 will become famous soon enough
Send a message via AIM to Keyz333 Send a message via MSN to Keyz333 Send a message via Skype™ to Keyz333
Re: Possible Virus - QetqDB1E.exe

It's a really old machine now too, they just have kind of left it to die.

---------- Post added at 12:08 ---------- Previous post was at 12:02 ----------

And that's a whole disk recover not files etc
Keyz333 is offline   Reply With Quote
Old 01-07-2010, 14:21   #20
DaiNasty
Old dog, New tricks
 
DaiNasty's Avatar
 
Join Date: Dec 2006
Location: Lincoln UK
Age: 63
Services: 50Mb, TV & Phone
Posts: 3,431
DaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronze
DaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronze
Send a message via MSN to DaiNasty
Re: Possible Virus - QetqDB1E.exe

I don't like the look of this at all...

O4 - HKCU\..\Run: [\\BOB\EPSON Stylus Photo R220 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIA IE.EXE /FU "C:\DOCUME~1\emsadmin.asl\LOCALS~1\Temp\E_S2.t mp" /EF "HKCU"

It may be quite innocent but I'm always extremely suspicious of anything that references a Temp folder.
__________________
-= David =-

Under socialism ideology always trumps rationality.
DaiNasty is offline   Reply With Quote
Old 01-07-2010, 14:24   #21
zing_deleted
Guest
 
Posts: n/a
Re: Possible Virus - QetqDB1E.exe

I did google that and have done in the past iirc and its been innocent. If the user has a epson printer I think it can be seen as ok

---------- Post added at 14:24 ---------- Previous post was at 14:22 ----------

http://www.bleepingcomputer.com/foru...p/t165554.html could see what virus total says its gonna have been scanned before but it will give an idea
  Reply With Quote
Old 01-07-2010, 14:37   #22
Kymmy
Cable Forum Team
 
Kymmy's Avatar
 
Join Date: Dec 2007
Age: 43
Posts: 15,387
Kymmy has a pair of shiny starsKymmy has a pair of shiny stars
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Re: Possible Virus - QetqDB1E.exe

Printers reference temp folders a lot especially if the printre is networked on another machine and the drivers are being used from the other machine
Kymmy is online now   Reply With Quote
Old 01-07-2010, 15:18   #23
DaiNasty
Old dog, New tricks
 
DaiNasty's Avatar
 
Join Date: Dec 2006
Location: Lincoln UK
Age: 63
Services: 50Mb, TV & Phone
Posts: 3,431
DaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronze
DaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronze
Send a message via MSN to DaiNasty
Re: Possible Virus - QetqDB1E.exe

Quote:
Originally Posted by Kymmy View Post
Printers reference temp folders a lot especially if the printre is networked on another machine and the drivers are being used from the other machine
Ah yes. Didn't think of that. It seemed unlikely to me that drivers would be located in a Temp folder that could be cleaned at any time but it's the logical place to put work files that by nature are short-lived.

Thanks Kymmy.
__________________
-= David =-

Under socialism ideology always trumps rationality.
DaiNasty is offline   Reply With Quote
Old 01-07-2010, 17:38   #24
Matty_
cf.geek
 
Matty_'s Avatar
 
Join Date: May 2008
Location: Wherever i lay my hat!
Age: 41
Posts: 733
Matty_ has reached the bronze age
Matty_ has reached the bronze ageMatty_ has reached the bronze ageMatty_ has reached the bronze ageMatty_ has reached the bronze ageMatty_ has reached the bronze ageMatty_ has reached the bronze ageMatty_ has reached the bronze age
Re: Possible Virus - QetqDB1E.exe

This looks and smells like a runtime viral infection, you can probably run as many av scanners as you wan`t while booted into the system but it will still probably come back. Possibly Emsisoft`s emergency USB stick ran in Safe-Mode http://www.emsisoft.com/en/software/download/ Deep scan.

Also download Avira`s rescue cd, boot into that and scan http://www.free-av.com/en/products/1...ue_system.html it`s free.

Only other thing is to go the Combofix/OLT route but your better of doing that via Bleeping. My guess is there`s a hidden root kit snuck somewhere...
__________________
Have a nice day!!!
Matty_ is offline   Reply With Quote
Old 01-07-2010, 18:52   #25
DaiNasty
Old dog, New tricks
 
DaiNasty's Avatar
 
Join Date: Dec 2006
Location: Lincoln UK
Age: 63
Services: 50Mb, TV & Phone
Posts: 3,431
DaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronze
DaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronze
Send a message via MSN to DaiNasty
Re: Possible Virus - QetqDB1E.exe

Quote:
Originally Posted by Matty_ View Post
My guess is there`s a hidden root kit snuck somewhere...
My thought as well.

Keyz, is there any way you can hook this drive up as a secondary on another machine? If it's rootkitted you'd be able to scan and zap it while it's not running and able to hide itself.
__________________
-= David =-

Under socialism ideology always trumps rationality.
DaiNasty is offline   Reply With Quote
Old 01-07-2010, 19:22   #26
Kymmy
Cable Forum Team
 
Kymmy's Avatar
 
Join Date: Dec 2007
Age: 43
Posts: 15,387
Kymmy has a pair of shiny starsKymmy has a pair of shiny stars
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Re: Possible Virus - QetqDB1E.exe

Rootkits though normally show up in the reg section of HIJACKTHIS
Kymmy is online now   Reply With Quote
Old 01-07-2010, 19:31   #27
DaiNasty
Old dog, New tricks
 
DaiNasty's Avatar
 
Join Date: Dec 2006
Location: Lincoln UK
Age: 63
Services: 50Mb, TV & Phone
Posts: 3,431
DaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronze
DaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronze
Send a message via MSN to DaiNasty
Re: Possible Virus - QetqDB1E.exe

Quote:
Originally Posted by Kymmy View Post
Rootkits though normally show up in the reg section of HIJACKTHIS
Agreed. Most of the time..

However I've seen reports of wscntfy being hijacked and I'm sure it's possible for other apparently legit files to go the same way.
__________________
-= David =-

Under socialism ideology always trumps rationality.
DaiNasty is offline   Reply With Quote
Old 01-07-2010, 23:34   #28
Horace
© Beam Software
 
Horace's Avatar
 
Join Date: Jan 2004
Location: Teesside
Services: BB (30meg),2 x V+ L , XL Phone, IPad.
Posts: 1,370
Horace has disabled reputation
Re: Possible Virus - QetqDB1E.exe

Give combofix a shot, it'll probably remove anything else that may be installed that you don't know about too . http://www.bleepingcomputer.com/comb...o-use-combofix
Horace is offline   Reply With Quote
Old 02-07-2010, 10:16   #29
Keyz333
cf.addict
 
Keyz333's Avatar
 
Join Date: Oct 2007
Location: Yateley, Hampshire
Age: 21
Services: Virgin TV & Broadband
Posts: 261
Keyz333 will become famous soon enoughKeyz333 will become famous soon enoughKeyz333 will become famous soon enough
Send a message via AIM to Keyz333 Send a message via MSN to Keyz333 Send a message via Skype™ to Keyz333
Re: Possible Virus - QetqDB1E.exe

I will try these today

Combofix I get an instant error report.
Keyz333 is offline   Reply With Quote
Old 02-07-2010, 11:20   #30
zing_deleted
Guest
 
Posts: n/a
Re: Possible Virus - QetqDB1E.exe

combofix should not be run by the inexperienced
  Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



Google Search




All times are GMT +1. The time now is 13:12.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
Copyright © 2003 - 2012, Cable Forum.
(server1.cableforum.co.uk)

SEO by vBSEO 3.3.2