Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Possible Virus - QetqDB1E.exe

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion
Register FAQ Community Calendar

Possible Virus - QetqDB1E.exe
Reply
 
Thread Tools
Old 01-07-2010, 11:59   #16
Kymmy
Inactive
 
Join Date: Dec 2007
Posts: 18,385
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Re: Possible Virus - QetqDB1E.exe

Sorry but that is rediculous and I'm totally astounded that they'd remove an AV and not replace it with a backup.. We always had a policy that no company laptops ever left the building without nav corp on it and because they all were NAV clients we could check to see exactly who updated when and who was getting security alerts..

As said before the machine looks clean.. You really should though contact the IT department and specify that you've got a problem even if it's more a case of covering your back..
Kymmy is offline   Reply With Quote
Advertisement
Old 01-07-2010, 12:01   #17
Keyz333
cf.addict
 
Join Date: Oct 2007
Location: Fleet, Hampshire
Age: 35
Services: Cuckoo (BT) Broadband
Posts: 265
Keyz333 has a spectacular aura about themKeyz333 has a spectacular aura about themKeyz333 has a spectacular aura about themKeyz333 has a spectacular aura about them
Send a message via AIM to Keyz333 Send a message via MSN to Keyz333
Re: Possible Virus - QetqDB1E.exe

Just browsing the net when I get a chance - I have no idea how this got on here.

And wow, the closest recover point is feb.
Keyz333 is offline   Reply With Quote
Old 01-07-2010, 12:01   #18
zing_deleted
Guest
 
Posts: n/a
Re: Possible Virus - QetqDB1E.exe

is that your ITs fault also?
  Reply With Quote
Old 01-07-2010, 12:08   #19
Keyz333
cf.addict
 
Join Date: Oct 2007
Location: Fleet, Hampshire
Age: 35
Services: Cuckoo (BT) Broadband
Posts: 265
Keyz333 has a spectacular aura about themKeyz333 has a spectacular aura about themKeyz333 has a spectacular aura about themKeyz333 has a spectacular aura about them
Send a message via AIM to Keyz333 Send a message via MSN to Keyz333
Re: Possible Virus - QetqDB1E.exe

It's a really old machine now too, they just have kind of left it to die.

---------- Post added at 12:08 ---------- Previous post was at 12:02 ----------

And that's a whole disk recover not files etc
Keyz333 is offline   Reply With Quote
Old 01-07-2010, 14:21   #20
Dai
Inactive
 
Join Date: Dec 2006
Location: Lincoln UK
Age: 76
Services: 50Mb, TV & Phone
Posts: 3,673
Dai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronze
Dai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronze
Send a message via MSN to Dai
Re: Possible Virus - QetqDB1E.exe

I don't like the look of this at all...

O4 - HKCU\..\Run: [\\BOB\EPSON Stylus Photo R220 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIA IE.EXE /FU "C:\DOCUME~1\emsadmin.asl\LOCALS~1\Temp\E_S2.t mp" /EF "HKCU"

It may be quite innocent but I'm always extremely suspicious of anything that references a Temp folder.
Dai is offline   Reply With Quote
Old 01-07-2010, 14:24   #21
zing_deleted
Guest
 
Posts: n/a
Re: Possible Virus - QetqDB1E.exe

I did google that and have done in the past iirc and its been innocent. If the user has a epson printer I think it can be seen as ok

---------- Post added at 14:24 ---------- Previous post was at 14:22 ----------

http://www.bleepingcomputer.com/foru...p/t165554.html could see what virus total says its gonna have been scanned before but it will give an idea
  Reply With Quote
Old 01-07-2010, 14:37   #22
Kymmy
Inactive
 
Join Date: Dec 2007
Posts: 18,385
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Re: Possible Virus - QetqDB1E.exe

Printers reference temp folders a lot especially if the printre is networked on another machine and the drivers are being used from the other machine
Kymmy is offline   Reply With Quote
Old 01-07-2010, 15:18   #23
Dai
Inactive
 
Join Date: Dec 2006
Location: Lincoln UK
Age: 76
Services: 50Mb, TV & Phone
Posts: 3,673
Dai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronze
Dai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronze
Send a message via MSN to Dai
Re: Possible Virus - QetqDB1E.exe

Quote:
Originally Posted by Kymmy View Post
Printers reference temp folders a lot especially if the printre is networked on another machine and the drivers are being used from the other machine
Ah yes. Didn't think of that. It seemed unlikely to me that drivers would be located in a Temp folder that could be cleaned at any time but it's the logical place to put work files that by nature are short-lived.

Thanks Kymmy.
Dai is offline   Reply With Quote
Old 01-07-2010, 17:38   #24
Matty_
cf.geek
 
Join Date: May 2008
Location: Wherever i lay my hat!
Age: 54
Posts: 736
Matty_ has reached the bronze age
Matty_ has reached the bronze ageMatty_ has reached the bronze ageMatty_ has reached the bronze ageMatty_ has reached the bronze ageMatty_ has reached the bronze ageMatty_ has reached the bronze ageMatty_ has reached the bronze age
Re: Possible Virus - QetqDB1E.exe

This looks and smells like a runtime viral infection, you can probably run as many av scanners as you wan`t while booted into the system but it will still probably come back. Possibly Emsisoft`s emergency USB stick ran in Safe-Mode http://www.emsisoft.com/en/software/download/ Deep scan.

Also download Avira`s rescue cd, boot into that and scan http://www.free-av.com/en/products/1...ue_system.html it`s free.

Only other thing is to go the Combofix/OLT route but your better of doing that via Bleeping. My guess is there`s a hidden root kit snuck somewhere...
Matty_ is offline   Reply With Quote
Old 01-07-2010, 18:52   #25
Dai
Inactive
 
Join Date: Dec 2006
Location: Lincoln UK
Age: 76
Services: 50Mb, TV & Phone
Posts: 3,673
Dai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronze
Dai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronze
Send a message via MSN to Dai
Re: Possible Virus - QetqDB1E.exe

Quote:
Originally Posted by Matty_ View Post
My guess is there`s a hidden root kit snuck somewhere...
My thought as well.

Keyz, is there any way you can hook this drive up as a secondary on another machine? If it's rootkitted you'd be able to scan and zap it while it's not running and able to hide itself.
Dai is offline   Reply With Quote
Old 01-07-2010, 19:22   #26
Kymmy
Inactive
 
Join Date: Dec 2007
Posts: 18,385
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Re: Possible Virus - QetqDB1E.exe

Rootkits though normally show up in the reg section of HIJACKTHIS
Kymmy is offline   Reply With Quote
Old 01-07-2010, 19:31   #27
Dai
Inactive
 
Join Date: Dec 2006
Location: Lincoln UK
Age: 76
Services: 50Mb, TV & Phone
Posts: 3,673
Dai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronze
Dai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronze
Send a message via MSN to Dai
Re: Possible Virus - QetqDB1E.exe

Quote:
Originally Posted by Kymmy View Post
Rootkits though normally show up in the reg section of HIJACKTHIS
Agreed. Most of the time..

However I've seen reports of wscntfy being hijacked and I'm sure it's possible for other apparently legit files to go the same way.
Dai is offline   Reply With Quote
Old 01-07-2010, 23:34   #28
Horace
©Beam Software
 
Join Date: Jan 2004
Location: Teesside
Services: BB (200mbit), 1x V6, iPad, iPhone
Posts: 1,411
Horace has reached the bronze age
Horace has reached the bronze age
Re: Possible Virus - QetqDB1E.exe

Give combofix a shot, it'll probably remove anything else that may be installed that you don't know about too . http://www.bleepingcomputer.com/comb...o-use-combofix
Horace is offline   Reply With Quote
Old 02-07-2010, 10:16   #29
Keyz333
cf.addict
 
Join Date: Oct 2007
Location: Fleet, Hampshire
Age: 35
Services: Cuckoo (BT) Broadband
Posts: 265
Keyz333 has a spectacular aura about themKeyz333 has a spectacular aura about themKeyz333 has a spectacular aura about themKeyz333 has a spectacular aura about them
Send a message via AIM to Keyz333 Send a message via MSN to Keyz333
Re: Possible Virus - QetqDB1E.exe

I will try these today

Combofix I get an instant error report.
Keyz333 is offline   Reply With Quote
Old 02-07-2010, 11:20   #30
zing_deleted
Guest
 
Posts: n/a
Re: Possible Virus - QetqDB1E.exe

combofix should not be run by the inexperienced
  Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 01:14.


Server: osmium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2025, vBulletin Solutions Inc.
All Posts and Content are © Cable Forum