OK boys and girls....I walked into the house from work today and was greeted by an Avast warning saying that I was infected by the Nutcracker virus/worm and was prompted to place it in the virus chest which I did. I then googled to see what this thing was.
Upon opening the Virus chest and rescanning, this is the information given to me:
Scanning of selected files
------------------------------------------------------------------------------------------
Program will try to scan 1 selected file(s) in the Chest
Move files to temporary folder: C:\DOCUME~1\scott\LOCALS~1\Temp\_avast4_\unp189293 906.tmp
FileID: 0000000004 Original file name: C:\Documents and Settings\scott\Start Menu\Programs\Startup\work\wudata_08.chk New folder: C:\DOCUME~1\scott\LOCALS~1\Temp\_avast4_\unp189293 906.tmp\4.chk
Scan files in the temporary folder: C:\DOCUME~1\scott\LOCALS~1\Temp\_avast4_\unp189293 906.tmp
C:\DOCUME~1\scott\LOCALS~1\Temp\_avast4_\unp189293 906.tmp\4.chk Nutcracker family
------------------------------------------------------------------------------------------
Action was completed successfully!
McAfee says the following:
http://vil.nai.com/vil/content/v_98034.htm
I haven't rebooted this laptop in about 2 weeks and it doens't even have a floppy and the DVD drive is empty, so unless I'm totally off base here I'm wondering why I'm getting/how I've been infected. So I give thee my HiJack this log for further consideration...
Upon opening the Virus chest and rescanning, this is the information given to me:
Scanning of selected files
------------------------------------------------------------------------------------------
Program will try to scan 1 selected file(s) in the Chest
Move files to temporary folder: C:\DOCUME~1\scott\LOCALS~1\Temp\_avast4_\unp189293 906.tmp
FileID: 0000000004 Original file name: C:\Documents and Settings\scott\Start Menu\Programs\Startup\work\wudata_08.chk New folder: C:\DOCUME~1\scott\LOCALS~1\Temp\_avast4_\unp189293 906.tmp\4.chk
Scan files in the temporary folder: C:\DOCUME~1\scott\LOCALS~1\Temp\_avast4_\unp189293 906.tmp
C:\DOCUME~1\scott\LOCALS~1\Temp\_avast4_\unp189293 906.tmp\4.chk Nutcracker family
------------------------------------------------------------------------------------------
Action was completed successfully!
McAfee says the following:
Nutcracker is a boot sector virus which will not work on 586 systems. It rewrites sectors of floppy and hard drives, and these sectors become unreadable by device drivers.
Symptoms
Symptoms -
The virus has complex behavior. It can corrupt or encrypt files and drive sectors. It is probably better to reformat and restore from a backup than to attempt to clean the virus and repair damages.
Method of Infection
Method of Infection -
The only way to infect a computer with an MBR/Boot Sector infector is to attempt to boot from an infected floppy diskette. The boot sector of the diskette has the code to determine if the diskette is bootable, and to display the "Non-system disk or disk error" message. It is this code that harbors the infection. By the time the non-system disk error message comes up, the infection has occurred.
Once the virus is executed, it will infect the hard drive's MBR and may become memory resident. With every subsequent boot, the virus will be loaded into memory and will attempt to infect floppy diskettes accessed by the machine.
Symptoms
Symptoms -
The virus has complex behavior. It can corrupt or encrypt files and drive sectors. It is probably better to reformat and restore from a backup than to attempt to clean the virus and repair damages.
Method of Infection
Method of Infection -
The only way to infect a computer with an MBR/Boot Sector infector is to attempt to boot from an infected floppy diskette. The boot sector of the diskette has the code to determine if the diskette is bootable, and to display the "Non-system disk or disk error" message. It is this code that harbors the infection. By the time the non-system disk error message comes up, the infection has occurred.
Once the virus is executed, it will infect the hard drive's MBR and may become memory resident. With every subsequent boot, the virus will be loaded into memory and will attempt to infect floppy diskettes accessed by the machine.
I haven't rebooted this laptop in about 2 weeks and it doens't even have a floppy and the DVD drive is empty, so unless I'm totally off base here I'm wondering why I'm getting/how I've been infected. So I give thee my HiJack this log for further consideration...
Comment