Here is what I did...
1) Disconnected from the internet.
2) Searched for any files containing 'checkin'. There
were 4, one for each user login in the 'temp internet
files' directory.
3) Deleted each of these.
4) Rescanned the system32 folder and deleted the found
virus.
5) Did a complete rescan and no virus!
There you go.
>-----Original Message-----
>I just got the same virus. I will be watching and
>searching for a solution.
>>-----Original Message-----
>>I could not locate the "checkin a or b" files and the
>>system would not allow me to delete the owmngr.exe
file.
>>However the file does contain about 44kb.
>>What can I do next, I am not very technical.
>>>-----Original Message-----
>>>This is "downloader" trojan which downloads a given
file
>>>from a certain site and runs it. The trojan itself is a
>>>Windows PE EXE file, written in MS Visual C++.
>>>The trojan file size is about:
>>> "Checkin.a": 50Kb
>>> "Checkin.b": 45Kb
>>>The trojan EXE file does not copy itself to any
>>directory
>>>but creates the system registry auto-run key:
>>>"Checkin.a":
>>> HKCU\Software\Microsoft\Windows\CurrentVersion\Run
>>> SysReg = %SystemDir%\SysReg
>>>"Checkin.b":
>>> HKCU\Software\Microsoft\Windows\CurrentVersion\Run
>>> OWMngr = %SystemDir%\OWMngr.exe
>>>It seems that the trojan should be completed
>>>by "installator" that performs all steps of trojan
>>>installation into the system.
>>>The trojan also creates more registry keys:
>>> HKCU\Software\IExplore\
>>> Ads
>>> AID
>>> ID
>>> LoggedIn
>>>and uses these keys for its internal needs.
>>>The trojan then stays as active process (this process
is
>>>visible in the task list), downloads a file from a Web
>>>site, stores it on disk with "update.exe" name and
>>>executes it. The Web site name and remote file URL can
>>be
>>>variable. The trojan downloads that information from
>>>another Web site:
>>> "Checkin.a": http://tp.searchseekfind.com
>>> "Checkin.b": http://ads.onwebmedia.com
>>>with using the "Checkin.pl" file in there.
>>>>-----Original Message-----
>>>>I have a Trojan virus called OwMngr.exe on my
computer,
>>>my AV software
>>>>picked it up (AVG Grisoft).
>>>>I can't get rid of it. Every I delete the file it
comes
>>>back again and
>>>>re-inserts its self on my program start-up list.
>>>>Help appreciated........Please
>>>>Thanks
>>>>Tom
>>>>.
>>>.
>>.
>.