PC Review


Reply
Thread Tools Rate Thread

What virus is this?

 
 
Modecate
Guest
Posts: n/a
 
      11th Jan 2004
Found an executable on my windows\system dir: mpwzojgl.exe, though
earlier it had a different name, so it seems to spawn random names.
Size is 453K . Norton didn't turn up anything, neither did spybot or
adaware. First saw it while running a check on my running processes in
proport(recommended BTW) Pretty sure it knocked out my Norton
installation first time round and had to reinstall. Can't find any
suspicious HKLM or HKCU run, runonce or runservices. Oh, and running
the exec gives the error "can't load ak32dll.dll"(did a find file..no
luck) after which the exec deletes itself! WTF? Any ideas out there?

 
Reply With Quote
 
 
 
 
David W. Hodgins
Guest
Posts: n/a
 
      11th Jan 2004
On Sun, 11 Jan 2004 19:51:36 GMT, Modecate <(E-Mail Removed)> wrote:

> Found an executable on my windows\system dir: mpwzojgl.exe, though
> earlier it had a different name, so it seems to spawn random names.
> Size is 453K . Norton didn't turn up anything, neither did spybot or


Submit a copy for them to examine. See
http://groups.google.com/groups?q=su...ncis.de&rnum=3
for a list of addresses.

> adaware. First saw it while running a check on my running processes in
> proport(recommended BTW) Pretty sure it knocked out my Norton
> installation first time round and had to reinstall. Can't find any
> suspicious HKLM or HKCU run, runonce or runservices. Oh, and running
> the exec gives the error "can't load ak32dll.dll"(did a find file..no
> luck) after which the exec deletes itself! WTF? Any ideas out there?


See http://users.iafrica.com/c/cq/cquirke/startup.htm for most of the
places it could be starting. Also check the task scheduler.

Regards, Dave Hodgins

--
Change nomail.afraid.org to rogers.com to reply by email.
(nomail.afraid.org has been set up specfically for
use in usenet. Feel free to use it yourself.)
 
Reply With Quote
 
modecate
Guest
Posts: n/a
 
      11th Jan 2004
On Sun, 11 Jan 2004 20:52:42 GMT, "David W. Hodgins"
<(E-Mail Removed)> wrote:

>On Sun, 11 Jan 2004 19:51:36 GMT, Modecate <(E-Mail Removed)> wrote:
>
>> Found an executable on my windows\system dir: mpwzojgl.exe, though
>> earlier it had a different name, so it seems to spawn random names.
>> Size is 453K . Norton didn't turn up anything, neither did spybot or

>
>Submit a copy for them to examine. See
>http://groups.google.com/groups?q=su...ncis.de&rnum=3
>for a list of addresses.
>
>> adaware. First saw it while running a check on my running processes in
>> proport(recommended BTW) Pretty sure it knocked out my Norton
>> installation first time round and had to reinstall. Can't find any
>> suspicious HKLM or HKCU run, runonce or runservices. Oh, and running
>> the exec gives the error "can't load ak32dll.dll"(did a find file..no
>> luck) after which the exec deletes itself! WTF? Any ideas out there?

>
>See http://users.iafrica.com/c/cq/cquirke/startup.htm for most of the
>places it could be starting. Also check the task scheduler.
>
>Regards, Dave Hodgins

Would it be ok to rename it as a dat file and post it to
alt.binaries.test? This is some text I found in it:

Id: UPX 1.01 Copyright (C) 1996-2000 the UPX Team. All Rights Info:
This file is packed with the UPX executable packer http://upx.tsx.org
Reserved. $

 
Reply With Quote
 
David W. Hodgins
Guest
Posts: n/a
 
      12th Jan 2004
On Sun, 11 Jan 2004 20:58:20 GMT, modecate <(E-Mail Removed)> wrote:

> Would it be ok to rename it as a dat file and post it to
> alt.binaries.test? This is some text I found in it:
>
> Id: UPX 1.01 Copyright (C) 1996-2000 the UPX Team. All Rights Info:
> This file is packed with the UPX executable packer http://upx.tsx.org
> Reserved. $


You can email a copy to me if you like.

Regards, Dave Hodgins

--
Change nomail.afraid.org to rogers.com to reply by email.
(nomail.afraid.org has been set up specfically for
use in usenet. Feel free to use it yourself.)
 
Reply With Quote
 
kurt wismer
Guest
Posts: n/a
 
      12th Jan 2004
modecate wrote:
[snip]
> Would it be ok to rename it as a dat file and post it to
> alt.binaries.test? This is some text I found in it:


no, it would not be alright...

it would in fact be downright irresponsible of you to put a suspected
virus in a place where anyone could get it...

--
"hungry people don't stay hungry for long
they get hope from fire and smoke as the weak grow strong
hungry people don't stay hungry for long
they get hope from fire and smoke as they reach for the dawn"

 
Reply With Quote
 
Modecate
Guest
Posts: n/a
 
      12th Jan 2004
On Sun, 11 Jan 2004 19:41:16 -0500, kurt wismer <(E-Mail Removed)>
wrote:

>modecate wrote:
>[snip]
>> Would it be ok to rename it as a dat file and post it to
>> alt.binaries.test? This is some text I found in it:

>
>no, it would not be alright...
>
>it would in fact be downright irresponsible of you to put a suspected
>virus in a place where anyone could get it...

That's why I asked first,

Thanks
 
Reply With Quote
 
Modecate
Guest
Posts: n/a
 
      25th Jan 2004
On Sun, 11 Jan 2004 19:51:36 GMT, Modecate <(E-Mail Removed)> wrote:

>Found an executable on my windows\system dir: mpwzojgl.exe, though
>earlier it had a different name, so it seems to spawn random names.
>Size is 453K . Norton didn't turn up anything, neither did spybot or
>adaware. First saw it while running a check on my running processes in
>proport(recommended BTW) Pretty sure it knocked out my Norton
>installation first time round and had to reinstall. Can't find any
>suspicious HKLM or HKCU run, runonce or runservices. Oh, and running
>the exec gives the error "can't load ak32dll.dll"(did a find file..no
>luck) after which the exec deletes itself! WTF? Any ideas out there?

OK, I found out what it was....an anti keylogger demo that I thought
had been disabled. I have to say this use of random file names is
unusual though. I'm not suggestibg this is a virus, far from it, it
seems to be the most widely used akl around.
 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Re: Use this important VIRUS ALERT - VIRUS ALERT - W32.Swen.A@mm Worm - VIRUS ALERT - VIRUS ALERT - VIRUS ALERT - VIRUS ALERT nemo Microsoft VC .NET 0 3rd Nov 2003 09:34 PM
Re: See update - VIRUS ALERT - VIRUS ALERT - W32.Swen.A@mm Worm - VIRUS ALERT - VIRUS ALERT - VIRUS ALERT - VIRUS ALERT nemo Microsoft Dot NET Framework 0 12th Oct 2003 02:29 PM
Re: See update - VIRUS ALERT - VIRUS ALERT - W32.Swen.A@mm Worm - VIRUS ALERT - VIRUS ALERT - VIRUS ALERT - VIRUS ALERT nemo Microsoft Outlook Contacts 0 12th Oct 2003 02:29 PM
Re: See update - VIRUS ALERT - VIRUS ALERT - W32.Swen.A@mm Worm - VIRUS ALERT - VIRUS ALERT - VIRUS ALERT - VIRUS ALERT nemo Windows XP Print / Fax 0 12th Oct 2003 02:29 PM
New Virus detected as of yet unknown to Anti-Virus companied (Virus Name: MSBLAST.EXE) . Anti-Virus 6 12th Aug 2003 07:06 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 03:20 PM.