Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.
Unknown Zip / Exe files
Name: Bigfatdummy Date: February 25, 2004 at 12:38:11 Pacific OS: XP PRO CPU/Ram: P4 1024
Comment:
I recently discovered several zip files with a single exe file inside. (YWBBTX.ZIP and NZQQQUUEJZZIK.EXE) The name of the zip file as well as the name of the exe file varies. I suspect that these files are a virus of some type but I cant find anything about them. I am a bit concerned because I am finding these files on my servers as well as on the network pc's. I have run Symantec Enterprise Edition ver 8.6 and TrendMicro's housecall, but still am unable to detect anything. I have also run Spybot search & destroy and PC bug Doctor. Anyone have any suggestions?
Name: Solarian Date: February 25, 2004 at 12:58:08 Pacific
Reply:
Brian:
Research din't give me any hits, either.
When in doubt, delete.
Solarian
0
Response Number 2
Name: suzi Date: February 25, 2004 at 13:21:13 Pacific
Reply:
I agree with Solarian, but I'm curious if your firewall logs are showing any unusual activity. Hopefully you are running a firewall!
0
Response Number 3
Name: JackG Date: February 25, 2004 at 15:34:04 Pacific
Reply:
I would copy some of them to a safe place and submit them to several of the AV companies to look at and see what they think.
How big are the exe files? Are they all about the same size?
What do they look like if you open them in something like NotePad? Code or text messages in them. Text messages may give you a clue as to what they are for. You may be on to some Trojan hijacking your servers.
0
Response Number 4
Name: vipergg Date: February 25, 2004 at 17:08:43 Pacific
Reply:
What happens when you scan them with your AV , does it give you any hints ? Have you looked in your AV logs to see if it has quarantined anything lately . Just looked at my wifes laptop and AVG had quarantined about a dozen .zip files a week or two ago , just deleted them ,she didn't have logging turned on so I couldn't see what virus it was.
Summary: Ok, so guys, I have the exact same problem. Winlogonhook & those darn .tmp files. Here's my HT log: Logfile of HijackThis v1.99.1 Scan saved at 14:56:52, on 21.3.2006 Platform: Windows XP SP2 (WinNT 5...
Summary: Well thanks for the advice on avast, I installed it and it cleaned up the win*.exe files. Here is the (abridged) log file from the boot scan: 08/08/2006 13:42 Scan of all local drives File C:\System V...