Search Members Help

» Welcome Guest
[ Log In :: Register ]

 

[ Track This Topic :: Email This Topic :: Print this topic ]

reply to topic new topic new poll
Topic: Well somebody thinks they're effin' funny..., Bastards... all of them...< Next Oldest | Next Newest >
 Post Number: 1
^Oni^ Search for posts by this member.
Flagellate
Avatar



Group: Members
Posts: 209
Joined: Jun. 2002
PostIcon Posted on: Jul. 17 2002,03:12  Skip to the next post in this topic. Ignore posts   QUOTE

IRC.Trojan

I came home from work to find a little NAV2K2 window on my desktop saying it found this.

The infected file was called "winregsrv.exe" and thus far I can't find anything about whether it is supposed to be in my System32 dir or not. Effin' fuck.

If anyone has some idea about that filename, input would be appreciated.

--------------
Would you rather have perfectly developed trapezius muscles and shaky moral grounding or be able to generate complex shadow puppets but comprehend absolutely nothing said to you between the hours of 3 and 4 pm?
Offline
Top of Page Profile Contact Info 
 Post Number: 2
Jynx Search for posts by this member.
resident n0b0dy
Avatar



Group: Members
Posts: 333
Joined: Dec. 2000
PostIcon Posted on: Jul. 17 2002,20:16 Skip to the previous post in this topic. Skip to the next post in this topic. Ignore posts   QUOTE

What OS do you have?

At first glance, my guess is that the file is used to register either .dll files or services.  After all, I believe you can manually register them with "regsvr32", and the naming scheme is similar.

I am, however, too lazy to Google it for you - knock yerself out.
Offline
Top of Page Profile Contact Info 
 Post Number: 3
^Oni^ Search for posts by this member.
Flagellate
Avatar



Group: Members
Posts: 209
Joined: Jun. 2002
PostIcon Posted on: Jul. 18 2002,14:40 Skip to the previous post in this topic. Skip to the next post in this topic. Ignore posts   QUOTE

I'm running XP... I googled it and found nothing and there is nothing in the MS Knowledge base about it... that's why I'm asking...

--------------
Would you rather have perfectly developed trapezius muscles and shaky moral grounding or be able to generate complex shadow puppets but comprehend absolutely nothing said to you between the hours of 3 and 4 pm?
Offline
Top of Page Profile Contact Info 
 Post Number: 4
forumwhore Search for posts by this member.
Fear Me, I Am Change.
Avatar



Group: Members
Posts: 3282
Joined: Dec. 2001
PostIcon Posted on: Jul. 18 2002,14:43 Skip to the previous post in this topic. Skip to the next post in this topic. Ignore posts   QUOTE

Did not your link also detail removal?

--------------
Posting from; El Pueblo de Nuestra Senora la Reina de Los Angeles de Porciuncula
Offline
Top of Page Profile Contact Info 
 Post Number: 5
Wiley Search for posts by this member.
©0®ÞØ®4+3 whØ®3
Avatar



Group: Members
Posts: 1268
Joined: Oct. 2001
PostIcon Posted on: Jul. 18 2002,16:04 Skip to the previous post in this topic.  Ignore posts   QUOTE

Quote (^Oni^ @ 16 July 2002,19:12)
The infected file was called "winregsrv.exe"

hehe ...sneaky bastads.
The file Regsvr32.exe is used by windows to register .dll files.  If there were a win version of the file I'm sure it would keep the same naming convention of Winregsvr.exe and not Winregsrv.exe.  I'm pretty sure you've been hosed.
Just to be sure:
Right-click on the file and go to properties and check the version info.  If it's MS then you can bet your ass they filled that info out (since file size is not a concern after all).  
I would delete it, and check to make sure nothing is calling the file durring system startup.
Offline
Top of Page Profile Contact Info WEB 
4 replies since Jul. 17 2002,03:12 < Next Oldest | Next Newest >

[ Track This Topic :: Email This Topic :: Print this topic ]


 
reply to topic new topic new poll

» Quick Reply Well somebody thinks they're effin' funny...
iB Code Buttons
You are posting as:

Do you wish to enable your signature for this post?
Do you wish to enable emoticons for this post?
Track this topic
View All Emoticons
View iB Code