Our Success is in our members who value our strength as a valued community.
Forum Stats
12184 Members
65 Forums
72603 Topics
978365 Posts
69 posts in the last 24hrs
Max Online: 7831 @ 8th Apr 2013 4:18pm
Who's Online - Click Me
94 registered (11kendo, 18 invisible), 1518 Guests and 194 Spiders online.
Key: Admin, Global Mod, Mod
Social Media : Follow Us


(Views 7days)This Weeks Most Read
Secretive mega shake-up of NHS could cost 15 mil 627
Found a mobile phone 14/01/2017 WALLASEY 389
Asbestos shed removal 371
Paypal help 366
Sometimes You Could Strangle Someone 355
When we live to be a 100 yrs old 313
Best Price for Scarpping my car 286
Lost Mobile Phone 282
Spy in the wild 281
RAC ,AA v Breakdown Recovery 279
New General Forums
The Scouse Accent
by palemoon
18th Jan 2017 7:49pm
birthday wishes
by sunnyside
18th Jan 2017 12:48pm
The Green Eyed Girl
by granny
17th Jan 2017 10:33pm
Breastfeeding Dads Want to Be A Breastfeeding Hero
by fish5133
16th Jan 2017 1:24pm
New Wirral History
753 Sea Horse, Unit 9, Wallasey Waterfront
by Norton
18th Jan 2017 9:07pm
What was County Hall, Abbey Street, Birkenhead?
by yoller
15th Jan 2017 1:28pm
752 The Old Manor Club, Withens Lane, Liscard
by Norton
13th Jan 2017 2:20pm
751 Plough Inn, Mount Pleasant Rd, New Brighton
by Norton
13th Jan 2017 1:38pm
351 Prince Alfred 30 Tunnel Road 30 30 to 32
by yoller
8th Jan 2017 7:18pm
Forum Tips
Photo Gallery Forums
fireworks on the Mersey last night
Hadlow train station
Topic Replies
Melamine faced chipboard ( Walnut or Oak )
by Reno37
Sanctuary awaits 5 bears
by venice
10:19 AM
Parking Charges
by Gibbo
10:03 AM
Musicals
by casper
07:21 AM
What song are you listening to?
by diggingdeeper
05:57 AM
Question Time
by paxvobiscum
12:50 AM
Spy in the wild
by cools
11:15 PM
Asbestos shed removal
by Snodvan
06:45 PM
Taylors Villas 1874 any info?
by locomotive
06:31 PM
January
M Tu W Th F Sa Su
1
2 3 4 5 6 7 8
9 10 11 12 13 14 15
16 17 18 19 20 21 22
23 24 25 26 27 28 29
30 31
Recent Posts : What's On ?
Indian/Jazz fusion music Liverpool
by buddy
17th Jan 2017 9:46am
Chinese New Year Liverpool
by paxvobiscum
15th Jan 2017 11:08am
Topic Options
Rate This Topic
#279867 - 3rd Jan 2009 6:44pm ~.exe virus?
diggingdeeper Offline

Wiki Guardian

Registered: 9th Jul 2008
Posts: 9668
Loc: Birkenhead
I have a file ~.exe in c:windows\system32 directory/folder - does anybody know anything about his, it runs at boot somehow and tries to access the internet occasionally.

I strongly suspect this is a trojan keylogger (like somebody else on the net), but there is no mention by any of the virus people and only a couple of queries by punters.

It is not helped that google can't search for the tilde character ~

I can stop the process easy enough and it is well and truly blocked from talking to the internet.

For the moment I have renamed the file to stop it being run.

It is 8238 bytes long (9K), the only times it could have come onto my computer is either through an "Adobe Reader" update or a "Mozilla Thunderbird" update (which I might have OK'd without looking too closely), nothing else was given permission to run at about the time the file was created.

The only other funny that has happened recently was Windows Installer popping up sometimes looking for a CD that isn't there and asking me to insert a vdrive CD (I do have vdrive installed, but haven't used it for ages), this happens when I try to run programs that I use all the time from the hard drive, but happens only occasionally.

Any help appreciated.
_________________________
In a time of universal deceit - telling the truth is a revolutionary act. George Orwell

When the debate is lost, slander becomes the tool of the loser. Socrates

Top
Digital Wirral : Advertising
Click me for more Information......

* * * vipimages.co.uk - Photographic services * * *
Now Advertise with WikiWirral.
WikiWirral stats 35,000 Page Views a Day +500 Search Engines.. Click Me
#279871 - 3rd Jan 2009 6:48pm Re: ~.exe virus? [Re: diggingdeeper]
Mark Online   Reading


Wiki Master

Registered: 9th Nov 2003
Posts: 21001
Loc: Wirral
Check

msconfig

and see if its in the list to run at boot up.
You can probably get rid, run a malware program too.

Start >> RUN >>> msconfig wink (Type in the Run Box)
_________________________
My Avatar images are all from the Wirral Gallery.Click Me
Wow Wirral History is coming along Great! Wirral History

we get +200 new members a month now smile

Top
#279873 - 3rd Jan 2009 6:52pm Re: ~.exe virus? [Re: Mark]
diggingdeeper Offline

Wiki Guardian

Registered: 9th Jul 2008
Posts: 9668
Loc: Birkenhead
Thanks Mark - I had checked with Spybot startup tool, but YES it is there in msconfig under HKLM/Microsoft/Windows/currentversion/run

But I still don't know if it a goody or a baddy

Spybot and AVG don't recognise it as a baddy and none of the other virus companies mention it in there lists of baddies as far as I can see.


Edited by diggingdeeper (3rd Jan 2009 6:54pm)

Top
#279877 - 3rd Jan 2009 7:00pm Re: ~.exe virus? [Re: diggingdeeper]
Mark Online   Reading


Wiki Master

Registered: 9th Nov 2003
Posts: 21001
Loc: Wirral
HKLM/Microsoft/Windows/currentversion/run

That's where most of the virus sit,
as it will start.

Get rid mate, if it had a job to do it would have a name simple as.

Dont for get to turn off your system restore,
as the virus can hide in there too.

Turn system restore off,
remove the virus
re-boot
turn system restore back on smile
_________________________
My Avatar images are all from the Wirral Gallery.Click Me
Wow Wirral History is coming along Great! Wirral History

we get +200 new members a month now smile

Top
#279878 - 3rd Jan 2009 7:01pm Re: ~.exe virus? [Re: diggingdeeper]
Tony_1985 Offline

Forum Master

Registered: 19th Aug 2006
Posts: 2421
Loc: Ellesmere Port
delete it from the registry

reboot

then delete the file


that usually works

Top
#280092 - 4th Jan 2009 11:33am Re: ~.exe virus? [Re: Tony_1985]
diggingdeeper Offline

Wiki Guardian

Registered: 9th Jul 2008
Posts: 9668
Loc: Birkenhead
What worries me is what other files it has "played" with which is why I am trying to find out about it.

I hate doing a full Windows install - takes hours.
_________________________
In a time of universal deceit - telling the truth is a revolutionary act. George Orwell

When the debate is lost, slander becomes the tool of the loser. Socrates

Top
#280742 - 5th Jan 2009 9:57pm Re: ~.exe virus? [Re: diggingdeeper]
diggingdeeper Offline

Wiki Guardian

Registered: 9th Jul 2008
Posts: 9668
Loc: Birkenhead
AVG was updated today, identified ~.exe in system32 as Trojan.Win32.Agent.AKSO

This is obviously getting round so watch out for it.

Though this trojan was known about Oct2008, it looks like it has been disguised in ~.exe (which is a packed exe file), none of the normal online scanners nor AVG, Spybot or Adaware recognised it as a baddie yesterday.
_________________________
In a time of universal deceit - telling the truth is a revolutionary act. George Orwell

When the debate is lost, slander becomes the tool of the loser. Socrates

Top
#337849 - 23rd Jul 2009 11:13am Re: ~.exe virus? [Re: diggingdeeper]
diggingdeeper Offline

Wiki Guardian

Registered: 9th Jul 2008
Posts: 9668
Loc: Birkenhead
This nasty little b*gg*r is floating around again - I have yet to discover how it gets into my computer - it is the only virus that sneaks in undetected, it is contained immediately so can't actually do anything.

The only programs I have installed recently have been very established ones, downloaded from the program's own site or filehippo or download.com

The lastest installs/updates were Aspell (GNU spelling checker), Duplicate Cleaner update, AVG update, CCleaner update.

Forgot to check the install date of ~.exe which would have told me what it came in with. I was too quick to BLAST it off this planet.

Although AVG recognised this virus previously, it has gone undetected again so must have been reformed, it is definately the sneakiest trojan around, I do suggest checking if it exists on your computers c:\windows\system32\~.exe

If you find it delete it, there maybe some .dat file in the same directory starting with _c these seem to be its data collection files, I have read about them but never seen them (because on my computer ~.exe is prevented from functioning)

more info

here - clicky

Please no lectures on AVG, F-secure, Avast, Norton etc - they ALL missed this trojan last time it came around in 2008, AVG was the first to correctly recognise it although F-secure was the first that could fix it (unbelievably, before it could detect it).

Top
#337870 - 23rd Jul 2009 12:51pm Re: ~.exe virus? [Re: diggingdeeper]
Shadow_Omega Offline

Wise One

Registered: 29th Apr 2009
Posts: 871
Loc: Leasowe
perhaps you should try the free version of malaware anti malware if Norton and the likes missed it. i had a similar virus a year back and malaware removed it completly. you can find there website here http://www.malwarebytes.org/

Top
#337895 - 23rd Jul 2009 2:24pm Re: ~.exe virus? [Re: Shadow_Omega]
MattLFC Offline
Wiki Master

Registered: 14th Aug 2004
Posts: 22315
Loc: Moreton/Beirut/Mobile
AVG is utter shite at best, and if you are running multiple instances of AV software it is little suprise they are failing to detect virus's.

smile

Top
#337927 - 23rd Jul 2009 3:34pm Re: ~.exe virus? [Re: diggingdeeper]
topofthepops Offline

Addict

Registered: 2nd Nov 2008
Posts: 218
Loc: Wallasey
AVG used to have a function to make a "boot from floppy or CD", but I can't find it in the latest version? I remember having to do one for a friend and could only make a floppy, but then copied this to a CD, as the friends pc didn't have a floppy drive.

You used to be able to use this bootable floppy or CD to boot the pc with, then run the anti virus programe from there, like in DOS mode. First make sure the BIOS setting is enabled (for the needed floppy or CD) as the 1st boot.

I think F-secure does one? If you can do this I'm sure it will make a better job of finding the hidden file that recreates the ~.exe file.

Hope this helps

Top
#337929 - 23rd Jul 2009 3:49pm Re: ~.exe virus? [Re: diggingdeeper]
topofthepops Offline

Addict

Registered: 2nd Nov 2008
Posts: 218
Loc: Wallasey
Originally Posted By: diggingdeeper
Thanks Mark - I had checked with Spybot startup tool, but YES it is there in msconfig under HKLM/Microsoft/Windows/currentversion/run

But I still don't know if it a goody or a baddy

Spybot and AVG don't recognise it as a baddy and none of the other virus companies mention it in there lists of baddies as far as I can see.


A good little programe that gives extra info for whats running on your pc Process Explorer v11.33, By Mark Russinovich. It doesn't install, you just run it.

I don't know if we are allowed to do direct links for files but here it is if you want to try it:

Process Explorer in a zip file

Top
#337943 - 23rd Jul 2009 5:49pm Re: ~.exe virus? [Re: topofthepops]
diggingdeeper Offline

Wiki Guardian

Registered: 9th Jul 2008
Posts: 9668
Loc: Birkenhead
It did turn out to be a Trojan, as I suspected by the way it tried to behave - it was formally identified on 4th Jan 2009, the day after I was playing with it (or it was trying to play with me!).

It concerns me that I have security very well clamped down on my computers AND I am very careful what I run on my computer (I have been an IT professional for 32 years) yet this little blighter still sneaked in TWICE now - if it has infiltrated my computer with the care I take, there must be an awful lot of computers infected by it out there.

To put peoples mind at rest, most firewalls will stop this Trojan from talking back home, BUT I don't know if Windows Firewall will, it is partly disguised as a microsoft program and may be trusted by the microsoft system, I can't find out without risking my system and having to do an 8 hour recovery, not my favourite past-time.
_________________________
In a time of universal deceit - telling the truth is a revolutionary act. George Orwell

When the debate is lost, slander becomes the tool of the loser. Socrates

Top
#337990 - 23rd Jul 2009 8:15pm Re: ~.exe virus? [Re: diggingdeeper]
topofthepops Offline

Addict

Registered: 2nd Nov 2008
Posts: 218
Loc: Wallasey
Do you know if you have completley "bannished" it yet?

I'm as careful as you said you are & I have been lucky upto now & never had a virus/trojan etc. Maybe I shouldn't have said that doh

Top
#338003 - 23rd Jul 2009 9:08pm Re: ~.exe virus? [Re: topofthepops]
diggingdeeper Offline

Wiki Guardian

Registered: 9th Jul 2008
Posts: 9668
Loc: Birkenhead
Originally Posted By: topofthepops
Do you know if you have completley "bannished" it yet?

I'm as careful as you said you are & I have been lucky upto now & never had a virus/trojan etc. Maybe I shouldn't have said that doh
It doesn't make any difference, on my computers it is completely blocked from doing anything. I have deleted the file and done a complete registry clean. It isn't one of these persistent little things (seen enough of those in my job, heal six files and by then another ten have got infected), it just is very sneaky how it gets on! Got to admit, I am very impressed that it has got me twice, six months apart, nothing else has ever got in.
_________________________
In a time of universal deceit - telling the truth is a revolutionary act. George Orwell

When the debate is lost, slander becomes the tool of the loser. Socrates

Top

Moderator:  Mark 
Random Wirral Images

Click to View Topic.
Newest Topics
Question Time
by derekdwc
11:27 PM
Sanctuary awaits 5 bears
by venice
06:25 PM
Parking Charges
by diggingdeeper
03:01 PM
Kitten found Arrowe park car park
by Greenwood
02:42 PM
Paper Recycling. ?
by fish5133
11:16 AM
For Sale & Free
Melamine faced chipboard ( Walnut or Oak )
by Reno37
Wanted freezer kit
by dodie
18th Jan 2017 9:58pm
2pioneer speakers Free
by dodie
18th Jan 2017 9:54pm
Looking to swap an xbox one for a ps4
by surykata
18th Jan 2017 8:10pm
Wanted old cars spares or repairs
by vw_kyle
17th Jan 2017 1:08pm
Featured Member
Registered: 7th Dec 2008
Posts: 453
Newest Members
Branco, Smudge22, Collette63, shellylou, sgjrob
12184 Registered Users
Today's Birthdays
No Birthdays
New Wirral Info
Paper Recycling. ?
by fish5133
11:16 AM
Paypal help
by venice
17th Jan 2017 8:59pm
Brown Bin Collections Restarting Today 17th Jan
by fish5133
17th Jan 2017 9:04am
Indian/Jazz fusion music Liverpool
by paxvobiscum
15th Jan 2017 11:19am
Chinese New Year Liverpool
by paxvobiscum
15th Jan 2017 11:08am
News : New Topics
Parking Charges
by diggingdeeper
03:01 PM
Spectacles found.
by Beethoven
18th Jan 2017 1:02pm
When we live to be a 100 yrs old
by granny
18th Jan 2017 11:46am
Secretive mega shake-up of NHS could cost 15 mil
by RUDEBOX
16th Jan 2017 5:58pm
Lost Mobile Phone
by spinner1
15th Jan 2017 6:56pm
New Enthusiast Forums
Question Time
by derekdwc
Yesterday at 11:27 PM
Sanctuary awaits 5 bears
by venice
Yesterday at 06:25 PM
Kitten found Arrowe park car park
by Greenwood
Yesterday at 02:42 PM
Puppy wanted good careing home offered
by chris7777
Yesterday at 09:07 AM
New Car tax Rates For New Cars
by fish5133
Yesterday at 01:42 AM
(Views 24hrs)Trending Newest Topics
Parking Charges 135
Sanctuary awaits 5 bears 129
Question Time 122
Kitten found Arrowe park car park 59
Melamine faced chipboard ( Walnut or Oak ) 0
Wirral Sunrise Sunset
Sunrise Fri 8:13am
Sunset Fri 4:33pm
Local Time Fri 11:45am
WikiWirral Can . . . .