SUCATREG.EXE trying to access the Internet

From: Donut (none@none.com)
Date: 04/16/03


From: Donut <none@none.com>
Date: 16 Apr 2003 20:25:49 GMT

I saw this in my firewall log for the first time today - about a dozen
instances of C:\Windows\System\SUCATREG.EXE attempting to access the
Internet.

I did a Google search and was alarmed to see this activity associated with
the Win32Magistr-A virus. The virus definition page at sophos.com did
mention that this file can be present on non infected systems.

A complete virus scan revealed nothing. I haven't received any emails with
attachments.

My question now is - does anybody know what the purpose of this file is?
>From it's name, I would guess some kind of automatic update or registration
phone home. But I never saw it before, and I don't have anything on my
system now I didn't always have.

Suspects could be MusicMatch Jukebox, SpyBlocker, or MS Works auto updater.

Is there any kind of utility that can examine files and trace their origin,
use and activity? How handy would THAT be!



Relevant Pages

  • RE: [Full-Disclosure] (no subject)
    ... New Bagle Variant Spreading ... We received a number of reports about a new virus. ... Infected systems will likely attempt to contact these URLs. ...
    (Full-Disclosure)
  • Re: can not open e-mail attachment
    ... "A quick Google search with the exact" ANYTHING ie. virus ... the questions posted to these Newsgroups. ...
    (microsoft.public.windowsxp.security_admin)
  • RE: PLEASE Help -- Windows very slow starting up
    ... Google Search "NEWDOT" ... Is NEWDOT~2.DLL spyware or a virus? ... > I also have been having a problem after system loading and coming on, ... >>> when the startup sound plays. ...
    (microsoft.public.windowsxp.help_and_support)
  • RE: Internet Explorer has been hijacked by "About:Blank"
    ... Open Hijack This again and select "Scan". ... > I've found a virus on one of the 2 systems. ... > infect a system that is running Sun Java VM. ... Both infected systems were running XPSP1 Home ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: A weird problem when I surf internet with IE 6, Can anyone help?
    ... answer just for my peace of mind. ... It doesn't look like some automatic update interrupt IE ... software, virus, internet traffics, system logs, and the ... >Andy Lee wrote: ...
    (microsoft.public.windows.inetexplorer.ie6.browser)