Re: MORICONS.EXE trojan/virus?

From: Tim (Tims-News123_at_carolina.rr.comRemove#s)
Date: 05/15/04

  • Next message: Chuck: "Re: What if no firewall when using eDonkey or Kazaa?"
    Date: Sat, 15 May 2004 16:19:44 GMT
    
    

    Here's the info on the file:
    Location: c:\windows\system32\moricons.exe
    Size: 48.8 KB (50,042 bytes)
    Size on disk: 52.0 KB (53,248 bytes)
    Created, modified and accessed: Wednesday, August 22, 2001, 9:02:03 PM

    Found a link to it in the reg:
    HKEY_CURRENT_USER\Software\Microsoft\SearchAssistant\ACMru\5603
    Name:000
    Type: REG_SZ
    Data: MORICONS.EXE

    I'll try renaming it and if that works I'll remove the link in the reg and
    then try to delete it. I would really like to know where it came from
    though.

    > I don't know what that file is, but the correct name for the file that it
    > is impersonating is "moricons.dll". Have you tried renaming the exe to
    > something else ( like moricons.suspect) so that it doesn't get executed?
    > If it is a required file, you should get some kind of error message after
    > renaming and rebooting.


  • Next message: Chuck: "Re: What if no firewall when using eDonkey or Kazaa?"

    Relevant Pages

    • Re: What still uses the block layer?
      ... there are some controllers that don't generate sdX devices) ... But nowadays an external disk may have several ... renaming an ethernet interface does. ... That way mapping error messages to ...
      (Linux-Kernel)
    • Re: Error report: MikTeX format generation fails
      ... In article, Dr Engelbert Buxbaum wrote: ... The actual file name on the disk is "ukhyphen.tex", ... renaming the file and refreshing the file name data base solves the ...
      (comp.text.tex)
    • Error report: MikTeX format generation fails
      ... after a recent update the format generation fails because "ukhyph.tex" ... The actual file name on the disk is "ukhyphen.tex", ... renaming the file and refreshing the file name data base solves the ... This inconsistency should be repaired. ...
      (comp.text.tex)
    • Re: MORICONS.EXE trojan/virus?
      ... >Found a link to it in the reg: ... >I'll try renaming it and if that works I'll remove the link in the reg and ... way more information than Task Manager, ... Paranoia comes from experience - and is not necessarily a bad thing. ...
      (comp.security.firewalls)
    • disk damaged
      ... My xp disk was damaged and i need a copy... ... I reg. ... wanting to know if you could send me a new one and how ... oklahoma city, ok 73109 ...
      (microsoft.public.windowsxp.general)