Sospected process with randomic alphanumeric name!!!

darkad_at_tiscali.it
Date: 08/02/05

  • Next message: Tom St Denis: "Re: Barcode Email"
    Date: 2 Aug 2005 02:17:15 -0700
    
    

    my sys: Win2000 sp4,ms beta antiSpyware, Sygate firewall

    In the taskmanager it appears a process (.exe) with a randomic name
    composed by numbers and letters for example AS4L05F.EXE or BEL01GT.EXE
    or other names that i'm trying to search on google groups without any
    result.
    I tried with Trend Micro office scan (Updated and with a resident
    shield) to scan the dir Temp in wich the .exe is situated, but nothing
    to do!
    If I try to terminate it on taskmanager, It doesn't stops!
    I know, it's a virus, troyan o keylogger, but I don't stop working.

    Here it is: nod2e7.exe

    System Information available in: 02/08/2005 09.42.55.
    [Task in execution]

    Name Path ID process Priority Working set min Working set max Start
    time Version Dimension Data file
    nod2e7.exe d:\winnt\temp\nod2e7.exe 836 8 204800 1413120 02/08/2005
    9.30.20 Not available 168,07 KB (172.099 byte) 02/08/2005 9.30.19


  • Next message: Tom St Denis: "Re: Barcode Email"

    Relevant Pages

    • Re: Speicherauslastung der eigenen Anwendung
      ... Getestet in der IDE? ... ich für die gleiche Exe 1970176. ... der auch im Taskmanager angezeigt wird. ... Anwendung minimiert wurde oder nicht. ...
      (microsoft.public.de.vb)
    • Re: Nachtrag ...
      ... Im Beitrag steht was von EXE, ... Taskmanager ... sozusagen die Threads werden abgewürgt vom eifrigen ...
      (microsoft.public.de.fox)
    • Processes not Ending
      ... I run Windows XP. ... Lately I have noticed that when I close a program normally the .exe line is ... not removed from processes shown in Taskmanager. ... a trojan. ...
      (microsoft.public.windowsxp.general)
    • =?ISO-8859-15?Q?FTP-Klasse_f=FCr_Up-_&_Download_mit_Progressbar_m?= =?ISO-88
      ... Soweit sogut, dies funktioniert auch, aber beim Programmende bleibt die EXE im Arbeitspeicher und muss per Taskmanager beendet werden. ...
      (microsoft.public.de.vb)
    • Re: Visual Studio .NET 2003 editor bug?
      ... Well it's not likely that a C source file begins with letters MZ:) ... "Mark Randall" wrote: ...
      (microsoft.public.vc.language)