Re: iexpIorer.exe ..new virus? What is it?

From: Sarah (anonymous_at_discussions.microsoft.com)
Date: 01/01/04


Date: Wed, 31 Dec 2003 15:31:08 -0800

Mike writes:
>-----Original Message-----
>Hey all..
>
>A few days ago, I started getting a message
that "tskmg.exe" wasn't found on
>startup. I obviously assumed this was some sort of a
virus (even though I
>haven't run anything, and I'm up to date with Windows
Update). So I went and
>scanned at trendmicro's housecall. No viruses found..
>
>I tried firing up regedit and msconfig and both of them
close right away
>after 2 seconds.
>
>So, I checked taskmanager and there is a process running
called
>"iexpIorer.exe" running. When I kill it, a new one
always restarts...
>
>So, obviously I have a virus..
>
>But, the latest online scanners aren't picking it up and
there's no new
>windows updates..
>
>Any ideas?
>
>Mike
>
     Howdy, Mike. Found several references online to
iexpIorer.exe (noting that the letter following "iexp" is
a capitol "i", not an "L"). A year ago, one board's
poster was relating that Norton's had found but could not
delete it (she didn't mention whether she was using a
Safe mode start). Another poster (on a board I could only
get via Google's cache) was complaining about this
infector on a "Viruses everyone has"(!)list. Another was
saying that it is a sub-7 trojan, and listed the steps
they had taken to get rid of it. I don't suppose that the
fact that someone a year ago used that name for their
process stops a new writer from using it in a new
infector.
    _Assuming_ it were to be the "same old" thing, the
following from Sophos might be informative:
>>
Troj/Oblivion-B is a backdoor Trojan that allows others
remote access to your computer over a network. It copies
itself to the Windows System directory as iexpIore.exe,
and sets the registry keys

HKLM\Software\Microsoft\Windows\CurrentVersion
\Run\Default web browser
HKLM\Software\Microsoft\Windows\CurrentVersion
\RunServices\Default web browser
HKLM\Software\Microsoft\Active Setup
\Installed Components\Default web browser\StubPath
to all point to the executable.

It also changes the entry shell= in the [boot] section of
system.ini to "explorer.exe iexpIore.exe", and adds new
ini entries load=iexpIore.exe and run=iexpIore.exe in the
[windows] section of win.ini.

It uses ICQ and IRC channels to notify the sender of
activation.
<<



Relevant Pages

  • Re: Computing for Outlook Express in VB.
    ... >> Hello Mike, I know of a company called Computer Associates who ... Much depends on the actual viruses that you've ... > Windows are you using by the way?). ... With this infernal virus it I ...
    (comp.lang.basic.visual.misc)
  • RE: w32/MyDoom@MM infection
    ... >Hi Mike, ... >Was your system upgraded from Windows 98? ... >2000 file but is used by some viruses such as MyDoom so ... >>I was just infected with this virus. ...
    (microsoft.public.security.virus)
  • Bobax.C
    ... Other files containing the virus have been ... W32.Bobax.C is a worm that exploits both the LSASS ... While this threat may execute on Windows 95/98/Me/Server ... Virus Definitions * ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Pixelsrvr.exe wont load on bootup
    ... Sounds like you got yourself a virus,. ... Adds the following line to the [windows] section of the Win.ini file: ... antivirus products, including the Symantec AntiVirus and Norton AntiVirus ... Disabling System Restore ...
    (microsoft.public.windowsxp.video)
  • Re: HELP ON XP RE-INSTALLATION...
    ... > IF I REINSTALL XP ON MY COMPUTER HELP IF I HAVE A VIRUS THAT I CANT ... Don't have an AntiVirus software? ... There are more applications you may need to run to completely clean your ... It will probably save you time and effort in re-installing Windows XP ...
    (microsoft.public.windowsxp.general)