Re: Malware or no ?



Bill,

Scan " System.dll " at this website : http://www.virustotal.com/en/indexf.html

Please post back with what is detected.

MowGreen [MVP 2003-2006]
===============
*-343-* FDNY
Never Forgotten
===============


bill wrote:

XP with SP2

On every startup, a file named "System.dll" (size 10,240 bytes)
is created in my windows default temp directory in a newly created
subdirectory named "nsxx.tmp" (xx = it varies). The creation date &
time reflects when it was placed in the temp sub directory on startup.
There is no other identification even viewing it with a hex viewer.

There are also 4-6 prefetch related entries like
"\windows\prefetch\NS4.TMP-3A84D703.pf"
but putting them up in the hex viewer reveals nothing except they check
the standard system DLLs to hook various functions as obviously
whatever program it is needs them. I'm not experienced enough to ID
the program itself.

AdAware identifies it as "Adware Maxfiles". I have also tried HiJackThis and
many of the other recommeded malware detector/removers without luck.
My AVG free edition anti-virus program does not recognize it as a virus.

A google on it returns numerous hits describing it as malware but no
solutions other than what I've tried already.

Should I be worried about this ? Anyone familiar with it ? Suggestions ?

Bill Mudd




.



Relevant Pages

  • Re: periodic blank process - potential malware?
    ... Bill: Go to http://www.mlin.net/StartupCPL.shtml and download the ... standalone .exe version of "Startup Control Panel" ... Run it and look in all tabs and delete any process other than the antivirus ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Startup
    ... > Bill wrote: ... The startup property sheet only lists forms ... > and Current events will fire before the AutoExec macro is executed. ...
    (microsoft.public.access.formscoding)
  • Re: Screen Refresh Rate Dell Dimension 8100
    ... >>Hey, Bill! ... > 256 kilobyte secondary memory cache ... the first thing I'd try would be disabling your Startup ... it doesn't, come back and I'll/we'll tell you how to load startup programs, ...
    (alt.sys.pc-clone.dell)
  • Re: ZA Pro 4.5.538.000 - buggy as hell?
    ... You can recreate it by unchecking the 'Load ZA at startup' ... >> again and authorise your programs or put ZA in learning mode for a couple ... Regards ... Bill ...
    (comp.security.firewalls)

Loading