Overclock.net - Overclocking.net
     
 
Home Gallery Reviews Blogs Register Today's Posts Mark Forums Read Members List


Go Back   Overclock.net - Overclocking.net > Software, Programming and Coding > Operating Systems

Reply
 
LinkBack Thread Tools
Old 03-15-06   #1 (permalink)
Intel Overclocker
 
aweir's Avatar
 
intel nvidia

Join Date: Oct 2005
Location: Buffalo, NY
Posts: 832

Rep: 32 aweir is acknowledged by some
Unique Rep: 29
Trader Rating: 0
Default Strange .exe file on hard disk, help

I have an executable batch file on the root of my C: drive called "lol.exe".

When I double click on lol.exe it creates a folder called "owned" that contains the files install.bat, lol.txt, and systemdebug.dll.

When I click on lol.exe a cmd prompt shows up and then quickly closes. I took screenshot of the cmd prompt right before it closes.

In the "owned" folder there is the file "lol.txt" that contains a list of networked computers and the possible machine name, who owns it, and if it is a server, what type of server it is running.
Attached Thumbnails
Strange .exe file on hard disk, help-screenshot3.jpg  
__________________
System: My System
CPU
Q6600 G0 @ 3Ghz
Motherboard
Abit IP35 Pro v.17
Memory
4Gb G-Skill PC6400
Graphics Card
MSI 8800GT 512MB OC
Hard Drive
Samsung SpinPoint 500Gb SATAII
Sound Card
Realtek HD 888 onboard
Power Supply
PC P&C 610
Case
Rocketfish Full Tower
CPU cooling
Tuniq Tower 120
OS
Vista Ultimate x64 SP2
Monitor
Sceptre X22-HG 22"
aweir is offline   Reply With Quote
Old 03-15-06   #2 (permalink)
Intel Overclocker
 
amped's Avatar
 
intel nvidia

Join Date: Oct 2005
Posts: 1,699

Rep: 123 amped is acknowledged by manyamped is acknowledged by many
Unique Rep: 105
FAQs Submitted: 5
Hardware Reviews: 2
Trader Rating: 1
Default

I suggest you delete lol.exe, delete the folder is created, and run a full out virus/spyware scan.
__________________
System: My System
CPU
Intel Core 2 Quad Q6700 Kentsfield
Motherboard
DFI DK P35-T2RS
Memory
G.SKILL DDR2-800 4x2GB
Graphics Card
eVGA 9800GTX 512MB
Hard Drive
160GB WD SATA2
Sound Card
Asus Xonar DX 7.1
Power Supply
PC Power & Cooling 750W
Case
Antec P182
CPU cooling
OCZ Vendetta 2
GPU cooling
Stock
Monitor
Acer 22 in.
amped is offline   Reply With Quote
Old 03-15-06   #3 (permalink)
PC Gamer
 
amd ati

Join Date: Sep 2005
Location: Easley, SC
Posts: 3,578

Rep: 189 Ch13f121 is acknowledged by manyCh13f121 is acknowledged by many
Unique Rep: 151
FAQs Submitted: 2
Hardware Reviews: 1
Trader Rating: 20
Default

http://www.symantec.com/avcenter/ven...lw.reckus.html
some info on what lol.exe is, if its of any help.

System: The Black Dragon
CPU
Phenom II X4 940 BE
Motherboard
Gigabyte GA-MA790GP-UD4H
Memory
4x2gb G.Skill DDR2 800 (PQ)
Graphics Card
Sapphire 4870x2
Hard Drive
2x250gb Barracuda
Sound Card
Razer Barracuda AC-1
Power Supply
PC P&C Silencer 750w
Case
Gigabyte 3d Mars
CPU cooling
Noctua NH-U12P
GPU cooling
AC Accelero Xtreme 4870x2
OS
Windows 7 RC 64-bit
Monitor
Samsung T240HD
Ch13f121 is offline   Reply With Quote
Old 03-15-06   #4 (permalink)
Intel Overclocker
 
aweir's Avatar
 
intel nvidia

Join Date: Oct 2005
Location: Buffalo, NY
Posts: 832

Rep: 32 aweir is acknowledged by some
Unique Rep: 29
Trader Rating: 0
Default

Am running McAfee antivirus. It would have detected a virus, right?
__________________
System: My System
CPU
Q6600 G0 @ 3Ghz
Motherboard
Abit IP35 Pro v.17
Memory
4Gb G-Skill PC6400
Graphics Card
MSI 8800GT 512MB OC
Hard Drive
Samsung SpinPoint 500Gb SATAII
Sound Card
Realtek HD 888 onboard
Power Supply
PC P&C 610
Case
Rocketfish Full Tower
CPU cooling
Tuniq Tower 120
OS
Vista Ultimate x64 SP2
Monitor
Sceptre X22-HG 22"
aweir is offline   Reply With Quote
Old 03-15-06   #5 (permalink)
New rig again :s
 
wowza's Avatar
 
intel nvidia

Join Date: Jun 2005
Location: Orinda, California
Posts: 4,069

Rep: 493 wowza is a proven memberwowza is a proven memberwowza is a proven memberwowza is a proven memberwowza is a proven member
Unique Rep: 341
FAQs Submitted: 2
Hardware Reviews: 6
Trader Rating: 18
Default

Quote:
Originally Posted by amped
I suggest you delete lol.exe, delete the folder is created, and run a full out virus/spyware scan.
yep, I wouldn't trust anything like that on my compy.. btw, where did you get it from? Did it just appear? and for the future, don't click on stuff like that again.
__________________
Fold For Team 37726!! Get Started Here
Upgrades---> T7200 Core 2 Duo
Guide---> What Core 2 Duo Motherboard is right for me?
Projects---> Waterchiller Build
Rig 2---> P4 640 @ 4GHz, Asus P5P800-SE, 512MB crap, Sunbeam NUUO 550w
My Old Rig --->2.4AE @ 4.15GHz , semi Stable, yes 1.75GHz OC ...

System: Dude, I got a Dell
CPU
T2500 Core Duo
Motherboard
Dell Laptop
Memory
2x1GB G.Skill DDR2-800
Graphics Card
Quadro 1500m flashed--> 7900GTX
Hard Drive
200GB SATA 5400RPM
Sound Card
Audigy 2 Onboard
Power Supply
9 Cell Battery
Case
E1705 Frame
OS
XP Home SP2
Monitor
17" LCD (1920x1200) + 20.1" Samsung Widescreen
wowza is offline Overclocked Account   Reply With Quote
Old 03-15-06   #6 (permalink)
PC Gamer
 
amd ati

Join Date: Sep 2005
Location: Easley, SC
Posts: 3,578

Rep: 189 Ch13f121 is acknowledged by manyCh13f121 is acknowledged by many
Unique Rep: 151
FAQs Submitted: 2
Hardware Reviews: 1
Trader Rating: 20
Default

symantec says that its transferred thru p2p file networks, like kazaa, morpheus, limewire, etc.

System: The Black Dragon
CPU
Phenom II X4 940 BE
Motherboard
Gigabyte GA-MA790GP-UD4H
Memory
4x2gb G.Skill DDR2 800 (PQ)
Graphics Card
Sapphire 4870x2
Hard Drive
2x250gb Barracuda
Sound Card
Razer Barracuda AC-1
Power Supply
PC P&C Silencer 750w
Case
Gigabyte 3d Mars
CPU cooling
Noctua NH-U12P
GPU cooling
AC Accelero Xtreme 4870x2
OS
Windows 7 RC 64-bit
Monitor
Samsung T240HD
Ch13f121 is offline   Reply With Quote
Old 03-15-06   #7 (permalink)
Case Modder
 
thehybridpyro's Avatar
 
intel nvidia

Join Date: Sep 2005
Location: Shaker Heights Ohio
Posts: 2,127

Rep: 109 thehybridpyro is acknowledged by manythehybridpyro is acknowledged by many
Unique Rep: 88
Trader Rating: 5
Default

KILL IT AND DELETE ALL TRACES OF IT!!!!
it could make big holes that other viruses could exploit

I sugest shredding the files and folders that its contained in
__________________
Quote:
Originally Posted by Sladesurfer View Post
I just played mario a while ago. When i go to school today im gonna start stomping on people:
Looking for cheap compressors for phase change

System: Finaly Dual Core
CPU
Pentium D 805 4Gz
Motherboard
ABIT AW9D-MAX
Memory
4x512 Buffalo Firestix
Graphics Card
Saphire x1950 Pro 512
Hard Drive
160 SATAII 2x30 IDE RAID
Sound Card
ABIT Sound Max 7.1 Ch
Power Supply
500 generic 20amp 12v
Case
My Sexy Baby
CPU cooling
AquaXtreme MP-05 Pro
GPU cooling
Stock
OS
e / XP Pro / Ubuntu 7.04
Monitor
Viewsonic 19" Pro
thehybridpyro is offline   Reply With Quote
Old 03-15-06   #8 (permalink)
Intel Overclocker
 
aweir's Avatar
 
intel nvidia

Join Date: Oct 2005
Location: Buffalo, NY
Posts: 832

Rep: 32 aweir is acknowledged by some
Unique Rep: 29
Trader Rating: 0
Default

Ok let me say that this a university computer. I was browsing my network share when I noticed it. These computers are running McAfee.

I logged onto another computer right next to me and the same file is there. Gulp, the whole netowrk is infected then,

I should inform Computer Services?
__________________
System: My System
CPU
Q6600 G0 @ 3Ghz
Motherboard
Abit IP35 Pro v.17
Memory
4Gb G-Skill PC6400
Graphics Card
MSI 8800GT 512MB OC
Hard Drive
Samsung SpinPoint 500Gb SATAII
Sound Card
Realtek HD 888 onboard
Power Supply
PC P&C 610
Case
Rocketfish Full Tower
CPU cooling
Tuniq Tower 120
OS
Vista Ultimate x64 SP2
Monitor
Sceptre X22-HG 22"
aweir is offline   Reply With Quote
Old 03-15-06   #9 (permalink)
PC Gamer
 
amd ati

Join Date: Sep 2005
Location: Easley, SC
Posts: 3,578

Rep: 189 Ch13f121 is acknowledged by manyCh13f121 is acknowledged by many
Unique Rep: 151
FAQs Submitted: 2
Hardware Reviews: 1
Trader Rating: 20
Default

lol nah just let em rot I mean they're school computers, and they're running mcafee, they deserve it

System: The Black Dragon
CPU
Phenom II X4 940 BE
Motherboard
Gigabyte GA-MA790GP-UD4H
Memory
4x2gb G.Skill DDR2 800 (PQ)
Graphics Card
Sapphire 4870x2
Hard Drive
2x250gb Barracuda
Sound Card
Razer Barracuda AC-1
Power Supply
PC P&C Silencer 750w
Case
Gigabyte 3d Mars
CPU cooling
Noctua NH-U12P
GPU cooling
AC Accelero Xtreme 4870x2
OS
Windows 7 RC 64-bit
Monitor
Samsung T240HD
Ch13f121 is offline   Reply With Quote
Old 03-15-06   #10 (permalink)
AMD Overclocker
 
amd nvidia

Join Date: Feb 2006
Location: Brampton, Ontario.
Posts: 239

Rep: 9 rcantec Unknown
Unique Rep: 8
Trader Rating: 0
Default

you may have to re-install windows now.
__________________
*Cpuz validation*

2601:http://valid.x86-secret.com/show_oc?id=77521Stable 100% (5:4DDR)

2640:http://valid.x86-secret.com/show_oc?id=79809Stable 100% (1:1DDR)

2.6ghzAMD=4.0ghzINTEL and still faster.

System: My System
CPU
Athlon 64 3500+
Motherboard
A8N-SLI (Nforce4)
Sound Card
Optical/Digital 5.1
Power Supply
Antec 480 2.0 True Power
Case
Antec TX 1088 AMG
OS
Xp home
Monitor
LG 17" crt
rcantec is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools



All times are GMT -5. The time now is 12:12 PM.


Overclock.net is a Carbon Neutral Site Creative Commons License

Terms of Service / Forum Rules | Privacy Policy | DMCA Info | Advertising | Become an Official Vendor
Copyright © 2009 Shogun Interactive Development. Most rights reserved.
Page generated in 0.17054 seconds with 9 queries