regsvr.exe and q387.exe



Very little about this set of rogue diallers / trojans / virii or whatever
it would seem on the net
so if any use placed here.
Had regsvr.exe (not regsvc.exe) activating every 20 seconds , reading ports
, and creating ever growing files comreads.dbg and comused.dbg
First 2 lines of comreads reading (edited)
Port opened, internal buffer = 0x007... to 0x00..
Overlapped Read -- 24 bytes 0x007... to 0x007... :

Disabled those but could not track down where q387.exe was hiding.
In Task Manager the name would blip up on Processes and disappear again
every 10 seconds or so,
the cursor dipping at same times and in other appls.
Every now and then CMD.EXE (as upper case) would do the same in TM .

I updated spybot search & destroy but it told me congratulations for
having no immediate threats.

Found and disabled CMD.EXE and after that (coincidence ?) q387.exe has
disappeared, apparently, since.
That is distinct from cmd.exe (lower case) files which I left in place.

Perhaps q387.exe has been converted so it can hide itself.
previous net references to it have precise locations
eg
hidden in \countrydial.exe
or as
.... \Local Settings\Temp\q387.exe
....\WINDOWS\q387.exe

Anyone know what q387 was doing ?

Now nice flatlining in Task Manager / CPU Usage and no wraithing q387 in
Processes, for the moment





.



Relevant Pages

  • Re: Task mgr, Regedit, MSconfig
    ... > the task manager would disappear before I could close the ... > pop-up windows. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Windows Explorer
    ... Close on the Taskbar doesn't work either. ... Task manager shows no active ... The only way I can get it to disappear from the ... >> Once I open Windows explorer and do what I have to, ...
    (microsoft.public.windowsxp.general)
  • Windows Explorer will not go away
    ... I close it by clicking x, or File/close etc but all it ... Close on the Taskbar doesn't work either. ... Task manager shows no active ... The only way I can get it to disappear from the ...
    (microsoft.public.windowsxp.general)
  • Re: Notification Area:Weird Disappearance
    ... happens for most Auto-Logon users. ... Once done, Open Task Manager, click the Processes tab, click Explorer.exe, ... Icons in the Notification Area May Disappear If You Use High-Contrast Color ...
    (microsoft.public.windowsxp.basics)