Emuforums.com

Go Back   Emuforums.com > General Discussion > Software Discussion
Home Register Downloads FAQ Members List Calendar Arcade Mark Forums Read

Closed Thread
 
Thread Tools Display Modes
Old April 6th, 2002, 00:34   #1
Kellicros
Administrator
 
Kellicros's Avatar
 
Join Date: Nov 2001
Location: Kuala Lumpur, Malaysia.
Posts: 7,719
Question win***.exe

Recently, I keep getting an illegal operation error on a file named winfba.exe, I searched for that file and deleted it, but after a while, another error of winkql.exe popup, I deleted it's as well but that's no help at all, the win***.exe error just keep popping up, what the heck is it?
__________________
Kellicros' DeviantArt
Kellicros is offline  

Advertisement [Remove Advertisement]

Old April 6th, 2002, 00:53   #2
kairi00
Puchiko-nyu!
 
kairi00's Avatar
 
Join Date: Jul 2001
Location: 49° 11' N 123° 10' W
Posts: 2,853
That sounds suspiciously close to this virus:

http://securityresponse.symantec.com...klez.e@mm.html
__________________
"Not every ejaculation deserves a name."

--- George Carlin
kairi00 is offline  

Old April 6th, 2002, 01:05   #3
Kane
邪魔ゎ指せない
 
Kane's Avatar
 
Join Date: Jan 2002
Location: Gosport, England
Posts: 26,303
Do you reckon it might be a virus/trojan/spyware?
Kairii bet me too it. Get a freeware virus scanner.... I'm trying to remember the name....
__________________

>Site Live<
Pop over to my site for help with setting up PSX emulators.
Help for the Final Fantasies and other RPGs avalaible

Celes: (Desktop) Phenom II X4, 4Gb DDR2, GeForce 8800 GTS 320Mb, 32Gb OCZ Vertex SSD, 500Gb RAID HDD, Windows 7 Home Premium
Erika: (MCPC) Revo3610, Windows 7 Home Premium
Kimiko: (Craptop) HP Mini 210

Kane is offline  

Old April 6th, 2002, 01:11   #4
Kellicros
Administrator
 
Kellicros's Avatar
 
Join Date: Nov 2001
Location: Kuala Lumpur, Malaysia.
Posts: 7,719
I followed the steps in that url from kairri, hopefully the virus is removed.
__________________
Kellicros' DeviantArt
Kellicros is offline  

Old April 6th, 2002, 02:37   #5
Badaro
I'm in despair!
 
Badaro's Avatar
 
Join Date: Apr 2001
Location: Brazil
Posts: 3,419
Quote:
Originally posted by Lord Kane
Do you reckon it might be a virus/trojan/spyware?
Kairii bet me too it. Get a freeware virus scanner.... I'm trying to remember the name....
AVG? That's the one I use.

http://www.grisoft.com

[]s Badaro
Badaro is offline  

Old April 6th, 2002, 03:07   #6
Kellicros
Administrator
 
Kellicros's Avatar
 
Join Date: Nov 2001
Location: Kuala Lumpur, Malaysia.
Posts: 7,719
now, i keep getting a "Error Starting program" error message whenever I start a software. Will get a anti-virus asap...
__________________
Kellicros' DeviantArt
Kellicros is offline  

Old April 6th, 2002, 03:49   #7
Esturk
Registered User
 
Esturk's Avatar
 
Join Date: Sep 2001
Location: Edmonton, Alberta, Canada
Posts: 6,964
Whenever I see something suspicious I download McAfee Viruscan trial and scan my comp then uninstall it afterwards. Works great.
__________________
Necrosaro: Windows 7 Ultimate x64 Edition SP1 | Intel Core i5 2500K - 3.30GHz, 8MB L3 Cache | Asus P8P67 Deluxe, Intel P67 Chipset, Socket 1155 | 8GB Kingston PC3-10600 DDR3 | Nvidia GeForce GTX460, 1024MB | Creative SB X-Fi Fatality Edition | Western Digital Raptor WD1500HLFS, 150Gb, SATA, Western Digital WD1001FALS, 1000GB, SATA | LG 16x DVD-RWx2 SATA.
Esturk is offline  

Old April 6th, 2002, 03:49   #8
Demigod
これはバタスです
 
Demigod's Avatar
 
Join Date: Jun 2001
Location: Toronto, Ontario, Canada
Posts: 6,332
I occasionally see that program (winfba.exe) in my processes. It doesn't seem to do anything though so I just leave it alone. My anti-virus software doesn't pick up anything either, even with the latest definitions, so I'm guessing it's safe.
__________________
CPU: Intel Core 2 Quad Q9450 Mobo: Intel DX48BT2 Memory: 4096 MB PC10600 DDR3 Videocard: PNY Geforce 9800 GX2 Soundcard: On-board SigmaTel High Definition Audio Hard drive: 120 GB OCZ RevoDrive PCI-E SSD & 1 TB Hitachi Optical drive: LG GGW-H20L (2x BD-R DL) PSU: Nexus 1000 Watt PSU OS: Microsoft Windows 7 Ultimate (64-bit)

Proud millionaire folder of the NGEmu folding team
Demigod is offline  

Old April 6th, 2002, 04:05   #9
NickK
Emu author
 
NickK's Avatar
 
Join Date: Jul 2001
Posts: 1,756
I have my virus scanner and firewall on all of the time, you can be attacked at any moment without warning. The virus scanner is especially useful when reading e-mails, since some of the infected ones love to try to force the application to start without warning.
NickK is offline  

Old April 6th, 2002, 04:31   #10
Esturk
Registered User
 
Esturk's Avatar
 
Join Date: Sep 2001
Location: Edmonton, Alberta, Canada
Posts: 6,964
There are some things running here that I have no idea what they're for.
__________________
Necrosaro: Windows 7 Ultimate x64 Edition SP1 | Intel Core i5 2500K - 3.30GHz, 8MB L3 Cache | Asus P8P67 Deluxe, Intel P67 Chipset, Socket 1155 | 8GB Kingston PC3-10600 DDR3 | Nvidia GeForce GTX460, 1024MB | Creative SB X-Fi Fatality Edition | Western Digital Raptor WD1500HLFS, 150Gb, SATA, Western Digital WD1001FALS, 1000GB, SATA | LG 16x DVD-RWx2 SATA.
Esturk is offline  

Old April 6th, 2002, 06:25   #11
Kellicros
Administrator
 
Kellicros's Avatar
 
Join Date: Nov 2001
Location: Kuala Lumpur, Malaysia.
Posts: 7,719
I 'm getting that AVG mentioned by Badaro now, it will take a while anyway(dial-up connection), and here's what I got when starting any program, after clicking "OK" everythings seems to be fine, looking for a quick fix if possible.
__________________
Kellicros' DeviantArt
Kellicros is offline  

Old April 6th, 2002, 12:54   #12
gerbilcannon
The Pretty One
 
gerbilcannon's Avatar
 
Join Date: May 2001
Location: Collegedale, TN
Posts: 1,247
housecall.antivirus.com

free virus scan there.
__________________
"Me? I'm a pop idol."
"And you will shed tears of scarlet!"
gerbilcannon is offline  

Old April 8th, 2002, 05:25   #13
Death Metal
Translator
 
Death Metal's Avatar
 
Join Date: Oct 2001
Location: South Town
Posts: 1,775
Quote:
Originally posted by Evil Squall
I 'm getting that AVG mentioned by Badaro now, it will take a while anyway(dial-up connection), and here's what I got when starting any program, after clicking "OK" everythings seems to be fine, looking for a quick fix if possible.
Strange. I'm also an user of AVG at work, and it runs fine w/out this warning you posted. Furthermore, I consider AVG as one of the bests freeware virus scanner available.
__________________
"It sure is pleasurable to live your dreams as long as possible, but reality sure has a way of jolting you to your senses eventually."
Death Metal is offline  

Old April 9th, 2002, 04:45   #14
ShADoWFLaRe85
Guest
 
Posts: n/a
Quote:
Originally posted by Death Metal

Strange. I'm also an user of AVG at work, and it runs fine w/out this warning you posted. Furthermore, I consider AVG as one of the bests freeware virus scanner available.
I don't think he said AVG was issuing that warning. I'm guessing it's the current state of his machine when executing ANY application.
 

Old April 9th, 2002, 15:57   #15
Unicron
Git er done
 
Unicron's Avatar
 
Join Date: Mar 2002
Location: Raleigh, NC USA GO us!
Posts: 2,829
A while ago my dad got unusual emails from someone we knew but didn't expect to get emails from and attached to them were pictures. Later I decided for the hell of it to go download norton antivirus 30 day demo. I installed it and it found all those pictures as being part of a worm vm33 or something I can't remember but after all this stuff and the worm was deleted I could not run an
.exe file to save my life. I searched norton's site for a while and found a patch that gets rid of the problem that the worm caused on my machine...just my $.025.
__________________
It is the soldier, not the court, that has given us freedom of speech. It is the soldier, not the agitator, who has given us the freedom to protest. It is the soldier who salutes the flag, serves beneath the flag, whose coffin is draped by the flag, who gives that protestor the freedom he abuses to burn that flag.

-Senator Zell Miller

Unicron is offline  

Old April 9th, 2002, 19:28   #16
ShADoWFLaRe85
Guest
 
Posts: n/a
I've seen viruses that corrupt images, but never before have I seen a virus that was executable from an image. You sure they were picture format? Maybe an *.exe disguised as an image or possibly they were just infected? Images themselves can't hold viruses, as far as I know.
 

Old April 9th, 2002, 19:49   #17
Demigod
これはバタスです
 
Demigod's Avatar
 
Join Date: Jun 2001
Location: Toronto, Ontario, Canada
Posts: 6,332
I've never encountered viruses in images before, although I've encountered them in .htm and .eml files.
__________________
CPU: Intel Core 2 Quad Q9450 Mobo: Intel DX48BT2 Memory: 4096 MB PC10600 DDR3 Videocard: PNY Geforce 9800 GX2 Soundcard: On-board SigmaTel High Definition Audio Hard drive: 120 GB OCZ RevoDrive PCI-E SSD & 1 TB Hitachi Optical drive: LG GGW-H20L (2x BD-R DL) PSU: Nexus 1000 Watt PSU OS: Microsoft Windows 7 Ultimate (64-bit)

Proud millionaire folder of the NGEmu folding team
Demigod is offline  

Old April 9th, 2002, 19:51   #18
ShADoWFLaRe85
Guest
 
Posts: n/a
Quote:
Originally posted by Demigod79
I've never encountered viruses in images before, although I've encountered them in .htm and .eml files.
That's because they have embedded malicious scripts. It's funny how much scripting will let you do these days, even on web pages. Check out what I managed to do with a bit of script -> http://www.flaredomain.net/radio/eject2.htm

*edit* just a note...this isn't really malicious. it opens your cdrom drive.
 

Old April 9th, 2002, 22:47   #19
Death Metal
Translator
 
Death Metal's Avatar
 
Join Date: Oct 2001
Location: South Town
Posts: 1,775
Quote:
Originally posted by ShADoWFLaRe85

I don't think he said AVG was issuing that warning. I'm guessing it's the current state of his machine when executing ANY application.
You're right.
__________________
"It sure is pleasurable to live your dreams as long as possible, but reality sure has a way of jolting you to your senses eventually."
Death Metal is offline  

Old December 28th, 2002, 11:55   #20
ice2hot
Avatar says it all.
 
ice2hot's Avatar
 
Join Date: Apr 2001
Location: Dubai
Posts: 526
son of a Bit**. I mean fine the scripts do that but shouldnt there be patch for these sort of things. I mean what about sites which have pops ups they can easilt embed scripts and make them do whatever they want
__________________
cant think up of a cool one yet
ice2hot is offline  

Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

All times are GMT +1. The time now is 23:03.

© 2006 - 2012 Emu Forums | About Emu Forums | Advertisers | Investors | Legal | A member of the Crowdgather Forum Community


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2013, vBulletin Solutions, Inc.