Archived from groups: comp.security.firewalls (More info?)
Hi,
every time I connect my computer to internet, my firewall allert me about
the program "4HTCLVT.EXE" is trying to connect to IP:69.20.61.166
The directory is
C:\WINDOWS\Downloaded Program Files\g7kg\
only visible from DOS, inside this there's the file
4HTCLV EXE 49.152 13/05/02 15.45 4htclv.exe
a log file with the same name contain
{
o d65cb410 2800 "C:\WINDOWS\DOWNLO~1\G7KG\4HTCLVT.EXE"
R d65cb410 0 40
R d65cb410 d0 f8
R d65cb410 d0 170
R d65cb410 2600 200
R d65cb410 2400 200
R d65cb410 400 1000
R d65cb410 1400 1000
o d65602b0 8000 "C:\WINDOWS\SYSTEM\REDIR32.EXE"
R d65602b0 0 40
R d65602b0 80 f8
R d65602b0 80 1e8
r d65602b0 6000 1000
R d65602b0 5000 200
R d65602b0 5000 1000
o d65836d0 3998 "C:\WINDOWS\SYSTEM\CONAGENT.EXE"
R d65836d0 0 40
R d65836d0 3d70114 40
C d65836d0
o d65836d0 3920 "C:\WINDOWS\SYSTEM\VGAFULL.3GR"
R d65836d0 0 40
R d65836d0 80 40
R d65836d0 c0 db
R d65836d0 340 33e0
R d65836d0 360 327e
R d65836d0 35de 108
o d65c9fe0 f3bf "C:\WINDOWS\SYSTEM\WINOA386.MOD"
R d65c9fe0 0 40
R d65c9fe0 80 40
R d65c9fe0 c0 288
R d65c9fe0 3a0 8000
R d65c9fe0 83a0 7a0
r d65602b0 1000 1000
R d65602b0 4000 c00
r d65602b0 2000 1000
o d65f0460 177d2 "C:\WINDOWS\COMMAND.COM"
R d65f0460 0 40
C d65f0460
}
AVG antivirus dosn't find it, and the same is with AdAware 6.0
I've looking for with google but I've found nothing
Thankyou for all counsels,
Checco
You are about to answer a thread that has been inactive for more than 6 months. If you still wish to proceed, please ensure that your posting is original and does not duplicate or overlap any prior responses to this thread.