New User? Need help? Click here to register for free! Registering removes the advertisements.

Computer Cops
image image image image image image image image
Donations
If you found this site helpful, please donate to help keep it online
Don't want to use PayPal? Try our physical address
image
Prime Choice
· Head Lines
· Advisories (All)
· Dnld of the Week!
· CCSP News Ltrs
· Find a Cure!

· Ian T's (AR 22)
· Marcia's (CO8)
· Bill G's (CO10)
· Paul's (AR 5)
· Robin's (AR 2)

· Ian T's Archive
· Marcia's Archive
· Bill G's Archive
· Paul's Archive
· Robin's Archive
image
Security Central
· Home
· Wireless
· Bookmarks
· CLSID
· Columbia
· Community
· Downloads
· Encyclopedia
· Feedback (send)
· Forums
· Gallery
· Giveaways
· HijackThis
· Journal
· Members List
· My Downloads
· PremChat
· Premium
· Private Messages
· Proxomitron
· Quizz
· RegChat
· Reviews
· Search (Topics)
· Sections
· Software
· Statistics
· Stories Archive
· Submit News
· Surveys
· Top
· Topics
· Web Links
· Your Account
image
CCSP Toolkit
· Email Virus Scan
· UDP Port Scanner
· TCP Port Scanner
· Trojan TCP Scan
· Reveal Your IP
· Algorithms
· Whois
· nmap port scanner
· IPs Banned [?]
image
Survey
How much can you give to keep Computer Cops online?

$10 up to $25 per year?
$25 up to $50 per year?
$10 up to $25 per month?
$25 up to $50 per month?
More than $50 per year?
More than $50 per month?
One time only?
Other (please comment)



Results
Polls

Votes: 827
Comments: 19
image
Translate
English German French
Italian Portuguese Spanish
Chinese Greek Russian
image
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Login to check your private messagesLogin to check your private messages   LoginLogin 

ieaksie.exe ????

 
Post new topic   Reply to topic       Computer Cops Forum Index -> General Security
View previous topic :: View next topic  
Author Message
lisavan

Cadet
Cadet



Joined: Apr 15, 2004
Posts: 8
Location: USA

PostPosted: Tue May 11, 2004 7:34 pm    Post subject: ieaksie.exe ????
Reply with quote

can anyone tell me what ieaksie.exe is and what it does? I have done a couple searches and come up with nothing. Thanks!
Back to top
View users profile Send private message
k027

1st Responder
1st Responder



Joined: Aug 25, 2003
Posts: 1171
Location: USA

PostPosted: Tue May 11, 2004 9:24 pm    Post subject:
Reply with quote

Hello lisavan,

Do you mean ieaksie.dll? Confused
Back to top
View users profile Send private message
lisavan

Cadet
Cadet



Joined: Apr 15, 2004
Posts: 8
Location: USA

PostPosted: Tue May 11, 2004 9:43 pm    Post subject:
Reply with quote

No, I mean ieaksie.exe. Sygate kept telling me that "ieaksie.exe is trying to connect to 206.58.237.248 using port ?? (don't remember, I didn't write that part down) ....." I also looked in my task manager and it showed ieaksie.exe.
Back to top
View users profile Send private message
IamHypnoS

Trooper
Trooper



Joined: May 11, 2004
Posts: 28
Location: USA

PostPosted: Wed May 12, 2004 12:30 am    Post subject:
Reply with quote

ieaksie is not an application (exe) it is a dynamic link library (dll)

ieaksie.exe I have never heard of.... in all my life.... HOWEVER CAUTION! viruses offen use names of programs that really exist or other file names that really exist but change them some to make the virus harder to find... I mean you wouldn't name a virus, BADBADVIRS.exe would you? nah you'd name is something like explores.exe or svchosts.exe both are real programs but the virus creator added an s to each one to try to make his code harder to detect... real examples Razz
Back to top
View users profile Send private message Send email
k027

1st Responder
1st Responder



Joined: Aug 25, 2003
Posts: 1171
Location: USA

PostPosted: Wed May 12, 2004 8:19 am    Post subject:
Reply with quote

Hello lisavan,

ieaksie.dll is legitimate, ieaksie.exe does not appear to be. Search for ieaksie.exe on your computer, right click (do not doubleclick) on "Properties", click on "Version", scroll through the menu and report back with what you find.

206.58.237.248 resolves to update.requestlookup.net. requestlookup.net is a search engine. You may have adware and/or spyware on your computer.

Download, install, update, and run Ad-aware and Spybot S&D:

http://computercops.biz/downloads-file-292.html
http://computercops.biz/downloads-file-108.html

Reboot your computer after running each program. Smile
Back to top
View users profile Send private message
lisavan

Cadet
Cadet



Joined: Apr 15, 2004
Posts: 8
Location: USA

PostPosted: Thu May 13, 2004 9:35 pm    Post subject:
Reply with quote

Sorry it took so long to get back to you. I think I found the information you were asking me about. Here it is ...

Name: ieaksie.exe - 2A070641.pf
type of file: PF File
Opens with: Unknown Application
Location: C:\Windows\Prefetch
Size: 46.0 KB (47,202 bytes)
Size on disk: 48.0 KB (49,152 bytes)
Date created: Monday, May 10, 2004, 10:52:13 AM
Modified: Tuesday, May 11, 2004, 7:23:34 PM
Accessed: Today, May 13, 2004, 8:14:38 PM

I am guessing that since it was just created a few days ago, that it is something I don't need. I have done several virus scans and they all come up with nothing (AVG, Panda, Trend Micro). I also have Spybot & Ad-aware and run them daily (sometimes more than once), spybot shows nothing and Ad-aware has just been coming up with cookies for websites that I have been to (I have removed all of them). I did a sytem restore to last week and the program is currently not running (as far as I can tell), but I would like to get rid of it all together if it a possible virus. Thanks!
Back to top
View users profile Send private message
DaveSW

Cadet
Cadet



Joined: May 14, 2004
Posts: 3
Location: Uk

PostPosted: Fri May 14, 2004 1:42 pm    Post subject:
Reply with quote

start -> run -> msconfig
click the startup tag, see if you can find it. If you do simply deselect the tickbox next to it.

It is sometimes necessary to reboot in safemode to do this, and the other step I sometimes use is start -> run -> regedit and use the find tool on the edit menu to locate any references to it. Then delete them.

I usually follow the first step because if it kills your computer because it was essential you can boot in safemode to retick it!

The other possibility is something like coreflood - http://us.mcafee.com/virusInfo/default....s_k=100312
It uses randomly generated filenames 7 characters long, although the fact it starts with ie would suggest otherwise.

_________________
http://www.emdevelopments.co.uk - accessible web design
Back to top
View users profile Send private message Visit posters website
PDragon616

Cadet
Cadet



Joined: Jun 09, 2004
Posts: 1
Location: USA

PostPosted: Wed Jun 09, 2004 10:03 pm    Post subject:
Reply with quote

What a coincidence. Mad I happen to have an executable that showed up in my SYSTEM32 directory in the last week, which is also named after a DLL in the same directory and ZoneAlarm has been blocking its attempts to connect to the exact same IP you are seeing. 206.58.237.248:80

My guess is that there is a piece of hackerware that was deposited on my machine somehow or a virus, and it names the executable after *any* DLL in your system32 directory.

For me the exe is "iglzw32s.exe". When I bring up the process monitor, I can see it among the processes. Killing it does not appear to affect the computer. I've asked ZoneAlarm to permanently block it.

Something to watch out for... by picking a random real DLL and naming the exe after it, the hacker avoids people from searching for the filename in google and finding anything unusual. Sleazy.

Does anyone here have the ability to decompile an executable and figure out what it does? I'd be happy to send the exe to anyone who wants to look at it.
Back to top
View users profile Send private message
dakikat

Cadet
Cadet



Joined: Jun 11, 2004
Posts: 1
Location: USA

PostPosted: Fri Jun 11, 2004 3:51 pm    Post subject:
Reply with quote

I also just encountered the same thing, except in my case my executable was named mqqm.exe. My firewall blocked it from accessing search.requestlookup.net port 80. (206.58.237.248:80)

Mine is a 52KB file

C:\WINDOWS\SYSTEM32
Size: 51.3 KB (52,626 bytes)
Size on disk: 52.0 KB (53,248 bytes)

I blocked it and renamed it ...Symantec anti-virus, Adaware, and Spybot didn't find anything
Back to top
View users profile Send private message
faithhope

Cadet
Cadet



Joined: Jun 13, 2004
Posts: 2
Location: Afghanistan

PostPosted: Sun Jun 13, 2004 9:25 am    Post subject:
Reply with quote

Me too. My file is d3d8.exe and it is in the Windows\system32 directory. Zone Alarm alerted me this was trying to connect. Hopefully we will figure out what this thing is soon.
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       Computer Cops Forum Index -> General Security All times are GMT - 5 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB 2.0.8a © 2001 phpBB Group

Version 2.0.6 of PHP-Nuke Port by Tom Nitzschner © 2002 www.toms-home.com
Version 2.2 by Paul Laudanski © 2003-2004 Computer Cops