Re: mstcpcon20.dll found on Windows\system32

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



MA P wrote:
just wanted to know what does this file do to windows XP, any idea?
"Elmo" <elmogeek@xxxxxxxxxxxxx> wrote in message news:OdpUQycuHHA.3400@xxxxxxxxxxxxxxxxxxxxxxx
MA P wrote:
Just received notification from Symantec Antivirus after the weekly update that some of our desktops are infected by a virus. Is this really a virus or an error on the antivirus definition?
Why would you doubt the notification? Just delete it.

A Google search followed by a Google Groups search showed few hits because it's one of the random filenames used by a particular piece of malware. If not random, it's so new that there have been few posts on it. Symantec Antivirus recognized a piece of coding used by malware, after it updated its virus definitions. If Symantec Antivirus gave a name for the malware, you could look up the description there. The name of the malware could differ between Antivirus sites.

If it's a dialer, it watches keystrokes, and password entries, and reports back with the data. There are also worms, Trojans, and other malware and spyware which are named according to their specific tasks.

--
Joe =o)
.



Relevant Pages

  • Re: What is YIH0L80A.EXE
    ... of occasions I've found 3 or 4 instances of it running, ... Might be malware, virus, trojan that generates random filenames for its ...
    (microsoft.public.windowsxp.general)
  • >>>> REMOVE MANUALLY <<<<
    ... Remove Virus Manually ... How To Remove Spyware Manually ... Manually Remove Trojan Horse ... Manually Remove Symantec Antivirus ...
    (sci.math.num-analysis)
  • Re: Trojan horse Downloader.Generic.ML
    ... >> Malware doesn't make arbitrary changes, ... > so data diddlers don't exist? ... is the now extinct Ripper boot virus. ... As to disinfection vs integrity restoration, everything disinfection can do, ...
    (comp.security.firewalls)
  • Re: Trojan horse Downloader.Generic.ML
    ... >> Malware doesn't make arbitrary changes, ... > so data diddlers don't exist? ... is the now extinct Ripper boot virus. ... As to disinfection vs integrity restoration, everything disinfection can do, ...
    (alt.computer.security)
  • Re: RFC: virus handling
    ... > the virus or the test conducted. ... English speakers where the malware in question was not forged from some ... > their infection and should thereafter be disconnected entirely or ... Connect to open wireless network. ...
    (Bugtraq)