Welcome, Guest. Please login or register.
November 22, 2008, 09:58:24 AM

Login with username, password and session length

213636 Posts
24712 Topics
57950 Members

Latest Member: johnsmail

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Firewall
| | |-+  Frequently Asked Questions (FAQ) for Comodo firewall
| | | |-+  Problem with "fedcbaqpon.exe"
« previous next »
Pages: [1] Go Down Print
Author Topic: Problem with "fedcbaqpon.exe"  (Read 1953 times)
Stefano BZ
Newbie
*
Offline Offline

Posts: 8


« on: August 19, 2007, 11:56:23 AM »

Hello,

I use Comodo as spyware, and lately it asks me if a lot of programs are authorized to access the net, like Internet Explorer, svchost application and more. Comodo says, e.g. with Internet Explorer:
C:\WINDOWS\system32\fedcbaqpon.exe has tride to use iexplorer.exe through OLE Automation, which can be used to hijack other application. fedcbaqpon.exe might be using iexplorer.exe to connect the Internet

With other programs, already authorized defenetively in the past  to have access to the net,like for example Microsoft Messenger:
C:\WINDOWS\system32\fedcbaqpon.exe has modified msnmsgr.exe in memory. This is typical of Virus, Trojan and Spyware behaviour
 
I made a scan with Adware but it didn't find anything, I looked for the file with Search function of Windows, but it doesn't find anything and I even looked for info on Google and other searching engines, but nothing.

Is it truely something or it's just a bug of the programme???
Logged
zurst
Newbie
*
Offline Offline

Posts: 9


« Reply #1 on: August 19, 2007, 12:37:47 PM »

I think you can submit that .exe to the people working on Comodo Antivirus / Comodo Anti-malware

Another tip is use Firefox instead of IE
Logged
Stefano BZ
Newbie
*
Offline Offline

Posts: 8


« Reply #2 on: August 19, 2007, 12:48:33 PM »

... The problem is that I don't find the .exe file on my computer!
How can I submit it to Comodo programmers when I cannot find it by myself?

As I already wrote in my previous message, I tried to find it in the path Comodo told me, but once I was there, there wasn't any file like that, neither hidden.
Logged
zurst
Newbie
*
Offline Offline

Posts: 9


« Reply #3 on: August 19, 2007, 02:39:10 PM »

Mmm this seems to be serious, try this --> http://www.adstools.net.nz/

Or maybe a rootkit remover . . . I'm not sure about this, try antispyware/malware comodo forums.

Mmm try to locate the "strange process" using:

Dtaskmanager --> http://dimio.altervista.org/eng/

Or MS Process Explorer --> http://www.microsoft.com/technet/sysinternals/utilities/ProcessExplorer.mspx

I hope something will be useful
Logged
N.T.T.W.
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1124


A minute of your time can help many.


« Reply #4 on: August 19, 2007, 03:29:11 PM »

You could also try downloading agent ransack:

http://www.mythicsoft.com/agentransack/

this is fantastic free search utility that is handy for finding those files that are difficult to find with the built in windows search tools.

 Smiler
Logged

Post proelia praemia.
Die dulci fruere.
Stefano BZ
Newbie
*
Offline Offline

Posts: 8


« Reply #5 on: August 20, 2007, 04:34:12 AM »

I made a search with File Locator Pro, and I found this programme in the system32 folder. In the properties nothing appears, so I don’t know if this is Windows regular file or not.

Anyways I solved it in part... I made "run" and wrote "msconfig". I went in the “Start” window and there I found this .exe, that used to start every time Windows starts.

I unchecked it so that it doesn’t start, and now Comodo doesn’t write me anything anymore. Smiley

So the problem is solved now, partly, but I still have this doubt about what that file is, since also in the internet I couldn’t find any info about that.
Logged
N.T.T.W.
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1124


A minute of your time can help many.


« Reply #6 on: August 20, 2007, 04:47:50 AM »

Now that you know the location of the file you could also add the file to the application monitor in CFP settings with a block rule. This would make it easier to submit the file to Comodo also.

 Smiler
Logged

Post proelia praemia.
Die dulci fruere.
Tags: Help pls  no info in Internet! 
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.153 seconds with 20 queries.
Powered by SMF 1.1.7 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com