Welcome, Guest. Please login or register.
November 17, 2009, 12:09:50 AM

Login with username, password and session length

335066 Posts
37061 Topics
84053 Members

Latest Member: EnglishRose

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Virus/Malware Removal Assistance
| | | |-+  Winudpmgr.exe Problem
« previous next »
Pages: [1] Go Down Print
Author Topic: Winudpmgr.exe Problem  (Read 1079 times)
JonnyDark
Newbie
*
Offline Offline

Posts: 2


« on: June 29, 2009, 11:38:16 AM »

Hi all,
First to say I'm new here so sorry if I put this in the wrong location or if it's already been discussed somewhere but searching winudpmgr.exe over the forum turned up nothing.

But just thought I'd join and see if anyone else has had an encounter with this bit of malware? I installed a driver package on my system (while CIS was active) and noticed this executable tried gaining some system priveleges from windows that I was none too happy with.

I brought up CIS UI afterwards and noticed around 200 intrusion attempts had been blocked and the number was rising very rapidly. So I checked them out and noticed it was something called Winudpmgr.exe going through my ports one-by-one (all of which had been blocked luckily by my earlier skepticism) and attempting to set up an external connection to an unknown IP address on the net every 8 seconds.

So I ended its process, did a search on this little file name and turned up zero on google, Spybot S&D, COMODO and MalwareBytes all dont recognize it as malware and cant detect it and the path that the process in the task manager and COMODOS intrusion attempt log identified as C:\Windows\winudpmgr.exe just isn't there, as a normal or hidden file.

Luckily the intrusion attempts are stopped by COMODO and the process can be terminated using task manager but it starts automatically right after a system startup (nothing in the startup menu of windows defender or services btw).

So the main question is, has anybody had a run-in with this before and if so, how do I kill it?

Thanks for any and all help offered.
Logged
EricJH
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 4138



« Reply #1 on: June 30, 2009, 06:53:50 PM »

The file name is at least bit suspect to me. It looks like a windows update file but it is not something I immediately recognise.

Please try the following:
Check the properties of the file and see if it is an officially signed file made by Microsoft.
Upload it to the the following sites and let us know what they tell:
www.virustotal.com
http://camas.comodo.com/cgi-bin/submit (Comodo Instant Malware Analysis).
Logged

Triple boot: XP SP3, Vista Ultimate 32 SP2 and Win7 RTM (default) , Always the latest CIS or CIS Beta (too lazy to update my sig) Athlon XP 2600 1 GB RAM. Opera Browser always using the latest snapshots; Opera 10.10 as of now
kail
Autonomous
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5320


I'm not a complete idiot, some bits are missing.


« Reply #2 on: June 30, 2009, 07:04:52 PM »

Google searches & ThreatExpert suggest that this is potentially something nasty.
Logged

Vista Business x32+SP2 with CIS 3.12 & Firefox 3.5 & Becky! 2.52
__
A positive and polite attitude may not solve all your problems, but it will annoy enough people to make it worth the effort.
JamesFrance
Comodo's Hero
*****
Offline Offline

Posts: 616



« Reply #3 on: July 01, 2009, 04:07:19 AM »

This one seems to be well known at Bleeping Computer, see here:
http://www.bleepingcomputer.com/startups/winudpmgr.exe-23094.html

Edit: Malwarebytes should be able to remove this, it has done so before, so make sure your program is updated and the database is also up to date, then run a quick scan with it again.
« Last Edit: July 01, 2009, 04:21:40 AM by JamesFrance » Logged

James
JonnyDark
Newbie
*
Offline Offline

Posts: 2


« Reply #4 on: July 01, 2009, 07:48:15 AM »

Hi all, thanks for the reply,
I managed to get it off with Malwarebytes after a manual update (forgot the the free edition doesn't auto update  Grin)

EricJH - You're right, it wasn't the file, Winudpmgr is for Windows update manager (I'm such a dunce) but the reason I couldn't check the file properties was because it doesn't appear in the Windows directory even with hidden files set to show, so sorry, couldn't get any info on it.

Kail - I remember when I googled and looked at the ThreatExpert definition it did say it was nasty, but it was referring to winupdmgr, so I got confused, especially when winudpmgr turned up zilch anywhere on google or ThreatExpert - even that winudpmgr was a system file (though after some system monitoring i realized it was the vista update manager)

JamesFrance - thanks for reminding me about updating MalwareBytes, it identified it as a Backdoor.bot that had hijacked windows update.

So thanks for your help you guys, if I hadn't had your replies to kick some common sense in to me I'd probably still be threatening my laptop with the hammer lol
Logged
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.036 seconds with 19 queries.
Powered by SMF 1.1.10 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com