Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old March 19th, 2010, 08:30 PM
twodogs44 twodogs44 is offline
Regular Poster
 
Join Date: Feb 2007
Posts: 90
Default Have you heard of this one?

When I turn my computer on and the firewall will ask me if I wish to allow or decline programs from getting on line. It seems that there is one I have not noticed in the past. It is gycpsftav.exe has anyone here know what it is.
I have ran several search programs and not found a thing.

Thanks for taking the time to read this. Any and all help will be highly thought of.

Dave aka twodogs44
  #2  
Old March 19th, 2010, 09:57 PM
mvario's Avatar
mvario mvario is offline
Frequent Poster
 
Join Date: Sep 2008
Location: Haddonfield, IL
Posts: 316
Default Re: Have you heard of this one?

Hmmm, unknown executable, running at startup, trying to connect to the net.

Have you found it on disk? What ports is it opening?
  #3  
Old March 19th, 2010, 09:57 PM
innerpeace's Avatar
innerpeace innerpeace is offline
Very Frequent Poster
 
Join Date: Jan 2007
Location: Mountaineer Country
Posts: 1,940
Default Re: Have you heard of this one?

Try uploading it to VirusTotal so it can be scanned by multiple scanners. You will need to know the location of the file to upload it.
__________________
XP Home SP3, Nat router, Firefox3.5, Online Armor Premium 4.5, AntiVir 9 free, Sandboxie, and Returnil RVS
Are you running vulnerable programs? Check online now with the Secunia Online Software Inspector.
  #4  
Old March 19th, 2010, 10:15 PM
twodogs44 twodogs44 is offline
Regular Poster
 
Join Date: Feb 2007
Posts: 90
Default Re: Have you heard of this one?

I am running Comodo Firewall and I hit the DECLINE so many times it quit coming up. Now I cannot find it when I run the Search Program in Windows!
Beats me. If its gone then good because the PC has not suffered a bit.

Thanks everyone, Dave aka twodogs44
  #5  
Old March 19th, 2010, 10:18 PM
crofttk's Avatar
crofttk crofttk is online now
Very Frequent Poster
 
Join Date: May 2004
Location: Eastern PA, USA
Posts: 1,952
Default Re: Have you heard of this one?

Looks like the rogue antivirus I had to clean off of two PCs (so far) at work. It was nasty, I had to repair the MBR and, even after cleaning, it had disabled Windows Update and implemented a proxy connection in Internet Explorer which I had to turn off and also reset IE LAN settings to automatically detect. Each infection involved an executable with a name in the form of xxxxxav.exe that was added to the run/startup key in the registry.

MBAM alongside mbrfix was very helpful in breaking the back of this one.
__________________
"Ignorance more frequently begets confidence than does knowledge..." - Charles Darwin -
  #6  
Old March 20th, 2010, 06:07 AM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,848
Lightbulb Re: Have you heard of this one?

@twodogs44

gycpsftav.exe very similar to gesvsftav.exe http://www.dslreports.com/forum/r23910637-

Quote:
did a scan, using all those tools, after opening the hidden files. The search found a Trojan Fraudpack.

Quote:
Trojan.FraudPack will download the fraud tool "Antispyware PRO XP" or similar and install it on user's computer.
__________________
.
Malware = You don't scare me

A different perspective https://rt.com - https://rt.com/on-air
  #7  
Old March 20th, 2010, 01:39 PM
twodogs44 twodogs44 is offline
Regular Poster
 
Join Date: Feb 2007
Posts: 90
Default Re: Have you heard of this one?

Thank you one and all for your assistance!

Dave aka twodogs44
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 09:04 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums