dxdllreg - dxdllreg.exe - Process Information
Process File: dxdllreg or dxdllreg.exe
Process Name: Microsoft DXDllRegExe
Description:
dxdllreg.exe is an application which is supposed to request you register your version of DirectX, however sometimes it stays resident.
Author: Microsoft Corp.
Part Of: Microsoft Windows Operating System
=======================================================
netsetup.exe is a generic install program for some 3rd party apps, and there is also a file by the same name that is part of the Windows OS. The OS needs this file, do not delete it.
=======================================================
migpwd.exe is the file that allows you to migrate your Windows passwords. It is an important system file and without it you can't log into Windows.
=======================================================
Win32/Parite
=======================================================
The virus consists of a dropper, which is witten in assembler, and the virus part itself, written in Borland C++.
When an infected file is launched, the control flow is passed to the virus dropper, which writes the virus to a temporary file and executes its infection procedure.
The virus searches for Win32 EXE PE files with .scr and .exe extensions on all logical drives of computer, and also in shared resources of local network, and infects them.
The virus doesn't manifest itselfs presence in any way.
The structure of infected file looks like this:
Host file
Virus
dropper - drops "main" to TEMP dir and executes it.
main - searches for files and infects them, e.t.c.
Removal Tool:
http://www.bitdefender.com/bd/site/viru ... &v_id=137#
"FlickR is supposed to be weird, fun, experimental, way out-there -- oh no, wait, now that it's so close to being part of Microsoft, FlickR's supposed to bore people to death and empty their pockets while pretending to innovate." - Bruce Sterling