PDA

View Full Version : IXFCUPMEDOGO.scr: SBSD IE Protection?



Tom.K
2008-10-15, 21:30
I don't understand why this "screen saver" is shown as a SBSD IE Protection which acutally has .dll extension.
And why the file isn't hidden (including system attribute)?
Note that the file comes like that as useless (except if you change it to .dll extension); when you run it, says that the program is not a valid Win32 app.

File Hashes:
CRC32: C2F522E6
MD5: 32981ADE44D01EC2A9EBC2E311291707

PepiMK
2008-10-15, 21:41
Backup copies of the executables are stored inside the Spybot-S&D, using a random filename, folder in case malware tries to block Spybot by filename.

Regular files with the extension .scr can be run the same as .exe. So we chose this for the rare case when a system is no longer be able to execute any .exe files.

Which btw is a great trick for repair: if the system cannot run any .exe, copy regedit.exe to regedit.scr, run that (it still will), and you can repair the registry even if regedit.exe wouldnt launch.

A copy of the DLL isn't as useful of course, that kind of backup mechanism is more useful for the .exes.

Will have to check the hash for more...