Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

WININIGO.EXE - What is it?

Status
Not open for further replies.
Aug 4, 2004
2
GB
Each time I connect to the web my firewall is asking if I want to let WININIGO.EXE access the internet and act as a server. I have declined.
Does anyone know what this app is? I can find no reference to it anywhere on the web, except for one entry in a 'HijackThis' log in this forum. Registry says it's Microsoft Update Machine and I'd like to believe it but I'm not convinced. Many thanks
 
Looks like it's part of a W32/Gaobot (aka WORM_RBOT.DM) worm variant. Suggest you check your AV software settings. More information at
"The Crystal Wind is the storm, and the storm is data, and the data is life. You have been slaves, denied the storm, denied the freedom of your data. That is now ended; the whirlwind is upon you . . . . . . Whether you like it or not."

"Trent the Uncatchable" in The Long Run by Daniel Keys Moran
 
Thanks JB - just read your reply. I removed wininigo from the registry after turning off system restore. It kept coming back but after doing the registry clean for all the family accounts, it has finally gone. Norton Antivirus and Sophos did not recognise it which is a bit of a pain. Had trouble connecting to the web but sorted that out by killing msnmsgr and msmsgs(I just got a wireless router/firewall and need to get port forwarding sorted)
 
Gaobot has been a real pain to the A/V companies because the code was posted somewhere on the web and a lot of different people have modified. The problem isn't so much finding the infecting files as it is finding the files creating them at start up.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top