PDA

View Full Version : Unknown .exe harming my comp!


ThrewLaptopOutWindow
06-21-2006, 10:49 PM
There is a .exe in my Windows\System32 folder called 4224ccfe.exe - And I have no idea how to get rid of it! After a series of problems I got rid of the common .atmclk and others, but this remains. So to does my hijacked homepage, I don't know how to get my old one back! Any one have any ideas? I have been fighting with this for two weeks now.

newmodder
06-21-2006, 10:55 PM
i would try some virus cans and adware scans if they dont work try system restore and restore to a time befor you got this stuff, if that dont work reinstall windows

magibeg
06-21-2006, 10:56 PM
What anti-virus software are you using right now?

newmodder
06-21-2006, 11:03 PM
i am using Norton antivirus spyware edition.here you should find a free trial version that will help you get rid of you comp problems.Or there are quit a few free programs out here

www.symantec.com

rh535
06-22-2006, 01:13 AM
If you are not using AVG free use it. unlike norton it is not a system hog.

http://free.grisoft.com/doc/1

Ketxxx
06-22-2006, 02:00 AM
Yep, AVG rules all. Also look up spybot and noadware to scan for spy programs etc.

{JNT}Raptor
06-22-2006, 02:19 AM
If your convinced It's a spyware bug Then you should try XoftSpySE...It's getting some good reviews for nailing all the Bugs.
Home page here...
http://paretologic.com/

Click on Free Scan and DL the App.....Update it and run It.....You may be surprised what It finds.

Happy Bug Hunting. :)

Alec§taar
06-22-2006, 05:39 PM
RC operates before any Windows Explorer (or other gui shell) runs, maybe this will help you remove it, by booting to it!

You can bootup from your install CD & run it, OR install it as a bootup option via:

[cd-rom driveletter]:\...i386\winnt32.exe /cmdcons

IIRC, that is how you install it as a bootup option.

Once in it? Use its "DOS-like" commandline interface & its DEL command to fry that s.o.b. & see if it goes away... if not, then it has "tentacles" & backup helping it elsewhere, which means you'd need a FULL startup list possibles, so here that is:

================================================== ===

<Prior to Logon Prompt>

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\RunServicesOnce

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\RunServices

<Logon Prompt>

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\RunOnce

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run

HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run

StartUp Folders (BOTH the COMMON TO ALL USERS type & CURRENT USER only folder type)

HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\RunOnce

(WIN.INI & PROGMAN.INI Run= & Load = lines as well)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"="Explorer.exe"
================================================== ===

* If that all doesn't help? Then, whatever it is starting this thing up has overwritten or infested executables the OS uses... that means antivirus removal tools time, & possibly even reinstalling your service pack & hotfixes that came after it, to hopefully replace the infected files.

(That's what I'd try, short of any removal tool being useless against it, that is possible too, I have seen it in the Win32 PinFi virus back in 2001 on my nephew's PC... iirc, that was its name, you have to "repave" once you sucked that one in, because nothing would/could remove that one, @ least back then, & I'd strongly wager that now as well!)

APK

i_am_mustang_man
06-23-2006, 12:19 AM
system restore is my favorite way to go. remember what the name of the exe is, restore to a point until it doesn't start up, and then go delete. system restore usually won't get rid of the program, just remove it from being executed automatically. it's my favorite form of virus control when mcafee lets me down.

only downside is reinstalling any other programs since your restore point..

BigD6997
06-23-2006, 12:31 AM
^^ yup, and use avg

Alec§taar
06-23-2006, 06:33 AM
system restore is my favorite way to go.

Well, since they already have it, I put up what I would do to try to "manually" remove it, should all others fail (there are a few out there like that (one I mention in Win32 PinFi), & worse coming/here now, in rootkits, imo...).

In lieu of "System Restore" (or things like Norton GoBack)?

Norton Ghost 2003 (yes, I like the old DOS one, because it installs in Windows Server 2003, w/out a version check & still works (yes!))...

OR

Acronis TrueImage

* Either works!

(My images are current as of 2 weeks ago (regular schedule) here on USB 2.0 SATA external drive letter storage (74gb WD "Raptor" 10k rpm, 8mb buffer), w/ 1 backup of the one before that one on DvD+RW (4))...

APK

P.S.=> Long running installations, & methods for easy/quick + "bug" free & clean? They rule... having QUICKLY restored system images, along with regular backups, imo makes for progress, & in whatever you do on a PC! apk

BigD6997
06-24-2006, 01:07 AM
or if its been awhile and u dont care about some stuff on your comp.... back up what u need and make sure its non-infected... and reformat! clean everything up a bit