Jump to content

Question

Posted

This cannot be deleted, it uses up cpu and lags the network connection. Ending the process doesn't work, it starts back up. You cannot delete the file from the system because it is always in use (There may be a way to unfreeze the folder with MalwareBytes) And it is hidden in the registry.

Any clues as to what it is and how to remove it?

5 answers to this question

Recommended Posts

  • 0
Posted

seeing that it's a .exe... it's a command file, so it could probably be some sort of virus... and yes, I know that i'm not that good with all the problems with computers, but I know my way around ;)

  • 0
Posted

Use process explorer (google it in quotes) and you can find what program launches it.

I would also look at using Hijack This (see the other post about Marsden needing help).

But, I would first try malwarebytes. www.malwarebytes.org.

  • 0
Posted

Reboot your computer in safe mode. This keeps drivers and startup apps from launching. Then you can go and find the offending .exe and delete it.

Also go to Start > Run > regedit32 search for runonce When it finds the keys you actually want to go to run. It will be right next to runonce. Look in this key and see if this .exe is called in there. If so highlight the line and delete it.

Look me up in vent when I'm around and I can talk you through this if you don't feel comfortable. Any changes to the registry could have a desasterous effect. Do this only if you feel comfortable doing it.

MSgt. Francoeur

  • 0
Posted
Use process explorer (google it in quotes) and you can find what program launches it.

I found that program, I'll be suggesting it.

I would also look at using Hijack This (see the other post about Marsden needing help).

Good suggestion. Hijackthis is a great program, I will suggest it.

But, I would first try malwarebytes. www.malwarebytes.org.

I mentioned that in my first post, it's on the list of things to try.

Reboot your computer in safe mode. This keeps drivers and startup apps from launching. Then you can go and find the offending .exe and delete it.

It does not appear in safe mode.

Also go to Start > Run > regedit32 search for runonce When it finds the keys you actually want to go to run. It will be right next to runonce. Look in this key and see if this .exe is called in there. If so highlight the line and delete it.

It is apparently hidden/not found in the registry, but I'll mention the runonce as a place to check.

Look me up in vent when I'm around and I can talk you through this if you don't feel comfortable. Any changes to the registry could have a desasterous effect. Do this only if you feel comfortable doing it.

Luckily it's not on my computer, it's on my professor's computer.

I've asked my CS prof about it too, he suggests booting from a Linux boot disk and then try to delete the file/end the process.

Thanks for the suggestions everyone.

  • 0
Posted

If I remember correctly, I think you are dealing with a virtumondo/virtumumdo type of issue. These are 2 or 3 layer issues. The file you are dealing with, if deleted, will be respawned by a backup process that only exists to spawn the exe again. And sometimes, there is another backup process that only spawns the other process. These can be real bears to remove. I'd go malwarebytes, full scan, and see what happens.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Answer this question...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Recent Posts

    • Its Friday Night Fight Night in HLL and me and Muthas are in different squads. We meet up while attacking a point: Me: Muthas! Let's go get the poiple toineps! Muthas: Hah poi....   We are immediately cut down by a MG.   Steam messages:  Muthas: LMFAOO Me:OMFG! ROFLMAO!
    • Name: elon musk   Steam I.D: STEAM_0:0:918906720   Duration of Ban: Permanent   Reasons for the Ban: Racist comments and Mass Team Killing   Demo Provided?: N   Comments: Keebler reported in public chat, sent screen shot of typed comments  
    • Hey Reis! Great to see you again, man. The unit means a lot to all of us and I know you were here for quite some time. There’s always room for you to come back   *Salute*
    • I dont know how many of the people that know me or what i did in the unit are still here. But i just wanted to leave a huge thank you on the forums to this unit, that i was a part of for so many years, and all the good times and hardships i shared with a lot of different people from all over the world.    Maybe i'll still see you in DoD:s   *Salute*
    • 2nd Platoon Weekly Attendance   Week of 10NOV2024   P = Present | E = Excused | A = Absent   Platoon Staff WO. A. Pitteway - Excused MSgt. J. Candy - Present TSgt. A Yoder - Present   1st Squad Squad leader:  SSgt. R. Fielding - Present Cpl. B. Grande - Present Pfc. R. Smith - Excused Pfc. M. Noel - Present Pfc. C. Keebler - Present Pvt. D. Moffat - Present Pvt. R. Zera - Absent Pvt. N. Clement - Excused       2nd Squad Squad leader:  Cpl. S. Holquist - Present Pfc. A. Cannon - Excused Pfc. T. Scary - Present Pfc. C. Marsh - Present Pfc. M. Oake - Excused Pvt. L. Whistle - Present Pvt. M. Clarkson - Excused Pvt. W. Swift - Present           Helpers: WO. S. Belcher
×
×
  • Create New...