1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Reboot.exe [friend or foe? Trojan ??]

Discussion in 'Malware and Virus Removal Archive' started by Roger100UK, 2005/07/06.

Thread Status:
Not open for further replies.
  1. 2005/07/06
    Roger100UK

    Roger100UK Inactive Thread Starter

    Joined:
    2005/02/22
    Messages:
    22
    Likes Received:
    0
    Reboot.exe

    Can any one tell me what this programme does in XP. I did a Google Search on it and I am none the wiser I am afraid. It may be a Trojan but Norton AntiVirus does not detect it as one. Roger
     
  2. 2005/07/06
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389

  3. to hide this advert.

  4. 2005/07/06
    Roger100UK

    Roger100UK Inactive Thread Starter

    Joined:
    2005/02/22
    Messages:
    22
    Likes Received:
    0
  5. 2005/07/07
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Would you please confirm that this is exactly what is shown in StartUp - I can find no reference to it on Google.
     
  6. 2005/07/13
    Roger100UK

    Roger100UK Inactive Thread Starter

    Joined:
    2005/02/22
    Messages:
    22
    Likes Received:
    0
    Sorry for delay in replying but I have been away.
    I ran msconfig and under StartUp it just says

    Startup Item Command Location
    Reboot C: Documents & Set StartUp

    A Google search of "Reboot" gives this as a DOS Programme under the first item of the search result. Roger
     
  7. 2005/07/13
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
  8. 2005/07/13
    Roger100UK

    Roger100UK Inactive Thread Starter

    Joined:
    2005/02/22
    Messages:
    22
    Likes Received:
    0
    Hi Pete. I have spoken to a friend of mine who has Windows XP and he checked with his computer and could not find Reboot.exe. I therefore deleted it from my computer five minutes ago using HijackThis. From memory it was about 350. Roger
     
  9. 2005/07/13
    Roger100UK

    Roger100UK Inactive Thread Starter

    Joined:
    2005/02/22
    Messages:
    22
    Likes Received:
    0
    Hi Pete. I have just checked my internet connection and whilst the bytes received was static bytes sent were still increasing even though I was not doing anything. Do you think that is significant. Roger
     
  10. 2005/07/13
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Probably not. As you are connected to somewhere there will be some 'handshaking' going on anyway.

    I don't have reboot.exe either and having read a bit about it on Google I have no real idea whether or not it is harmful. Hopefully there will be a comment or two from the Security experts when they come on line (most are in the States).
     
  11. 2005/07/14
    Roger100UK

    Roger100UK Inactive Thread Starter

    Joined:
    2005/02/22
    Messages:
    22
    Likes Received:
    0
    I think I have found the culprit that was making my bytes sent increase. I have a programme called Doctor SpeedTouch and when I unchecked this from the startup menue it also stopped my bytes sent increasing.
    I also do not seem to have suffered any problems after I got rid of Reboot.exe so hopefully all is now well.
    I am still wondering why sychost.exe, lsass.exe and alg.exe appear every day in my Firewall Log as accessing the internet. They are Microsoft programmes but why do they need the internet?.
    Roger
     
  12. 2005/07/14
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Roger

    svchost.exe is a legitimate Windows file - sychost.exe is NOT. Please check the spelling! Is it a v or a y?

    lsass.exe is nominally a Windows process, but there are some viruses which masquerade as lsasse.exe.

    alg.exe - Application Layer Gateway should be legit.
     
  13. 2005/07/14
    Roger100UK

    Roger100UK Inactive Thread Starter

    Joined:
    2005/02/22
    Messages:
    22
    Likes Received:
    0
    Hi Pete. It is definitely a v not a y. I would hope that Norton AntiVirus would have sorted out lsass if it had been a virus. My old computer was a Gateway product and I am still using the monitor and the old hard drive.
    If these three programmes appear in the Firewall Log does that mean they were trying to access the internet but were refused as it just says that they were preparing to access the internet. Roger
     
  14. 2005/07/14
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    This is becoming rather a grey area for me - I can't answer you directly one way or another.

    I'll bring this thread to the attention of one of our security experts.
     
  15. 2005/07/14
    Roger100UK

    Roger100UK Inactive Thread Starter

    Joined:
    2005/02/22
    Messages:
    22
    Likes Received:
    0
    I have just been to the Iamnotageek web site and downloaded a trial version of NoAdware which found 36 "dangerous" items all of which were something like:
    WhenUSearch HKEY_CLASSES_ROOT\INTERFACE{ O.RegKey etc etc
    To remove them I would have to pay a one off payment of $29.95!!!!.
    None of my other spyware programmes has ever revealed anything like these before. Is it worth the money do you think. Roger
     
  16. 2005/07/14
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Doubtful - had a very bad press with false positives, but now supposedly 'improved' ....

    The following (all freeware) are highly recommended and used by many on this Board, including myself.

    If you have not already done so download via Quicklinks in my signature ....

    Ad-Aware SE - update and run and delete all it finds.

    Spybot - update and run and delete all it finds. Use the immunize feature to provide a degree of permanent blocking of nasties.

    For additional blocking download SpywareBlaster 3.4 - update it and enable all protection. This is a not a scanner, but a permanent blocker and should be updated regularly and additional protection applied.

    Microsoft AntiSpyware Beta - continuous monitoring of your system for adware and automatic updating.

    You really do not need anything more than this plus a read of How to Surf Safely by Arie, the BBS Administrator
     
  17. 2005/07/14
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
  18. 2005/07/15
    Roger100UK

    Roger100UK Inactive Thread Starter

    Joined:
    2005/02/22
    Messages:
    22
    Likes Received:
    0
    Hi Pete. I already use all those programmes and I update them before I do my weekly scans. I also use another excellent programme called Spyware Doctor which sometimes finds things that the other 3 miss.
    I will take on board all the recommendations mentioned in "How to Surf Safely" though. Thanks again. Roger
     
    Last edited: 2005/07/15
  19. 2005/07/15
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    You're welcome :)
     
  20. 2005/07/15
    Roger100UK

    Roger100UK Inactive Thread Starter

    Joined:
    2005/02/22
    Messages:
    22
    Likes Received:
    0
    Hi This is it, I don't know. They are mentioned in the Firewall Log as "preparing to access the internet" but does that mean they were allowed or refused?.
    Thanks for the advice re NoAdware I have uninstalled the trial version and I will take a look at the site you mentioned. Roger
     
  21. 2005/07/16
    Roger100UK

    Roger100UK Inactive Thread Starter

    Joined:
    2005/02/22
    Messages:
    22
    Likes Received:
    0
    I have now carried out all the recommendations of "How to surf the Internet more safely" and also downloaded the Ewido Security Suite.
    Hopefully I should not get any more problems. Thanks Pete and Dave. Roger
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.