1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

System32.exe

Discussion in 'Malware and Virus Removal Archive' started by GaryMaton, 2003/04/26.

Thread Status:
Not open for further replies.
  1. 2003/04/26
    GaryMaton

    GaryMaton Inactive Thread Starter

    Joined:
    2003/04/25
    Messages:
    93
    Likes Received:
    0
    System32.exe was infeted with a virus, I need to replace it but don't have the disk... Any ideas?

    Its for XP Home

    Thank you
     
  2. 2003/04/26
    Abraxas

    Abraxas Inactive

    Joined:
    2002/08/16
    Messages:
    2,361
    Likes Received:
    3

  3. to hide this advert.

  4. 2003/04/26
    GaryMaton

    GaryMaton Inactive Thread Starter

    Joined:
    2003/04/25
    Messages:
    93
    Likes Received:
    0
    Thank you

    I need somewhere to download the file though... I have removed the virus (W32.pinfi) fully... I just want to get my PC running as it was!

    Thank you anyway!

    Ps. Can anyone send me a genuine copy of there system32.exe (running of XP Home please?)
     
  5. 2003/04/26
    Abraxas

    Abraxas Inactive

    Joined:
    2002/08/16
    Messages:
    2,361
    Likes Received:
    3
    There is no system32.exe in XP. That is the virus. What makes you think you need the file? Is there a message appearing?
     
  6. 2003/04/26
    GaryMaton

    GaryMaton Inactive Thread Starter

    Joined:
    2003/04/25
    Messages:
    93
    Likes Received:
    0
    Yes, saying that system32.exe could not be found! It apprears as I log on! Can you help please?
     
  7. 2003/04/26
    Abraxas

    Abraxas Inactive

    Joined:
    2002/08/16
    Messages:
    2,361
    Likes Received:
    3
    OK. It's looking for the old virus file.

    Download and install this Startup Control Panel.

    http://www.mlin.net/files/StartupCPL.zip

    Then, go to your Control Panel and you will see an applet called "Startup ". Look through the entries until you find system32.exe and remove it from startup.
     
  8. 2003/04/26
    GaryMaton

    GaryMaton Inactive Thread Starter

    Joined:
    2003/04/25
    Messages:
    93
    Likes Received:
    0
    System32.exe doesn't apear in that program...

    Any ideas?
     
  9. 2003/04/26
    Abraxas

    Abraxas Inactive

    Joined:
    2002/08/16
    Messages:
    2,361
    Likes Received:
    3
    Strange. Try going to Strat > Run and typing: msconfig

    Chances are you'll see the same startups, but worth a try. If there, you can uncheck it.

    You should also check the registry. Start > Run: regedt32
    Navigate to:

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer

    and look for an entry: PINF

    Delete it.

    Empty all your temporary files under Documents and Settings\<username>\Local Settings\Temp

    (If this is not visible, you need to unhide hidden folders in Control Panel, Folder Options, View tab.)

    Then, right-click My Computer, Properties, System Restore tab. Turn off SR on all drives to delete all SR files that may contain the virus, restart and turn SR back on.
     
    Last edited: 2003/04/26
  10. 2003/04/26
    GaryMaton

    GaryMaton Inactive Thread Starter

    Joined:
    2003/04/25
    Messages:
    93
    Likes Received:
    0
    no sorry, I've already tried that... how sure are u XP doesnt use system32.exe
     
  11. 2003/04/26
    Abraxas

    Abraxas Inactive

    Joined:
    2002/08/16
    Messages:
    2,361
    Likes Received:
    3
    Very sure. Please look at my edit above and remove the entry from mthe registry.
     
  12. 2003/04/26
    GaryMaton

    GaryMaton Inactive Thread Starter

    Joined:
    2003/04/25
    Messages:
    93
    Likes Received:
    0
    Yeah, that is all done!

    Message is still poping up!

    Thats how I got rid of the virus! The virus is 100% gone! There is no problem with that! It is just calling "system32.exe" from somewhere that I can't find.

    Thank you for your help so far
     
  13. 2003/04/26
    Abraxas

    Abraxas Inactive

    Joined:
    2002/08/16
    Messages:
    2,361
    Likes Received:
    3
    See what is running in Task Manager that looks like this (or any temp file, for that matter). Check under the applications tab, too:

    [3 random letters][4 random hexadecimal digits].tmp

    If there is such a process, terminate it and empty your temp folder again, including Windows\Temp.

    Look for entries for cmd32.exe, too. This isn't a Windows file, either.
     
    Last edited: 2003/04/26
  14. 2003/04/26
    GaryMaton

    GaryMaton Inactive Thread Starter

    Joined:
    2003/04/25
    Messages:
    93
    Likes Received:
    0
    I have done all this still it pops up.. should I just give up?
     
  15. 2003/04/26
    BruceKrymow

    BruceKrymow Inactive

    Joined:
    2002/03/20
    Messages:
    548
    Likes Received:
    0
    Have you checked these 4 keys?
    • HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ Run
    • HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Run
    • HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ RunOnce
    • HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ RunOnce
     
  16. 2003/04/26
    Abraxas

    Abraxas Inactive

    Joined:
    2002/08/16
    Messages:
    2,361
    Likes Received:
    3
    That's up to you. Can you list your startups so we can take a look at them?

    You may want to run the scan again to be sure you aren't reinfected and check the startups again, including

    HKEY_CURRENT_USER>Software>Microsoft>Windows>
    CurrentVersion>Runonce

    HKEY_LOCAL_MACHINE>Software>Microsoft>Windows>
    CurrentVersion>RunServices

    HKEY_USERS>.DEFAULT>Software>Microsoft>Windows>
    CurrentVersion>Runonce

    Look for cmd32.exe as well, since that is not an XP file, either.
     
  17. 2003/04/26
    BruceKrymow

    BruceKrymow Inactive

    Joined:
    2002/03/20
    Messages:
    548
    Likes Received:
    0
    Gary ~

    Also, delete the items in your C:\WINDOWS\Downloaded Program Files. Reboot.

    If you still get the pop-up, then run StartupList and post the results back here.
     
  18. 2003/04/26
    GaryMaton

    GaryMaton Inactive Thread Starter

    Joined:
    2003/04/25
    Messages:
    93
    Likes Received:
    0
    Yeah, thanx, all clear!

    Any other ideas? This is really annoying
     
  19. 2003/04/26
    BruceKrymow

    BruceKrymow Inactive

    Joined:
    2002/03/20
    Messages:
    548
    Likes Received:
    0
    Gary ~

    Post you your results now please with StartupList.
     
  20. 2003/04/26
    GaryMaton

    GaryMaton Inactive Thread Starter

    Joined:
    2003/04/25
    Messages:
    93
    Likes Received:
    0
  21. 2003/04/26
    BruceKrymow

    BruceKrymow Inactive

    Joined:
    2002/03/20
    Messages:
    548
    Likes Received:
    0
    Gary ~

    We don't want the pop-up. Click on the link above that says "StartupList ", download it, run it, and post the results here, please.
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.