Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

.exe infected


  • Please log in to reply
3 replies to this topic

#1 simpson_miller

simpson_miller

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Local time:01:53 PM

Posted 14 May 2010 - 12:48 PM

Hi,

I have seen on several of my client's computers that there were exe files been replaced with infections on same name and running instead.
For eg:
lets say Adobe file: Acrord32.exe is infected. There will be another file with the same name but different icon. The original files will have space in between the .exe; say Acrord32 .exe. The file active running on the computer will be the infected one.
I have tried to remove them but was not able to as they are recreating. I have tried Combofix on this, but found that infection replaces combofix when I try to run it. Can any one help me on this?
Simpson

BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,490 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:02:53 PM

Posted 14 May 2010 - 02:25 PM

Hello Simpson.
We need a deeper look. Please go here....
Preparation Guide ,do steps 6 - 9.

Create a DDS log and post it in the new topic explained in step 9,which is here Virus, Trojan, Spyware, and

Malware Removal Logs
and not in this topic,thanks.
If Gmer won't run,skip it and move on.
Let me know if that went well.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 simpson_miller

simpson_miller
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Local time:01:53 PM

Posted 16 May 2010 - 08:27 AM

Hi,

Thanks for your quick response.

As of now I have no computers with that infections; I have reinstalled the OS on those which I found the infection. But I certainly would request you to give me time. I will do the steps and will paste the log, the moment I get one.
Simpson

#4 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,490 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:02:53 PM

Posted 16 May 2010 - 08:58 AM

We will keep this open if you need it.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users