PC Review


Reply
Thread Tools Rate Thread

can't get rid of file

 
 
Huwy
Guest
Posts: n/a
 
      22nd Jun 2009
Hi,

I've a problem on my windows xp PC where there is a file
(c:\windows\system32\twex.exe) that just won't be deleted. I have tried
various:-
- I suspect it's malware as it's loaded at startup - I've tried to use
hijackthis to remove the startup link but it keeps returning at reboot.
- Anti-virus won't scan it - reports permissions denied.
- I can't take ownership of the file (despite being an administrator)
- I've tried booting in safe mode - still can't remove it.
- I've also tried booting of a boot CD (bart) but this just bluescreens the
PC. I think that may be because it doesn't like sata disks?

Can anyone recommend how I can delete this bl**dy file?

-H


 
Reply With Quote
 
 
 
 
Gerry
Guest
Posts: n/a
 
      22nd Jun 2009

Huwy

Something like Malwarebytes might be worth a try.

Malwarebytes' Anti-Malware
1.37 -freeware (if you upgrade you pay).
http://www.download.com/Malwarebytes...-10804572.html

Run Malwarebytes' and turn off your current anti-virus
before you do to avoid a conflict. Disregard the invitation on the web
site regarding the Registry Optimiser -a Registry Optimiser is not a
helpful utility.

--


Hope this helps.

Gerry
~~~~
FCA
Stourport, England
Enquire, plan and execute
~~~~~~~~~~~~~~~~~~~



Huwy wrote:
> Hi,
>
> I've a problem on my windows xp PC where there is a file
> (c:\windows\system32\twex.exe) that just won't be deleted. I have
> tried various:-
> - I suspect it's malware as it's loaded at startup - I've tried to use
> hijackthis to remove the startup link but it keeps returning at
> reboot. - Anti-virus won't scan it - reports permissions denied.
> - I can't take ownership of the file (despite being an administrator)
> - I've tried booting in safe mode - still can't remove it.
> - I've also tried booting of a boot CD (bart) but this just
> bluescreens the PC. I think that may be because it doesn't like sata
> disks?
> Can anyone recommend how I can delete this bl**dy file?
>
> -H


 
Reply With Quote
 
Roy
Guest
Posts: n/a
 
      22nd Jun 2009
On Jun 22, 5:46*pm, "Gerry" <ge...@nospam.com> wrote:
> Huwy
>
> Something like Malwarebytes might be worth a try.
>
> Malwarebytes' Anti-Malware
> 1.37 -freeware (if you upgrade you pay).http://www.download.com/Malwarebytes...8022_4-1080457...
>
> Run Malwarebytes' and turn off your current anti-virus
> before you do to avoid a conflict. Disregard the invitation on the web
> site regarding the Registry Optimiser -a Registry Optimiser is not a
> helpful utility.
>
> --
>
> Hope *this helps.
>
> Gerry
> *~~~~
> FCA
> Stourport, England
> Enquire, plan and execute
> ~~~~~~~~~~~~~~~~~~~
>
>
>
> Huwy wrote:
> > Hi,

>
> > I've a problem on my windows xp PC where there is a file
> > (c:\windows\system32\twex.exe) that just won't be deleted. I have
> > tried various:-
> > - I suspect it's malware as it's loaded at startup - I've tried to use
> > hijackthis to remove the startup link but it keeps returning at
> > reboot. - Anti-virus won't scan it - reports permissions denied.
> > - I can't take ownership of the file (despite being an administrator)
> > - I've tried booting in safe mode - still can't remove it.
> > - I've also tried booting of a boot CD (bart) but this just
> > bluescreens the PC. I think that may be because it doesn't like sata
> > disks?
> > Can anyone recommend how I can delete this bl**dy file?

>
> > -H- Hide quoted text -

>
> - Show quoted text -


Have you tried unlocker?
 
Reply With Quote
 
David H. Lipman
Guest
Posts: n/a
 
      22nd Jun 2009
From: "Gerry" <(E-Mail Removed)>


| Huwy

| Something like Malwarebytes might be worth a try.

| Malwarebytes' Anti-Malware
| 1.37 -freeware (if you upgrade you pay).
| http://www.download.com/Malwarebytes...-10804572.html

| Run Malwarebytes' and turn off your current anti-virus
| before you do to avoid a conflict. Disregard the invitation on the web
| site regarding the Registry Optimiser -a Registry Optimiser is not a
| helpful utility.

| --


It is malware and MBAM is at v1.38.


--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


 
Reply With Quote
 
Gerry
Guest
Posts: n/a
 
      22nd Jun 2009
David

I will update the version im my next post. Thanks for pointing this out.


--


Gerry
~~~~
FCA
Stourport, England
Enquire, plan and execute
~~~~~~~~~~~~~~~~~~~


David H. Lipman wrote:
> From: "Gerry" <(E-Mail Removed)>
>
>
>> Huwy

>
>> Something like Malwarebytes might be worth a try.

>
>> Malwarebytes' Anti-Malware
>> 1.37 -freeware (if you upgrade you pay).
>> http://www.download.com/Malwarebytes...-10804572.html

>
>> Run Malwarebytes' and turn off your current anti-virus
>> before you do to avoid a conflict. Disregard the invitation on the
>> web site regarding the Registry Optimiser -a Registry Optimiser is
>> not a helpful utility.

>
>> --

>
>
> It is malware and MBAM is at v1.38.


 
Reply With Quote
 
Huwy
Guest
Posts: n/a
 
      22nd Jun 2009
Thanks guys. I'll try malwarebytes.



"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:(E-Mail Removed)...
> From: "Gerry" <(E-Mail Removed)>
>
>
> | Huwy
>
> | Something like Malwarebytes might be worth a try.
>
> | Malwarebytes' Anti-Malware
> | 1.37 -freeware (if you upgrade you pay).
> |
> http://www.download.com/Malwarebytes...-10804572.html
>
> | Run Malwarebytes' and turn off your current anti-virus
> | before you do to avoid a conflict. Disregard the invitation on the web
> | site regarding the Registry Optimiser -a Registry Optimiser is not a
> | helpful utility.
>
> | --
>
>
> It is malware and MBAM is at v1.38.
>
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
>
>



 
Reply With Quote
 
Gerry
Guest
Posts: n/a
 
      22nd Jun 2009

Huwy

We'll be sitting on the edge of our seats waiting on your further report
<G>.

--


Gerry
~~~~
FCA
Stourport, England
Enquire, plan and execute
~~~~~~~~~~~~~~~~~~~


Huwy wrote:
> Thanks guys. I'll try malwarebytes.
>
>
>
> "David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
> news:(E-Mail Removed)...
>> From: "Gerry" <(E-Mail Removed)>
>>
>>
>>> Huwy

>>
>>> Something like Malwarebytes might be worth a try.

>>
>>> Malwarebytes' Anti-Malware
>>> 1.37 -freeware (if you upgrade you pay).
>>>

>> http://www.download.com/Malwarebytes...-10804572.html
>>
>>> Run Malwarebytes' and turn off your current anti-virus
>>> before you do to avoid a conflict. Disregard the invitation on the
>>> web site regarding the Registry Optimiser -a Registry Optimiser is
>>> not a helpful utility.

>>
>>> --

>>
>>
>> It is malware and MBAM is at v1.38.
>>
>>
>> --
>> Dave
>> http://www.claymania.com/removal-trojan-adware.html
>> Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


 
Reply With Quote
 
Newman
Guest
Posts: n/a
 
      22nd Jun 2009
Unlocker *rocks*.

On Mon, 22 Jun 2009 03:28:18 -0700 (PDT), Roy <(E-Mail Removed)>
wrote:

>On Jun 22, 5:46*pm, "Gerry" <ge...@nospam.com> wrote:
>> Huwy
>>
>> Something like Malwarebytes might be worth a try.
>>
>> Malwarebytes' Anti-Malware
>> 1.37 -freeware (if you upgrade you pay).http://www.download.com/Malwarebytes...8022_4-1080457...
>>
>> Run Malwarebytes' and turn off your current anti-virus
>> before you do to avoid a conflict. Disregard the invitation on the web
>> site regarding the Registry Optimiser -a Registry Optimiser is not a
>> helpful utility.
>>
>> --
>>
>> Hope *this helps.
>>
>> Gerry
>> *~~~~
>> FCA
>> Stourport, England
>> Enquire, plan and execute
>> ~~~~~~~~~~~~~~~~~~~
>>
>>
>>
>> Huwy wrote:
>> > Hi,

>>
>> > I've a problem on my windows xp PC where there is a file
>> > (c:\windows\system32\twex.exe) that just won't be deleted. I have
>> > tried various:-
>> > - I suspect it's malware as it's loaded at startup - I've tried to use
>> > hijackthis to remove the startup link but it keeps returning at
>> > reboot. - Anti-virus won't scan it - reports permissions denied.
>> > - I can't take ownership of the file (despite being an administrator)
>> > - I've tried booting in safe mode - still can't remove it.
>> > - I've also tried booting of a boot CD (bart) but this just
>> > bluescreens the PC. I think that may be because it doesn't like sata
>> > disks?
>> > Can anyone recommend how I can delete this bl**dy file?

>>
>> > -H- Hide quoted text -

>>
>> - Show quoted text -

>
>Have you tried unlocker?


 
Reply With Quote
 
HeyBub
Guest
Posts: n/a
 
      22nd Jun 2009
Huwy wrote:
> Hi,
>
> I've a problem on my windows xp PC where there is a file
> (c:\windows\system32\twex.exe) that just won't be deleted. I have
> tried various:-
> - I suspect it's malware as it's loaded at startup - I've tried to use
> hijackthis to remove the startup link but it keeps returning at
> reboot. - Anti-virus won't scan it - reports permissions denied.
> - I can't take ownership of the file (despite being an administrator)
> - I've tried booting in safe mode - still can't remove it.
> - I've also tried booting of a boot CD (bart) but this just
> bluescreens the PC. I think that may be because it doesn't like sata
> disks?
> Can anyone recommend how I can delete this bl**dy file?
>


This is a double-nasty:

"Threat characteristics of ZBot - a banking trojan that disables firewall,
steals sensitive financial data (credit card numbers, online banking login
details), makes screen snapshots, downloads additional components, and
provides a hacker with the remote access to the compromised system.

"Creates a startup registry entry."

Also it rootkits your system and enrolls you in the American Nazi Party.

See:
http://www.threatexpert.com/report.a...d4b1f6903dafaf


 
Reply With Quote
 
Elmo
Guest
Posts: n/a
 
      23rd Jun 2009
Huwy wrote:
> Hi,
>
> I've a problem on my windows xp PC where there is a file
> (c:\windows\system32\twex.exe) that just won't be deleted. I have tried
> various:-
> - I suspect it's malware as it's loaded at startup - I've tried to use
> hijackthis to remove the startup link but it keeps returning at reboot.
> - Anti-virus won't scan it - reports permissions denied.
> - I can't take ownership of the file (despite being an administrator)
> - I've tried booting in safe mode - still can't remove it.
> - I've also tried booting of a boot CD (bart) but this just bluescreens the
> PC. I think that may be because it doesn't like sata disks?
>
> Can anyone recommend how I can delete this bl**dy file?


If Malwarebytes doesn't work, try this:

Burn BitDefender Rescue to a CD (using a working machine) and test the
infected machine with it:

http://www.techmixer.com/free-bootab...download-list/

Then run Malwarebytes again.

--
Joe =o)
 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
File sort order reversed or wrong in File Open or File Save dialog box NinerSevenTango Windows XP General 1 1st Aug 2009 01:48 PM
coping file from a remote file share - FILE IS NO LONG THERE bogus error message Heith Windows Vista Networking 0 18th Oct 2007 09:58 PM
In file parsing, taking the first few characters of a text file after a readfile or streamreader file read... .Net Sports Microsoft ASP .NET 11 17th Jan 2006 12:44 AM
An Automated process of watching a network file folder, reading a file in it and deleting the file using ASP.NET ? Luis Esteban Valencia Muņoz Microsoft ASP .NET 3 4th Jun 2005 11:56 AM
i received a file that reads powerpoint document file file exten. =?Utf-8?B?Q0NBUk9MQUNFUkVD?= Microsoft Excel Misc 1 4th Dec 2004 05:02 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 02:10 PM.