Huwy wrote:
> Hi,
>
> I've a problem on my windows xp PC where there is a file
> (c:\windows\system32\twex.exe) that just won't be deleted. I have
> tried various:-
> - I suspect it's malware as it's loaded at startup - I've tried to use
> hijackthis to remove the startup link but it keeps returning at
> reboot. - Anti-virus won't scan it - reports permissions denied.
> - I can't take ownership of the file (despite being an administrator)
> - I've tried booting in safe mode - still can't remove it.
> - I've also tried booting of a boot CD (bart) but this just
> bluescreens the PC. I think that may be because it doesn't like sata
> disks?
> Can anyone recommend how I can delete this bl**dy file?
>
This is a double-nasty:
"Threat characteristics of ZBot - a banking trojan that disables firewall,
steals sensitive financial data (credit card numbers, online banking login
details), makes screen snapshots, downloads additional components, and
provides a hacker with the remote access to the compromised system.
"Creates a startup registry entry."
Also it rootkits your system and enrolls you in the American Nazi Party.
See:
http://www.threatexpert.com/report.a...d4b1f6903dafaf