T
Tommies
Here is the info from Windows Defender:
and result from command "dir t*" in C:\windows\system32
more mysterious is the questioned file (twex.exe) is no where to see inside
window explorer, even window search comes up empty. But I do know that it
exist some where (alphabetically) between TsWpfWrp.exe and twext.dll
I update MRT (MS Malicious Software Remove Tool) today, but the scan results
is negative.
I have to use Recovery Console to remove it
Any idea???
Summary:
Auto Start change occurred.
This agent monitors the various mechanisms that software can use to
automatically start when you log on to Windows. Programs that auto start can
affect system performance and start without your knowledge.
Path:
C:\WINDOWS\system32\twex.exe
Detected changes:
winlogonuserinit:
HKLM\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\\Userinit:C:\WINDOWS\system32\twex.exe
file:
C:\WINDOWS\system32\twex.exe
Advice:
Permit this detected item only if you trust the program or the software
publisher.
Publisher:
Not available
Digitally Signed By:
NOT SIGNED
Product name:
Not available
Description:
Not available
Original name:
Not available
Creation date:
8/23/2001 8:00 AM
Size:
223744 bytes
Version:
Not available
Type:
file type unknown
Checkpoint:
Winlogon Userinit
Category:
Not Yet Classified
and result from command "dir t*" in C:\windows\system32
However when i do "dir twex.exe" it result in "file not found", and evenVolume in drive C has no label.
Volume Serial Number is ECE0-0CDE
Directory of C:\WINDOWS\system32
04/13/2008 08:12 PM 117,760 t2embed.dll
08/23/2001 08:00 AM 19,200 tapi.dll
04/13/2008 08:12 PM 858,624 tapi3.dll
04/13/2008 08:12 PM 181,760 tapi32.dll
08/23/2001 08:00 AM 5,632 tapiperf.dll
04/13/2008 08:12 PM 249,856 tapisrv.dll
08/23/2001 08:00 AM 78,848 tapiui.dll
04/13/2008 08:12 PM 76,288 taskkill.exe
04/13/2008 08:12 PM 77,824 tasklist.exe
08/23/2001 08:00 AM 15,360 taskman.exe
04/13/2008 08:12 PM 135,680 taskmgr.exe
08/23/2001 08:00 AM 12,288 tcmsetup.exe
04/13/2008 08:12 PM 14,848 tcpmib.dll
04/13/2008 08:12 PM 45,568 tcpmon.dll
07/17/2004 02:46 PM 53,478 tcpmon.ini
04/13/2008 08:12 PM 45,568 tcpmonui.dll
08/23/2001 08:00 AM 19,456 tcpsvcs.exe
08/13/2007 07:32 PM 66,560 tdc.ocx
08/23/2001 08:00 AM 28,160 telephon.cpl
04/13/2008 08:12 PM 75,776 telnet.exe
08/23/2001 08:00 AM 862 termcap
04/13/2008 08:12 PM 358,400 termmgr.dll
04/13/2008 08:12 PM 295,424 termsrv.dll
08/23/2001 08:00 AM 16,896 tftp.exe
04/13/2008 08:12 PM 385,536 themeui.dll
09/01/2006 09:44 AM 1,988 ticrf.rat
04/13/2008 08:12 PM 94,208 timedate.cpl
08/23/2001 08:00 AM 4,048 timer.drv
04/13/2008 08:12 PM 61,440 tlntadmn.exe
04/13/2008 08:12 PM 78,336 tlntsess.exe
04/13/2008 08:12 PM 73,216 tlntsvr.exe
04/13/2008 08:12 PM 7,168 tlntsvrp.dll
08/23/2001 08:00 AM 13,888 toolhelp.dll
04/13/2008 08:12 PM 347,136 tourstart.exe
05/26/2008 11:21 PM 1,582,592 tquery.dll
05/26/2008 11:17 PM 221,184 tquery.dll.mui
04/13/2008 08:12 PM 259,584 tracerpt.exe
04/13/2008 08:12 PM 12,288 tracert.exe
08/23/2001 08:00 AM 31,744 tracert6.exe
08/23/2001 08:00 AM 31,232 traffic.dll
04/13/2008 08:12 PM 12,800 tree.com
04/13/2008 08:12 PM 90,112 trkwks.dll
08/23/2001 08:00 AM 52,224 tsappcmp.dll
08/23/2001 08:00 AM 8,192 tsbyuv.dll
04/13/2008 08:12 PM 93,696 tscfgwmi.dll
08/23/2001 08:00 AM 14,848 tscon.exe
08/04/2004 01:59 AM 44,544 tscupgrd.exe
08/23/2001 08:00 AM 15,360 tsd32.dll
04/13/2008 08:13 PM 12,168 tsddd.dll
08/23/2001 08:00 AM 14,848 tsdiscon.exe
04/13/2008 08:12 PM 53,248 tsgqec.dll
08/23/2001 08:00 AM 16,384 tskill.exe
08/23/2001 08:00 AM 3,286 tslabels.h
08/23/2001 08:00 AM 13,223 tslabels.ini
04/13/2008 08:12 PM 50,688 tspkg.dll
08/23/2001 08:00 AM 16,896 tsshutdn.exe
08/23/2001 08:00 AM 8,192 tssoft32.acm
07/29/2008 10:10 PM 26,112 TsWpfWrp.exe
04/13/2008 08:11 PM 223,744 twex.exe
04/13/2008 08:12 PM 57,856 twext.dll
04/13/2008 08:12 PM 101,376 txflog.dll
08/23/2001 08:00 AM 177,856 typelib.dll
08/23/2001 08:00 AM 36,352 typeperf.exe
10/23/2008 06:06 AM 62,976 tzchange.exe
12/12/2008 09:47 PM 838,618 TZLog.log
65 File(s) 8,101,303 bytes
0 Dir(s) 11,429,130,240 bytes free
more mysterious is the questioned file (twex.exe) is no where to see inside
window explorer, even window search comes up empty. But I do know that it
exist some where (alphabetically) between TsWpfWrp.exe and twext.dll
I update MRT (MS Malicious Software Remove Tool) today, but the scan results
is negative.
I have to use Recovery Console to remove it
Any idea???