Can't stop process - filename changes

G

Guest

I have found that I have a process running that tries to add itself to the
registry. I'm not sure what is starting the process but I cannot stop it.
I can go to the task manager and the process will be listed with a filename
like 'lzwmqmi.exe'. I can end the process, but immediately another process
begins with a different odd looking name (ijaqabyvzvh.exe). I have seen about
10-12 diferent names used and some duplicates.
I can open Windows Explorer, go to the windows/system32 folder and see the
file name listed before stopping the process. I cannot delete the file
because it is in use. If I stop the process in task manager, the file leaves
the windows/system32 folder and the new filename appears as the new process
begins in task manager.
Some process must be running that is not only starting but creating these
odd named "exe' files, but I can't determine what it is. I am running the
Spybot Search & Destroy feature that alerts you when a task is trying to
change the registry. The alerts from Spybot Search & Destroy is how I
discovered these programs where running.
I have run virus scan on the drive with no problems found. I have run both
Spybot Search & Destroy and Ad-Aware and the processes continue.
Any help?
 
A

Abe Coates

I have found that I have a process running that tries to add itself to the
registry. I'm not sure what is starting the process but I cannot stop it.
I can go to the task manager and the process will be listed with a filename
like 'lzwmqmi.exe'. I can end the process, but immediately another process
begins with a different odd looking name (ijaqabyvzvh.exe). I have seen about
10-12 diferent names used and some duplicates.
I can open Windows Explorer, go to the windows/system32 folder and see the
file name listed before stopping the process. I cannot delete the file
because it is in use. If I stop the process in task manager, the file leaves
the windows/system32 folder and the new filename appears as the new process
begins in task manager.
Some process must be running that is not only starting but creating these
odd named "exe' files, but I can't determine what it is. I am running the
Spybot Search & Destroy feature that alerts you when a task is trying to
change the registry. The alerts from Spybot Search & Destroy is how I
discovered these programs where running.
I have run virus scan on the drive with no problems found. I have run both
Spybot Search & Destroy and Ad-Aware and the processes continue.
Any help?

When you ran these programs did you disable system restore and then re enable it after reboot? Sometime these files are
placed in system restore and they cannot be deleted unless system restore is turned off. Hope this helps.
 
D

Dean Walker

I have system restore disabled...

Abe Coates said:
When you ran these programs did you disable system restore and then re
enable it after reboot? Sometime these files are
placed in system restore and they cannot be deleted unless system restore
is turned off. Hope this helps.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top