winycm32.exe

  • Thread starter Thread starter Guest
  • Start date Start date
G

Guest

I have no clue what this file does, but i keep getting this -- "winycm32.exe
has encountered a problem and needs to close." every time i say ok, my comp
goes blue screen and does a physical memory dump. I can't for the life of me
figure out how to fix it, any suggestions?
 
If that is the correct spelling, dunno! Either way, start here:

Run Ad-Aware SE, Spybot and HijackThis:
http://www.majorgeeks.com/downloads31.html

Note: Update each program, once installed, before running.

Note2: To avoid the False-Flag for the DSO Exploit (W3), open
Spybot/Advanced Mode/Settings/Ignore Products. On the All Products Tab,
scrol to DSO Exploit and check that item only. Randy (silj)

Free Online Virus Scan
http://housecall.trendmicro.com/housecall/start_corp.asp

--
All the Best,
Kelly (MS-MVP)

Troubleshooting Windows XP
http://www.kellys-korner-xp.com
 
BCordrey said:
I have no clue what this file does, but i keep getting this --
"winycm32.exe has encountered a problem and needs to close." every
time i say ok, my comp goes blue screen and does a physical memory
dump. I can't for the life of me figure out how to fix it, any
suggestions?

Because a Google for "winycm32.exe" didn't bring up any hits, it is most
probably malware. Run through the following steps, making sure all
scans are done in Safe Mode. Links follows the steps:

1) Scan in Safe Mode with current version (not earlier than 2003)
antivirus using updated definitions.

2) Remove spyware with Spybot Search & Destroy and Ad-aware. These
programs are free, so use them both since they complement each other.
There is a new version of CWShredder from Intermute. I would not
install the other Intermute programs, however. Alternately, there are
CoolWebSearch malware removal steps at SilentRunners.

Be sure to update these programs before running, and it is a good idea
to do virus/spyware scans in Safe Mode. Make sure you are able to see
all hidden files and extensions (View tab in Folder Options).

HijackThis is an excellent tool to discover and disable hijackers, but
it requires expert skill. See below for HijackThis links. A combination
of HijackThis and About:Buster works well in removing the About:Blank
homepage hijacker. Again, this is an expert tool and novices should get
help with it.

3) If you are running Windows ME or XP, you should disable/enable System
Restore because malware will be in the Restore Points. With ME, you
must disable System Restore completely. With XP, you can delete all but
the most recent (presumably clean) System Restore point from the More
Options section of Disk Cleanup (Run>cleanmgr).

4) Make sure you've visited Windows Update and applied all security
patches. Do not install driver updates from Windows Update.

5) Run a firewall.

Links to help with malware:

Software/Methods:
http://www.safer-networking.org - Spybot Search & Destroy
http://www.lavasoftusa.com - Ad-aware
http://www.majorgeeks.com - good download site
http://www.intermute.com/spysubtract/cwshredder_download.html
http://www.silentrunners.org/sr_cwsremoval.html. - SilentRunners

HijackThis:
http://www.aumha.org/a/hjttutor.htm - HijackThis tutorial by Jim
Eshelman
http://spywarewarrior.com/viewforum.php?f=5 - Spyware Warrior HijackThis
forum
http://www.lavasoftsupport.com/index.php?showforum=44
http://www.wilderssecurity.com/
http://forums.tomcoyote.org/
http://www.spywareinfo.com/forums/

General:
http://www.doxdesk.com/parasite/
http://mvps.org/winhelp2002/unwanted.htm
http://forum.aumha.org/ - look under "Security" for various forums
http://www.pchell.com/
http://www.spywareguide.com/index.php
http://scumware.com/
http://www.aumha.org/a/parasite.htm - The Parasite Fight
http://www.spywarewarrior.com/rogue_anti-spyware.htm
http://rgharper.mvps.org/cleanit.htm

Malke
 
Hi,

It's a trojan (virus) file. Follow these "relatively" simple removal steps:

Restart in Safe mode by hitting F8 as Windows first begins to load on boot.
Logon as administrator. As this can be tricky, you will find help in doing
this here:
http://www.rickrogers.org/fixes.htm#Safe mode

Start/search/files and folders, look for <filename> and delete it wherever
it is found.

Start/run regedit, expand the + signs to look under these keys:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg

Look in the right hand pane for the string or strings that load that file.
Delete just those strings that contain the reference. Do not delete other
strings or the keys from the left pane. Close the registry editor when
completed, make sure you check all strings.

Go to the Control Panel/System/System Restore tab. Check the box to "Turn
off system restore on all drives". Click apply/ok. This will remove all
restore points, however you don't want them back as some or all of them will
contain the virus depending upon how recently you got infected.

Restart the system normally. Go back to the Control Panel/System and restart
System Restore.

Update your antivirus software, run a full system scan.

--
Best of Luck,

Rick Rogers, aka "Nutcase" - Microsoft MVP

Associate Expert - WindowsXP Expert Zone

Windows help - www.rickrogers.org
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads

blue screen 4
Blue Screen Error 0x0000008E 1
memory dump 6
problem with Windows XP 1
invalid_worke_queue_item 1
problem 2
viscious crash cycle 19
Error on friend's computer while trying to uninstall Intel Applica 1

Back
Top