G

Guest

Guest
Archived from groups: microsoft.public.windowsxp.security_admin (More info?)

I have recently loaded a computer on a network and updated it to sp2.

A new task item appears called windexv1.exe.

There are several registry entries and the file is supposed to be in the
windows\system32 folder.

I can't find any info on the net about this file nor is it signed.

Any help here on what it is?

Rob

P.S. I spent $245 on a call to MS but couldn't communicate with the non-US
person on the other end of the phone and was disconnected with no
resolution.
 
G

Guest

Guest
Archived from groups: microsoft.public.windowsxp.security_admin (More info?)

"Rob Bergstrom" <nospam@backatcha.com> wrote in message
news:OxI04SERFHA.248@TK2MSFTNGP15.phx.gbl
| I have recently loaded a computer on a network and updated it to sp2.
|
| A new task item appears called windexv1.exe.
|
| There are several registry entries and the file is supposed to be in the
| windows\system32 folder.
|
| I can't find any info on the net about this file nor is it signed.
|
| Any help here on what it is?
|
| Rob
|
| P.S. I spent $245 on a call to MS but couldn't communicate with the non-US
| person on the other end of the phone and was disconnected with no
| resolution.

Please submit "windexv1.exe" to Virus Total --
http://www.virustotal.com/flash/index_en.html
The submission will then be tested against several different AV vendor's scanners.

Another way to submit is to send the suspect file to the following email address
scan<at>virustotal.com
{ replace <at> with @ } with only the word SCAN as the subject.

Please post back the EXACT results.


Dump the contents of the IE Temporary Internet Folder cache (TIF)

Start --> Settings --> Control Panel --> Internet Options --> Delete Files


Dump the contents of the Mozilla FireFox Cache

Tools --> Options --> Privacy --> Cache --> Clear


1) Download TrendMicro Sysclean by one of the following 2 methods

Trend Sysclean Method 1
---------------------------------------
Trend Sysclean Package
http://www.trendmicro.com/download/dcs.asp

Latest Trend signature files.
http://www.trendmicro.com/download/pattern.asp

Create a directory.
On drive "C:\"
(e.g., "c:\sysclean")

Download SYSCLEAN.COM and place it in that directory.
Download the signature files (pattern files) by obtaining the ZIP file.
For example; lpt580.zip

Extract the contents of the ZIP file and place the contents in the same directory as
SYSCLEAN.COM.

Trend Sysclean Method 2
---------------------------------------
Download the utility SYSCLEAN_FE at the following URL --
http://www.ik-cs.com/got-a-virus.htm
SYSCLEAN_FE automates the download and execution process of the Trend Sysclean Package.
Direct URL --
http://www.ik-cs.com/programs/virtools/Sysclean_FE.exe

2) Download Ad-aware SE (free personal version v1.05)
http://www.lavasoftusa.com/

Update Ad-aware with the latest definitions.
3) Reboot your PC into Safe Mode and shutdown as many applications as possible.
4) Using both the Trend Sysclean utility and Ad-aware, perform a Full Scan of your
platform and clean/delete any infectors/parasites found.
(a few cycles may be needed)
5) Restart your PC and perform a "final" Full Scan of your platform using both the
Trend Sysclean utility and Adaware

* * * Please report back your results * * *


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm