Archived from groups: microsoft.public.windowsxp.security_admin (
More info?)
"Rob Bergstrom" <nospam@backatcha.com> wrote in message
news:OxI04SERFHA.248@TK2MSFTNGP15.phx.gbl
| I have recently loaded a computer on a network and updated it to sp2.
|
| A new task item appears called windexv1.exe.
|
| There are several registry entries and the file is supposed to be in the
| windows\system32 folder.
|
| I can't find any info on the net about this file nor is it signed.
|
| Any help here on what it is?
|
| Rob
|
| P.S. I spent $245 on a call to MS but couldn't communicate with the non-US
| person on the other end of the phone and was disconnected with no
| resolution.
Please submit "windexv1.exe" to Virus Total --
http://www.virustotal.com/flash/index_en.html
The submission will then be tested against several different AV vendor's scanners.
Another way to submit is to send the suspect file to the following email address
scan<at>virustotal.com
{ replace <at> with @ } with only the word SCAN as the subject.
Please post back the EXACT results.
Dump the contents of the IE Temporary Internet Folder cache (TIF)
Start --> Settings --> Control Panel --> Internet Options --> Delete Files
Dump the contents of the Mozilla FireFox Cache
Tools --> Options --> Privacy --> Cache --> Clear
1) Download TrendMicro Sysclean by one of the following 2 methods
Trend Sysclean Method 1
---------------------------------------
Trend Sysclean Package
http://www.trendmicro.com/download/dcs.asp
Latest Trend signature files.
http://www.trendmicro.com/download/pattern.asp
Create a directory.
On drive "C:\"
(e.g., "c:\sysclean")
Download SYSCLEAN.COM and place it in that directory.
Download the signature files (pattern files) by obtaining the ZIP file.
For example; lpt580.zip
Extract the contents of the ZIP file and place the contents in the same directory as
SYSCLEAN.COM.
Trend Sysclean Method 2
---------------------------------------
Download the utility SYSCLEAN_FE at the following URL --
http://www.ik-cs.com/got-a-virus.htm
SYSCLEAN_FE automates the download and execution process of the Trend Sysclean Package.
Direct URL --
http://www.ik-cs.com/programs/virtools/Sysclean_FE.exe
2) Download Ad-aware SE (free personal version v1.05)
http://www.lavasoftusa.com/
Update Ad-aware with the latest definitions.
3) Reboot your PC into Safe Mode and shutdown as many applications as possible.
4) Using both the Trend Sysclean utility and Ad-aware, perform a Full Scan of your
platform and clean/delete any infectors/parasites found.
(a few cycles may be needed)
5) Restart your PC and perform a "final" Full Scan of your platform using both the
Trend Sysclean utility and Adaware
* * * Please report back your results * * *
--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm