Go Back   Velocity Reviews > Newsgroups > Computer Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Computer Security - Malicious startup programs

 
Thread Tools Search this Thread
Old 01-04-2005, 12:33 AM   #1
Default Malicious startup programs


A malicious program keeps re-inserting itself in my start-up list.

I've "Startup Control Panel 2.8 by Mike Lin" which conventiently displays
startup items in a tabbed interface.

The following is a real bugger.

In HKLM/Run I have an item named '4GDY2Ml296K6CX' with path
C:\WINDOWS\SYSTEM\Xej7.exe

If tried to uncheck it but doing that resulted in it creating a duplicate
entry immediately with the other one checked! Trying to uncheck the other
one resulted in an error message "There is already and enabled/disabled
entry with the same name..." and a simple OK button. Hit OK and the second
duplicated entry remains checked.

I cannot delete Xej7.exe because it is "in use"

I've had this problem repeatedly. Last time I finally rebooted in safe mode,
made sure nothing extra was loaded and deleted Xej7.exe (actually a
precursor), removed all entries from startup and searched windows registry
for it and deleted anything that was connected to it.

Within a day or so it returned. Not the same name but something like it. I
think it was named 'AOzdf.exe'. I could tell was the same thing because it
acted the same.

It looks like something is lurking somewere on my system and it checks to
see if it's exe is there and in startup and if not creates it and adds it to
the start up list. Question is how do I find it.

In other words something created/wrote Xej7.exe and set it up to load at
startup. That something is lurking somewhere on my system. This exe gets
recreated even if I disconnect the wire to the internet.

I have Spy Bot Search and Destroy and Add Aware and run them on a schedule.
I have anti virus software. All of this has failed to get rid of the
problem I describe.

The key is to find what is creating the 'Xej7.exe' and getting rid of that.

Any ideas on how to diagnose this.




tvfun
  Reply With Quote
Old 01-04-2005, 12:58 AM   #2
David Postill
 
Posts: n/a
Default Re: Malicious startup programs
In article <PvlCd.4817$>, on Tue, 04 Jan 2005 00:33:51 GMT,
"tvfun" <> wrote:

| A malicious program keeps re-inserting itself in my start-up list.
|
| I've "Startup Control Panel 2.8 by Mike Lin" which conventiently displays
| startup items in a tabbed interface.
|
| The following is a real bugger.
|
| In HKLM/Run I have an item named '4GDY2Ml296K6CX' with path
| C:\WINDOWS\SYSTEM\Xej7.exe

<http://www.google.co.uk/search?q=Xej7+removal>

<davidp />

--
DavidPostill


David Postill
  Reply With Quote
Old 01-04-2005, 08:53 AM   #3
Jim Watt
 
Posts: n/a
Default Re: Malicious startup programs
On Tue, 04 Jan 2005 00:33:51 GMT, "tvfun" <> wrote:

>A malicious program keeps re-inserting itself in my start-up list.


Then its still running. Kill its process and then remove its
startup entry.
--
Jim Watt
http://www.gibnet.com


Jim Watt
  Reply With Quote
Old 01-05-2005, 03:00 AM   #4
Sasquatch
 
Posts: n/a
Default Re: Malicious startup programs
Do like Jim suggested. Kill the process and then get rid of the file
Xej7.exe. Be forewarned though, that many of these nasties are set to auto
download/repair themselves if you should remove their key files. Ensure you
dump all temp files as well as checking the following keys in the registry:

Start-->Run-->Regedit
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\RunO nce

Delete anything that may reference Xej7.exe

Download and use Spybot Search and Destroy ***AND*** Ad Aware. Both find
things the other misses.

Once accomplished, stop using IE and start using Mozilla Firefox.




"tvfun" <> wrote in message
newsvlCd.4817$ ...
> A malicious program keeps re-inserting itself in my start-up list.
>
> I've "Startup Control Panel 2.8 by Mike Lin" which conventiently displays
> startup items in a tabbed interface.
>
> The following is a real bugger.
>
> In HKLM/Run I have an item named '4GDY2Ml296K6CX' with path
> C:\WINDOWS\SYSTEM\Xej7.exe
>
> If tried to uncheck it but doing that resulted in it creating a duplicate
> entry immediately with the other one checked! Trying to uncheck the other
> one resulted in an error message "There is already and enabled/disabled
> entry with the same name..." and a simple OK button. Hit OK and the second
> duplicated entry remains checked.
>
> I cannot delete Xej7.exe because it is "in use"
>
> I've had this problem repeatedly. Last time I finally rebooted in safe

mode,
> made sure nothing extra was loaded and deleted Xej7.exe (actually a
> precursor), removed all entries from startup and searched windows registry
> for it and deleted anything that was connected to it.
>
> Within a day or so it returned. Not the same name but something like it. I
> think it was named 'AOzdf.exe'. I could tell was the same thing because it
> acted the same.
>
> It looks like something is lurking somewere on my system and it checks to
> see if it's exe is there and in startup and if not creates it and adds it

to
> the start up list. Question is how do I find it.
>
> In other words something created/wrote Xej7.exe and set it up to load at
> startup. That something is lurking somewhere on my system. This exe gets
> recreated even if I disconnect the wire to the internet.
>
> I have Spy Bot Search and Destroy and Add Aware and run them on a

schedule.
> I have anti virus software. All of this has failed to get rid of the
> problem I describe.
>
> The key is to find what is creating the 'Xej7.exe' and getting rid of

that.
>
> Any ideas on how to diagnose this.
>
>





Sasquatch
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
2007/11/29 Boris 7 new programs, Logic Studio 8 for Mac, MicrosoftVisual Studio 2008 Professional Edition, Microsoft Windows Vista UltimateNov-2007.Win32/64, other new programs ola@mail.gr DVD Video 0 11-29-2007 06:15 AM
startup xp home russfraz General Help Related Topics 2 09-15-2006 05:39 AM
Burner Program(s) Don't Recognize DVD Writers John DVD Video 2 01-01-2005 09:37 PM
Startup problems Cheifno A+ Certification 5 06-07-2004 08:30 PM
Window xp and startup disk Raymond A+ Certification 2 10-22-2003 10:06 AM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46