Forum Home
Press F1
 
Thread ID: 43529 2004-03-17 19:55:00 homepage changed by web srm33 (3954) Press F1
Post ID Timestamp Content User
223370 2004-03-30 04:45:00 Advice I have received regarding your HijackThis log is that the following line looks rather dodgy and ought to be checked out:

C:\WINDOWS\System32\cp.e xe

Notice the space in the cp.e xe bit? Not sure if that is a forum glitch or not but it would be advisable to do the following:

Go here (www.kaspersky.com), scroll to the bottom of the page and look for the Submit button.

Click on Browse then navigate to the C:\WINDOWS\System32 folder and upload the .... cp.exe.... file and let us know what you find.

This file may be hidden so click on My Computer. Go to Tools > Folder Options. Click on the View tab and make sure that "Show hidden files and folders" is checked. Also uncheck "Hide protected operating system files" and "Hide extensions for known file types" . Now click "Apply to all folders"
Click "Apply" then "OK"

Please report back with your results.
Susan B (19)
223371 2004-03-30 19:37:00 Still 'clean'!
Cannot find any c/windows/system32/cp file of any sort, hidden or not. Reran Hijackthis and it doesnt come up there either. Must have been cleaned?

So far so good anyway.

srm
srm33 (3954)
223372 2004-03-30 20:43:00 SusanB, you listed it on one of your posts, as one to remove previously. :)

Great news srm33, and we hope it stays that way for you. Damn interesting exercise though, determined, and it was disguised under a known legitimate program.
Pheonix (280)
1 2 3 4 5