That's a good result Jose
Is there any further details on this trick!
"Some malicious software will not let processes run just by their name
you see in Task Manager - mbam.exe, regedit.ext, cmd.exe, rstrui.exe,
etc. They think they know all the tricks. That is why renaming
sometimes will work enough to get you going. Try copying to something
besides test.exe. Maybe they already thought about test.exe."
--
Gerry
~~~~
FCA
Stourport, England
Enquire, plan and execute
~~~~~~~~~~~~~~~~~~~
I made that up all by myself.
I learned this trick while trying to figure out how to fix the problem
of regedit(.exe) and cmd(.exe) not working. I have that down to a
science and a single post reply the next time I see somebody with that
problem. But you must be MBAM (or maybe SAS) first. No format/
reinstall, no last know good configuration, no going back to possible
already corrupted restore point, no safe mode, no boot disk, no "try
this", and thankfully no 25 posts back and forth. At least for the
problem I have become so intimate with.
To finish solving the problem above you have to get regedit working
somehow. The infestation will not allow regedit.exe or cmd.exe to
appear as a Process in Task Manager. If you copy regedit.exe to
copy.exe, copy.exe is allowed to run, so then you can then fix it for
good. I have learned that it is not smart enough to know about
command.exe (yet). regedt32.exe won't run either because it is just
regedit.exe in disguise (in XP) and that is what shows up in Task
Manager (try it) - not allowed to run!
The malicious software (I reckoned) has gotten smart enough to look
for things that might help remove it, like mbam.exe,
superantispyware.exe, cmd.exe, regedit.exe, rstrui.exe - and now I
figure it also won't let something like test.exe run either (what a
good name for a copy), but I have never tried test.exe before.
So, maybe the OP used something like august.exe for MBAM. No way it
would know about that. It doesn't seem to know about copy.exe yet
either. This is my first encounter with test.exe not working, but now
we know.