System32.exe trojan



Ok I have a slight problem, somehow I appear to have got
myself a trojan thats parked it's self in my System32.exe
file, NAV can't clear it out so short of a full reinstall
of windows (not another one) is there anyway to get rid
of this wee beasty. I'm using XP pro.

Has the System32.exe been updated since XP came out,
stupid ? I know but I could always drag the file from the
XP CD and copy it over the infected file. Would this work
or would it screw up my system.

Yves Leclerc

System32 is not an EXE but a folder. It keeps being updated whenever you
add software/hardware.



In my system32 folder is a file called system32.exe, I
just checked my ladtop (also installed with XP pro)which
I use for business and that doesn't have the system32.exe
file, the infected computer I use for games and general
web browsing so wherever the file came from I don't know,
either from istalling a game or game add-on or from
verious driver installs I've done lately, NAV can't get
rid of it, and just keeps bugging me about it..... :),
I'll have a fish around the registry see if I can figure
out what calls it/starts it.


Thanks for the help, I quess thats what it must be,
strange thing is I don't use any P2P client software like
KaZaa for this reason, so god knows where it came from.

Oh well, it's fixed now.... hopefully....... :)
-----Original Message-----


As windows doesn't have a file called system 32.exe this may be due to
an infection of Backdoor.SysXXX trojan
or,W32.Kwbot.C.Worm.So scan your

Daniel L. Belton

In my system32 folder is a file called system32.exe, I
just checked my ladtop (also installed with XP pro)which
I use for business and that doesn't have the system32.exe
file, the infected computer I use for games and general
web browsing so wherever the file came from I don't know,
either from istalling a game or game add-on or from
verious driver installs I've done lately, NAV can't get
rid of it, and just keeps bugging me about it..... :),
I'll have a fish around the registry see if I can figure
out what calls it/starts it.

updated whenever you

in message
I had the same thing on mine, and it was started from an alternate data
stream entry. Virus scanner wouldn't even touch it.

Daniel L. Belton

purplehaz said:
System32.exe file is a virus, you don't want it back. It is not a real XP
system file.
Your seeing your computer ask for it because the virus was not cleaned out
Follow the link for removal instructions.

that's not the same one I had on my system. I still haven't found out
all I want to know about the one I had, but it was really nasty.

Bruce Chambers

Greetings --

You really don't want to get that file back. It's part of several
well-known viruses/worms. It is *not* a valid Windows file. Pay
particular attention to _all_ of the removal instructions:


Additionally, MS-MVP Doug Knox has kindly scripted a tool that
should help:

Bruce Chambers

Help us help you:

You can have peace. Or you can have freedom. Don't ever count on
having both at once. -- RAH

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question
