View Full Version : how to remove 399406.EXE
sxe
April 1st, 2009, 11:29 PM
It keep on connecting and using my internet connection? how to remove this file?
Is this a virus?
xMarkx
April 1st, 2009, 11:39 PM
Hello,
This sounds like a piece of malware to me. Have you tried running an in-depth scan with your ESET Smart Security product fully up-to-date with the latest virus signature database, 3982? Also, can you locate where the malicious file is located (e.g: C:\WINDOWS\SYSTEM32 or C:\Program Files\...\)
Regards,
Mark.
sxe
April 1st, 2009, 11:43 PM
Yup i already in-depth full scan my system, but seems no virus detected.
Im using the latest Eset 4 version with latest virus signature database 3982
The file is located at C:\WINDOWS\SYSTEM32\634055\399406.EXE
here's the screenshot
http://img16.imageshack.us/img16/787/virusxgd.jpg
xMarkx
April 1st, 2009, 11:57 PM
-{ Quote: "Yup i already in-depth full scan my system, but seems no virus detected.
Im using the latest Eset 4 version with latest virus signature database 3982
The file is located at C:\WINDOWS\SYSTEM32\634055\399406.EXE
here's the screenshot
http://img16.imageshack.us/img16/787/virusxgd.jpg" }-
Hello,
If there's a weird file name like that in your SYSTEM32 folder then it's more than likey a virus. Since ESET's latest virus signature isn't detecting it as a virus, I would send the file to ESET using funkydude's directions (http://www.wilderssecurity.com/showpost.php?p=1346902&postcount=4) so that hopefully in the next virus signature update, EAV/ESS will be able to detect it.
In the meantime, you can download and install free on-demand antimalware scanners such as AntiMalwareBytes (http://www.malwarebytes.org/mbam.php) and SUPERAntiSpyware (http://www.superantispyware.com/download.html) and run them in SafeMode. You can enter safe mode by hitting F8 a bunch of times during boot-up. Make sure both products are up-to-date before scanning with them.
Regards,
Mark.
Try using either MalwareBytes or SUPERAntiSpyware (or both) and see what they report. Official site for download is above.
agoretsky
April 2nd, 2009, 12:31 AM
Hello,
If you believe your computer is infected with malware that is not detected by ESET Smart Security, then create a .ZIP or .RAR file protected with a password of "infected" containing the suspicious files and send it, along with an ESET SysInspector log file, to ESET's virus lab for further analysis.
You can download a copy of ESET SysInspector (http://www.eset.com/download/sysinspector.php) from http://www.eset.com/download/sysinspector.php (http://www.eset.com/download/sysinspector.php) and run it to create a log file.
The email address for ESET's virus lab is support@eset.sk (support@eset.sk).
Regards,
Aryeh Goretsky
sxe
April 2nd, 2009, 02:10 AM
Thank You guys, file sent.
=]
xMarkx
April 2nd, 2009, 02:15 AM
-{ Quote: "Thank You guys, file sent.
=]" }-
Hopefully it will be added in the next virus signature database update. Did you try any of the two Antimalware programs I suggested as well to see what they could detect?
The PIT
April 2nd, 2009, 03:49 AM
Try scanning with malwarebytes antimalware see if that finds anything.
sxe
April 4th, 2009, 10:44 AM
Virus Deleted.
Win32/FlyStudio.NIV trojan
Thank You Eset
xMarkx
April 4th, 2009, 11:00 PM
-{ Quote: "Virus Deleted.
Win32/FlyStudio.NIV trojan
Thank You Eset" }-
Hello,
Glad to here the infection is gone and that it's been added to ESET's virus signatures.
Regards,
Mark.
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums