2 weird messages

neo01

New Member
when i start my windows vista i got 2 messages


1.c:\windows\inf\other.exe specified in the registry make sure the file exists on your computer or remove the reference to it in the registry



2.could not load or run c:\windows\system32\config\win.exe specified in the registry.make sure the file exists on your computer or remove the rference to it in the registry


what this 2 means please i am very worried :(

thanks for the helpers :D
 

My Computer

what this 2 means please i am very worried

As well you should be. Not to try and scare you too much but,

win.exe - Program Information

Other.exe - Program Information

You have a couple of lovely little worms/trojans that look like they may have been partially removed (or being blocked from starting), hence the error messages.

If you don't have it already grab Hijackthis,

TrendSecure | TrendMicro™ HijackThis™ Overview

Not sure that there are any Hijackthis pros here (or at least if there are I haven't seen them. If there speak up please :D ) so go to this link,

AnalyzeThis

and select one of the forums from the list on the left that as sections dedicated to dealing with HJT logs, and post your HJT log there including any steps or other programs you may have used to try and clean up the infection.
 

My Computer

System One

  • Manufacturer/Model
    Me
    CPU
    Athlon x2 7750 BE
    Motherboard
    Asus M4A78 Pro
    Memory
    2x2gb Kingston
    Graphics Card(s)
    Sapphire HD 4830
    Sound Card
    X-Fi Xtreme Music
    Monitor(s) Displays
    Acer P221w and Acer 1916w
    Screen Resolution
    1680x1050 and 1440x900
    Hard Drives
    2x80 GB Seagate 7200.10 in RAID0, 500 GB Seagate 7200.12
    PSU
    Antec Earthwatts 500W
    Case
    Antec Sonata III
    Cooling
    AC Freezer 64 Pro and a couple of 120 mm case fans
    Keyboard
    Logitech Wave
    Mouse
    Logitech G5 v2
    Internet Speed
    10000/1000
is this can harm my saved files? you say "they may have been partially removed (or being blocked from starting" you mean i am safe

i got 2 times blue screen and power failure of c: hard drive is this from worms or trojan?

please help for 5 days i dont understand my pc
 

My Computer

neo01,
What type of Anti-Virus, Anti-Malware, and Anti-Spyware programs are you using?
This is very helpful to know in these cases.
 

My Computer

System One

  • Manufacturer/Model
    Dell
    CPU
    Intel(R) Celeron(R) CPU 420 @1.60 GHz
    Motherboard
    Dell Inspion 530 Default
    Memory
    PNY 4GB 240-Pin SDRAM DDR2 800 (PC2 6400) Dual Channel
    Graphics Card(s)
    ATI Radeon HD 2400 PRO
    Sound Card
    Realtek HD Audio
    Monitor(s) Displays
    Gateway PnP Monitor
    Screen Resolution
    1024x768 @ 75 Hz
    Hard Drives
    Seagate 250G ATA SATA-II
    Case
    Dell Inspiron 530
    Cooling
    None
    Keyboard
    Logitech EX100 Combo
    Mouse
    Logitech EX100 Combo
    Internet Speed
    100 MB/s
if i format my computer everything back to normal?


Win.exe is a Trojan Dropper usually associated with a malware program such as Anti Virus 2009(among many others). You should be able to remove it with Microsoft Malicious Software Removal Tool. If you still have problems with the registry try running a system restore to before you had the problem. Then run your AV scan and MSRT again.

Let us know how you go. Reformat should be the last resort as you'll have to reinstall everything.

Norm
 

My Computer

System One

  • Manufacturer/Model
    Scratch Built
    CPU
    Intel Quad Core 6600
    Motherboard
    Asus P5B
    Memory
    4096 MB Xtreme-Dark 800mhz
    Graphics Card(s)
    Zotac Amp Edition 8800GT - 512MB DDR3, O/C 700mhz
    Monitor(s) Displays
    Samsung 206BW
    Screen Resolution
    1680 X 1024
    Hard Drives
    4 X Samsung 500GB 7200rpm Serial ATA-II HDD w. 16MB Cache .
    PSU
    550 w
    Case
    Thermaltake
    Cooling
    3 x octua NF-S12-1200 - 120mm 1200RPM Sound Optimised Fans
    Keyboard
    Microsoft
    Mouse
    Targus
    Internet Speed
    1500kbs
    Other Info
    Self built.

My Computer

System One

  • Manufacturer/Model
    Compaq
    CPU
    intel core 2 duo T 5550 @ 1.83 MHz
    Motherboard
    intel 965 chipset family
    Memory
    2 GB DDR 2 SD RAM @ 667 MHz
    Graphics Card(s)
    On board upto 358 MB RAM
    Sound Card
    Onboard
    Monitor(s) Displays
    15"
    Hard Drives
    160 GB WDC
thank for the help but the main thing i need to know if there a connection between blue screen and hard drive power failure to this Trojan?
 

My Computer

thank for the help but the main thing i need to know if there a connection between blue screen and hard drive power failure to this Trojan?
Trojans could cause blue screens but cannot cause HDD power failure.
 

My Computer

System One

  • Manufacturer/Model
    Compaq
    CPU
    intel core 2 duo T 5550 @ 1.83 MHz
    Motherboard
    intel 965 chipset family
    Memory
    2 GB DDR 2 SD RAM @ 667 MHz
    Graphics Card(s)
    On board upto 358 MB RAM
    Sound Card
    Onboard
    Monitor(s) Displays
    15"
    Hard Drives
    160 GB WDC
thank for the help but the main thing i need to know if there a connection between blue screen and hard drive power failure to this Trojan?
Trojans could cause blue screens but cannot cause HDD power failure.


I agree Dinesh. However, if he's getting blue screens etc. it looks like he's got more than the Dropper. May well be a format is a good option. I haven't had too much success completely removing everything from a full blown infection

Norm
 

My Computer

System One

  • Manufacturer/Model
    Scratch Built
    CPU
    Intel Quad Core 6600
    Motherboard
    Asus P5B
    Memory
    4096 MB Xtreme-Dark 800mhz
    Graphics Card(s)
    Zotac Amp Edition 8800GT - 512MB DDR3, O/C 700mhz
    Monitor(s) Displays
    Samsung 206BW
    Screen Resolution
    1680 X 1024
    Hard Drives
    4 X Samsung 500GB 7200rpm Serial ATA-II HDD w. 16MB Cache .
    PSU
    550 w
    Case
    Thermaltake
    Cooling
    3 x octua NF-S12-1200 - 120mm 1200RPM Sound Optimised Fans
    Keyboard
    Microsoft
    Mouse
    Targus
    Internet Speed
    1500kbs
    Other Info
    Self built.

My Computer

System One

  • Manufacturer/Model
    Scratch Built
    CPU
    Intel Quad Core 6600
    Motherboard
    Asus P5B
    Memory
    4096 MB Xtreme-Dark 800mhz
    Graphics Card(s)
    Zotac Amp Edition 8800GT - 512MB DDR3, O/C 700mhz
    Monitor(s) Displays
    Samsung 206BW
    Screen Resolution
    1680 X 1024
    Hard Drives
    4 X Samsung 500GB 7200rpm Serial ATA-II HDD w. 16MB Cache .
    PSU
    550 w
    Case
    Thermaltake
    Cooling
    3 x octua NF-S12-1200 - 120mm 1200RPM Sound Optimised Fans
    Keyboard
    Microsoft
    Mouse
    Targus
    Internet Speed
    1500kbs
    Other Info
    Self built.
Hi neo01,

The "best" is very subjective you may want to try downloading, installing, and running the following preferably from safe mode.

Spybot S&D
The home of Spybot-S&D!
Malware Bytes
Malwarebytes' Anti-Malware - Free software downloads and reviews - CNET Download.com

When they have finished download and run this ...

CCleaner - Download

use this to generally clean up your system and then use the registry cleaner option to tidy the registry (use the backup registry option before you clean the registry)

After this is completed run this to check your system files.

System Files - SFC Command - Vista Forums

this will hopefully clean up the trojans and their damage
 

My Computers

System One System Two

  • Operating System
    Windows 10 Pro x64 Latest Release Preview
    Monitor(s) Displays
    Acer G276HL 27", (DVi) + Samsung 39" HDTV (HDMI)
    Screen Resolution
    2 x 1920x1080 @50Hz
  • Manufacturer/Model
    Real World Computers (Custom by Me)
    CPU
    AMD FX8350 Vishera 8 Core @4GHz
    Motherboard
    Asus M5A78L-M USB3
    Memory
    32GB [4x8GB] DDR3 1600 MHz
    Graphics card(s)
    Asus nVidia GTX750TI-OC-2GD5 (2GB DDR5)
    Sound Card
    ASUS Xoner DG + SPDIF to 5.1 System + HDMI
    Monitor(s) Displays
    Samsung 32" TV
    Screen Resolution
    1920 x 1080
    Hard Drives
    Internal
    Crucial CT256MX100SSD1 256GB SSD,
    Seagate ST2000DM001-1CH1 2TB,

    External (USB3)
    Seagate Backup+ Hub BK SCSI Disk 8TB
    2.5/3.5 Hot Swap Cradle, USB3 + eSata (client HDDs)
    NAS 4TB
    PSU
    Aerocool Templarius Imperator 750W 80+ Silver
    Case
    AeroCool X-Warrior Red Devil Tower
    Cooling
    Hyper103 CPU, Rear 120mm, Front 2x120mm, Side 2x120mm
    Internet Speed
    68 MB Down 18.5 MB Up
    Other Info
    Six Sensor Auto / Manual Digital cooling (Fan) control with Touch control Panel

My Computers

System One System Two

  • Operating System
    Vista
    CPU
    Intel E8400
    Motherboard
    ASRock1333-GLAN R2.0
    Memory
    4gb DDR2 800
    Graphics Card(s)
    nvidia 9500GT 1gb
  • Operating System
    win7/vista
    CPU
    intel i5-8400
    Motherboard
    gigabyte b365m ds3h
    Memory
    ballistix 2x8gb 3200
Hi NormCameron, i agree to what you say.
but format is the last resort as he will have to start everything from the stratch. But then, sometimes we do not have any other option but to format the computer.
Ok, and which blue screen is this? For ex: 0X000000ED or 0X0000007B.
 

My Computer

System One

  • Manufacturer/Model
    Compaq
    CPU
    intel core 2 duo T 5550 @ 1.83 MHz
    Motherboard
    intel 965 chipset family
    Memory
    2 GB DDR 2 SD RAM @ 667 MHz
    Graphics Card(s)
    On board upto 358 MB RAM
    Sound Card
    Onboard
    Monitor(s) Displays
    15"
    Hard Drives
    160 GB WDC
i have a update for you i install Malwarebytes' Anti-Malware run a check here is the result

Malwarebytes' Anti-Malware 1.31
Database version: 1546
Windows 6.0.6001 Service Pack 1
25/12/2008 21:50:39
mbam-log-2008-12-25 (21-50-39).txt
Scan type: Full Scan (C:\|)
Objects scanned: 216133
Time elapsed: 52 minute(s), 24 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\Typelib\{4509d3cc-b642-4745-b030-645b79522c6d} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\urlsearchhook.toolbarurlsearchhook (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\urlsearchhook.toolbarurlsearchhook.1 (Trojan.BHO) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\resycled (Trojan.DNSChanger) -> Quarantined and deleted successfully.
Files Infected:
C:\Program Files\Common Files\chd.exe (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\Windows\System32\msqpdxmnmxkedr.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\resycled\boot.com (Trojan.DNSChanger) -> Quarantined and deleted successfully.


but still get the 2 massages every time when windows is on what do you say?
 

My Computer

when i start my windows vista i got 2 messages


1.c:\windows\inf\other.exe specified in the registry make sure the file exists on your computer or remove the reference to it in the registry



2.could not load or run c:\windows\system32\config\win.exe specified in the registry.make sure the file exists on your computer or remove the rference to it in the registry


what this 2 means please i am very worried :(

thanks for the helpers :D

if i format my computer everything back to normal?


Win.exe is a Trojan Dropper usually associated with a malware program such as Anti Virus 2009(among many others). You should be able to remove it with Microsoft Malicious Software Removal Tool. If you still have problems with the registry try running a system restore to before you had the problem. Then run your AV scan and MSRT again.

Let us know how you go. Reformat should be the last resort as you'll have to reinstall everything.

Norm

Hi neo01,

The "best" is very subjective you may want to try downloading, installing, and running the following preferably from safe mode.

Spybot S&D
The home of Spybot-S&D!
Malware Bytes
Malwarebytes' Anti-Malware - Free software downloads and reviews - CNET Download.com

When they have finished download and run this ...

CCleaner - Download

use this to generally clean up your system and then use the registry cleaner option to tidy the registry (use the backup registry option before you clean the registry)

After this is completed run this to check your system files.

System Files - SFC Command - Vista Forums

this will hopefully clean up the trojans and their damage

Which of the above advice did you take? Did you also do a full system restore to BEFORE you had the problem (then run your various Spyware removers again)?

Norm
 

My Computer

System One

  • Manufacturer/Model
    Scratch Built
    CPU
    Intel Quad Core 6600
    Motherboard
    Asus P5B
    Memory
    4096 MB Xtreme-Dark 800mhz
    Graphics Card(s)
    Zotac Amp Edition 8800GT - 512MB DDR3, O/C 700mhz
    Monitor(s) Displays
    Samsung 206BW
    Screen Resolution
    1680 X 1024
    Hard Drives
    4 X Samsung 500GB 7200rpm Serial ATA-II HDD w. 16MB Cache .
    PSU
    550 w
    Case
    Thermaltake
    Cooling
    3 x octua NF-S12-1200 - 120mm 1200RPM Sound Optimised Fans
    Keyboard
    Microsoft
    Mouse
    Targus
    Internet Speed
    1500kbs
    Other Info
    Self built.
Well, the log that he posted is from Malwarebytes' AntiMalware so I'd guess that is the path he took....

neo01 - if you have good backups of all your files, then I'd recommend a clean reinstall of Vista to start back over. Just realize by clean I mean formatting the HD and then letting Vista install, not installing it over itself. You'll need to install all apps, programs, etc again, and apply any and all tweaks / customizations that you previously applied.
 

My Computers

System One System Two

  • Operating System
    Windows 10 Pro X64 Insider Preview (Skip Ahead) latest build
    Manufacturer/Model
    The Beast Model V (homebrew)
    CPU
    Intel Core i7 965 EE @ 3.6 GHz
    Motherboard
    eVGA X58 Classified 3 (141-GT-E770-A1)
    Memory
    3 * Mushkin 998981 Redline Enhanced triple channel DDR3 4 GB CL7 DDR3 1600 MHz (PC3-12800)
    Graphics Card(s)
    eVGA GeForce GTX 970 SSC ACX 2.0 (04G-P4-3979-KB)
    Sound Card
    Realtek HD Audio (onboard)
    Monitor(s) Displays
    2 * Lenovo LT2323pwA Widescreeen
    Screen Resolution
    2 * 1920 x 1080
    Hard Drives
    SanDisk Ultra SDSSDHII-960G-G25 960 GB SATA III SSD (System)
    Crucial MX100 CT256MX100SSD1 256GB SATA III SSD (User Tree)
    2 * Seagate Barracuda 7200.12 ST31000528AS 1TB 7200 RPM SATA II Mech. HD
    Seagate ST1500DL001-9VT15L Barracuda 7200.12 1.5 TB S
    PSU
    Thermaltake Black Widow TX TR2 850W 80+ Bronze Semi-Mod ATX
    Case
    ThermalTake Level 10 GT (Black)
    Cooling
    Corsair H100 (CPU, dual 140 mm fans on radiator) + Air (2 *
    Keyboard
    Logitech G15 (gen 2)
    Mouse
    Logitech MX Master (shared)
    Internet Speed
    AT&T Lightspeed Gigabit duplex
  • Operating System
    Sabayon Linux (current, weekly updates, 5.1.x kernel)
    Manufacturer/Model
    Lenovo ThinkPad E545
    CPU
    AMD A6-5350M APU
    Motherboard
    Lenovo
    Memory
    8 GB
    Graphics card(s)
    Radeon HD (Embedded)
    Sound Card
    Conextant 20671 SmartAudio HD
    Monitor(s) Displays
    Lenovo 15" Matte
    Screen Resolution
    1680 * 1050
    Hard Drives
    INTEL Cherryvill 520 Series SSDSC2CW180A 180 GB SSD
    PSU
    Lenovo
    Case
    Lenovo
    Cooling
    Lenovo
    Mouse
    Logitech MX Master (shared) | Synaptics TouchPad
    Keyboard
    Lenovo
    Internet Speed
    AT&T LightSpeed Gigabit Duplex
if you have good backups of all your files
If not, back them up now....

Then....
Try running Spybot S&D, then Smitfraudfix, then Combofix, then Spybot again
Then run NOD32 online scanner and Live OneCare Safety Scanner.

This has, (in the past) completely cleaned up a Antivirus XP 2008 and 2009 infected system (among other infections).

If that does not work, Nuke and Reload.
 

My Computer

Back
Top