XP Pro - System2.exe  
Author Message
NicholasJFiorelloJr





PostPosted: Sun May 02 07:41:49 CDT 2004 Top

Windows XP Security >> XP Pro - System2.exe I have just come up with a virus check on the file
system2.exe in Windows\System32\. The file cant be
deleted but it can be renamed making me suspect that it
is not a system file.

The virus type is for spyware "spybot.js"

Has anyone come across this file or able to shed any
light on this?

Windows XP1313  
 
 
Russ





PostPosted: Sun May 02 07:41:49 CDT 2004 Top

Windows XP Security >> XP Pro - System2.exe Just managed to discover that this is another name for
the W32.Sasser.B.Worm. If anyone else gets it the
removal info is on the Symantec site, but its a pain.
Good luck.

>-----Original Message-----
>I have just come up with a virus check on the file
>system2.exe in Windows\System32\. The file cant be
>deleted but it can be renamed making me suspect that it
>is not a system file.
>
>The virus type is for spyware "spybot.js"
>
>Has anyone come across this file or able to shed any
>light on this?
>.
>
 
 
Lanwench





PostPosted: Sun May 02 08:30:12 CDT 2004 Top

Windows XP Security >> XP Pro - System2.exe Make sure you turned on your firewall & ran Windows Update to get all
critical patches, or you'll just get reinfected.

Russ wrote:
> Just managed to discover that this is another name for
> the W32.Sasser.B.Worm. If anyone else gets it the
> removal info is on the Symantec site, but its a pain.
> Good luck.
>
>> -----Original Message-----
>> I have just come up with a virus check on the file
>> system2.exe in Windows\System32\. The file cant be
>> deleted but it can be renamed making me suspect that it
>> is not a system file.
>>
>> The virus type is for spyware "spybot.js"
>>
>> Has anyone come across this file or able to shed any
>> light on this?
>> .


 
 
Bruce





PostPosted: Sun May 02 10:48:15 CDT 2004 Top

Windows XP Security >> XP Pro - System2.exe Greetings --

System32.exe is _not_ a valid Windows file, but rather a file name
commonly used for a component of several well-known viruses, worms,
and Trojans.

To name a few:

W32.Kwbot.C.Worm
http://securityresponse.symantec.com/avcenter/venc/data/w32.kwbot.c.worm.html

W32.Mari.mm
http://securityresponse.symantec.com/avcenter/venc/data/EMail@HideDomain.com

Backdoor.SysXXX
http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sysxxx.html

Backdoor.Miranda
http://securityresponse.symantec.com/avcenter/venc/data/backdoor.miranda.html

W32.Kitro.A.Worm
http://securityresponse.symantec.com/avcenter/venc/data/w32.kitro.a.worm.html

W32.HHLW.Logpole.C
http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.logpole.c.html

Backdoor.Darksun
http://securityresponse.symantec.com/avcenter/venc/data/backdoor.darksun.html

W32.Trilisa.mm
http://securityresponse.symantec.com/avcenter/venc/data/EMail@HideDomain.com

Additionally, MS-MVP Doug Knox has kindly scripted a tool that
could help:
http://www.dougknox.com/xp/scripts_desc/xp_clean_kwbot.htm


Bruce Chambers

--
Help us help you:
http://dts-l.org/goodpost.htm
http://www.catb.org/~esr/faqs/smart-questions.html


You can have peace. Or you can have freedom. Don't ever count on
having both at once. -- RAH


"Russ" <EMail@HideDomain.com> wrote in message
news:70ca01c43039$8ee41d40$EMail@HideDomain.com...
>I have just come up with a virus check on the file
> system2.exe in Windows\System32\. The file cant be
> deleted but it can be renamed making me suspect that it
> is not a system file.
>
> The virus type is for spyware "spybot.js"
>
> Has anyone come across this file or able to shed any
> light on this?