Technology Questions

Go Back   Technology Questions > Software Questions > Operating System Questions > Windows XP

Windows XP Discuss the Microsoft Windows XP Operating System

Reply
 
LinkBack Thread Tools
  #1 (permalink)  
Old 11-01-2009, 06:20 PM
jpBless
Newsgroup Contributor
 
Posts: n/a
Registry key 79932434

My XP/SP3 system recently got infected with Alpha (dubious) Antivirus. I
followed intsruction posted on the web to uninstall this malicious trojan.

Under registery:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run

I found an entry 79932434.exe pointing to Windows prefetch folder...

I checked the folder and found the file (C:\Windows\Prefetch)
79932434.Exe/018DD50B.pf

The file's property indicated it was created about the same day my system
got infected. Does anyone about this file ... I want to be sure before
deleting the registry key

thanks


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

 
Old 11-01-2009, 06:20 PM
  #2 (permalink)  
Old 11-02-2009, 06:10 AM
Bernd
Newsgroup Contributor
 
Posts: n/a
Re: Registry key 79932434



-------- Original-Nachricht --------

> My XP/SP3 system recently got infected with Alpha (dubious) Antivirus. I
> followed intsruction posted on the web to uninstall this malicious trojan.
>
> Under registery:
> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run
>
> I found an entry 79932434.exe pointing to Windows prefetch folder...
>
> I checked the folder and found the file (C:\Windows\Prefetch)
> 79932434.Exe/018DD50B.pf
>
> The file's property indicated it was created about the same day my system
> got infected. Does anyone about this file ... I want to be sure before
> deleting the registry key
>
> thanks
>
>


If you search with Google for 79932434.exe you get 6 hits, ALL pointing
to your question ..

I think that anwers your question !

Bernd
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #3 (permalink)  
Old 11-02-2009, 07:30 AM
Jose
Newsgroup Contributor
 
Posts: n/a
Re: Registry key 79932434

On Nov 1, 9:17*pm, "jpBless" <jp3blessNoS...********.com> wrote:
> My XP/SP3 system recently got infected with Alpha (dubious) Antivirus. I
> followed intsruction posted on the web to uninstall this malicious trojan..
>
> Under registery:
> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run
>
> I found an entry 79932434.exe pointing to Windows prefetch folder...
>
> I checked the folder and found the file (C:\Windows\Prefetch)
> 79932434.Exe/018DD50B.pf
>
> The file's property indicated it was created about the same day my system
> got infected. Does anyone about this file ... I want to be sure before
> deleting the registry key
>
> thanks


I don't know how the Google hits help the OP with the issue.

It is suspicious since it is not a Windows XP file and has been added
to your LM/run settings so it will start whenever your machine
starts. It looks like leftovers from some malicious software.

If you can't identify it, delete it.

Backup your registry first with this popular tool:

http://www.larshederer.homepage.t-online.de/erunt/

Run these scans:

Download, install, update and do a full scan with these free malware
detection programs:

Malwarebytes (MBAM): http://malwarebytes.org/
SUPERAntiSpyware: (SAS): http://www.superantispyware.com/

They can be uninstalled later if desired.

Remove the suspicious registry key, remove the executable if it still
exists, remove the .pf file from the Prefetch folder.

Reboot and check to see if everything is still gone and report results/
other issues.

Zero items automatically starting in HKLM and HKCU is a very good goal
if you can achieve it.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #4 (permalink)  
Old 11-02-2009, 08:50 AM
jpBless
Newsgroup Contributor
 
Posts: n/a
Re: Registry key 79932434


Yes I did search for 79932434.exe before posting this but did not get any
helpful info. Anyway thanks. I wanted to be absolutely sure!

"Bernd" <fake@gmx.de> wrote in message
news:ufWf3S8WKHA.508@TK2MSFTNGP06.phx.gbl...
>
>
> -------- Original-Nachricht --------
>
>> My XP/SP3 system recently got infected with Alpha (dubious) Antivirus. I
>> followed intsruction posted on the web to uninstall this malicious
>> trojan.
>>
>> Under registery:
>> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run
>>
>> I found an entry 79932434.exe pointing to Windows prefetch folder...
>>
>> I checked the folder and found the file (C:\Windows\Prefetch)
>> 79932434.Exe/018DD50B.pf
>>
>> The file's property indicated it was created about the same day my system
>> got infected. Does anyone about this file ... I want to be sure before
>> deleting the registry key
>>
>> thanks
>>
>>

>
> If you search with Google for 79932434.exe you get 6 hits, ALL pointing to
> your question ..
>
> I think that anwers your question !
>
> Bernd



Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #5 (permalink)  
Old 11-02-2009, 08:50 AM
jpBless
Newsgroup Contributor
 
Posts: n/a
Re: Registry key 79932434

Thanks for your response; very much appreciated. That registry key looked
super suspicious. Again thanks a lot


"Jose" <jose_ease******.com> wrote in message
news:753502f8-3fa3-438d-9141-ae22293ee264@b15g2000yqd.googlegroups.com...
On Nov 1, 9:17 pm, "jpBless" <jp3blessNoS...********.com> wrote:
> My XP/SP3 system recently got infected with Alpha (dubious) Antivirus. I
> followed intsruction posted on the web to uninstall this malicious trojan.
>
> Under registery:
> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run
>
> I found an entry 79932434.exe pointing to Windows prefetch folder...
>
> I checked the folder and found the file (C:\Windows\Prefetch)
> 79932434.Exe/018DD50B.pf
>
> The file's property indicated it was created about the same day my system
> got infected. Does anyone about this file ... I want to be sure before
> deleting the registry key
>
> thanks


I don't know how the Google hits help the OP with the issue.

It is suspicious since it is not a Windows XP file and has been added
to your LM/run settings so it will start whenever your machine
starts. It looks like leftovers from some malicious software.

If you can't identify it, delete it.

Backup your registry first with this popular tool:

http://www.larshederer.homepage.t-online.de/erunt/

Run these scans:

Download, install, update and do a full scan with these free malware
detection programs:

Malwarebytes (MBAM): http://malwarebytes.org/
SUPERAntiSpyware: (SAS): http://www.superantispyware.com/

They can be uninstalled later if desired.

Remove the suspicious registry key, remove the executable if it still
exists, remove the .pf file from the Prefetch folder.

Reboot and check to see if everything is still gone and report results/
other issues.

Zero items automatically starting in HKLM and HKCU is a very good goal
if you can achieve it.


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Registry Search Tool... Cleaning Up Vista Registry... Susan Windows Vista 12 03-23-2009 10:55 PM
Windows Registry Cleaner - Download Free Registry Software voujnbwuotkd@yahoo.com Windows XP 18 07-27-2008 09:01 AM
What is Windows registry (Registry Keys) Omar Abid Windows XP 5 03-28-2008 10:20 AM
What is Windows registry (Registry Keys) Omar Abid Windows Vista 0 03-28-2008 08:30 AM
Registry Semi-Disaster: I am an idiot - used 2 registry 'cleaners' dczarniak Windows Vista 4 02-18-2008 10:10 AM


New To Technology Questions? Do You Need Help with Your Computer or Device? Do You Need Help with this site?

All times are GMT -8. The time now is 05:49 PM.


2003 - 2009 All Rights Reserved. Technology Questions

Search Engine Friendly URLs by vBSEO 3.3.0