Question about Computers & Internet

Open Question

Mchta.exe - Computers & Internet

Posted by on

Ad

Add Your Answer

Uploading: 0%

my-video-file.mp4

Complete. Click "Add" to insert your video. Add

×

Loading...
Loading...

Related Questions:

1 Answer

Disconnectivity within 1 minute I install a fresh


ftp://ftp.hp.com/pub/softpaq/sp47501-48000/sp47845.exe
A lot of Windows Update Issues are linked to this Intel Storage Technology Driver being out of date. Hope this helps!

Aug 16, 2013 | Computers & Internet

1 Answer

Spcmd.sys


The file "spcmd.sys" is known to be created under the following filenames: %System%\cc.sys %System%\dboy1.sys %System%\g3i2ll.sys %System%\setuplk.exe %System%\setuplk.sys %System%\spcmd.sys %System%\tencent.sys %System%\zzjkxs.sys %Temp%\xpanxionvirus\a1.exe %Temp%\xpanxionvirus\a2.exe %Temp%\xpanxionvirus\tmd.exe %Temp%\xpanxionvirus\tmd1.exe %Temp%\xpanxionvirus\tmd2.exe %Temp%\xpanxionvirus3\boot.exe %Temp%\xpanxionvirus3\cc.exe %Temp%\xpanxionvirus3\s.exe %Temp%\xpanxionvirus3\sc.exe %Temp%\xpanxionvirus3\se.exe %Windir%\a1.exe %Windir%\a2.exe %Windir%\s.exe %Windir%\se.exe %Windir%\tmd.exe %Windir%\tmd1.exe %Windir%\tmd2.exe c:\boot.exe c:\cc.exe c:\sc.exe Go to this link for more info http://www.threatexpert.com/files/spcmd.sys.html it is said to be of no threat.

Your timely rating of this soloution is much appreciated.
Thanks

Nov 01, 2010 | Computers & Internet

1 Answer

Worm.autoit virus(mgy.exe) make folder and all of my data files add extension .exe.exe.exe(example: desktop.ini.exe.exe.exe, mydata.xls.exe.exe, after cleaning and delete this all, my data and same file...


Boot from a Linux Live-CD and recover your files - Linux ignores the extensions so if your files are still there then they will be clearly visible.

Jul 05, 2010 | Computers & Internet

2 Answers

How do you remove Virtumonde from Windows XP? I have tried malwarebytes and Ad Adware both with no success. I use Avast 5.0 which didn't catch it and Spybot S & D doesn't even spot it as a virus. This...


As far as free tools, you will want to try VundoFix and/or VirtumundoBegone.

VirtuMonde manual removal instructions:
Kill VirtuMonde processes:
kopCFEWV.exe
castlecops[1].exe
unknown.exe
svci.exe
psdrv.exe
rasrun.exe
nwonknu.exe
editpad.exe
quicken.exe
winhost.exe
editpad.exewindowsupd2.exe
quicken.exe
winhost.exe
windowsupd2.exe
Delete VirtuMonde files\folders and unregister dll’s:
opnnljj.dll
cbxxywx.dll
nnnmmlk.dll
vtuspmn.dll
mllkk.dll
sstrs.dll
awtqqnl.dll
kopCFEWV.exe
gf1.0.0.2
castlecops[1].exe
ddcbabx.dll
iifddby.dll
2chkdsk
pmnlk.dll
SbCIe02b.dll
ssttr.dll
geebc.dll
pmnno.dll
jtr0079me.dll
hrj6051se.dll
unknown.exe
svci.exe
psdrv.exe
rasrun.exe
nwonknu.exe
cidrules.dll
rulesak.dll
lspak.dll
editpad.exe
quicken.exe
winhost.exe
unknown.exewindowsupd2.exe
svci.exe
psdrv.exe
rasrun.exe
nwonknu.exe

Remove VirtuMonde registry values (keys and subkeys):
MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\nnnmmlk
59B5C788-4D95-4610-B1ED-AD9DC7CD86E0
05029E1B-4C41-4681-8F7F-2AEC346136F4
01ABD624-98FE-4B37-81F2-4E5B41799B6B
1FB63E52-4D6E-48C1-A08F-F630FE50F337
5A4A2D56-931A-4733-9121-033A2D95A274
3F82D203-999F-4FF4-9F07-5F9EBFCCE20F
22E58089-6DB5-45D9-BF87-6C8975246D26
F73AF695-229D-4549-B1A0-20DA99A81F19
F00EFDF5-0042-4F5E-9F20-C688409CF918
B2030C9A-DE59-457D-A042-D827AD69C8F3
9CF8EE9B-0B2E-464A-9700-D7B46142BD99
SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\ssttr
SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\pmnno
662BB3E3-204F-44FA-A827-143B8AB4B036
C78658B2-CDE5-4FD1-B73B-B9FF478DBE54
B763C083-57E0-4993-B058-13008952DF68
Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ddcbabx
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\A05DA7E0-383C-4E99-A72A-742050A152A2
A05DA7E0-383C-4E99-A72A-742050A152A2
Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\iifddby
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\6148028B-D532-4417-8C0B-5A4A0B745393
6148028B-D532-4417-8C0B-5A4A0B745393
D38439EC-4A7F-42b4-90C2-D810D7778FDD
Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmnlk
2FCAB754-0535-470E-8F80-BACB6CA1ACC1
83B28A74-640D-48F4-9F51-E80EED7CC7E0
Software\Microsoft\Internet Explorer\Explorer Bars\83B28A74-640D-48F4-9F51-E80EED7CC7E0
D714A94F-123A-45CC-8F03-040BCAF82AD6
Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssttr
22B271AB-3D0A-4CCB-8AD9-DD08183C356A
68616403-4FFB-4B19-B360-0B0B1F55D5EC
Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmnno
1B34D3EC-4AC7-41EC-ACC8-C9A2C0CBA2E5
D01C9902-73AF-47FF-B784-05FDB6604FCF
HKEY_LOCAL_MACHINE\software\targetsoft
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\*catw
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\windowsupd
HKEY_LOCAL_MACHINE\software\microsoft\windowsnt\currentversion\winlogon\notify\psdrv
HKEY_LOCAL_MACHINE\software\microsoft\windowsnt\currentversion\winlogon\notify\catw
HKEY_CURRENT_USER\software\microsoft\windowsupd
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce\*winlogon
13589181-4f0d-4553-b9f8-b4b72172c139
HKEY_LOCAL_MACHINE\software\targetsoftHKEY_CLASSES_ROOT\atlevents.atlevents
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\*catw
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\windowsupd
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psdrv
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\catw
HKEY_CURRENT_USER\software\microsoft\windowsupd
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce\*winlogon
HKEY_CLASSES_ROOT\clsid\{13589181-4f0d-4553-b9f8-b4b72172c139}
HKEY_CLASSES_ROOT\atlevents.atlevents

Mar 19, 2010 | Dell Dimension 3000 PC Desktop

3 Answers

Be.tmp.exe application error. the instruction at "0x0040c173" referenced memory at "0x0040c173". the memory could not be read


This should all be done in safe mode and with system restore turned off for now.

This is a virus and You need to run your antivirus scan and remove what it finds,Run a cleaner program such as Ccleaner

Hit Ctrl+Alt+Delete and open the task manager,Under the process tab find and end task on tmp.exe and/or BE.tmp.exe.
It is a process belonging to an advertising program by 123bar. This process monitors your browsing habits and distributes the data back to the author's servers for analysis. This also prompts advertising popups. This process is a security risk and should be removed from your system.

%FontsDir%\nwlnkfwd.exe %FontsDir%\nwlnkipx.exe %FontsDir%\nwlnknb.exe %FontsDir%\nwlnkspx.exe %FontsDir%\nwrdr.exe %FontsDir%\oprghdlr.exe %FontsDir%\p3.exe %ProgramFiles%\internet explorer\keymaker.exe %ProgramFiles%\outlook express\keymaker.exe %System%\1025\zipfldr.exe %System%\1028\zipfldr.exe %System%\1028myztx.exe %System%\1031\zipfldr.exe %System%\1033\zipfldr.exe %System%\1037\zipfldr.exe %System%\1041\zipfldr.exe %System%\1042\zipfldr.exe %System%\1054\zipfldr.exe %System%\2052\zipfldr.exe %System%\3076\zipfldr.exe %System%\3com_dmi\edb.exe %System%\3com_dmi\edb0000a.exe %System%\3com_dmi\edb0000b.exe %System%\3com_dmi\edb0000c.exe %System%\3com_dmi\edb0000d.exe %System%\3com_dmi\edb0000e.exe %System%\3com_dmi\zipfldr.exe %System%\catroot\zipfldr.exe %System%\catroot2\{127d0a1d-4ef2-11d1-8608-00c04fc295ee}\tmp.exe %System%\catroot2\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\tmp.exe %System%\catroot2\tmp.exe %System%\catroot2\zipfldr.exe %System%\com\zipfldr.exe %System%\dhcp\zipfldr.exe %System%\directx\zipfldr.exe %System%\dllcache\zipfldr.exe %System%\drivers\disdn\ws2ifsl.exe %System%\drivers\etc\atmlane.com %System%\drivers\etc\atmuni.com %System%\drivers\etc\audstub.com %System%\drivers\etc\battc.com %System%\drivers\etc\beep.com %System%\drivers\etc\bridge.com %System%\drivers\etc\cbidf2k.com %System%\drivers\etc\ws2ifsl.exe %System%\drivers\ws2ifsl.exe %System%\drivers\zipfldr.exe %System%\export\zipfldr.exe %System%\grouppolicy\adm\gpt.exe %System%\grouppolicy\gpt.exe %System%\grouppolicy\machine\gpt.exe %System%\grouppolicy\user\gpt.exe %System%\grouppolicy\zipfldr.exe %System%\ias\zipfldr.exe %System%\icsxml\zipfldr.exe %System%\ime\zipfldr.exe %System%\inetsrv\zipfldr.exe %System%\keymaker.exe %System%\macromed\comadmin.exe %System%\macromed\comempty.exe %System%\macromed\comexp.exe %System%\macromed\edb00017.exe %System%\macromed\res1.exe %System%\macromed\res2.exe %System%\macromed\tmp.exe %System%\macromed\zipfldr.exe %System%\microsoft\zipfldr.exe %System%\msdtc\msdtc.exe %System%\msdtc\trace\msdtc.exe %System%\msdtc\zipfldr.exe %System%\mui\0418\ftdisk.exe %System%\mui\0418\gm.exe %System%\mui\0418\gmreadme.exe %System%\mui\0418\hgfs.exe %System%\mui\0418\http.exe %System%\mui\0418\i8042prt.exe %System%\mui\0418\imapi.exe %System%\schost.exe %System%\services32.exe %System%\spool\drivers\w32x86\3\mouclass.sys %System%\spool\drivers\w32x86\3\mountmgr.sys %System%\spool\drivers\w32x86\3\mqac.sys %System%\spool\drivers\w32x86\3\mrxdav.sys %System%\spool\drivers\w32x86\3\mrxsmb.sys %System%\spool\drivers\w32x86\3\msfs.sys %System%\spool\drivers\w32x86\3\msgpc.sys %System%\syskey_dll\sysupdate.exe %System%\system\system.exe %System%\tmp.exe %Temp%\5.exe %Temp%\70554keygen1.exe %Temp%\guqf296\keymaker.exe %Temp%\ixp000.tmp\efubtgis.exe %Temp%\ixp000.tmp\key_gen.exe %Temp%\ixp000.tmp\keygen.exe %Temp%\ixp000.tmp\keymaker.exe %Temp%\ixp000.tmp\tmp.exe %Temp%\ixp000.tmp\tvonuaek.exe %Temp%\ixp000.tmp\zwwltphz.exe %Temp%\ixp001.tmp\keymaker.exe
You should also download and run Spybot search and destroy and delete what it finds.

If

May 21, 2009 | HP Compaq Presario V3000T Notebook

1 Answer

Windows Freezing


Boot the system in safe mode
1.) restart the system
2.) pump the F8 Key until a screen comes up with different options
3.) select safe mode,

Try right clicking there and see what happens,, I,m guessing here this is a result of damages done by a previoulsy removed virus (GUESSING) it is possible that the same one could have been shard by all 3,,

I'd advise you'd uninstall norton and use the new avg free
www.free.grisoft.com
Let me know what hgappens and we can tgake this a bit further

Jul 14, 2008 | Microsoft Windows XP Home Edition

1 Answer

",.exe" (comma.exe) causing a problem


Its your OS affected by virus..

Mar 04, 2008 | Computers & Internet

Not finding what you are looking for?
Computers & Internet Logo

Related Topics:

19 people viewed this question

Ask a Question

Usually answered in minutes!

Top Computers & Internet Experts

Les Dickinson
Les Dickinson

Level 3 Expert

18424 Answers

Doctor PC
Doctor PC

Level 3 Expert

7733 Answers

David Payne
David Payne

Level 3 Expert

14162 Answers

Are you a Computer and Internet Expert? Answer questions, earn points and help others

Answer questions

Manuals & User Guides

Loading...