Re: file exphard.exe memory hog, help

From: Rick \ (rick_at_mvps.org)
Date: 10/20/04


Date: Tue, 19 Oct 2004 21:30:11 -0400

Hi,

It's a trojan, delete the one in the prefetch folder, then follow these
"relatively" simple removal steps:

Restart in Safe mode by hitting F8 as Windows first begins to load on boot.
Logon as administrator.

Start/search/files and folders, look for <filename> and delete it wherever
it is found.

Start/run regedit, expand the + signs to look under these keys:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg

Look in the right hand pane for the string or strings that load that file.
Delete just those strings that contain the reference. Do not delete other
strings or the keys from the left pane. Close the registry editor when
completed, make sure you check all strings.

Go to the Control Panel/System/System Restore tab. Check the box to "Turn
off system restore on all drives". Click apply/ok. This will remove all
restore points, however you don't want them back as some or all of them will
contain the virus depending upon how recently you got infected.

Restart the system normally. Go back to the Control Panel/System and restart
System Restore.

Update your antivirus software, run a full system scan.

-- 
Best of Luck,
Rick Rogers, aka "Nutcase" - Microsoft MVP
http://mvp.support.microsoft.com/
Associate Expert - WindowsXP Expert Zone
www.microsoft.com/windowsxp/expertzone
Windows help - www.rickrogers.org
"Pat82" <Pat82@discussions.microsoft.com> wrote in message 
news:C372193B-E002-4085-8646-60AEF5CD1FF8@microsoft.com...
> My computer's been real, real slow.  ctrl/alt/del, then process tab yields
> the file exphard.exe is utlizing like 50mb-70mb (floating around) of ram.
>
> I chose to 'end process' (selected the file) and the pc is back to normal
> speed.
>
> I recently tried to install XP sp2 (ordered the cd from MS) and was
> unsuccessful.  It didn't complete the install and the computer attempted 
> to
> do an undelete and restore.  Wondering if this file has something to do w/ 
> XP
> sp2.
>
> I searched google and it brought back nothing via exphard or exphard.exe
> word  search.
>
> I searched my pc for the file and this is what it returned.
> name: exphard.exe-07DDE2B4.pf
> in folder:  c:\windows\prefetch
> size: 54kb
> type file: pf file.
>
> anyone have a clue why this file is active and eating up so much memory? 


Relevant Pages

  • Re: sraytb.exe
    ... Restart in Safe mode by hitting F8 as Windows first begins to load on boot. ... Look in the right hand pane for the string or strings that load that file. ...
    (microsoft.public.windowsxp.general)
  • Re: canti.exe
    ... It's a trojan (virus) file. ... Restart in Safe mode by hitting F8 as Windows first begins to load on boot. ... Look in the right hand pane for the string or strings that load that file. ...
    (microsoft.public.windowsxp.general)
  • Re: adminamok
    ... Restart in Safe mode by hitting F8 as Windows first begins to load on boot. ... Look in the right hand pane for the string or strings that load that file. ... off system restore on all drives". ...
    (microsoft.public.windowsxp.newusers)
  • Re: LIBVGA.EXE???
    ... Restart in Safe mode by hitting F8 as Windows first begins to load on boot. ... Look in the right hand pane for the string or strings that load that file. ... off system restore on all drives". ...
    (microsoft.public.windowsxp.general)
  • Re: RE : After installing SP2 my Start-Menu disappear...
    ... Last time I restore to previous restore-point and it worked, ... But when I install Norton Antivirus few days ago, ... I'll try to use XP CD to repair Windows, but don't know if it will ... >>> restart the computer in normal mode ...
    (microsoft.public.windowsxp.general)