Re: what is fcfB.exe?

From: David H. Lipman (DLipman~nospam~_at_Verizon.Net)
Date: 02/24/05


Date: Thu, 24 Feb 2005 07:08:28 -0500

An alternmate, but similar, set of instructions to that of Kelly's.

Dump the contents of the IE Temporary Internet Folder cache (TIF)

start --> settings --> control panel --> internet options --> delete files

1) Download the following three items...

         Trend Sysclean Package
         http://www.trendmicro.com/download/dcs.asp

         Latest Trend Pattern File.
         http://www.trendmicro.com/download/pattern.asp

         Adaware SE (free personal version v1.05)
         http://www.lavasoftusa.com/

Create a directory.
On drive "C:\"
(e.g., "c:\New Folder")
or the desktop
(e.g., "C:\Documents and Settings\lipman\Desktop\New Folder")

Download Sysclean.com and place it in that directory.
Download the Trend Pattern File by obtaining the ZIP file.
For example; lpt442.zip

Extract the contents of the ZIP file and place the contents in the same directory as
sysclean.com.

2) Update Adaware with the latest definitions.
3) Disable System Restore
        http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm
4) Reboot your PC into Safe Mode and shutdown as many applications as possible
5) Using both the Trend Sysclean utility and Adaware, perform a Full Scan of your
        platform and clean/delete any infectors/parasites found.
        (a few cycles may be needed)
6) Restart your PC and perform a "final" Full Scan of your platform using both the
        Trend Sysclean utility and Adaware
7) Re-enable System Restore and re-apply any System Restore preferences,
        (e.g. HD space to use suggested 400 ~ 600MB),
8) Reboot your PC.
9) Create a new Restore point

* * * Please report your results ! * * *

-- 
Dave
http://www.claymania.com/removal-trojan-adware.html
"bob engler" <engler@0sand1s-software.com> wrote in message
news:RdfTd.18810$q04.15699@fe03.lga...
| A neighbor has WINXP on a compaq that was very infected. Running
| Norton Virus 2005 and Spybot I got rid of most problems. I found some
| leftover viruses and manually deleted them. There is still a program
| named fcfB.exe running when I use taskmanager. I ended it but it came
| back in seconds while I watched taskmanager and replicated itself
| constantly until I rebooted.
| Any ideas what it is and if I need to do something with it.
| Also, how do I delete a file with "Share" on doing attrib on it? I tried to
| delete 'w?wexec.exe' but couldn't and it showed 'share'.
|
| Thanks.......
|
|
|


Relevant Pages

  • Re: mszx23.exe Trojan
    ... (e.g., "c:\New Folder") ... Download Sysclean.com and place it in that directory. ... If you are using WinME or WinXP, disable System Restore ... Reboot your PC into Safe Mode and shutdown as many applications as possible ...
    (microsoft.public.security.virus)
  • Re: System Freeze - 100% CPU Usage
    ... (e.g., "c:\New Folder") ... Download SYSCLEAN.COM and place it in that directory. ... Reboot your PC into Safe Mode and shutdown as many applications as possible ... Re-enable System Restore and re-apply any System Restore preferences, ...
    (microsoft.public.windowsxp.general)
  • Re: 100% CPU Usage
    ... folder probably caused by interference by an AV scan during the Update ... Stop and Disable Automatic Updates, ... Now Reboot Again. ... Go to http://wiki.djlizard.net/Dial-a-fix and download Dial-a-fix ...
    (microsoft.public.windowsupdate)
  • Re: rulechinbait.exe anybody?
    ... (e.g., "c:\New Folder") ... Download Sysclean.com and place it in that directory. ... Reboot your PC into Safe Mode and shutdown as many applications as possible ... Re-enable System Restore and re-apply any System Restore preferences, ...
    (microsoft.public.windowsxp.general)
  • Re: "about:blank" home page
    ... THEN REBOOT AND RUN THEM AGAIN TO BE SURE ALL FILES ... > Unzip the Download file in a NEW FOLDER that you can create before you start ... > DO NOT install in your Desktop folder. ... > Download Registrar Lite 2.0, ...
    (microsoft.public.windows.inetexplorer.ie6.browser)