DeviiceEject.exe


  1. Posts : 12
    Windows 7 professional 32 bit
       #1

    DeviiceEject.exe


    There is DeviceEject.exe, with one - i -

    Then there is DeviiceEject.exe, with two - ii -

    Both programs are in C:\Windows\System32

    MSE removed a Trojan, and traced it to DeviiceEject.exe, the one with two - ii -

    I tried to get information about DeviiceEject.exe , the one with two - ii -. But nothing exists.

    Can someone, please tell me if this is a legit program. I am about to delete it!
      My Computer


  2. Posts : 53,363
    Windows 10 Home x64
       #2

    Elixxir as I replied in the other thread, this is likely one of many files. Suggest running MalwareBytes from safe mode. It would be wise to scab with a bootable AV program as well. These trojans are insidious, and can hide numerous files.

    See this thread:

    virus removal from within safe mode

    A Guy
      My Computer


  3. Posts : 12
    Windows 7 professional 32 bit
    Thread Starter
       #3

    A Guy said:
    Elixxir as I replied in the other thread, this is likely one of many files. Suggest running MalwareBytes from safe mode. It would be wise to scab with a bootable AV program as well. These trojans are insidious, and can hide numerous files.

    See this thread:

    virus removal from within safe mode

    A Guy
    I scanned with MalwareBytes in Safe Mode as you suggested, and followed it up with MSE scan. But everything was clean.

    However, I was stilled troubled that I could not find any information about DeviiceEject.exe (two - ii -). I went ahead and renamed the file DeviiceEject.bak. Since, I renamed the file, I have not experienced any problems at all. In fact, it seems as if internet no longer lags; there used to be a split second lag, but now there is instant response.

    Should I go ahead and delete the file?

    (I must also report that people have responded to e-mails which I did not send, but seemed to originate from my e-mail address)
      My Computer


  4. Posts : 927
    windows 7 ultimate
       #4

    I'd give it a couple of days + just to make sure nothing is broken. But to be honest, with a typo like that in its name, I would probably ignore my own advice and just bin it!
      My Computer


  5. Posts : 53,363
    Windows 10 Home x64
       #5

    Files such as this, with just slightly altered names of legit files are a common method used by Trojans. They use an extra letter, or a capital instead of the legit files lower case (svchost legit, svcHost not legit, etc.). You can upload any of these suspect files to Virus Total A fake file will not have the correct md5 sum, and it will not say the file has already been scanned, but instead will make a new scan.

    I think you are safe to rename, and eventually delete, but you want to make sure you are no longer infected. Emails being sent is another telltale sign of infection. Often sending an attached file to spread the infection, or even spam if your system has been taken over by a bot.

    Scanning with a bootable AV disk is suggested, as it runs outside of windows, and will not let these files load. A rootkit scan would also be wise

    Panda Anti-Rootkit - Free software downloads and software reviews - CNET Download.com

    for instance is free, and does run fine on my x64 Home Premium.

    A Guy
      My Computer


 

Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 05:25.
Find Us