is system32/root/system32.exe a virus?

quiclslvr

Banned
Local time
1:51 PM
Messages
42
when i installed windows 7 any version after installing the drivers a dialog box poped up saying system32.exe has stopped working and many such box appeared at once....then when i got a software called combofix.exe which was a boon to me and ran then in the result it deleted system32/root/system32.exe and system32/root folder too,,,,, then pc worked and no such warning again

my question is
1. is that path which i have mention is not needed
2. was that virus
3, does Ur c drive contains that folder or not please confirm me friends...
4,,,in reality (healthy pc) that path and directory is available or it was only created in my pc and later deleted....is that directory needed or not
4. main strange is that when it is been deleted and pc works well then when i re install any version of win 7 same thing repeated and i have to run the software again,,,why does it reappears in each installation with drive formatting even though it is deleted



plese help me exeperts with the solution that same thing doesn't appear in new installation
 

My Computer

OS
win 7
Last edited by a moderator:

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Employer provided Dell Latitude
OS
W7 Pro SP1 64bit
CPU
i7
Memory
8GB
Graphics Card(s)
Intel HD Graphics
Hard Drives
crappy SSD
Antivirus
Employer mandated Symantec Endpoint Protection
Browser
Pale Moon 64bit, IE11 64bit & Chrome 64bit
thanks for reply but why ...will that software harm?
 
Last edited by a moderator:

My Computer

OS
win 7
Last edited by a moderator:

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Employer provided Dell Latitude
OS
W7 Pro SP1 64bit
CPU
i7
Memory
8GB
Graphics Card(s)
Intel HD Graphics
Hard Drives
crappy SSD
Antivirus
Employer mandated Symantec Endpoint Protection
Browser
Pale Moon 64bit, IE11 64bit & Chrome 64bit
There is no \Windows\system32\root directory on my system. Was it created by one of the device driver installs?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Lenovo IdeaCenter 450
OS
Windows 10 Pro X64
CPU
Intel Quad Core i7-4770 @ 3.4Ghz
Memory
16.0GB PC3-12800 DDR3 SDRAM 1600 MHz
Graphics Card(s)
Intel Integrated HD Graphics
Sound Card
Realtek HD Audio
Monitor(s) Displays
HP 22" LCD
Screen Resolution
1680 x 1050
Hard Drives
250GB Samsung EVO SATA-3 SSD
2TB Seagate ST2000DM001 SATA-2
1.5TB Seagate ST3150041AS SATA
Keyboard
Dell USB
Mouse
Lenovo USB
Internet Speed
Cable via Road Runner 3MB Upload, 30MB Download
Antivirus
Windows Defender, MBAM Pro, MBAE
Browser
Seamonkey
Other Info
UEFI/GPT
PLDS DVD-RW DH16AERSH
quiclslvr,

You have posted this issue not only here, but also saw it at BleepingComputer.

ComboFix 13-03-24.03 - Dare2winn 03/27/2013 21:40:46.1.4 - x64, found the following in your system:

c:\windows\root\system32.exe

It is manifesting on the following Active Setup Registry key:

HKLM_Wow6432Node-ActiveSetup-{08B0E5JF-4FCB-11CF-AAA5-00401C6XX500} - c:\windows\root\system32.exe

The CLSID: {08B0E5JF-4FCB-11CF-AAA5-00401C6XX500} is associated with a Trojan.
ComboFix did remove it, though.

As to ComboFix, it is not a scan for the everyday user to casually run on a computer, and see what it finds. Its output, the ComboFix log, in many cases requires further actions in the form of a script.
It is a tool specifically created for the use of malware eradicators that have been trained on its operation.
Even then, it is used cautiosly, and only when it is called for.

Since you already posted at the BleepingComputer forums prior to coming here, I suggest you follow up with the guidance given to you there.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
2. was that virus

Most likely. Viruses like to camouflage themselves by either naming themselves after a common known system file to avoid detection or corrupting a system file and taking over the function, along with added virus code injected into the process.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Hell oh Well
OS
Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
CPU
Intel Core 2 Duo 2.93GHz
Memory
Not much with my ADHD
Graphics Card(s)
ATI Radeon HD 4350
Monitor(s) Displays
24" HDTV/Monitor
Screen Resolution
Blurry after a Scotch or 2
Hard Drives
1 HDD 250 GB, 1 HDD 1 TB, 3 - 1 TB Externals
Case
Don't get on my case...man :D
Cooling
I have an Air Conditioner & Diet Pepsi
Keyboard
Saitek Cyborg
Mouse
10 yr old MS optical mouse that still works
Internet Speed
Never fast enough
Antivirus
Various
Browser
Various

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
I don't know, that's what I'm asking you :D

What is in it? Maybe something there will give you a clue to its origin.

You can rename \system32\root to system32\root-save then reboot and see how the system runs. If okay then after a bit you can delete it, but if it's not very big, why not just leave it alone unless you can determine where it came from?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Lenovo IdeaCenter 450
OS
Windows 10 Pro X64
CPU
Intel Quad Core i7-4770 @ 3.4Ghz
Memory
16.0GB PC3-12800 DDR3 SDRAM 1600 MHz
Graphics Card(s)
Intel Integrated HD Graphics
Sound Card
Realtek HD Audio
Monitor(s) Displays
HP 22" LCD
Screen Resolution
1680 x 1050
Hard Drives
250GB Samsung EVO SATA-3 SSD
2TB Seagate ST2000DM001 SATA-2
1.5TB Seagate ST3150041AS SATA
Keyboard
Dell USB
Mouse
Lenovo USB
Internet Speed
Cable via Road Runner 3MB Upload, 30MB Download
Antivirus
Windows Defender, MBAM Pro, MBAE
Browser
Seamonkey
Other Info
UEFI/GPT
PLDS DVD-RW DH16AERSH
The virus must be hiding somewhere. The OP will have to pay attention to when it reappears.
 

My Computer

OS
Windows 7 Home Premium x64
Repeated:

System32.exe seems like a virus to me (Read comments down on this page: system32.exe Windows process - What is it?). You must have formatted only one of your partitions ( probably C: ) during Windows 7 installation. The malware is probably resides on some other partition which can easily infect your system again. Use MalwareBytes to clean your system along with a good anti virus software.
 
Back
Top