We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide

System32.1exe

Can anyone please help. I kept getting pop ups saying critical system errors have been detected, or registry corrupt or buffer overun in messenger service allows remote code execution and various others. These all direct me to repairmyreg.com or some other variant which offers to scan and fix my system.

Trying to stop this I have installed ZoneAlarms free firewall - and this now tells me that system32.1exe is trying to connect to the internet.


I have also updated the antivirus to the latest AVG.

What do I do next??????????????

Thanks

Comments

  • pks00
    pks00 Posts: 559 Forumite
    Looks like you got some dodgy stuff installed. Try some Spyware removal software
    Freeones like adaware, spy bot


    Look at the sticky on this forum - spyware removal
    http://forums.moneysavingexpert.com/showthread.html?t=133269
    :hello:

    Surviving A Day In The Office
    9am Switch on PC, 9.05am - Check Email, 9.10am - Download Virus, 9.30am - Call Helpdesk, 10am - Relax all day whilst engineer fixes problem!

    Shopping Tips
    Don't spend five pounds to dry clean a shirt. Donate it to the charity shop instead. They'll clean it and put it on a hanger. Next morning buy it back for two pounds.
  • GreenNotM
    GreenNotM Posts: 1,087 Forumite
    Poing - how long have you been on the internet without a firewall ? just curious as most investigations say it takes on average 10-12 mins to get infected without a fire wall.

    First thing to do is if you get a pop up - do not click any buttons - just close it by clicking the "x" top right corner.
    Do not allow system32.1exe to access the internet ! Put a tick in the box to "remember this action " when u click deny.

    Are you familiar with the ZoneAlarm Control Centre ? If so look at the program control tab and see what programs/processes are accessing the internet - right click the dodgy looking ones and set as deny.

    Follow the actions in the above post. Do the downloads and installs - print the post if need be - turn off system restore - boot to safe mode - run anti- virus/mal/spyware keep rebooting to safe mode and running till clear. When you def can't clear what you have - get back set IE to med/high security to stop any nasties running without asking. Somebody here may ask you to post a HiJackThis log here or on another site, if you still have problems.

    Good luck
    Rich people save then spend.
    Poor people spend then save what's left.
  • Browntoa
    Browntoa Posts: 49,620 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    I'd do an initial scan with restore on in this case

    System32 is a legitamate process, I wonder if they have just mistyped the name in this case

    no point in losing your restore points unless you really have to

    I hope the scans will come up clean
    Ex forum ambassador

    Long term forum member
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 353.5K Banking & Borrowing
  • 254.1K Reduce Debt & Boost Income
  • 455K Spending & Discounts
  • 246.6K Work, Benefits & Business
  • 602.9K Mortgages, Homes & Bills
  • 178.1K Life & Family
  • 260.6K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.