Unsolved
This post is more than 5 years old
6 Posts
0
3946
January 22nd, 2004 12:00
still seeking solution to Randex
my norton virus protection tells me it can not remove, also can not quarantine. virus name W32.Randex and the object is C:/Windows/system32/spoole32exe
does anyone know what this spoole is? Is it safe to delete? What will I lose? Is there a safe way to get rid of the Randex? All solutions I have seen relate to randex with letters following, but this one does not.
Thanks for any and all help
No Events found!


BBlackie
426 Posts
0
January 22nd, 2004 13:00
Hi tholar. Have you followed the instructions found here to remove the virus?
http://securityresponse.symantec.com/avcenter/venc/data/w32.randex.e.html
BBlackie
426 Posts
0
January 22nd, 2004 14:00
I think that the spoole is a legitimate program that is being interfered with by the trojan. Typically, most files that begin with *spool* are related to the print spooler for a printer. It may not be, but if you rid yourself of the trojan, this message might disappear.
tholar
6 Posts
0
January 22nd, 2004 14:00
BBlackie
426 Posts
0
January 22nd, 2004 15:00
Message Edited by BBlackie on 01-22-2004 11:17 AM
tholar
6 Posts
0
January 22nd, 2004 15:00
ChrisRLG
2 Intern
•
3.9K Posts
0
January 22nd, 2004 20:00
----------------------
Use these to remove Malware (Spyware and Adware).
1) SpyBot Search and Destroy
After installing SpyBot Search & Destroy, first press Online, and search for, put a check mark at, and install all updates.
Next, close all Internet Explorer windows, hit 'Check for Problems', and have SpyBot remove all the items it marks in red.
2) Get Ad-Aware
After installing Ad-Aware, and before running the program, first press “check for updates now".
Click "Connect" and install all updated components available. Click 'Finish'.
Press "Scan Now", then 'next', and let Ad-Aware scan your drives.
It will find a number of "bad" files and registry keys. Click 'Next' again.
Check all found items, and click 'next' once more.
It will ask you whether you'd like to remove all checked items. Click OK.
Always reboot the computer between each program - both of these may find things that they need to have a reboot of the machine to clear - please reboot and let them finish .
Failing those solving your problems a post of a hijackthis log for the experts to advise.
HijackThis From Here
Important: Create a folder on the C: drive called C:\HJT.
You can do this by going to My Computer (Windows key+e) then double click on C: then right click and select New then Folder and name it HJT.
Unzip HijackThis into this folder. When you run HijackThis from this folder and have it "Fixed checked" it will create a backup file of modifications to use if restore is necessary. Then run, scan, save log, then in notepad copy the FULL log by copy and paste as a reply to this post and an expert with HijackThis Knowldge, will have a go at giving advice. Please note the list of experts names below, very few forum regulars here have had this training.
DO NOT FIX ANYTHING WITH HIJACKTHIS WITHOUT EXPERT ADVICE, most of what it finds you need for normal MS Windows tasks.
Known Spyware HijackThis fighters in DellTalk - If you are, and are not on the list please PM Me.
TomCoyote (of http://tomcoyote.org/forums/index.php fame)
YoKenny (Accredited Expert at TomCoyotes)
baskar1234 (Spyware Classroom Teaching Assistant at TomCoyotes)
ChrisRLG (Spyware Classroom Teaching Assistant at TomCoyotes)
Yellowhammer (In Training at TomCoyotes)
therock247uk (In Training at TomCoyotes)
irelynmisses (In Training at TomCoyotes)
You could also go to one of the more specalist forums where more experts will be able to help.
http://tomcoyote.org/forums/index.php
http://forums.spywareinfo.com/index.php
http://www.net-integration.net/cgi-bin/forum/ikonboard.cgi (Home of Spybot S&D)
http://boards.cexx.org/index.php
Do read the sites FAQ before posting, and advise your problem and what steps you have already done to try to cure your problem.
I, and the other hijack experts mentioned above, are in all those sites (and more) with the same login names. You might get one of us at those sites also to anwser your log, but other experts will also be available.