Ive got this program sitting in my C:/ drive and it won't go away. Live OneCare has blocked it from the internet but i just want to get rid of it to keep a clean system. Can anyone help me?

Recommended Answers

All 3 Replies

prunnex.exe is malware. Download and install Malware/Trojan scanner http://www.malwarebytes.org/

After installation, update it, and run a scan, it should find the file and remove it. Post back here and let us know how you are doing...

Good luck!

Thanks!
I ran the scan but it wan't able to delete the mshelp.exe....
heres the log:

Malwarebytes' Anti-Malware 1.31
Database version: 1528
Windows 5.1.2600 Service Pack 3

21/12/2008 15:23:23
mbam-log-2008-12-21 (15-23-23).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 120909
Time elapsed: 1 hour(s), 0 minute(s), 52 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 4
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 5

Memory Processes Infected:
C:\WXP\system32\mshelp.exe (Trojan.Downloader) -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\prunnet (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\prunnet (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Generic Host Process for WinXP Services (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\Generic Host Process for WinXP Services (Trojan.Downloader) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WXP\system32\prunnet.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\sg\Local Settings\Temp\wcrnomaesx.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\sg\Local Settings\Temp\prun.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WXP\system32\mshelp.exe (Trojan.Downloader) -> Delete on reboot.
C:\WXP\system32\sqla.dll (Trojan.Downloader) -> Quarantined and deleted successfully.

It seems that it found and removed the file in many locations on your pc. It also looks as if you should be ok, regarding this specific file now, after you rebooted. After reboot you may run malware bites again just to make sure. Let us know if you are back to normal now?

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.