anupam_luv Posted November 29, 2021 Author Share Posted November 29, 2021 @visshaJust did some risky experiment... The file setup.exe get downloaded to c:\windows\performance which has admin rights to copy any file .... it means there is some file in process which is loaded with admin rights which is trying to download that file... So what I did is, in the Norton history I restored that removed setup.exe file .... Cut it and moved it to another Virtual machine running windows 10 without any antivirus .. I checked its properties ... It is Remote Utilities version 6.10 ... I extracted this file , it has a fie version.txt which has following content FILEVERSION 6,10,10,0 PRODUCTVERSION 6,10,10,0 FILEFLAGSMASK 0x3F FILEFLAGS 0x0 FILEOS VOS_UNKNOWN | VOS__WINDOWS32 FILETYPE VFT_APP FILESUBTYPE 0x0 { BLOCK "StringFileInfo" { BLOCK "040904E4" { VALUE "CompanyName", "Remote Utilities LLC" VALUE "FileDescription", "Remote Utilities" VALUE "FileVersion", "6.10.10.0" VALUE "LegalCopyright", "Copyright © 2019 Remote Utilities LLC. All rights reserved." VALUE "ProgramID", "com.remoteutilities.SfxExtractor" VALUE "ProductName", "Remote Utilities" VALUE "ProductVersion", "6.10.10.0" } } BLOCK "VarFileInfo" { VALUE "Translation", 0x409, 1252 } } This setup file is same at https://www.remoteutilities.com/download/host6.10.exe which was renamed as setup.exe .... Both files has exact same size and content but first one detected as virus and other is clean ... I extracted its contents and compared... Both are exactly same bit by bit ... Now I have to check which program want me to download remote utilities.... Israeli_Eagle and vissha 2 Quote Link to comment Share on other sites More sharing options...
anupam_luv Posted November 29, 2021 Author Share Posted November 29, 2021 Just found in autoruns under services "Remote Utilities-Host" and removing its all traces in file system and registry.... will restart and check if the problems appears again ... vissha and Israeli_Eagle 2 Quote Link to comment Share on other sites More sharing options...
Israeli_Eagle Posted November 29, 2021 Share Posted November 29, 2021 (edited) 3 hours ago, MrZeb said: As I posted the guys at bleepingcomputer can help you cleaning the computer only in very bad cases you have to do a clean install... On that weird bleeping planet any help or tools to clean the registry are not allowed, instead they wanna you to publish your privacy & files history. LMAO... And only super-n00bs would ever reinstall the system. Edited November 29, 2021 by Israeli_Eagle Quote Link to comment Share on other sites More sharing options...
Solution anupam_luv Posted November 30, 2021 Author Solution Share Posted November 30, 2021 @vissha @MrZeb Mission accomplished.... removed all traces of "Remote Utilities-Host" from my PC, registry services.... and more interestingly there were some related setup files hidden in C:\Windows\Performance folder which were not only hidden but ther were visible after I unchecked "Hide Protected operating system files" ... means these files were marked as important to run operating system ... thats why the antivirus or antimalware was not even scanning them... cleaned all that clutter and in that process i felt that i might have deleted some genuine windows files , so i reinstalled windows 11 again .... Till now restarted 4-5 times , no "setup.exe" file bothering to run now.... but a strange SecurityCenter.bat file is there in my startup folder... it contains the following command taskkill /f /im explorer.exe start explorer.exe exit /B Dont know why it there ? why would a program want explorer to be restarted on startup? Can I safely delete it? vissha and MrZeb 1 1 Quote Link to comment Share on other sites More sharing options...
Israeli_Eagle Posted November 30, 2021 Share Posted November 30, 2021 (edited) If the different explorer.exe is not in the normal folder C:\Windows then you can simply delete it. And also delete that .bat as well. Edited November 30, 2021 by Israeli_Eagle anupam_luv 1 Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.