Author Topic: winntify.exe  (Read 4692 times)

0 Members and 1 Guest are viewing this topic.

mootze

  • Guest
winntify.exe
« on: July 06, 2007, 02:22:13 PM »
There's a prompt on the taskbar "Windows Notification Software" that says 29xx attacks and what not on it. Ask me to click on the balloon to start or download the software. I checked the Task Manager and i noticed this process running 'winntify.exe'

I located it in windows/system32 and deleted it.

Hope it works. Need your help to show me the proper way to get rid of this thing.

Thanks.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89689
  • No support PMs thanks
Re: winntify.exe
« Reply #1 on: July 06, 2007, 02:55:28 PM »
You did the right thing in not downloading it, this is a scam and the only thing wrong with your system is likely to be this rogueware.

Apart from the fact that deletion isn't really a good first option (you have none left), 'first do no harm' don't delete. It would have been better if you had first added it to the User Files section of the avast chest and then deleted the original. Since it was in the system32 folder, if you had system restore enabled then it is likely that a restore point was created and a copy of this file (now with a different name, like A0001234.exe, etc.), so you may not have completely removed it.

A new tool RogueRemover, available here http://www.malwarebytes.org/rogueremover.php, this is designed for these type of rogue programs and is worth running just to be sure.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

xiaochugang

  • Guest
Re: winntify.exe
« Reply #2 on: July 07, 2007, 08:37:36 AM »
thanks DavidR ,the new tool  RogueRemover  is great helpful! ;)

xiaochugang

  • Guest
Re: winntify.exe
« Reply #3 on: July 07, 2007, 08:47:58 AM »
But I can`t install the rogueremover into my computer?

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4871
  • I'm a GNU
    • Don't Surf in the Nude!
Re: winntify.exe
« Reply #4 on: July 07, 2007, 08:57:27 AM »
Have you tried the usual free adware/spyware scanners?

AVG Anti-Spyware Free (Requires Win2k/XP)
Ad-Aware Free
Spybot Search & Destroy
SUPERAntiSpyware Free
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

mootze

  • Guest
Re: winntify.exe
« Reply #5 on: July 07, 2007, 11:43:59 AM »
THANKS.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89689
  • No support PMs thanks
Re: winntify.exe
« Reply #6 on: July 07, 2007, 02:43:38 PM »
But I can`t install the rogueremover into my computer?


This is very strange and the first occurrence of rogueremover not being able to be installed I have seen in the forums. It may be worth checking the MalwareBytes (RogueRemover) forums http://www.malwarebytes.org/forums/ and see if there is a similar problem and post if not.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Spiritsongs

  • Guest
RogueRemover
« Reply #7 on: July 07, 2007, 07:15:05 PM »
 :)  Hi all :

     To "install" Rogueremover, you need to "unzip" it, by means of an
     unzipping application, such as WinZip, etc .

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89689
  • No support PMs thanks
Re: winntify.exe
« Reply #8 on: July 07, 2007, 09:00:53 PM »
I think xiaochugang image would appear to indicate that he did ???

Or that the downloaded file wasn't a zip file, http://files4.majorgeeks.com/.../.../spyware/rr-free-setup.exe that would appear to be an installation file not a zip file.
« Last Edit: July 07, 2007, 09:04:27 PM by DavidR »
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

xiaochugang

  • Guest
Re: winntify.exe
« Reply #9 on: July 09, 2007, 07:50:15 AM »
OMG!
Indicate What I did?
I don`t know... :'(
and I can`t download the file from the link that I gave(http://files4.majorgeeks.com/.../.../spyware/rr-free-setup.exe)
... ???

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89689
  • No support PMs thanks
Re: winntify.exe
« Reply #10 on: July 09, 2007, 03:02:25 PM »
The URL was simply to indicate (to SpiritSongs) that rogueremover can come as an executable installation file or as a zip file and if you downloaded it as a zip file you had obviously unzipped it otherwise you wouldn't see the images you posted.

You have pasted the shortened URL 'name' and the underlying URL (with a session code) when you hover the mouse you will see a full URL.

However, you can't download directly from majorgeeks.com as it blocks direct download, you have to go to majorgeeks.com and and then download it (http://majorgeeks.com/RogueRemover_Free_d5360.html). This might be worth downloading again (assuming you didn't get it from majorgeeks.com, use a different location from the original link I gave you) just to ensure that the installation files wasn't corrupt.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security