What is _ex-08.exe, How to remove _ex-08.exe
This is a harmful program.
It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. |
Name: _ex-08
Filename: _ex-08.exe
Registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | PromoReg
Command: C:\WINDOWS\Temp\_ex-08.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [PromoReg] C:\WINDOWS\Temp\_ex-08.exe
Description: Trojan.Agent
How to remove: use MalwareBytes Anti-malware.
October 5th, 2009 at 9:25 am
Hello… i found this file constantly running and eating up CPU…so i tried unsuccessfully to delete it…manually to the trash. After i received a slap for such a weak effort i tried removal thro spybot…everytime it id’s it it crashes spybot!!!! i then tried MS Config and turned it off; along with its associated prefixes (anything with the same prefix)….result computer no longer starts up meaning am a complete idiot.
Basically i get a start up screen and everything is ok then screen stays black and only my cursor (and safe mode titles are visable) i cant access my right click menu and i cant access ctrl-alt-del menus either….
Can sombody please please please help!
Gareth – considering a full time idiot title!
October 7th, 2009 at 8:34 am
Try also SuperAntispyware. If it does not help you, then ask for help in Spyware removal forum.
November 28th, 2009 at 4:15 pm
Question: I have this virus on my computer, but every time I start my computer up and log into my name, it says \
February 19th, 2010 at 4:30 pm
This is a fairly low-intrusion however, its obnoxious because anything which uses a DLL gets shut down unless you’re browsing. Its purpose is to log password information and to repopulate itself.
If you have a back-end tool such as the one available through logmein.com (remotely anywhere), it’s pretty dang easy to get rid of. However, if you’re using your computer as a normal user, it might pose to be problematic.
This plants itself in only a few locations.
C:\Documents & Settings\All Users\Application Data\ (a random series of 8 or 9 numbers)
c:\WINNT\Temp\_ex-08.exe
You’ll likely find both running in the background (processes) – the randomly generated 8 or 9 digit number, and the _ex-08.exe. You cannot remove either of these until you end the process. If you can accomplish that w/o the trojan’s detection, the rest is a piece of cake.
Delete the entire folder under the documents & settings (the one w/ a bunch of random generated numbers) and the actual _ex-08.exe
Now its time to open the registry.
(start menu, run, regedit, press enter)
Go to: HKey_Local_machine>Software>Microsoft>Windows>Current Version>Run
Locate the 2 items in there which resemble what you just removed from your folders.
Now for the last bit in the registry: Current_user>Software>Microsoft>Windows>MUICache – this is where it gets a little difficult. You need to locate the two again and there are a ton of things here. Just find the random generated number and the _ex-08.exe
Once you’ve located those and removed them, you’re done. I’ve noticed that in some computers, the random generated one is NOT in the MUI cache, only the _ex-08.exe is.
Reboot and be happy that you got rid of the thing.