|
| Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free! |
loadcfg32.exe
|
Original Message
|
Name: ChRiS A
Date: March 14, 2002 at 09:57:46 Pacific
Subject: loadcfg32.exe
|
Comment: Today my Norton AV software notified me that i had a "backdoor.trojan" on my system infecting the file "loadcfg32.exe" within my D:\Windows\System32 folder. It couldn't repair the file nore gain access to it, so all i could do was remove it. I sent it to a floppy disk (incase the system needed the file, and for other purposes) and rebooted doing another system scan and this time everything was fine. My question though is what is the loadcfg32.exe file, and what is it for? Do i need it, and is there a way of getting the file cleaned? Like i say i have it on floppy, would it be good to send it to Symantec? -ChRiS
Report Offensive Message For Removal
|
|
Response Number 1
|
Name: robert451
Date: March 14, 2002 at 11:20:42 Pacific
|
Reply: All I found on this is a German site related to trojans.I did not see it listed as any windows program.I would keep floppy handy just in case.
Report Offensive Follow Up For Removal
|
|
Response Number 2
|
Name: oaxixao
Date: March 14, 2002 at 11:37:32 Pacific
|
Reply: http://www.computing.net/security/wwwboard/forum/98.html This artical was talk about before. The loadcfg32.exe is not part of Windows that I am aware of since I have tried to search for it and none was found. The search including hidden folders/files. OAxIxAO
Report Offensive Follow Up For Removal
|
|
Response Number 3
|
Name: Rick Smith
Date: March 16, 2002 at 11:26:45 Pacific
|
Reply: I discovered this after running a Norton virus scan on WINXP Pro. I also noticed that the "Security" tab is no longer available on the XP file/folder Properties sheet. Weird! Any one have any ideas? Feel free to Email me directly, that would be great. Rick
Report Offensive Follow Up For Removal
|
|
Response Number 4
|
Name: Felt
Date: March 30, 2002 at 16:38:59 Pacific
|
Reply: i'm not sure what this does either, but I came accross this file when my zonealarm said it was trying to access the internet. As far as I can remeber, the only programs I installed were system mechanic, and specifically the incenerator utility that comes with it. It is ment to throughly wipe any file from your harddrive. Anyway, whenever I "incenerate" something, this loadcfg32 thing attempts to acces the internet. So it's a pretty safe assumption that it is connected to this. What type of information or for what purposes can only be guessed at, but I have a feeling that it's nothing good. It also attempts to connect spurratically (i don't really know how often, or if it's a set interval), but I use zonealarm and do not allow it access to the internet. Not sure if I should delete it, but I am going to report it to the people at ad-aware and see what they make of it. My 2 cents, later.
Report Offensive Follow Up For Removal
|
|
Response Number 5
|
Name: Felt
Date: March 30, 2002 at 22:45:51 Pacific
|
Reply: I was wrong. I have no idea what this came bundled with. It attempts to acces the internet every few seconds and that was about how long it takes that incinerator program to work, so it just was timed odd. Anyway, I use Windows ME, and the only way that I could remove this was by going into the registry becasue the file was always in use. Go to "HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RunServices /" and the registry value is "Configuration Loader." Delte that then restart your computer. Then go to C:\Windows\System\Loadcfg32.exe and delete it. My comptuer still works fine, so this is in no way an important file. If it pops back up again i'll try to figure out exactly what it is bundled in, but for now just be happy with the solution. Later.
Report Offensive Follow Up For Removal
|
|
Response Number 7
|
Name: michael
Date: July 14, 2002 at 05:57:45 Pacific
|
Reply: I had this virus, i think it should be safe to delete because when I checked the properties of the file, there was nothing to say that this is linked in anyway to microsoft.
Report Offensive Follow Up For Removal
|

Post Locked
This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
Go to Security and Virus Forum Home
Results for: loadcfg32.exe
loadcfg32.exe Summary: Very easy : 1) user Regedit to remove the loadcfg32.exe from HKLM\Software\Microsoft\Windows\CurrentVersion\Run and may be HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce 2) reboot 3) delete c:... www.computing.net/answers/security/loadcfg32exe/98.html
loadcfg32.exe ACCESS DENIED Summary: hi joe, try this: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RunServices / loadcfg32.exe Delete the value of loadcfg32.exe then restart your computer. Then go to C:\Windo... www.computing.net/answers/security/loadcfg32exe-access-denied/1750.html
W32.apolre Summary: hi carrol, if the worm is aplore and not apolre, here's some info for you: This worm combines a VBS mass-mailing routine and includes an IRC bot which may allow an attacker to gain remote access to th... www.computing.net/answers/security/w32apolre/2848.html
|
|

|