• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

Malware Removel.. atmclk.exe, dcomcfg.exe

Pheonix_789

New Member
Joined
Nov 6, 2005
Messages
178 (0.03/day)
Location
Canada Edmonton Alberta
Processor Pentium D 805 @ 3.8Ghz
Motherboard Asus P5N-E SLI
Cooling Igloo 5600 X2 92mm High CFM Fans
Memory 2.0Gb Dual DDR 5300 667Mhz@ 760Mhz
Video Card(s) Geforce 7600 GT @ 650Mhz Core 1.7Ghz Mem
Storage 250Gb Sata 2 HD
Display(s) LG Flattron 19in flatscreen CRT
Case Thernaltake Matrix VX
Audio Device(s) Intergrated
Power Supply 500 watt Thermaltake Pure Power
Software Windows XP Pro SP2
I keep getting a annoying pop-ups when I am not even surfing the internet, I have downloaded several programs to remove this problem with no success, I have discovered what the malicious programs are and I am having a lot of difficulty removing it, I have used a program called Prevx1 to quarantine them but is there a way to permanently remove them?


-atmclk.exe 10kb
-dcomcfg.exe 10kb


I have used and downloaded the following programs with no sucess:

-Adaware
-Avast home edition
-System mechanic Pro
-Webroot Spywaresweeper
-Prevx1
-XP repairer PRO


Is there a way to remove the problem without reinstalling Windows XP?
 
Joined
Dec 18, 2005
Messages
8,253 (1.23/day)
System Name money pit..
Processor Intel 9900K 4.8 at 1.152 core voltage minus 0.120 offset
Motherboard Asus rog Strix Z370-F Gaming
Cooling Dark Rock TF air cooler.. Stock vga air coolers with case side fans to help cooling..
Memory 32 gb corsair vengeance 3200
Video Card(s) Palit Gaming Pro OC 2080TI
Storage 150 nvme boot drive partition.. 1T Sandisk sata.. 1T Transend sata.. 1T 970 evo nvme m 2..
Display(s) 27" Asus PG279Q ROG Swift 165Hrz Nvidia G-Sync, IPS.. 2560x1440..
Case Gigabyte mid-tower.. cheap and nothing special..
Audio Device(s) onboard sounds with stereo amp..
Power Supply EVGA 850 watt..
Mouse Logitech G700s
Keyboard Logitech K270
Software Win 10 pro..
Benchmark Scores Firestike 29500.. timepsy 14000..
something else is creating them.. something is causing them to run with a windows or browser start up.. windows wont let u delete files that are in use.. which is a basic problem..

one trick to disable a file u might think is causing problems but arnt sure is to rename it.. or create a new folder and put the file in it.. but again windows in a self protective manner wont often let u do this..

somehow u have to stop them running then delete them and anything associated with them.. plus find out how u got them in the first place..

i use an oem win pe disk for such things.. not much help if u cant lay your hands on a copy.. but i wouldnt be without mine..

trog
 
Joined
Apr 8, 2006
Messages
714 (0.11/day)
System Name Xbox 360 Super Elite
Processor 3.2GHz PowerPC Tri-Core Xenon
Memory 512MB 700MHz GDDR3 RAM
Video Card(s) ATI Xenos @ 500 MHz
Storage 250GB
Display(s) 26" Samsung LCD HDTV
Case Super Elite (COD:MW2 Edition)
Audio Device(s) 5.1
Power Supply 120w
Software NXE
try running SpyBot, it has the option of running at windows start up. so it maybe able to remove this malware before it even loads.

http://www.spybot.info/ :nutkick:
 
Joined
May 27, 2005
Messages
3,651 (0.53/day)
Location
Little Rock Arkansas, United States
System Name Monolith
Processor Intel Xeon E3110 Wolfdale@3.5GHz
Motherboard MSI P35-Neo
Cooling Active Air
Memory 4GB DDR2 800
Video Card(s) Sapphire HD 3850 512MB PCI-E
Storage 1 x 80GB Internal, 1 x 250GB Internal, 1 x 40GB External
Display(s) Acer X203w
Case Generic black case with locking front bezel
Audio Device(s) Creative SB Audigy 2 ZS
Power Supply 500 Watt Seasonic M12
Software Windows 7 Ultimate x64
Go to Start > Run > Type msconfig > Press enter > Choose "Diagnostic Startup" > Press Ok > Restart computer > attempt to delete files.

Diagnostic startup does not allow internet access. It loads basic programs/drivers that allow the computer to function at it's minimum capacity.
 

DominicStockford

New Member
Joined
May 5, 2006
Messages
2 (0.00/day)
I am getting the same malware. Having used Prevx1 to try to remove it, and also started up in safe mode to try to remove it, I have had no success. The programmes are allegedly in jail, according to Prevx1, but one is still active and the files have vanished from view. Have they transmogrified into something else? Anyone any ideas?
 

DominicStockford

New Member
Joined
May 5, 2006
Messages
2 (0.00/day)
Update! It only affects one of the user names on the computer. Maybe there is a way I can copy all my email from Outlook over to the Outlook in the other user name and then just close the affected user down? Does anyone know of a way to do that?
 

Polaris573

Senior Moderator
Joined
Feb 26, 2005
Messages
4,268 (0.61/day)
Location
Little Rock, USA
Processor LGA 775 Intel Q9550 2.8 Ghz
Motherboard MSI P7N Diamond - 780i Chipset
Cooling Arctic Freezer
Memory 6GB G.Skill DDRII 800 4-4-3-5
Video Card(s) Sapphire HD 7850 2 GB PCI-E
Storage 1 TB Seagate 32MB Cache, 250 GB Seagate 16MB Cache
Display(s) Acer X203w
Case Coolermaster Centurion 5
Audio Device(s) Creative Sound Blaster X-Fi Xtreme Music
Power Supply OCZ StealthXStream 600 Watt
Software Windows 7 Ultimate x64
Download Hijack this. Run it and post the log, maybe there is something running at startup that needs to be deleted.
 
Joined
Mar 26, 2005
Messages
1,807 (0.26/day)
Location
Hamburg
Processor Intel I7 2600k@ 4.5
Motherboard Gigabyte p67 ud4 b3
Cooling AC Cuplex kryos Hf
Memory 8096 Exceleram 1600@ 1333 Cl9 1.35v
Video Card(s) Palit Gtx570@950/1900@1.063v
Storage Ocz Vertex 3 120gb, 2tb Seagate 7200rpm s-ata3
Display(s) Asus 24inch Lcd
Case Coolermaster Cosmos S
Audio Device(s) Creative X-fi with Teufel Magnum Power Edition
Power Supply Coolermaster 700W Silent Pro Gold
Software Linux?^^ ;P Windows 7 64bit

usctrojansfan04

New Member
Joined
May 7, 2006
Messages
2 (0.00/day)
Hey Pheonix_789, I used to have the same problem. Here's the solution:

Please download SmitfraudFix (by S!Ri) (http://siri.urz.free.fr/Fix/SmitfraudFix.zip)
Extract the content (a folder named SmitfraudFix) to your Desktop.

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Then select option #2 (Clean) - It will find the problem, but will at first not be able to fix it because it is being used by another process. Then allow it to reboot, and SmitfraudFix will appear at start up and clean the annoying buggers.

Note: For me, when SmitfraudFix appeared at start up to clean the malware, it said it had an error cleaning the files. If it does display that, just click ignore and it will delete them once and for all!
 

Azn Tr14dZ

New Member
Joined
Mar 2, 2006
Messages
5,288 (0.80/day)
Processor AMD Athlon 64 3200+
Motherboard DFI LanParty nf4 Ultra-D
Cooling Thermaltake Big Typhoon
Memory 2x512MB GeIL
Video Card(s) ATI Radeon X800XL
Storage 2x80GB Western Digital
Display(s) HP vs17
Case SuperTalent
Audio Device(s) Soundblaster
Power Supply Ultra X-Finity 500 Watt
And if nothing else works, I always do a clean re/install of Windows XP. My comp used to never shut down and I would have to manually shut it down each time until I did a clean re/install of Windows XP. It took 2 hours but cleaned out everything and works faster. Only do it though if nothing else works.
 

Mercenary4

New Member
Joined
Feb 5, 2006
Messages
116 (0.02/day)
Location
Planet Earth
Processor Intel P4 3.0e
Motherboard Abit IS-7
Cooling Vantec, except ThermalTake video memory coolers and Logisys duct
Memory 4X Corsair 256Mb DDR400(PC3200)
Video Card(s) ATI AIW AGP 2006 Edition
Storage Western Digital Raptor 37Gb
Display(s) Envision 17" CRT
Case FMI/CompUSA
Audio Device(s) Creative Labs Soundblaster Audigy2 ZS w/4.1
Power Supply E-Power Puma II
Software XP2 w/Live, ATI CCC/MMC, ATI Tool, Creative HQ, Logitech, FutureMark, Rockstar
Have you tried MS's Beta: Windows Defender2 or MS's Beta: Windows Live Safety Center? They may work, or not. Never had any infections on my rigs (well except my wifes rig, go figure), but still run these new Beta security software from MS for giggles and grins.

The Windows Defender Beta 2.0 runs before log on, so it may work. Once you do manage to clean out the malware, clean your registery to ensure complete removal.
 

EveryoneHasItInThem

New Member
Joined
May 7, 2006
Messages
2 (0.00/day)
The latest release of Prevx1 v.1.2.0.33 will remove this

I would give Prevx1 another try. I tried the latest release v.1.2.0.33 last night and it sorted it perfectly. You should see the clean up list it builds, quite amazing and very thorough. Shows why so many of the products we all use are struggling with this.

According to prevx support there are a number of these nasties out there which some AVs and Antispyware are detecting but failing badly to disinfect and cleanup. This latest release of Prevx1 includes a ton of new clean up techniques. They also said another even more powerful version is hot on the heels. Should be out sometime next week.

Here's the post back from prevx support:

"Thanks for reporting your issues with the removal of ATMCLK.EXE. We're sorry you had problems. Prevx1 detects and disables this infection but where a new user has a prior infection Prevx1 was having difficulty disinfecting and cleaning up. These issues are now fixed in v.1.2.0.33 which shipped for new users late in the day on May 6th. Existing users of v.1.2.0.2 will be receiving an automatic update early Monday.

v.1.2.0.33 includes a lot of new clean up functionality. It has been built to deal with really persistent 'state-of-the-art' spyware and malware infections like Free.Serials, Spy Falcon, Spyware Quake (occasionally these are referred to as you say SmitFraud).

If you de-install v.1.2.0.2 and install Prevx1fresh from the web site then it will sort your problems. Or you could wait for the update kit early next week. Personally, I'd get this thing off now!

As ever let us know if you have any further issues. We are totally committed to giving you the best Antivirus, Antispyware and Anti-malware protection we can.

Regards
Prevx Support"

I am still using the 60 day free trial and this has performed brilliantly for 3 weeks now and support as you can see is fantastic. Might be well worth the $20 to use it long term.

Good luck
 

nwadel

New Member
Joined
May 7, 2006
Messages
1 (0.00/day)
I've tried Prevx, doesn't work, it just keeps it in jail but the next day the trojan comes back. Tried the other suggestions, didn't work. Any other ideas?
 

EveryoneHasItInThem

New Member
Joined
May 7, 2006
Messages
2 (0.00/day)
Sorry, I got it wrong

Sorry, my fault for wasting your time.

You need run v.1.2.0.34 of Prevx1 not v.1.2.0.33 as I stated in my previous email.

This is currently only available as a fresh download and install (must de-install earlier versions first including v.1.2.0.33). It will then run the advanced cleanup and disinfection which will remove this once and for all.

Also Prevx support say that v.1.2.0.34 will also be available as an upgrade next week.
 

jcokkinias

New Member
Joined
May 8, 2006
Messages
1 (0.00/day)
Here's how u do it

Caution. . . Use the Registry Editor at your own risk. If you are not familiar with the registry, take you computer to someone who is.

Open Registry Editor (regedit).

Go to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies
Under this key you should see a key named "explorer" with a sub key named "run".
You can probably deleted the entire "explorer" key, but if you don't feel comfortable doing this you can go into the "run" key and delete the following three string values:
1. dcomcfg.exe
2. kernel32.exe
3. wininet.dll

After u have done this you can reboot and now you can delete these three files:
1. %systemroot%\system32\dcomcfg.exe
2. %systemroot%\system32\atmclk.exe
3. %systemroot%\system32\regperf.exe

Now you are cleaned up, no more popups.
 

emptymind

New Member
Joined
May 9, 2006
Messages
1 (0.00/day)
usctrojansfan04 said:
Hey Pheonix_789, I used to have the same problem. Here's the solution:

Please download SmitfraudFix (by S!Ri) (http://siri.urz.free.fr/Fix/SmitfraudFix.zip)
Extract the content (a folder named SmitfraudFix) to your Desktop.

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Then select option #2 (Clean) - It will find the problem, but will at first not be able to fix it because it is being used by another process. Then allow it to reboot, and SmitfraudFix will appear at start up and clean the annoying buggers.

Note: For me, when SmitfraudFix appeared at start up to clean the malware, it said it had an error cleaning the files. If it does display that, just click ignore and it will delete them once and for all!


Thanks for posting that link, I have been trying for ages to remove that spyware, even Norton 2006 would not see it but what you posted worked 100%

Many Thanks
 

JVansia

New Member
Joined
May 9, 2006
Messages
1 (0.00/day)
I Have a solution!

Hey guys, ok this virus/spyware has been a major annoyance but i think i've found a way to get rid of it. atmclk.exe and dcomcfg/exe were sitting comfortable in my C:\WINDOWS\System32 directory, trying to directly delete them was hopeless as they would either regenerate each other or would say that these files are locked and so windows could not delete them, so i figured there must be some software out there that lets you delete locked files...and there is.

Download any good program to delete locked files upon rebooting ur comp, enter the 2 bastards above and voila its off ur comp. Just FYI its likely that there are other things on ur comp that would like to see those files back on ur C:\\ so i'd advise doing full anti-virus, spyware and adware scans as soon as the files have been deleted. The software i used was EMCO MoveOnBoot and has seemed to work wonders....however when i update my msn messender, the files seem to come back and i had to delete them again, but so far, no sign of them and its been a few days. Was so relieved to get red of that damned yellow triangle! Hope it works for you to! - Jugal Vansia. :D
 
Joined
Dec 18, 2005
Messages
8,253 (1.23/day)
System Name money pit..
Processor Intel 9900K 4.8 at 1.152 core voltage minus 0.120 offset
Motherboard Asus rog Strix Z370-F Gaming
Cooling Dark Rock TF air cooler.. Stock vga air coolers with case side fans to help cooling..
Memory 32 gb corsair vengeance 3200
Video Card(s) Palit Gaming Pro OC 2080TI
Storage 150 nvme boot drive partition.. 1T Sandisk sata.. 1T Transend sata.. 1T 970 evo nvme m 2..
Display(s) 27" Asus PG279Q ROG Swift 165Hrz Nvidia G-Sync, IPS.. 2560x1440..
Case Gigabyte mid-tower.. cheap and nothing special..
Audio Device(s) onboard sounds with stereo amp..
Power Supply EVGA 850 watt..
Mouse Logitech G700s
Keyboard Logitech K270
Software Win 10 pro..
Benchmark Scores Firestike 29500.. timepsy 14000..
the remove on boot software is a good idea.. it gets around the windows not letting u delete a file while its in use factor very well..

the only real downside is u have to know exactly what files to aim it at.. if u do its clever idea..

trog
 

GroundMeat

New Member
Joined
May 10, 2006
Messages
1 (0.00/day)
The files are launched by the registry..

[This is just a copy from another board: Original Post]

Hi demerzel. Please download SmitfraudFix (by S!Ri)
Extract the content (a folder named SmitfraudFix) to your Desktop.

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present). [EDIT] if you restart in safe mode and run this program, you can clean the system, however it can take a long time to clean up depending on your system and the infection level[/EDIT]

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.

[This is just a copy from another board: Original Post]
 
Last edited:

Comporit

New Member
Joined
May 10, 2006
Messages
8 (0.00/day)
My Comp is Safe

usctrojansfan04 said:
Hey Pheonix_789, I used to have the same problem. Here's the solution:

Please download SmitfraudFix (by S!Ri) (http://siri.urz.free.fr/Fix/SmitfraudFix.zip)
Extract the content (a folder named SmitfraudFix) to your Desktop.

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Then select option #2 (Clean) - It will find the problem, but will at first not be able to fix it because it is being used by another process. Then allow it to reboot, and SmitfraudFix will appear at start up and clean the annoying buggers.

Note: For me, when SmitfraudFix appeared at start up to clean the malware, it said it had an error cleaning the files. If it does display that, just click ignore and it will delete them once and for all!

I was so desperate, I googled the name of dcomcfg.exe file! This forum came up and thanks to usctrojansfan04, I can go to sleep and have my computer for another day. The thought of reformatting was horrible.

Thanks, usctrojansfan04!
:roll: :roll:
 

Tatty_Two

Gone Fishing
Joined
Jan 18, 2006
Messages
25,801 (3.87/day)
Location
Worcestershire, UK
Processor Rocket Lake Core i5 11600K @ 5 Ghz with PL tweaks
Motherboard MSI MAG Z490 TOMAHAWK
Cooling Thermalright Peerless Assassin 120SE + 4 Phanteks 140mm case fans
Memory 32GB (4 x 8GB SR) Patriot Viper Steel 4133Mhz DDR4 @ 3600Mhz CL14@1.45v Gear 1
Video Card(s) Asus Dual RTX 4070 OC
Storage WD Blue SN550 1TB M.2 NVME//Crucial MX500 500GB SSD (OS)
Display(s) AOC Q2781PQ 27 inch Ultra Slim 2560 x 1440 IPS
Case Phanteks Enthoo Pro M Windowed - Gunmetal
Audio Device(s) Onboard Realtek ALC1200/SPDIF to Sony AVR @ 5.1
Power Supply Seasonic CORE GM650w Gold Semi modular
Mouse Coolermaster Storm Octane wired
Keyboard Element Gaming Carbon Mk2 Tournament Mech
Software Win 10 Home x64
Also, and perhaps an easier way is load windows in "safe mode", then it will load with minimal drivers, you should then be able to go into Windows explorer and delete the little monsters as their associated files should not be running, then just re-boot normally, it has worked for me in the past.
 

Comporit

New Member
Joined
May 10, 2006
Messages
8 (0.00/day)
Tatty_One said:
Also, and perhaps an easier way is load windows in "safe mode", then it will load with minimal drivers, you should then be able to go into Windows explorer and delete the little monsters as their associated files should not be running, then just re-boot normally, it has worked for me in the past.

Thanks. Actually, I did that and the buggers wouldn't budge. Then, I restored my system to a month ago and THAT didn't help. I SAW the files in the directory and couldn't get them out...I'm relieved and am glad I found this forum.

:)
 
Joined
Dec 18, 2005
Messages
8,253 (1.23/day)
System Name money pit..
Processor Intel 9900K 4.8 at 1.152 core voltage minus 0.120 offset
Motherboard Asus rog Strix Z370-F Gaming
Cooling Dark Rock TF air cooler.. Stock vga air coolers with case side fans to help cooling..
Memory 32 gb corsair vengeance 3200
Video Card(s) Palit Gaming Pro OC 2080TI
Storage 150 nvme boot drive partition.. 1T Sandisk sata.. 1T Transend sata.. 1T 970 evo nvme m 2..
Display(s) 27" Asus PG279Q ROG Swift 165Hrz Nvidia G-Sync, IPS.. 2560x1440..
Case Gigabyte mid-tower.. cheap and nothing special..
Audio Device(s) onboard sounds with stereo amp..
Power Supply EVGA 850 watt..
Mouse Logitech G700s
Keyboard Logitech K270
Software Win 10 pro..
Benchmark Scores Firestike 29500.. timepsy 14000..
i have been useing a little proggy i have carried from system to system for some some years called StartMgr.exe..

it just lists the things that start up with windows and easily lets u switch them on or off..

the secret is to switch off all the junk u dont want or need and then keep a regular eye on what does start up.. if u see something new appear and u dont know for sure exactly what it is.. be suspicious..

after a while u can just look at it and know exactly what should be running and what shouldnt..

i have about ten items listed in my start manager and i know exactly what each one is.. if u dont prune this start up list on a regular basis tons of extra junk gets fired up with windows and most of it u dont need.. the malware and virus crap gets hidden amonst the junk.. clean out the junk and its easy to spot..

trog
 

gygabite

New Member
Joined
Dec 18, 2005
Messages
486 (0.07/day)
Location
Aschaffenburg,Germany
Processor AMD Athlon X2 4200+, not overclocked yet ;)
Motherboard MSI K8N Neo4-F @5x220MHz
Cooling Alphacool Cool-answerII Dual80 !!! ;-)
Memory 2GB Corsair XMS DDR 400 2-2-2-5 Dual-Channel
Video Card(s) Powercolor GameFX Radeon X850XT
Case AOpen H600C
Audio Device(s) Onboard
Power Supply Revoltec ChromusII RPS-450 V2
Software WinXP-Home SP2
Aw, i have atmclk.exe , too, but none of your tipps helped me, so the only chance i have is to format C: :wtf:
 
Top