PDA

View Full Version : PCTSPK.EXE = Bad Guy



Mighty_Jah
09-01-07, 11:51
Just encountered a nice little file in the system processes, so heads up on pctspk.exe, its supposed to be some kinda PCTEL modem file.

What it does is, claim 99% of system resources, grinding your pc to a halt leaving you with a locked up system, and in my case not even allowing windows to boot up.

at first I could end its task then search for the file, delete it and all would be as normal, after a reboot it would show up again in task manager, I probably could have used msconfig to halt its execution from the start up, but as it now stands I power up, HDD led is solid and remains that way, resulting in a non booting PC.

Im not that bothered about re-formatting the drive etc, and usually make sure I have important stuff backed up to my storage drives anyway, I could probably rescue it, in safe mode with command prompt, but as it stands I cant even get a safe mode boot.

Any suggestions??? before I wipe it from all existance.

Regards Mighty... :wink:

Firerat
09-01-07, 12:01
Mount the drive in Linux and remove the file ;)

You could use a live CD like www.knoppix.org

Now NTFS support isn't great , but in the least you can overwrite teh file

Then boot up Windows and clean up your registry

Mighty_Jah
09-01-07, 12:17
Cheers dude, Lol sounds like another one of your attempts to convert me to Linux :lol: , I could just bang another HD in as Master put the poxed drive in as slave then try deleting the file that way, but I fear It may re-appear after the first shutdown when rebooted as a master, do you reckon renaming the file would make any difference, till I muster the energy to re-format?

Cheers Mighty... :wink:

Anonymous
09-01-07, 12:21
[Removed at the request of the author]

Mighty_Jah
09-01-07, 12:42
Cheers PP...Got it on my Usb stick as we speak, will try it later when I get home, was also thinking of a system restore if I get a boot, just to take it back a few days, dunno how I ended up getting poxed, Im usually quite careful what I DL or install, on researching the little blighter, sounds like it could have been all manner of things from Phone Software to printer installations, sound applications etc, so Im non the wiser as to how I got it.

I did however download some drivers for a bust Laptop I was repairing, but they were official Dell Modem, Sound & VGA Drivers which non of were actually run on my machine.(obviously)

I like to trace things back to the original source if I can, often helps when I encounter similar probs with other clients PC's.

Cheers Mighty... :wink:

Anonymous
09-01-07, 12:49
[Removed at the request of the author]

Mighty_Jah
09-01-07, 15:23
Yep its a bit of a Doozy, I aint encountered any Nasties this determined to cause havoc in a good while, well not since the last batch of Lsass variants.

Ive pretty much come to the point of having a spare drive with XP and all my drivers as an emergency measure to hand although sometimes I'll install xp to the other drive and set jumpers to slave so I can boot from it in emergencies just by changing the jumper back to master.

Cant be doing without the puter for any length of time, its my world.. :lol:
plus other peeps are relying on me to fix their crap.


Mighty... :wink:

Mighty_Jah
16-01-07, 17:09
The little sh!t crept in again last night.....right its over to drive 2, this ones getting the wipey...grrrrrrrr!!!

Weird thing is ...there has been no trace of the process or the pctspk.exe file for a good few days now, and when I did get it again, did the same fix, killed its process, did search for the pctspk.exe in the sys32 folder, was created 2001 and accessed or executed date was when I did a search for it...!



Note to self: >> must use decent firewall this time!(or Linux)...Slap!!!!


Mighty... :wink:

Anonymous
16-01-07, 17:24
[Removed at the request of the author]

Aaron
16-01-07, 18:05
dude, you need to stop going to 'those sites'... ;) I would have thought you learned from the first time!

cakehead
25-01-07, 22:18
I have just googled the file you mentioned, take a look at what I found. Its to do with a modem driver for a laptop !

http://www.neuber.com/taskmanager/process/pctspk.exe.html