SHOP PRODUCTS
Houzz Logo Print
andyf_gw

twunk_16.exe, (twunk_32) Can't delete

andyf
14 years ago

(Win XP,SP3,IE8)

I can't delete these in c:\windows. Well they delete, then they are built again. All this takes 5 seconds, and they return with the same timestamp and date. Same thing through the command line.

My question is What are these?

I tried to capture the process that rebuilds these by ctrl/alt/del, but the process is too fast for me to analyse.

My next option is to corrupt the files thru Debug, then change the time stamp to the original, hopefully to trick the monitoring program to think no change is occuring. The monitor may be cheksuming the program, if so then the Debug option won't work.

If successful the program when executed will throw a programming error, (probably divide by zero)then the owner won't know what the &^&*^ is happening.

But I need to know if the files are hostile first.

Thanks.

Andy

Comments (4)

  • zep516
    14 years ago

    "What are these"

    Twain_32.dll Client's 16-bit Thunking Server. Phew! Let's jump straight away to layman terms ! First, TWAIN : TWAIN is originally derived from "Technology Without An Important Name". TWAIN, or as it is most commonly know, the TWAIN Driver, is a program that is packaged with all scanners and which allows the user to scan images or text directly from the scanner into the application that will be used to manipulate the image or text. Thus, most graphics programs, and many of the newer Microsoft Office programs, enable you to scan a document directly into the program.

    http://searchtasks.answersthatwork.com/tasklist.php?File=Twunk_16

    And

    http://www.processlibrary.com/directory/files/twunk_16/

    The reason it keeps coming back is it's loading from the windows registry at start up.

    Double check for Malware always when unsure:

    Try running a Malwarebytes scan. Let it remove everything it finds. So make sure you click remove selected after scan is finished. Also after you download the free version it's important to click the update tab and let Malwarebytes update before scanning with it.

    http://www.malwarebytes.org/

    Then run an ESET on line scan.

    Then:

    The below guide is basic information for using CCleaner.

    http://reclaimyourgame.com/index.php?option=com_content&view=category&layout=blog&id=71&Itemid=95

    Then:

    Clean out your temporary internet files and temp files.

    Download TFC by OldTimer http://oldtimer.geekstogo.com/TFC.exe to your desktop.

    Double-click TFC.exe to run it.

    Note: If you are running on Vista, right-click on the file and choose Run As Administrator

    TFC will close all programs] when run, so make sure you have saved all your work before you begin

    * Click theStart button to begin the cleaning process.
    * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
    * Please let TFC run uninterrupted until it is finished

    Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

  • ravencajun Zone 8b TX
    14 years ago

    in most cases I have seen them they were part of a scanner or printer so if you have one you use on that pc I sure would not try to remove it.

    that is usually a very legit file however in some cases there are malware that mimic the name, if you want to check the individual ones on your pc why not just summit them to virus total and see what it shows.
    Virustotal

    and or Jotti's
    Jotti's

  • andyf
    Original Author
    14 years ago

    zep516

    Thanks for the info!

    Both ESET Smart Sec 4 and Spybot see nothing wrong with these files. These are my two protection of the system. Malwarebytes I ran 4 days ago and shows nothing malicious either.

    Spybot, the less prominent of the virus detect suite, seems to work harder than all of them. It catches Bluestreak,doubleclick, and Medi-(whatever) cookies every time and now I have them blocked because it actually displays the originating site, which can be entered in IE under bad sites. It's doing a good job keeping these nuisances out of my system.

    I created this thread only because I browsed the system directory, not because I suspected anything wrong. My PC seems to be functioning normally.

    Usually once a year I have it cleaned regardless.

    Andy

  • andyf
    Original Author
    14 years ago

    Thanks Raven

    Will do

    Andy