HardwareHeaven.com

HardwareHeaven.com

Looking for the skin chooser?
 
 
  • Home

  • Hardware reviews

  • Articles

  • News

  • Tools

  • Gaming at HardwareHeaven

  • Forums

 

Go Back   HardwareHeaven.com > Forums > Software / Tools > Windows XP / 2000 / NT / 9x Forum


Windows XP / 2000 / NT / 9x Forum Discussion for Windows operating systems from XP right back to the very beginnings!

Reply
 
Thread Tools
Old Nov 18, 2004, 06:04 AM   #1
HardwareHeaven Lover
 
Join Date: Oct 2003
Location: Look up!
Posts: 234
Rep Power: 0
SkyBum is on a distinguished road

Donator
ID this application: tft4dmod.exe (google couldnt....)

I've been cleaning up my sister's family PC from spyware etc. (Adaware came up with 768 entries!!!) anyway, got that all under control.

There is an application listed in windows startup called tft4dmod.exe which I can't find any information on at all. I've tried multiple search engines but they all come back with no results. Under the startup tab in System Configuration Utility it shows up like this:

Startup Item: tft4dmod
Command: tft4dmod.exe
Location: HKCU/SOFTWARE/Microsoft/Windows/CurrentVersion/Run

One other thing that seems strange to me is that if I run a file search (including hidden files) no results are found. How can this be? The application is running at startup!

Can anyone ID this app? And how can there be no info on this .exe through the search engines? Sorta makes me suspicious of it.

PC is an eMachine T2692
__________________

Last edited by SkyBum; Nov 18, 2004 at 06:13 AM.
SkyBum is offline   Reply With Quote


Old Nov 18, 2004, 07:30 AM   #2
Member
 
Join Date: Mar 2003
Posts: 5,989
Rep Power: 71
PangingJr is just really nicePangingJr is just really nicePangingJr is just really nicePangingJr is just really nice

will try to get an info of the file,
here's thing you can do at your end D/L and run the win32 version of this program "Autoruns"
( http://www.sysinternals.com/ntw2k/fr...autoruns.shtml ), the autoruns.exe,
it'll give you the discription and location (image path) of the file. post back the info you find out.
PangingJr is offline   Reply With Quote
Old Nov 18, 2004, 07:47 AM   #3
Delete Me
 
Join Date: Mar 2004
Posts: 14,648
Rep Power: 0
pr0digal jenius is a name known to allpr0digal jenius is a name known to allpr0digal jenius is a name known to allpr0digal jenius is a name known to allpr0digal jenius is a name known to allpr0digal jenius is a name known to all

is it by any chance a TFT lcd monitor, Toshiba makes one called a TFT and the last portion fo the product ID if 4D?

that's all i can come with, but i'll keep looking
pr0digal jenius is offline   Reply With Quote
Old Nov 18, 2004, 08:00 AM Threadstarter Thread Starter   #4
HardwareHeaven Lover
 
Join Date: Oct 2003
Location: Look up!
Posts: 234
Rep Power: 0
SkyBum is on a distinguished road

Donator
"is it by any chance a TFT lcd monitor?"

That occured to me as well but the monitor is just a basic 15" flat screen. The system has never had anything else.


Ctrl-Alt-Del: I'm on it, will post back shortly...
__________________
SkyBum is offline   Reply With Quote
Old Nov 18, 2004, 08:28 AM Threadstarter Thread Starter   #5
HardwareHeaven Lover
 
Join Date: Oct 2003
Location: Look up!
Posts: 234
Rep Power: 0
SkyBum is on a distinguished road

Donator
Ran Autoruns.

The last entry under HKCU/SOFTWARE/Microsoft/Windows/CurrentVersion/Run was for: Z0o4RjNFi, no Description, no Publisher, but the image path said: file not found: tft4dmod.exe, can I assume that Ad-Aware or Spybot S&D must have removed this file?

I did a quick search on Google for Z0o4RjNFi and came up with only one link: http://castlecops.com/check60483previous.html, which made reference to Z0o4RjNFi along with tscnetsh.exe

What do you suppose we are dealing with here?
__________________
SkyBum is offline   Reply With Quote
Old Nov 18, 2004, 08:47 AM   #6
Delete Me
 
Join Date: Mar 2004
Posts: 14,648
Rep Power: 0
pr0digal jenius is a name known to allpr0digal jenius is a name known to allpr0digal jenius is a name known to allpr0digal jenius is a name known to allpr0digal jenius is a name known to allpr0digal jenius is a name known to all

looks like something that syware removal removed the file and nto the reference, perhaps?
pr0digal jenius is offline   Reply With Quote
Old Nov 18, 2004, 08:50 AM Threadstarter Thread Starter   #7
HardwareHeaven Lover
 
Join Date: Oct 2003
Location: Look up!
Posts: 234
Rep Power: 0
SkyBum is on a distinguished road

Donator
Quote:
Originally Posted by pr0digal jenius
looks like something that syware removal removed the file and nto the reference, perhaps?
That would be my guess, I'm just curious what such an obscure executable like that was up to......could have been harmless as well but it just makes me wonder...
__________________
SkyBum is offline   Reply With Quote
Old Nov 18, 2004, 08:58 AM   #8
Delete Me
 
Join Date: Mar 2004
Posts: 14,648
Rep Power: 0
pr0digal jenius is a name known to allpr0digal jenius is a name known to allpr0digal jenius is a name known to allpr0digal jenius is a name known to allpr0digal jenius is a name known to allpr0digal jenius is a name known to all

plotting world domination for some pimply faced socially detractive college student no doubt
pr0digal jenius is offline   Reply With Quote
Old Nov 18, 2004, 09:01 AM   #9
Member
 
Join Date: Mar 2003
Posts: 5,989
Rep Power: 71
PangingJr is just really nicePangingJr is just really nicePangingJr is just really nicePangingJr is just really nice

it is a bad Run registry.

place the folder "autoruns" anywhere you like or move it to your \Program Files,
create a shortcut to the "autoruns.exe", this will set the program's registry settings for you, just to make sure it'll work correctly.

then reopen the program, and uncheck the box in front of that line. close the program and reboot your PC. once you are in Windows, recheck in the autoruns.exe, to see if any new entry has been added, if none, R-click on the line and select Delete,
you can Export the registry entry before deleting it if you like.
PangingJr is offline   Reply With Quote
Old Nov 21, 2004, 03:44 PM   #10
DriverHeaven Junior Member
 
Join Date: Nov 2004
Location: Michigan, USA
Posts: 25
Rep Power: 0
Prime2515102 is on a distinguished road

Just a quick question here...

Wouldn't there be an error message when you boot up saying the file in autorun couldn't be found if it didn't exist?

Prime
Prime2515102 is offline   Reply With Quote
Old Nov 21, 2004, 04:02 PM   #11
Member
 
Join Date: Mar 2003
Posts: 5,989
Rep Power: 71
PangingJr is just really nicePangingJr is just really nicePangingJr is just really nicePangingJr is just really nice

you probably won't get any error message at bootup if the image path is missing fron the Run registry, whether the .exe file does exist or not.

if the file didn't exist but the image path is still in registry, in this case you will get an error message that says the file couldn't be found.
PangingJr is offline   Reply With Quote
Old Nov 21, 2004, 04:13 PM   #12
DriverHeaven Junior Member
 
Join Date: Nov 2004
Location: Michigan, USA
Posts: 25
Rep Power: 0
Prime2515102 is on a distinguished road

Ahh ok, thanks

Prime
Prime2515102 is offline   Reply With Quote
Old Nov 21, 2004, 06:17 PM Threadstarter Thread Starter   #13
HardwareHeaven Lover
 
Join Date: Oct 2003
Location: Look up!
Posts: 234
Rep Power: 0
SkyBum is on a distinguished road

Donator
Not getting any error messages at all....
__________________
SkyBum is offline   Reply With Quote
Old Nov 21, 2004, 07:00 PM   #14
Member
 
Join Date: Mar 2003
Posts: 5,989
Rep Power: 71
PangingJr is just really nicePangingJr is just really nicePangingJr is just really nicePangingJr is just really nice

that's why i told you it was a bad registry..
since only the registry value data (it was the image path in this case) had been removed, but the value name was still existing.
so i liked to see whether or not the .exe file still in your system, sometimes it's there but it does not have ability to write a new autorun registry by itself.

-----------------

and without a good Run registry key the .exe cannot be started.

if none of the 3rd party programs that you previously used could not locate the leftover file (if any), or not all of them, then the method that i've mentioned would be a way that you can use to find out or it can help you locate the file.


-

Last edited by Ctrl-Alt-Del; Nov 21, 2004 at 07:27 PM.
PangingJr is offline   Reply With Quote
Old Nov 26, 2004, 02:18 PM   #15
DriverHeaven Addict
 
Join Date: Nov 2003
Posts: 307
Rep Power: 0
refraction is on a distinguished road

it probably was spyware, i have had that file before, altho i think the letters are random on the filename, it probably was a bit of spyware, but due to you running ad-aware it god rid of most of it.



if you did the smart scan best idea is to run the full scan and see if there are any bits left anywhere.
__________________
[color=royalblue]Computer Specs[/color] := [color=royalblue]AMD Opteron 146 2.0Ghz @ 2.9Ghz[/color] = [color=royalblue]1024Mb PC4400 RAM Dual Channel[/color] = [color=royalblue]Gainward BLISS 7900GTX 512mb[/color] = [color=royalblue]SB Audigy 4 [/color]= [color=royalblue]250Gb SATA Hard Drive[/color] = [color=royalblue]Thermaltake Xaser Case [/color]= [color=royalblue]Benq FP91G+[/color][color=royalblue] 19" TFT[/color]
refraction is offline   Reply With Quote
Reply

Thread Tools