What is capilocx.exe?

Discussion in 'General Chat' started by BenjArriola, Oct 13, 2006.

  1. #1
    Now sure if this is the best place to ask this, but there seems to be no forum topic on PC files. I have one process running on my PC that is capilocx.exe, I searched online and found no info about it. It is in the c:\windows\system32\ directory. Just ran Ad-Aware and Spybot, all they found were just cookies. Has anyone encountered this file?
     
    BenjArriola, Oct 13, 2006 IP
  2. BenjArriola

    BenjArriola Peon

    Messages:
    175
    Likes Received:
    18
    Best Answers:
    0
    Trophy Points:
    0
    #2
    Still no reply from anyone on this. I just cancelled the process one time and I noticed after a few minutes it came back.

    I cannot delete the file, so I renamed it instead.

    Will still keep researching what this file is all about.
     
    BenjArriola, Oct 18, 2006 IP
  3. genkied

    genkied Active Member

    Messages:
    2,025
    Likes Received:
    39
    Best Answers:
    0
    Trophy Points:
    90
    #3
    hi kabayan na benj my desktop also have that kind of file...i just rename it... please update me if you found some very interesting info about is file.
     
    genkied, Oct 18, 2006 IP
  4. timsdd

    timsdd Peon

    Messages:
    21,102
    Likes Received:
    1,019
    Best Answers:
    0
    Trophy Points:
    0
    #4
    wow, not only have I never come across it, it seems no one else out there has either. I just spent 12.4 minutes trying to find any mention of it online and your thread here is the only hit!

    the only other thing I might suggest, is to find your self a 'process viewer' (I have one in System Mechanic 6 for instance but you can find apps online as well), that way if you ever see it running again or any file for that matter - you can at least see who 'owns' it.

    OR maybe submit it to a Anti-virus company? they could at least tell you if it's harmful - not sure if they would give you any more information than that.
     
    timsdd, Oct 19, 2006 IP
  5. Correctus

    Correctus Straight Edge

    Messages:
    3,453
    Likes Received:
    389
    Best Answers:
    0
    Trophy Points:
    195
    #5
    Send me a Hijackthis log and I'll see what I can do. Maybe I can try to find it out, also send me a log of all programs installed on your PC.

    Maybe its just an OCX component:

    http://www.webopedia.com/TERM/O/OCX.html

    Possibly the part of a Windows update? Have you done any recently?

    IT
     
    Correctus, Oct 19, 2006 IP
  6. BenjArriola

    BenjArriola Peon

    Messages:
    175
    Likes Received:
    18
    Best Answers:
    0
    Trophy Points:
    0
    #6
    Well updates about this capilocx.exe ....

    After searching for capilocx on my hard disk...

    1. I found a file in c:/windows/system32/
    2. I found a file in c:/windows/Prefetch/
    3. I found a file in one of the temp folders.

    I opened them all up in notepad (even if they are binary files and not ascii files) and the files in the temp folders had a bunch of garbage characters as suspected since it is compiled in some way, but I do see a few words like... keystroke, position, etc. So I was already convinced I have some type of spyware on my computer.

    I searched RegEdit and found a value with capilocx.exe that is part of the IE toolbar stuff and I deleted that.

    Since I cannot delete the capilocx.exe and other files, I rebooted and pressed F8 and chose Command Prompt/Safe Mode and deleted the files oldschool DOS style.

    I was convinced it was a keylogger, I never saw it running again. PC seems to be running fine now.

    Disclaimer: If you plan on doing something like this... and your computer get's messed up, don't blame me if you deleted from entries in your Windows Registry. I would follow timsdd's suggestion if you are not comfortable messing with the registry.

    Genkied - Kabayan, so I wonder what did you install, that I have installed too? Hmmm...

    Correctus - Nope it's not an OCX component. And everyone else in the office where I work who also did Windows Updates did not have the file.
     
    BenjArriola, Oct 23, 2006 IP
  7. genkied

    genkied Active Member

    Messages:
    2,025
    Likes Received:
    39
    Best Answers:
    0
    Trophy Points:
    90
    #7
    Genkied - Kabayan, so I wonder what did you install, that I have installed too? Hmmm...



    nope, it is a weird file hehehhehhe
     
    genkied, Oct 23, 2006 IP
  8. timsdd

    timsdd Peon

    Messages:
    21,102
    Likes Received:
    1,019
    Best Answers:
    0
    Trophy Points:
    0
    #8
    thanks for the U/D, good move cleaning it old school.

    and yeah, anytime you jack with the registry - watch out ;)
     
    timsdd, Oct 23, 2006 IP