PC Pitstop is the undisputed leader in PC diagnostics. Our running process library is culled from our database of over 100 million PC diagnostics and scans.

Tip from the PitCrew

Every process running on your computer takes up CPU cycles and valuable memory. For optimal PC performance and resource utilization, you should be aware of every process on your computer. PC Pitstop designed this process library to help you know which processes are worthwhile and others that slow system performance.

Furthermore, perhaps the quickest and most straight forward method to detect malware is through a running process analysis.

Process Library

  

More than one possible match was found; all matches are listed below in order of their prevalence. This only tells you what the file and the correct action might be.

To understand which possibility is actually running on your own system, perform an Overdrive test and then look at the Software|Processes tab.


Match #1

system.exe (W32.Pahatia.A)

Percentage of recently scanned PC's with this process running: 0.00%
Average CPU use for this program: %
Average RAM for this program: MB


PC Pitstop Analysis

system.exe - According to Symantec:

W32.Pahatia.A is a worm that can spread by copying itself into local folders and mapped network drives, and attempts to restart the compromised computer if certain processes are running.


Recommendation

CA AntiVirus

system.exe is a VIRUS. Stop all work until the virus is removed or you run the risk of spreading the virus to other people. Worse yet, the virus may be doing harm to your computer and your information.

system.exe is a virus and should be removed immediately to avoid doing further harm. PC Pitstop recommends CA Antivirus in these types of situations.



Identification

The file name alone identifies this program.


MD5 Hashes

MD5 hashes is the way that computers can define the uniqueness of a file. Anti malware vendors frequently use this technique to detect and clean malware. It is common for a program to have multiple MD5 hashes as the developers create newer versions of the program. For the program called system.exe, we have detected more than 20 different MD5 hashes. Click on a hash to research the hash in Google.
MD5 Report Summary
Program NameMD5 Count
system.exe> 20
#MD5Size
10xf6e547aa92078445aef8d6e052e6f2da24576 bytes
20x381093eb8de6742efe6bfc8393b2f3393593810 bytes
30xdd4ab823aedf142ce4adfacbaa152b865632 bytes
40x109ff58d292a9e7595aeb3e8c9deed0a88593 bytes
50x2fc7ce087fc7c8847c1de12ba5ca14d85120 bytes
60xdb28e581fa8b13b3df14ab34b8a02b48413696 bytes
70x4e53529d8e80be09def364fee569731e89105 bytes
80x6fd6fa259a2c96ced8f38680f22c338358294 bytes
90xd575da1eafb29300f11c00d261889b87278528 bytes
100xda31bc11e509656c1e2538880538964b5548 bytes
110x77471a778e0939c8895b29845479e6ba3922019 bytes
120xd2fd57356cfeb71bb1860b4174e1a0f43705320 bytes
130xf89f34393cf71304e50dcd98e00d570768096 bytes
140xca2aea37449740d6793d9b822dfc3ae559513 bytes
150x97de357f8c81eff102b0d917b8ef324518432 bytes
160x1d82ae45fe993c10b6fad8e8f949135d4256783 bytes
170xa9b802c7b5a436159869f9764ffce2934459810 bytes
180x18e43d53753c21814dca5acb2f459196473088 bytes
190xbe9fe335edf24b44bbf6d521cc0287547680 bytes
200xab1b8cf7d7f4c24aab9ac467f072153322537 bytes

PC Pitstop Database Comparisons

Every week, we update our information about the running programs identified during the previous week's testing. system.exe (W32.Pahatia.A) has been seen on 0.00% of systems tested at PC Pitstop. As a point of comparison, it is rare for a particular malicious program (virus or spyware) to be seen on more than one or two percent of all systems tested. The average RAM memory usage for this process was MB. The average CPU load for this program was %.


Detailed Description and/or Removal Instructions

http://www.symantec.com/security_response/writeup.jsp?docid=2006-053012-1545-99&tabid=2


Match #2

system.exe (Tofger trojan)

This program has not been seen on any systems tested at PC Pitstop in the past week.


PC Pitstop Analysis

SYSTEM.EXE - Part of the Tofger trojan or a variant, see http://www.sophos.com/virusinfo/analyses/trojtofgerb.html.


Recommendation

CA AntiVirus

system.exe is a VIRUS. Stop all work until the virus is removed or you run the risk of spreading the virus to other people. Worse yet, the virus may be doing harm to your computer and your information.

system.exe is a virus and should be removed immediately to avoid doing further harm. PC Pitstop recommends CA Antivirus in these types of situations.



Identification

In addition to the file name, system.exe, the following version information is used to identify the file. If the file does not match this information, it may be a different file. To ensure the file is absolutely correct, run a free and comprehensive scan.

Vendor is not specified
Product is not specified
File name contains:\WIN

To view version information with Windows Explorer, right-click the file and click Properties, Version.


MD5 Hashes

MD5 hashes is the way that computers can define the uniqueness of a file. Anti malware vendors frequently use this technique to detect and clean malware. It is common for a program to have multiple MD5 hashes as the developers create newer versions of the program. For the program called system.exe, we have detected more than 20 different MD5 hashes. Click on a hash to research the hash in Google.
MD5 Report Summary
Program NameMD5 Count
system.exe> 20
#MD5Size
10xcd262133e65f6dcae37b87a438c85c8a1930240 bytes
20x9ba0fece2d996b80fec3572a496c3c5894208 bytes
30x1a6d63e0a1afbf7ebf6e19d4609bea3b75264 bytes
40x1cc06a403c61f98bf0ca5437e6894784696320 bytes
50xc3c4bb1529b639d04e2e53c07cbd84c3238802 bytes
60x031c23f4bad71570794dbfea6549e1333776512 bytes
70x74333affcf44e271950b2fc0122079e22560 bytes
80x6263a7c227651000f80ff39d20076236294912 bytes
90xdb8a02237d35ab10a3d2fb1f99cc984a4354046 bytes
100x2742a0aefe512a2607ce47932f5891211428480 bytes
110x76b26527e2f56f4a59e59493d0e3ef84347648 bytes
120x6815ede22c8300ddfd813eb7f251b1c41319424 bytes
130xe114d57f2bf26c170137409264c97a4e8704 bytes
140xda3ab952880b9abe8b89f42a9cfb45c6307200 bytes
150xef97d150fcde41bee8b80aa02039dd0d63488 bytes
160xd81688acf25e16fb35d9acd39f301c21636890 bytes
170xcc82750e2ac0357dec57cfa1f3b538e81478656 bytes
180x783084ef46b6d3f9b07fb6ba99f8dedf172032 bytes
190x53355cacbc6bf36445e552539e42e8a2119117 bytes
200xe8b3adc8e031aaea812f711e4f1dd540159744 bytes

PC Pitstop Database Comparisons

Every week, we update our information about the running programs identified during the previous week's testing. This program has not been seen on any systems tested at PC Pitstop in the past week.


Important note: A file name alone may not be enough for positive identification. PC Pitstop's Overdrive tests and spyware scan use information such as the company name, product name, or install directory. If you are unable to identify a file, ask about it in our forums after running our full tests.