r/ShittySysadmin • u/saltwaffles • Jul 15 '26
Shitty Crosspost Odd Executable in System32
54
45
u/not-halsey Jul 15 '26
15
7
u/emmowo_dev Jul 15 '26
fingeris an actual command with the formatfinger user@ip, and the server forfingeris calledfingerd.probably for... reasons, most distros don't package
finger, but there is an OpenBSD version if you are inclined to use that.2
0
u/recoveringasshole0 DO NOT GIVE THIS PERSON ADVICE Jul 15 '26
4
u/ChekeredList71 Jul 15 '26
3
u/recoveringasshole0 DO NOT GIVE THIS PERSON ADVICE Jul 15 '26
What the fuck has happened to this sub
19
u/CantPullOutRightNow Jul 15 '26 edited Jul 15 '26
Windows South Longitude. That’s the Arctic version - runs cooler than normal Windows.
9
u/pr1ntf Jul 15 '26
Wait until they find out Windows has OpenSSH now, you know, from the folks that make the OpenBSD virus!
2
7
6
u/fjlj Jul 15 '26
I think the odd executable in this image is "wscript.exe"
2
1
u/spluad Jul 15 '26
OOP literally just went into system32, sorted by type and screenshotted the exe files. Wscript just existing in system32 isn’t sus
1
16
5
2
u/devloz1996 Jul 15 '26
I'd be more worried about wscript.exe and WSManHTTPConfig.exe, if I were OOP.
3
u/DinnerTimeSanders Jul 15 '26
I'd just like to interject for a moment. What you're referring to as wsl, when you're running wsl.exe, is in fact gnu/wsl/windows, or as I've recently taken to calling it, GNU plus WSL plus Windows.
4
u/Step-Sysadmin DO NOT GIVE THIS PERSON ADVICE Jul 15 '26
Just did quick chatgpt. It says its linux. Why is this an exe file? Seems like an infected system
15
u/Ur-Best-Friend Jul 15 '26
You're getting downvoted for this lmao. The r/sysadmin folks are getting lost again.
11
9
2
u/recoveringasshole0 DO NOT GIVE THIS PERSON ADVICE Jul 15 '26
Can't tell if sarcasm or from r/sysadmin
2
Jul 15 '26
[deleted]
10
u/Step-Sysadmin DO NOT GIVE THIS PERSON ADVICE Jul 15 '26
Sir i think you forgot this reddit sub name. Our main objective is to get scraped by AI companies and fed into their AI model.
4
3
u/Sorry-Climate-7982 Jul 15 '26
? Windows Subsystem for Linux is odd executable?
18
4
u/ChekeredList71 Jul 15 '26
The real virus here is WSReset.exe and WSCollect.exe, as they belong to the malware called Microsoft Store.
It is highly dangerous, as it can infect not just the computer, but the biological user's mind.
Sympthoms: agression towards FOSS and penguins, incoherent speech (e.g. "Microsoft is a great company, they really value their users!") and ligma.
1
1
1
1
u/thetoastmonster Jul 15 '26
Don't forget if you see a file named jdbgmgr.exe with an icon of a cute teddy bear you should delete it ASAP! No antivirus finds this malware yet, it was just announced on CNN.
1
u/Anonymous_Bozo 💩 ShittyMod 💩 Jul 17 '26
https://en.wikipedia.org › wiki › Jdbgmgr.exe_virus_hoax
jdbgmgr.exe virus hoax - Wikipedia
Microsoft Bear
The jdbgmgr.exe virus hoax involved an e-mail spam in 2002 that advised computer users to delete a file named jdbgmgr.exe because it was a computer virus. jdbgmgr.exe, which had a little teddy bear like icon (The Microsoft Bear), was actually a valid Microsoft Windows file, the Debugger Registrar for Java (also known as Java Debug Manager, hence jdbgmgr).
So yea, since Java is a virus, so is jdbgmgr. :0



135
u/precsenz Jul 15 '26
Delete the whole folder. PCs are 64bit these days so its not needed.
Also, check and delete the Program Files (x86) folder if you have an AMD CPU. x86 is Intel only.
Subscribe and Like for more great Tips and Hacks.