How to Remove “SCANSTATE_A.EXE”

What is SCANSTATE_A.EXE?

Originally developed by Microsoft Corporation, SCANSTATE_A.EXE is a legitimate file process. This process is known as scanstate_a.exe and it belongs to Windows Operating System. It is located in C:\Documentsandsettings by default.
SCANSTATE_A.EXE virus is created when malware authors write virus files and name them after SCANSTATE_A.EXE with an aim to spread virus on the internet.

Affected Platform: Windows OS

How to check if your computer is infected with SCANSTATE_A.EXE malware?

If your system is affected by SCANSTATE_A.EXE malware, you will notice one or several of the symptoms below:

  • SCANSTATE_A.EXE occupies an unusually large CPU memory
  • Erratic internet connection
  • Your browser is bombarded with annoying popup ads
  • Computer screen freezes
  • PC's processing speed suffers
  • You are redirected to unknown websites

To pinpoint the virus file location, take the following steps:

Step 1: Press CTRL+ALT+DEL keys at once to open Task Manager.

Step 2: If you notice the file located outside C:\Documentsandsettings, you should run an antivirus scan to get rid of the malware.

How to remove SCANSTATE_A.EXE malware from system using Comodo Cleaning Essentials?

You can either choose to remove SCANSTATE_A.EXE and other malwares using Comodo Antivirus, or Comodo Cleaning Essentials (CCE) – both of which are absolutely free to download! CCE is a set of computer security tools designed to help you identify and remove malwares and unsafe processes from an infected computer.

To remove malwares using CCE, take the following steps:

1. Check the system requirements and download the feature-rich CCE suite for free.

2. After installation, choose the type of scan you want to perform. CCE offers 3 scan options to get rid of malwares from a PC:

  • Smart Scan: Does a scan on critical areas of your system.
  • Full Scan: Does a complete scan of your system.
  • Custom Scan: Does a scan only on selected items.

The process to initiate the above mentioned scans are self-explanatory and thus, easy-to-use. 
Additionally, it's recommended that you approve of any updates that the CCE will prompt you about to ensure it does a better job of identifying all the latest threats.

3. Click 'Next' to view the results.
Regardless of the type of scan you choose, the results will sometimes show false positive (flagging files that are actually safe), which has to be ignored. Only select the files you want to get rid of.

4. Click 'Apply' to apply the selected operations to the threats. The selected operations will be applied.

57

Malware Entries

First Seen: 15 February 2010 at 11:34 pm
No. Company File Type SHA1 MD5 Malware
Name
Digitally
Signed
File
Version
Product
Version
Submitted
From
Malware Behavior
1 Microsoft Corporation Executable 24ed5377920c0876
9ea558f60aef0ee4
0bb8299a
dc34c106fe9ae981
dccb0e760b04c497
Virus.Win32.
Sality.gen
No 5.1.2600.0
(xpclient.
010817-114
8)
5.1.2600.0 Brazil N/A
2 Корпорация Майкрософт Executable 7a2f2671a1788534
5d55130e73a67fa0
52ecc7f3
52642128116366da
50de0f5bd5c6bb98
MalCrypt.Ind
us!
No 5.1.2600.2
180
(xpsp_sp2_
rtm.040803
-2158)
5.1.2600.2
180
Russian Federation N/A
3 Microsoft Corporation Executable 06207128fd368f48
52a69174d9ecd5e3
be3c80df
cd8077560e8ad4da
8c2bd3595ab8d5fa
Virus.Win32.
Ramnit.K
No 5.1.2600.2
180
(xpsp_sp2_
rtm.040803
-2158)
5.1.2600.2
180
India N/A
4 Microsoft Corporation Executable ecac493c03fa81b6
4c9f64f41759dc27
36036968
2e19863a5bca4758
603384bfccc2b289
Virus.Win32.
Virut.AV
No 5.1.2600.0
(xpclient.
010817-114
8)
5.1.2600.0 Italy N/A
Display 4 items per page
  • 4 items per page
  • 8 items per page
  • 16 items per page
  • 32 items per page
15

Safe Entries

First Seen: 04 June 2008 at 12:35 am
No. Company File Type SHA1 MD5 Digitally
Signed
File
Version
Product
Version
Submitted
From
1 Microsoft Corporation Executable b54acdb075ef0058
d21e204415cb38a7
0d9cfab5
N/A No 5.1.2600.2
180
(xpsp_sp2_
rtm.040803
-2158)
5.1.2600.2
180
Italy
2 Корпорация Майкрософт Executable 7055edf6c234d5d9
165e59b3fea8b8e6
975027c0
0ade5fc810d70879
4940e26e632040f3
No 5.1.2600.0
(xpclient.
010817-114
8)
5.1.2600.0 Ukraine
3 ?????????? ?????????? Executable 4e70b370f63ef243
f053eaebbd1adad0
26e513d3
08d69dc64f2c1b61
823d7792abc8b85b
No 5.1.2600.0
(xpclient.
010817-114
8)
5.1.2600.0 Russian Federation
4 Microsoft Corporation Executable f620f95c732cfe16
4e6a08f543b400e1
cc43c5ac
662ee5031b1290c6
8326176c52f27e45
No 6.0.4029.0
(main.0306
19-0000)
6.0.4029.0 Italy
Display 4 items per page
  • 4 items per page
  • 8 items per page
  • 16 items per page
  • 32 items per page
 
Exclusive Offer
Get Free Endpoint Protection
Get Advanced
Endpoint
Protection

Award-Winning Security to Protect Your Clients from Cyber Attacks

Comodo Internet Security Pro

Free Antivirus protection from hackers! Get the ultimate Antivirus solution to keep your PC clean and to remove viruses from a slow or infected PC. Improve the PC performance at home or use it on-the-go!

Get Comodo Internet Security Comodo Internet Security