How to Remove “subst.exe”

What is subst.exe?

subst.exe is a legitimate file process developed by Microsoft Corporation. This process is known as Subst Utility and it belongs to Windows Operating System. You can locate the file in C:\Program Files. The virus is created by malware authors and is named after subst.exe file.

Affected Platform: Windows OS

How to check if your computer is infected with subst.exe malware?

Keep an eye for the following symptoms to check if your PC is infected with subst.exe malware:

  • Unstable internet connection
  • Browser redirects to unwanted websites
  • PC performance slows down
  • Browser is bombarded with hordes of popup ads
  • System screen freezes repeatedly

If you find any of  the above mentioned symptoms, take the following steps to be sure about the malware infection:

1) Press CTRL+ALT+DEL keys to open Task Manager.

2) Go to the process tab and right-click on the subst.exe file and open its location.

If the file is located outside C:\Program Files, then you should take measures to get rid of the malware.

How to remove subst.exe malware from system with Comodo Cleaning Essentials?

Comodo Cleaning Essentials (CCE) incorporates antivirus software with unique features like auto-sandboxing to identify and obstruct every suspicious process running on an endpoint with a single click. To remove subst.exe malware using CCE, follow the steps mentioned below:

Step 1: Download the CCE suite.

Step 2: To start the application, double-click on the CCE.exe file.

Step 3: It then probes the antivirus to initiate a full system scan to identify and remove any existing malicious files.

Step 4: If threats are found during the scanning, you will be prompted with an alert screen.

Step 5: Comodo Cleaning Essentials will remove subst.exe  malware from your computer including all other malwares!

16

Malware Entries

First Seen: 19 November 2017 at 6:27 pm
No. Company File Type SHA1 MD5 Malware
Name
Digitally
Signed
File
Version
Product
Version
Submitted
From
Malware Behavior
1 Microsoft Corporation Executable 609b49ab85373c31
e83a6853e142018e
cc9772f6
18c5f6f0abe132d2
dd59b61dc29b0160
Virus.Win32.
Virut.CE
No 6.1.7600.1
6385
(win7_rtm.
090713-125
5)
6.1.7600.1
6385
Morocco N/A
2 Microsoft Corporation Executable eb796e9c950cd710
08176c94ed4069d1
7bffd0a8
9d8ec4bbdad9de37
41ed5ae530308f80
Virus.Win32.
Virut.CE
No 5.1.2600.0
(xpclient.
010817-114
8)
5.1.2600.0 156.220.116.63/32 N/A
3 Microsoft Corporation Executable 308ff9a119b4157e
00300cf3d609ebb1
09437d15
bce1a4bd1f4590d8
e28fe7d6fb95637d
Virus.Win32.
Virut.CE
No 6.1.7600.1
6385
(win7_rtm.
090713-125
5)
6.1.7600.1
6385
197.210.47.180/32 N/A
4 Microsoft Corporation Executable e95888be190674cf
3faeb410df8fcd3c
81df9994
745e983cb294fe0b
a5820c6f7ddbee08
Virus.Win32.
Expiro.naf
No 6.1.7600.1
6385
(win7_rtm.
090713-125
5)
6.1.7600.1
6385
Russian Federation N/A
Display 4 items per page
  • 4 items per page
  • 8 items per page
  • 16 items per page
  • 32 items per page
16

Safe Entries

First Seen: 11 July 2009 at 11:34 pm
No. Company File Type SHA1 MD5 Digitally
Signed
File
Version
Product
Version
Submitted
From
1 ReactOS Development Team Executable faae13e7ec55eddd
6429e81c59ec647e
184730bd
36edebc9ada6b0ad
72b63c86b6577d81
No 0.4.7 0.4.7 Romania
2 Microsoft Corporation Executable 8d6580b6685db6ae
0d9ca0acf3a62a8f
61597f7f
e4f352be823590b5
8d6d494ccb14402b
No 6.3.9600.1
6384
(winblue_r
tm.130821-
1623)
6.3.9600.1
6384
10.100.19.136/32
3 ReactOS Development Team Executable d5f63e1766082566
f3b67541f543f7a7
92af33f4
d7ae53e74ef0788f
5bf696cee0b82cf3
No 0.4.8 0.4.8 10.108.51.194/32
4 Microsoft Corporation Executable e20a71a91dcaf188
e72ccc0a4889de0b
43edc41b
8ebcf8644b924f9b
642ac8ca2fe63406
No 6.1.7600.1
6385
(win7_rtm.
090713-125
5)
6.1.7600.1
6385
United States
Display 4 items per page
  • 4 items per page
  • 8 items per page
  • 16 items per page
  • 32 items per page
 
Exclusive Offer
Get Free Endpoint Protection
Get Advanced
Endpoint
Protection

Award-Winning Security to Protect Your Clients from Cyber Attacks

Comodo Internet Security Pro

Free Antivirus protection from hackers! Get the ultimate Antivirus solution to keep your PC clean and to remove viruses from a slow or infected PC. Improve the PC performance at home or use it on-the-go!

Get Comodo Internet Security Comodo Internet Security