Feedback
Skip to content

Why donate?

Which type of operating system are you running?



AVG Internet Security 2014

What is reader_s.exe?

reader_s.exe is usually located in the 'C:\Documents and Settings\weijie.WJMINI\' folder.

If you have additional information about the file, please share it with the FreeFixer users by posting a comment at the bottom of this page.

Vendor and version information [?]

reader_s.exe does not have any version or vendor information.

Hashes [?]

PropertyValue
MD5e97700144712c826c4b3527991738ead
SHA256da623062e0b7996620517634656e91d378d9fa5a568d6fdd6e3495f1c055f8ff

Error Messages

These are some of the error messages that can appear related to reader_s.exe:

reader_s.exe has encountered a problem and needs to close. We are sorry for the inconvenience.

reader_s.exe - Application Error. The instruction at "0xXXXXXXXX" referenced memory at "0xXXXXXXXX". The memory could not be "read/written". Click on OK to terminate the program.

reader_s.exe has stopped working.

End Program - reader_s.exe. This program is not responding.

reader_s.exe is not a valid Win32 application.

reader_s.exe - Application Error. The application failed to initialize properly (0xXXXXXXXX). Click OK to terminate the application.

What will you do with reader_s.exe?

To help other users, please let us know what you will do with reader_s.exe:



What did other users do?

The poll result listed below shows what users chose to do with reader_s.exe. 86% have voted for removal. Based on votes from 832 users.

User vote results: There were 718 votes to remove and 114 votes to keep

NOTE: Please do not use this poll as the only source of input to determine what you will do with reader_s.exe.

Malware or legitimate?

If you feel that you need more information to determine if your should keep this file or remove it, please read this guide.

Please select the option that best describe your thoughts on the information provided on this web page


Free online surveys

And now some shameless self promotion ;)

A screenshot of FreeFixer's scan result.Hi, my name is Roger Karlsson. I've been running this website since 2006. I want to let you know about the FreeFixer program. FreeFixer is a freeware tool that analyzes your system and let you manually identify unwanted programs. Once you've identified some malware files, FreeFixer is pretty good at removing them. You can download FreeFixer here. It runs on Windows 2000/XP/2003/20008/Vista/7/8/8.1/10. Supports both 32- and 64-bit Windows.

If you have questions, feedback on FreeFixer or the freefixer.com website, need help analyzing FreeFixer's scan result or just want to say hello, please contact me. You can find my email address at the contact page.

Comments

Please share with the other users what you think about this file. What does this file do? Is it legitimate or something that your computer is better without? Do you know how it was installed on your system? Did you install it yourself or did it come bundled with some other software? Is it running smoothly or do you get some error message? Any information that will help to document this file is welcome. Thank you for your contributions.

I'm reading all new comments so don't hesitate to post a question about the file. If I don't have the answer perhaps another user can help you.

Roger Karlsson writes

9 thumbs

There are a lot of Google searches for reader_s.exe right now. According to virscan.org reader_s is often classified as malicious. Here are some of the anti-virus classifications:

TR/Dropper.Gen
Trojan/Win32.Agent.atgt
BackDoor.Bulknet.320
Trojan.Win32.Pakes.may
Trojan/Pakes.dme
Trojan.Win32.Pakes.may
TrojanDropper:Win32/Cutwail.AL
Trojan.Win32.Agent.atdt

Trojan-Downloader.Win32.VB.bbi!IK
Win32/Virut.D
W32/Virut.R
W32/Virut.10392 (Possible)
Win32:Virut
Win32.Virtob.Gen.9
Win32/Virut.10392 virus.
W32.Virut.Gen.D-16
Win32.Virut.5
W32/Virut.10392
W32/Virut.F

Before you remove reader_s.exe (with FreeFixer or any other removal tool) please run it through the scanners over at http://virscan.org or http://virusscan.jotti.org/ to be 100% sure that it is malicious. If you like, please post the scan results here.

References:
http://virscan.org/report/5df0d1efaa18c43fe74a0fad07bac0a7.html
http://virscan.org/report/0f2dda688dec9fd0a26c8851c05edae8.html

# 13 Mar 2009, 9:54

che writes

1 thumb

This is in virus or malware. It is not a good software.
It modify the normal soft from your PC , first distroy your antivirus, after the internet explorer, opera, the account from your PC ,
When you give restart you receive just error, restart pc, you can not use safe mode and finaly you must reinstall windows. I did this 12 times in 6 days, Finaly I observe this reader_s.exe and i understand who made problem to my pc, and i decide to remove it, I use now the trial from dr.web ( i read on a forum that some others use this soft and now they dont have problem.
I hope it is good, I am working now at this problem .

# 28 Jun 2009, 2:40

cocutzamisca writes

0 thumbs

can the tool scan external hard drives for the reader_s.exe virus?if so,leave a replay,thx

# 10 Jul 2009, 7:31

che writes

0 thumbs

yes, the tool from dr web can scan external hard drives

# 11 Jul 2009, 10:11

Reo writes

0 thumbs

I've been trying to get rid of reader_s,servises and .tmp files.
but none of a software was really able to help me...
it seem like the virus was infected on my external hard drive but I don't want to delete my whole thing in my external, and even I had used Dr.Web to scan the whole computer, it still failed to get rid of the virus.

# 14 Aug 2009, 20:23

TheFrog writes

1 thumb

reader_s is part of a wicked virut virus.DO NOT confuse it with reader_sl which is part of Adobe reader.It is a pain in the butt to get rid of.This file also creates alot of other nasty files mostly which are .tmp files.
This virus will spread to all .exe and .scr files.rendering them usless, even when you finally remove this virus ( in safe mode ) all the .exe and .scr that were previously infected are no good because when the virus was removed it also strips out good code rendering the program useless. Sorry to say ,the best thing and easiest with this virus is to format and reinstall your o/s.
This thing also takes over a port and quietly dials out and grabs your personal info to their server.
Also be aware that this virus will spread quickly and quietly to any other attached h/d's zip drives usb storage devices. This virus blows and i say it's a shame this person can't use their talent for good.
BTW it took me a month to get rid of this bugger off all my stuff.Good luck.

# 23 Aug 2009, 17:51

Reo writes

1 thumb

I wonder if the virus does infect on other OS too?
coz it's impossible for me to format my whole important files which take 140GB+ on the external hard drive....

# 23 Aug 2009, 21:08

Mihai Costin writes

0 thumbs


at the moment i am trying to cure it with Dr Web. and seems to work. found the reader_s.exe files and deleted, found the .tmp files and deleted and all the infected files by the virus apear as cured. hope it works. after the complet scan i will restart my pc. keep your fingers crossed :)

# 12 Sep 2009, 18:48

Rock writes

1 thumb

This trick might be helpful to get rid of reader_s.exe
Now Listen!
use ur notepad to create a dummy program and save with the foolowing name: reader_s.exe, at the 'Save As Type' prompt of notepad choose 'All Files'
-- This should create a dummy executable file called reader_s.exe.

copy it to the following paths
%userprofile%
%windir%\system32
.....These are the locations where the virus resides and expand from......
now go cmd (COMMAND PROPMT)
type this commands
cd %userprofile% [ENTER]
attrib reader_s.exe +a +r +h +s [ENTER]
(This will make ur dummy reader_s.exe "Hidden")
type,
cd %systemroot%\system32 [ENTER]
attrib reader_s.exe +a +r +h +s [ENTER]

This will make reader.s.exe virus powerless, bcos when d Orignal READER-S.exe virus wants to put itself into its designated paths..it sees another copy there already with a stronger attribute.

I discoverd that whenever i call a website using Internet Explorer my Avast ANTIVIRUS detects the children of these virus 4.tmp, a1.tmp,b3.tmp and so on.
You should use taskmgr and end all .tmp task running in your PROCESSES.

??

# 22 Nov 2009, 8:44

Blue Sp33d writes

1 thumb

wrestled with reader_s for weeks. used AVG’s virut removal tool, it found numerous executables infected, safe mode was disabled, had to use winternals to do anything. i could get into my computer after using spybot to delete startup keys which came back every reboot. backed up my files onto an external hard drive. couldnt install any software, i would get multiple errors while installing software like “CTF loader needs to shutdown” “microsoft register server needs to shut down” “runtime error ‘0′”. couldnt install anything like kaspersky or malware bytes. used the dell system recovery feature (CTRL + F11) and reformatted and reinstalled windows. then purchased kaspersky at best buy and installed it before connecting to the net, connected to the net to get updates, downloaded all windows updates and spyware blaster which immunizes the browsers. used the kaspersky vulnerabilities scan to find weaknesses, updated and patched all results. virus is gone. when i reconnected removable storage which i had backed up files on kaspersky detected viruses, torjans and malware all over them. luckily kaspersky cleaned and deleted them although a thumb drive put up a good fight with the kaspersky but kaspersky won. i dont know about you guys but this reader_s seemed to come bundled with tons of other viruses and trojans. didnt matter how much i cleaned my system before, when i would reconnect to the internet it would all be back. it was also hiding in svchost and when i would terminate that svchost i would get a shutdown countdown with the message “remote procedure call has terminated unexpectedly and must be shut down. this shutdown initiated by NT authority/system.” with a 60 second countdown. i wouldnt waste my time trying to clean it if i were you, it corrupts windows to the core. backup, format, reinstall and get a great virus software (i recommend kaspersky) and then connect removable drives. i also disabled autoplay and autorun before connecting removable storage. good luck, she’s one tough mofo!!

# 6 Jan 2010, 9:11

bilal writes

0 thumbs

Dear fallows ....
The person who made this extra-ordinary software has spent his time may be many days...There is no way that he typed a code and that is working so well....

we lack in that extra ordinary skill that is required to make such an extra ordinary software......

All this excellence in computer industry is made by these genius people who keep on finding errors and bugs in the previous code so that we should change system.So that we write code to make it more secure.

My laptop is infected by this piece of code now-a-days. But i am thankful to this person who made this software (reader_s.exe) for providing me chance to again learn something.Thanks buddy.

# 4 Feb 2010, 10:00

DUCROCQ GILLES writes

0 thumbs

Reader_s.exe est bel et bien un tres mauvais (very bad) malware. Tres dangereux et surtout, pas.seul. Il est downloadé sous XPSP2 CD Neuf des la fin du setup....
On trouve "c:\windows\fonts\services.exe"
finstall.sys et mstct.sys ainsi que syncman.exe dans system32. souvent couplé avec Peresvc.exe et imgplayok.exe.
IR.TXT dans windows. La clé de registre HKLM_WBEM modifiée
ainsi que HKLM_RUN:Regedit32=regedit32.exe
Les dossiers cachés ainsique les SERVICES sont inaccesiibles. Peresvc est un "service" qui démarre en mode auto, couplé avec BTWSVC.DLL qui est un service aussi.
Lesjogiciels anti-malwares tels "malwarebyte" nettoyent tout parfaitement, mais ça revient. les anti-virus comme MOONSEVURE, PCTOOLS, AVIRA,ne voient rien. Search and Destroy ne nettoye pas tout.

# 20 Mar 2010, 12:26

Targenor writes

0 thumbs

Posting a link to a scan i made on reader_s.exe file

http://virscan.org/report/ec0d2f92742d8dabe8ae024b25ffc4ac.html

How do you get rid of this?

# 5 Apr 2010, 11:54

Leave a reply