home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Applications and Operating Systems
Ask a Tech Support Question (free)!

probable spyware/virus

Reply
Get bargains at  »  Dealighted.com
 
Thread Tools Search this Thread
Currently Active Users: 1453
Discussions: 200,932, Posts: 2,379,166, Members: 246,297
Old July 3rd, 2004, 04:01 AM     #11 (permalink)
Member
 
noseBleeD's Avatar
 
Join Date: Jun 2004
Location: usa
Posts: 250
i'm glad it saved your computer!

trust me? lol
noseBleeD is offline   Reply With Quote
Old July 3rd, 2004, 10:33 AM     #12 (permalink)
Senior Member
 
Gilthanaz's Avatar
 
Join Date: Dec 2003
Posts: 877
Sigh, whoever was on here this morning disabled the adaware resident. Whatever this piece of crapware was trying to do has been done. I've noticed im unable to use regedit, but only after these reg values find there way into my registry. Coincidence? hm..

Beemer, I will try your suggestions and post back
__________________
“One things for sure: Whenever we play, our goalie stays warm.”
- Ville Nieminen, Pittsburgh Penguins
Gilthanaz is offline   Reply With Quote
Old July 3rd, 2004, 11:53 AM     #13 (permalink)
Member
 
noseBleeD's Avatar
 
Join Date: Jun 2004
Location: usa
Posts: 250
Gilt, try renaming regedit.exe to regedit.com
works when infected with certain win32 worms,trojans,etc..

If you ever get problem opening task manager the same renaming process with taskman can be used.

http://www.mvps.org/sramesh2k/exefile.htm

Once registry ca be opened, the hacks can be done.
usually regedit.com will not have to be renamed back to the exe. Regedit.exe will already have duplicated itself when you renamed it to regedit.com
Just delete regedit.com (or rename back to exe if the exe isn't there.)

I hope this helps you

Last edited by noseBleeD : July 3rd, 2004 at 12:06 PM.
noseBleeD is offline   Reply With Quote
Old July 3rd, 2004, 01:43 PM     #14 (permalink)
Senior Member
 
Gilthanaz's Avatar
 
Join Date: Dec 2003
Posts: 877
Thanks nosebleed, that worked like a charm. Found and deleted reg entries associated with "aol messenger". AS soon as that was done, adawre started alerting me again, so it immidiately is trying to reinstall itsself. This is the most elusive spyware I've ever seen. Virus and spyware scans in safe mode show nothing except normal tracking cookies that always come up in scans after somone browses the web for a while. Spycleaner and Spysweeper as recommended above are showing nothing.
Gilthanaz is offline   Reply With Quote
Old July 5th, 2004, 03:24 PM     #15 (permalink)
Senior Member
 
Gilthanaz's Avatar
 
Join Date: Dec 2003
Posts: 877
I'm absoltely baffled here. I'm picking up a running process in adaware's adwatch called c:\winnt\system32\aolmsngr.exe

This file doesn't exist! How can it be a running process? I thought maybe somehow it was "hiding" in windows, so i booted to the recovery console and did DEL aolmsngr.exe
I got a file not found error.
Gilthanaz is offline   Reply With Quote
Old July 5th, 2004, 03:31 PM     #16 (permalink)
Member
 
Join Date: Jul 2004
Location: Oregon, US
Posts: 182
Send a message via AIM to hom3l3ssazn
are you sure it's not a Hidden file that you just didn't enable to view all the files, and also, try clean up your internet explorer's temp. folder. sometimes it runs in there as a different file, oh and maybe unplug your cable modem while you're doing it
hom3l3ssazn is offline   Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Similar Threads
Thread Thread Starter Forum Replies Last Post
Help check site, please mickwish IMO Community 15 July 3rd, 2004 10:22 AM
Probable Solution Found DVNT1 Distributed Computing 23 April 20th, 2004 05:55 AM
If UBL gets caught/killed before the election ... Bill in SD, CA IMO Community 33 February 28th, 2004 03:15 PM
Is your isp next? Or this one? whitebeard21 IMO Community 31 February 26th, 2004 04:00 AM
Computer not showing stuff on the screen!! naujcdl Technical Support 16 December 21st, 2003 06:48 AM


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Most Active Discussions
Is It Just Me? (2875)
Obama the Muslim (14)
California Passes Anti-Flat-HDTV Le.. (39)
Is the PSU I received dead? (10)
windows vista security holes (9)
Install XP pro and a Vista laptop ?.. (11)
HIS HD5770 graphic card question (15)
Print spooler problem (13)
Foreign voltage (10)
Dept. of HS: NSA 'Helped' Develop V.. (15)
A good PSU? (10)
Ideal cheap graph card for PC-Gamin.. (16)
EVGA 9800 gtx help with finding a g.. (8)
New Computer wont recognize XP disc (7)
Recent Discussions
BIOS won't read disk when I try to fl.. (0)
Wireless Televisions. (0)
Install XP pro and a Vista laptop ?? (11)
Partition Magic caused HDD problem (2)
Graphics Card Upgrade Question (1)
favorit (1)
solutions for virtical white lines on.. (1)
Regular Build (3)
Ideal cheap graph card for PC-Gaming? (16)
Fire in DVD (2)
Modern Warfare For the PC (33)
radeon x850xt platinum & shader 3 (3)
Have you switched yet? (84)
Wireless Router+Cable Modems and Much.. (0)
Optical Audio A-B Switch (1)
windows vista security holes (9)
The NTDVM CPU has encountered an ille.. (24)
[F@H SPAM 11/16/09] ! 1/2 months to r.. (34)
Wireless speakers for PC? (11)
Print spooler problem (13)
Help getting around port 80 for camer.. (2)
Display shows 3x5 inch in middle of s.. (3)
monitor will not turn on at all, (1)
World's largest Monopoly Game using G.. (331)
Foreign voltage (10)


All times are GMT -4. The time now is 08:29 AM.
TechIMO Copyright 2009 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28