home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > General Tech Discussion
Ask a Tech Support Question (free)!

virus, trojan or what?

Reply
Get bargains at  »  Dealighted.com
 
Thread Tools Search this Thread
Currently Active Users: 2178
Discussions: 200,512, Posts: 2,374,436, Members: 245,837
Old February 14th, 2002, 07:37 PM   Digg it!   #1 (permalink)
Senior Member
 
Join Date: Oct 2001
Location: Utah
Posts: 551
virus, trojan or what?

Hmm, weird one here.
My brother in laws work computer. He picked up something, that every once in a while pops up an internet explorer porn ad, that then prompts to download an activex type dialer program(I think they want you to run it, dial them, and pay a huge phone bill)
Anyway, Norton(fully updated) found nothing.

Also, this happens periodically, even when no browser is open, or when nothing is open actually. Windows XP, fully updated.

The only process running that didn't look familiar was one called openme.exe. Sounds fishy. located in the windows directory.
The only reference to it in the registry was under a key called shell with the value "explorer.exe openme.exe" not referenced in a startup key or anywhere else.
I'm guessing it just starts it up along with explorer upon boot?

I took it out, and deleted the actual file, and going to reboot now.
Just wanted to see if any of you have seen anything like this before?

p.s. downloading some trojan detection progs right now, and mcafee.

dragonb

Also, as per a thread talked about before, this definitely qualifies as "Scumware"!!!
dragonb is offline   Reply With Quote
Old February 14th, 2002, 07:44 PM     #2 (permalink)
Senior Member
 
crystaldragon's Avatar
 
Join Date: Oct 2001
Location: Springfield,Mo
Posts: 596
Send a message via Yahoo to crystaldragon Send a message via Skype™ to crystaldragon
Sounds like you prob found it. I've had three instances in the last two days of imbedded scripts trying to install them selves (2 in gifs and 1 ina jpg). I run Grisoft anti virus and so far nothing has gotten by it.
__________________
Those who cannot remember the past are condemned to repeat it
crystaldragon is offline   Reply With Quote
Old February 15th, 2002, 02:23 AM     #3 (permalink)
Not an OWO yet, just OLD!
 
sharder8's Avatar
 
Join Date: Oct 2001
Location: Uh, Central Oregon
Posts: 5,631
I don't know if it will catch it if it's already in place, but PC-cillin will definitely catch them trying to come in from the web.

You might want to run House Call and see if it can find it. It's a free on-line virus scan from Trend, the makers of PC-cillin 2000.

Harder
sharder8 is offline   Reply With Quote
Old February 22nd, 2002, 05:10 PM     #4 (permalink)
Junior Member
 
Join Date: Feb 2002
Location: Toronto, Canada
Posts: 29
Send a message via ICQ to Lonewolf54
That must be it. I just looked on my Win 98SE system and found no "openme.exe" program in the windows directory.
Lonewolf54 is offline   Reply With Quote
Old February 22nd, 2002, 05:20 PM     #5 (permalink)
nuisance since 1968
 
OuTpaTienT's Avatar
 
Join Date: Oct 2001
Location: ɐqɟs
Posts: 10,457
Hey crystaldragon, I'm curious about these imbedded scripts that you talk about being in image files. You didn't keep one did ya? I'd really like to see one and how it works.

If by chance you have one, you could send it to me at outpatient@speedracer.com I would appreciate it.

Last edited by OuTpaTienT : February 22nd, 2002 at 05:25 PM.
OuTpaTienT is offline   Reply With Quote
Old February 22nd, 2002, 06:02 PM     #6 (permalink)
Senior Member
 
crystaldragon's Avatar
 
Join Date: Oct 2001
Location: Springfield,Mo
Posts: 596
Send a message via Yahoo to crystaldragon Send a message via Skype™ to crystaldragon
OuTpaTienT

Just saw your note. I would send that to you but we are too late. I have the virus vault set to clear itself every week. I'll try to remember and the next one I'll let you know before it gets deleted.

The best I remember they where imbedded in .gif files like you find in the temp internet folder with the cookies.

JD
crystaldragon is offline   Reply With Quote
Old February 22nd, 2002, 06:40 PM     #7 (permalink)
The Mad Redhatter
 
storm2k's Avatar
 
Join Date: Oct 2001
Location: NJ
Posts: 3,552
Send a message via ICQ to storm2k Send a message via AIM to storm2k Send a message via MSN to storm2k Send a message via Yahoo to storm2k
have you tried ad-aware? download it, download the latest ref file and see if that gets rid of it.

edit: fixed the url, sorry

Last edited by storm2k : February 22nd, 2002 at 06:43 PM.
storm2k is offline   Reply With Quote
Old February 22nd, 2002, 07:49 PM     #8 (permalink)
Member
 
crzymt12's Avatar
 
Join Date: Jan 2002
Posts: 87
yeah i downloaded own of those phone things before too. it wanted to have me pay to use it. wut does it do.
crzymt12 is offline   Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Most Active Discussions
Is It Just Me? (1640)
windows 7 retail and rtm (5)
FT HOOD attack: 7 killed 12 injured (67)
HELP!!! What do you think of this s.. (21)
Review My Build (6)
Assosiations (21500)
Looking for a graphic card that wil.. (30)
My 1st pc build (40)
PC Modern Warfare 2: it's much wors.. (12)
core i7 extreme 975, nvidia 9400gt (9)
Aero in Vista (7)
How to Ship a PC (16)
Building my first computer (13)
[F@H SPAM 11/1/09]New month . . . n.. (33)
Recent Discussions
HELP!!! What do you think of this sys.. (21)
My Pc wont start after i interupted D.. (0)
windows 7 retail and rtm (5)
New processor technical problem (0)
boot from CD-ROM in chipset via P4M80.. (2)
Powe Director v8 (0)
Windows Experience Index is screwed u.. (3)
Review My Build (6)
FAT32 to NTFS file system in Win2kpro (4)
Internet very slow since updating AVG.. (8)
Motherboards and my curse... (25)
New Processor, Monitor will not turn .. (2)
2009 Build (4)
My 1st pc build (40)
Freezing During Music/Movies (1)
ext. sound card laptop to stereo syst.. (2)
Remote Desktop via SSH and error mess.. (2)
Help and Support disappeared from my .. (0)
[F@H SPAM 11/1/09]New month . . . new.. (33)
Basic applications needed for "r.. (1)
core i7 extreme 975, nvidia 9400gt (9)
hard drive problem (2)
Win7 TrustedInstaller Permissions (2)
Speed up Win 7 boot time a bit (1)
Hard Drive test program (2)


All times are GMT -4. The time now is 10:41 AM.
TechIMO Copyright 2008 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28