home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Security and Privacy Issues
Join TechIMO for Free!
Register Blogs FAQ Members List Calendar Search Today's Posts Mark Forums Read
Reply Get bargains at  »  Dealighted.com
 
Thread Tools
Currently Active Users: 1878
Discussions: 188,470, Posts: 2,244,174, Members: 232,724
Old November 1st, 2004, 01:24 PM   Digg it!   #1 (permalink)
Best To Avoid Me
 
Martoch's Avatar
 
Join Date: Mar 2002
Location: Under Your Bed
Posts: 8,596
What the heck is this???

Hey guys!

I checked out our laptop this morning to find this little critter loading up multiple times (see pic below). Adaware, Spybot, and Norton find nothing. I uncheck it in msconfig, reboot, it's checked again. I even deleted the registry entries and a few of them keep returning. I'm unable to delete the folder...says it's in use constantly...the folder contains two .exe files (qttuwx [inetsvc] and xwuttq [inetkw],) as well as numerous DAT files named url, exit, dfs, and babe. It's really slowing down the boot time and the comp speed in general. Win XP Home on Gateway laptop. I'm not sure when it started loading because I pretty much never use the laptop.



What do you make of it?

Thanks!
Mike

Martoch is offline   Reply With Quote
Old November 1st, 2004, 01:29 PM     #2 (permalink)
A hero in training
 
GroundZero3's Avatar
 
Join Date: Oct 2001
Location: Norfolk, VA
Posts: 22,774
Blog Entries: 5
what is the name of the folder it is in?

GroundZero3 is offline   Reply With Quote
Old November 1st, 2004, 01:31 PM     #3 (permalink)
Best To Avoid Me
 
Martoch's Avatar
 
Join Date: Mar 2002
Location: Under Your Bed
Posts: 8,596
C:\Program Files\wtpprvx

Martoch is offline   Reply With Quote
Old November 1st, 2004, 01:33 PM     #4 (permalink)
skating away.........
 
doddsy's Avatar
 
Join Date: Nov 2003
Location: purging the urge
Posts: 6,454
can we have a shot with the "command" section expanded.

might give us something more to google with
doddsy is offline   Reply With Quote
Old November 1st, 2004, 01:35 PM     #5 (permalink)
Best To Avoid Me
 
Martoch's Avatar
 
Join Date: Mar 2002
Location: Under Your Bed
Posts: 8,596
Sure can...registry entry screenie coming first.
Martoch is offline   Reply With Quote
Old November 1st, 2004, 01:36 PM     #6 (permalink)
Real gangstas sip on Yacc
 
jkrohn's Avatar
 
Join Date: Oct 2001
Location: Suckas-ville
Posts: 4,549
Send a message via ICQ to jkrohn Send a message via AIM to jkrohn Send a message via Yahoo to jkrohn
First thing I would do is boot into safe mode and toast all files associated with those entries.

If that doesn't work fire up knoppix or any other linux boot cd and toast them there. From there you should be able to remove the registry entries.

Jkrohn
jkrohn is offline   Reply With Quote
Old November 1st, 2004, 01:40 PM     #7 (permalink)
Ultimate Member
 
Join Date: Oct 2001
Posts: 10,821
might try running cwshredder http://www.majorgeeks.com/download4086.html

it will sometimes get things that adaware/spybot miss

maybe run www.trendmicro.com online scan in case norton has been compromised
__________________
"Even a fool is thought to be wise if he is silent"
John Prophet is offline   Reply With Quote
Old November 1st, 2004, 01:40 PM     #8 (permalink)
Best To Avoid Me
 
Martoch's Avatar
 
Join Date: Mar 2002
Location: Under Your Bed
Posts: 8,596
Here's the reg shot:



I'm not familiar with Knoppix or any other linux boot cd.

I've been running trend online scan for a few mins...so far nothing yet.
Martoch is offline   Reply With Quote
Old November 1st, 2004, 01:43 PM     #9 (permalink)
Member
 
clearbluereason's Avatar
 
Join Date: Jul 2003
Location: Savannah
Posts: 152
my vote is with safe mode to kill all associated files, and knoppix is a linux bootable CD that lets you get access to any comp w/ boot from cd checked kinda nice tool to work on stuff. But to use knoppix you need to be somewhat linux savvy.
clearbluereason is offline   Reply With Quote
Old November 1st, 2004, 01:48 PM     #10 (permalink)
Mean Moderator
 
EvilRick's Avatar
 
Join Date: Oct 2001
Location: N of Music City, USA
Posts: 7,791
First off, get rid of Norton Internet Security.

Download a REAL firewall like Sygate

Go and download SpySweeper and update it/scan your system.

Get NOD32 and update it/scan your system.

Download Hijack This if you're still having problems after all that.
__________________
This signature intentionally left blank.
EvilRick is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may post new threads
You may post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
how do I change CPUs demonchaos916 Processors, Memory, and Overclocking 13 July 12th, 2004 04:34 AM
Explorer messed up or is it TechIMO??? Sweeper General Tech Discussion 6 June 14th, 2004 09:14 AM
ASUS A7N8X Mobo's jch216 Motherboards 21 June 7th, 2003 05:10 PM
Prisoners in Canada win the right to vote daveleau IMO Community 32 November 8th, 2002 04:18 AM
Speaker Wiring Gurus Needed Whir General Tech Discussion 26 July 19th, 2002 09:34 AM

Most Active Discussions
Is It Just Me? (2999)
"mastermind" of London at.. (65)
Intel Pentium 4 531 (7)
Please don't divorce us (40)
AMD Phenom II X4 940 Black Edition (11)
nVidia GTX 295 now available (21)
Replacing integrated video card (5)
Folderchat Weekday thread (458)
building a gaming computer, input p.. (14)
Recent Discussions
canon eos20d problem (1)
I cant sign into msn messenger,.. (8)
nVidia GTX 295 now available (21)
Folderchat Weekday thread (458)
Could I run this set-up (15)
Bought the Visiontek Radeon 387.. (1)
CPU Overheating ?? (18)
Computer will not boot(powers o.. (2)
*TechIMO's Top 30 PCs* (44)
Blackberry Storm, Gears of War .. (2)
Core 2 Quad Q9550 system (3)
COWBOOM Ripoff! Used Laptop w/$.. (4)


All times are GMT -4. The time now is 06:46 AM.
TechIMO Copyright 2008 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28