home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Security and Privacy Issues
Ask a Tech Support Question (free)!

virus spyware what is this?

Reply
Get bargains at  »  Dealighted.com
 
Thread Tools Search this Thread
Currently Active Users: 2054
Discussions: 200,936, Posts: 2,379,239, Members: 246,301
Old February 8th, 2005, 09:14 PM     #31 (permalink)
It's the cheese guy! ¬_¬;
 
paul9's Avatar
 
Join Date: Aug 2003
Location: Gateshead U.K.
Posts: 9,167
Send a message via MSN to paul9 Send a message via Yahoo to paul9
jp, it was his thread
mbandela, i thought you already had shareaza, that is a clean program, as is emule.
paul9 is offline   Reply With Quote
Old February 8th, 2005, 09:48 PM     #32 (permalink)
Senior Member
 
micfau1091's Avatar
 
Join Date: Aug 2004
Location: ThisLand Was My Land
Posts: 512
Send a message via AIM to micfau1091 Send a message via Yahoo to micfau1091
Quote:
Originally Posted by pphalan
You nailed one, that sure does not belong there

It does...its a driver by Realtek sound cards.......trust me...i have it too on one of my comps...

http://www.liutilities.com/products/...rary/soundman/

http://www.2-spyware.com/file-soundman-exe.html
__________________
Gaming: AMD64 3K+, X1800GTO 256, 120gb7200
Personal/Living Room Gaming: (laptop)AMD64 3K+, 9700pro, 60gb5400
micfau1091 is offline   Reply With Quote
Old February 8th, 2005, 10:02 PM     #33 (permalink)
It's the cheese guy! ¬_¬;
 
paul9's Avatar
 
Join Date: Aug 2003
Location: Gateshead U.K.
Posts: 9,167
Send a message via MSN to paul9 Send a message via Yahoo to paul9
micfau, those look like the first two linkies i got when i plugged soundman.exe into a google search.
paul9 is offline   Reply With Quote
Old February 8th, 2005, 11:44 PM     #34 (permalink)
Ultimate Member
 
AzKidd69's Avatar
 
Join Date: Oct 2001
Location: Queen Creek, AZ
Posts: 1,480
Send a message via MSN to AzKidd69 Send a message via Yahoo to AzKidd69
From Sophos Antivirus

Quote:
W32/Agobot-JS is a worm that spreads to remote shares with weak passwords.

The worm copies itself as soundman.exe to the Windows system folder

To run on startup the worm installs itself as a service called soundman and sets the following registry entries:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run \soundman
= soundman.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Run Services\soundman
= soundman.exe

The Trojan attempts to terminate and disable various anti-virus and security-related programs and modifies the HOSTS file located at <WINDOWS>\System32\Drivers\etc\HOSTS, mapping selected anti-virus websites to the loopback address 127.0.0.1 in an attempt to prevent access to these sites. Typically the following mappings will be appended to the HOSTS file:

127.0.0.1 www.grisoft.com
127.0.0.1 www.trendmicro.com
127.0.0.1 trendmicro.com
127.0.0.1 rads.mcafee.com
127.0.0.1 customer.symantec.com
127.0.0.1 liveupdate.symantec.com
127.0.0.1 us.mcafee.com
127.0.0.1 updates.symantec.com
127.0.0.1 update.symantec.com
127.0.0.1 www.nai.com
127.0.0.1 nai.com
127.0.0.1 secure.nai.com
127.0.0.1 dispatch.mcafee.com
127.0.0.1 download.mcafee.com
127.0.0.1 www.my-etrust.com
127.0.0.1 my-etrust.com
127.0.0.1 mast.mcafee.com
127.0.0.1 ca.com
127.0.0.1 www.ca.com
127.0.0.1 networkassociates.com
127.0.0.1 www.networkassociates.com
127.0.0.1 avp.com
127.0.0.1 www.kaspersky.com
127.0.0.1 www.avp.com
127.0.0.1 kaspersky.com
127.0.0.1 www.f-secure.com
127.0.0.1 f-secure.com
127.0.0.1 viruslist.com
127.0.0.1 www.viruslist.com
127.0.0.1 liveupdate.symantecliveupdate.com
127.0.0.1 mcafee.com
127.0.0.1 www.mcafee.com
127.0.0.1 sophos.com
127.0.0.1 www.sophos.com
127.0.0.1 symantec.com
127.0.0.1 securityresponse.symantec.com
127.0.0.1 www.symantec.com

http://www.sophos.com/virusinfo/anal...2agobotjs.html

I think that about covers it for soundman.exe.. but also soundman.exe appears to be part of the realtek sound card drivers too.. sooo.. whic one is it? I would guess to say it is the virus peronally
__________________
Never argue with a computer, without a hammer.
Never program and drink beer at the same time.
Never trust a programmer who carries a screwdriver.
AzKidd69 is offline   Reply With Quote
Old February 9th, 2005, 05:59 AM     #35 (permalink)
27
Ultimate Member
 
27's Avatar
 
Join Date: Jun 2004
Location: England
Posts: 1,407
Well I have Creative 5.1 speakers and VIA 5 point audio on my sound card. I think I also have soundman.exe on my system.

I never installed any Creative software so is soundman a trojan or an audio driver? The automatic HijackThis log analysers say soundman is safe.
27 is offline   Reply With Quote
Old February 9th, 2005, 08:50 AM     #36 (permalink)
It's the cheese guy! ¬_¬;
 
paul9's Avatar
 
Join Date: Aug 2003
Location: Gateshead U.K.
Posts: 9,167
Send a message via MSN to paul9 Send a message via Yahoo to paul9
azkidd, the virus version is apparently
c:\windows\system\soundman.exe
but the clean version is apprently
c:\windows\soundman.exe
this second, aparrently clean, version is the one mentioned in the hjt log.

Last edited by paul9 : February 9th, 2005 at 09:20 AM.
paul9 is offline   Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Similar Threads
Thread Thread Starter Forum Replies Last Post
I got infected with startpag.hi, how do I clean it? Ruahrc Security and Privacy Issues 16 November 17th, 2004 10:06 AM
Help get rid of Java Virus Bizkitkid2001 Technical Support 7 September 29th, 2004 12:02 AM
multiple XP users..spyware q? John Prophet Applications and Operating Systems 7 June 25th, 2004 09:40 PM
HOW DID THIS HAPPEN?! durante IMO Community 36 August 7th, 2003 11:12 PM
ARGH! AOL Service squeech Applications and Operating Systems 16 June 17th, 2003 04:59 AM


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Most Active Discussions
windows 7 problem (6)
Is It Just Me? (2899)
CPU fan stops spinning randomly (8)
Wireless Televisions. (8)
California Passes Anti-Flat-HDTV Le.. (41)
Obama the Muslim (14)
Is the PSU I received dead? (11)
windows vista security holes (9)
HIS HD5770 graphic card question (15)
Install XP pro and a Vista laptop ?.. (11)
Print spooler problem (13)
Foreign voltage (10)
Dept. of HS: NSA 'Helped' Develop V.. (15)
A good PSU? (10)
Recent Discussions
CPU fan stops spinning randomly (8)
Partition Magic caused HDD problem (3)
Is the PSU I received dead? (11)
Have you switched yet? (85)
Regular Build (4)
windows 7 problem (6)
Point and Shoot Camera Suggestions. (2)
Modern Warfare 2 freeze (13)
Wireless Televisions. (8)
wireless user (1)
World's largest Monopoly Game using G.. (332)
Ideal cheap graph card for PC-Gaming? (17)
BIOS won't read disk when I try to fl.. (0)
Install XP pro and a Vista laptop ?? (11)
Graphics Card Upgrade Question (1)
favorit (1)
solutions for virtical white lines on.. (1)
Fire in DVD (2)
Modern Warfare For the PC (33)
radeon x850xt platinum & shader 3 (3)
Wireless Router+Cable Modems and Much.. (0)
Optical Audio A-B Switch (1)
windows vista security holes (9)
The NTDVM CPU has encountered an ille.. (24)
[F@H SPAM 11/16/09] ! 1/2 months to r.. (34)


All times are GMT -4. The time now is 11:53 AM.
TechIMO Copyright 2009 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28