Emergency Help Needed!
Viruses got you down? Spyware making your system sluggish? Post here for support on all your security needs.

Moderators: Management, Forum Experts

Postby purplehawk on Sat Jan 11, 2003 2:52 pm

Which online scan are you using?
purplehawk
 

Postby kanaloa on Sat Jan 11, 2003 2:55 pm

Not even sure of the name of it... but it's working.
"With realization of one's own potential and self-confidence in one's ability, one can build a better world." -Dalai Lama
Image

Follow me on Twitter: http://twitter.com/JCDerrick
User avatar
kanaloa
President
 
Posts: 24878
Joined: Sat Mar 09, 2002 8:18 pm
Location: Columbia, SC
Real Name: John Derrick

Postby RIP! on Sat Jan 11, 2003 2:56 pm

John feel free to holler at me if I can help u in any way.

GL man!
~One Liner!~
RIP!
PRO Level 15
PRO Level 15
 
Posts: 1009
Joined: Fri Jul 26, 2002 12:35 pm
Location: Va

Postby kanaloa on Sat Jan 11, 2003 2:57 pm

Thanks RIP. I'll keep you all posted on that scan... then go from there. I might just reinstall Windows.
"With realization of one's own potential and self-confidence in one's ability, one can build a better world." -Dalai Lama
Image

Follow me on Twitter: http://twitter.com/JCDerrick
User avatar
kanaloa
President
 
Posts: 24878
Joined: Sat Mar 09, 2002 8:18 pm
Location: Columbia, SC
Real Name: John Derrick

Postby kanaloa on Sat Jan 11, 2003 3:00 pm

The scanner is called: Trend Micro

http://housecall.antivirus.com/
"With realization of one's own potential and self-confidence in one's ability, one can build a better world." -Dalai Lama
Image

Follow me on Twitter: http://twitter.com/JCDerrick
User avatar
kanaloa
President
 
Posts: 24878
Joined: Sat Mar 09, 2002 8:18 pm
Location: Columbia, SC
Real Name: John Derrick

Postby Yappinator on Sat Jan 11, 2003 3:05 pm

That Actually is a great online scanner

I always have trend as a Just in case :yesnod:
To err is human, to really foul things up requires a computer.
Failure is not an option. It comes bundled with the software
Quoting one is plagiarism; Quoting many is research
Frogs have it easy; they can eat what bugs them..

Image
User avatar
Yappinator
Banned
 
Posts: 849
Joined: Thu Jul 04, 2002 10:12 pm
Location: On. Canada

Postby RIP! on Sat Jan 11, 2003 3:09 pm

Yeah that is one of the scanners that I use. It located the infected files but wasn't able to do anything about them.

Hope it helps you tho John!

McAfee also has a free online scanner.
~One Liner!~
RIP!
PRO Level 15
PRO Level 15
 
Posts: 1009
Joined: Fri Jul 26, 2002 12:35 pm
Location: Va

Postby kanaloa on Sat Jan 11, 2003 3:11 pm

How did you ultimately fix the problem on yours RIP?
"With realization of one's own potential and self-confidence in one's ability, one can build a better world." -Dalai Lama
Image

Follow me on Twitter: http://twitter.com/JCDerrick
User avatar
kanaloa
President
 
Posts: 24878
Joined: Sat Mar 09, 2002 8:18 pm
Location: Columbia, SC
Real Name: John Derrick

Postby kanaloa on Sat Jan 11, 2003 3:12 pm

I'm currently running that scan from another Windows XP installation on that machine. I'm hoping since it's installed on a seperate drive I can delete all those pesky things and not have problems... but i'l have to wait and see.
"With realization of one's own potential and self-confidence in one's ability, one can build a better world." -Dalai Lama
Image

Follow me on Twitter: http://twitter.com/JCDerrick
User avatar
kanaloa
President
 
Posts: 24878
Joined: Sat Mar 09, 2002 8:18 pm
Location: Columbia, SC
Real Name: John Derrick

Postby RIP! on Sat Jan 11, 2003 3:18 pm

John did you see my post on the two tools I end up using?

There is a registry key that trojans modify about 90% of the time, that is what keeps you from being able to stop the running processes and removing the file .... let me get the info on the key for ya. BRB

Ok .... here we go:
In the registry key

HKEY_LOCAL_MACHINE\Software\CLASSES\exefile\shell\open\command

the Trojan changes the (Default) value to:

wmmiexe.exe "%1" %*

This causes the Trojan to run when you run an .exe file.

But what I learned John was that the file name can be just about anything. So just look at that particular key and make sure it reads
"%1" %" with no file name at all.

*I would stop system restore from runing and reboot.*
But before you remove this, if your scanners are finding any files infected. Make sure they aren't running through your task manager (shift-ctrl-esc Processes) dbl click image name to arrange them in Alpha Order, then click the name of the program and then End Process.

(John I know this is basic stuff to you, but it was for others sake)
Last edited by RIP! on Sat Jan 11, 2003 3:28 pm, edited 2 times in total.
~One Liner!~
RIP!
PRO Level 15
PRO Level 15
 
Posts: 1009
Joined: Fri Jul 26, 2002 12:35 pm
Location: Va

PreviousNext

Return to Security & Virus

Who is online

Users browsing this forum: No registered users and 0 guests