SoftwareTipsandTricks Forum

Go Back   SoftwareTipsandTricks Forum > Software > Software Problems and Useful Utilities
User Name
Password


CurrentVersion/Run contents question

Reply
 
Thread Tools Search this Thread Rate Thread Display Modes

  #1  
Old 10-15-2005, 04:57 PM
Willie_Williams Offline
Registered User
 
Join Date: Jul 2005
Posts: 5
CurrentVersion/Run contents question

I'm trying to disinfect my daughter's XP Dell Inspiron Notebook, which is so under attack that she can't do anything. Two of these attackers are the "Casino" virus (which Symantec labels Adware.Jraun) and the "Adware.Websearch" virus.

I ran a Symantec scan (in Safe mode) and it found nothing.

I had removed the "Web Search" program from Add/Remove Programs, so maybe that actually did a through job of removing it.

I can't find the "Golden Palace Casino PT" program in Add/Remove Programs, (Symantec says to remove it from there) so it must be doing something under the covers.

Anyway, in the Symantec "manual" unstructions for removing the Casino virus, it says to go into regedit to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run and remove version.exe and keyhost.exe and HKEY_LOCAL_MACHINE\SOFTWARE\Redirectkey.

But none of these were there.

HOWEVER, there were all sorts of suspicious keys, like:

- adcomplusanalytic.exe
- exp.exe
- mmxp2passion.exe
- playandwin.exe
- Setup2-71.exe.exe

Can I remove these without worrying?

She's got dozens (maybe 45) executables being kicked off in this "Run" registry folder. This is excessive, isn't it.

Is there a way, other than writing them all down, of capturing a list of all those registry items so I could post it for your expert inspection?

Thanks,

- Willie Williams
Reply With Quote

  #2  
Old 10-15-2005, 06:14 PM
pip22's Avatar
pip22 Offline
Registered User
 
Join Date: Jun 2004
Location: United Kingdom
Posts: 1,297
Quote: "Is there a way, other than writing them all down, of capturing a list of all those registry items so I could post it for your expert inspection?"

Yes indeed there is a way. The accepted method is to download "HijackThis". Run it to create a log-file of everything that's running on the system, then post the log to the appropriate forum for analysis and instructions on what to 'fix'. It's important to remember that 'hijackthis' lists everything that's running, both good and bad, so don't attempt to analyse it yourself. 'HijackThis can be downloaded from here:
http://www.majorgeeks.com/download3155.htm
Reply With Quote

  #3  
Old 10-15-2005, 07:08 PM
Willie_Williams Offline
Registered User
 
Join Date: Jul 2005
Posts: 5
Hijackthis question

Since the machine I'm trying to revive/disinfect is completely useless at present--it starts attempting to download a Casino program and also puts up "Can't access locationXXXXXX" type error messages, and I can't even get it to respond to CNTL>ALT>DELETE or Task Manager. So I can only run hijackthis in Safe mode. But I think a much smaller (safer) number of processes are running in Safe mode.

I think I'll be able to download hijackthis in Safe mode with Network, but how will I run it when I'm not in Safe mode?

---------------------------------------------------------
You wrote:

Quote: "Is there a way, other than writing them all down, of capturing a list of all those registry items so I could post it for your expert inspection?"

Yes indeed there is a way. The accepted method is to download "HijackThis". Run it to create a log-file of everything that's running on the system, then post the log to the appropriate forum for analysis and instructions on what to 'fix'. It's important to remember that 'hijackthis' lists everything that's running, both good and bad, so don't attempt to analyse it yourself. 'HijackThis can be downloaded from here:
http://www.majorgeeks.com/download3155.htm[/quote]
Reply With Quote

  #4  
Old 10-16-2005, 12:51 PM
Willie_Williams Offline
Registered User
 
Join Date: Jul 2005
Posts: 5
CurrentVersion/Run contents question

I'm trying to disinfect my daughter's XP Dell Inspiron Notebook, which is so under attack that she can't do anything. Two of these attackers are the "Casino" virus (which Symantec labels Adware.Jraun) and the "Adware.Websearch" virus. (I discovered the Adware.Websearch likelihood because among the ~45 processes running after booting are:

- WSG.exe
- radio.exe
- PIB.exe
- TBPS.exe
-VPC32.exe

I Googled WSG.exe and the Symantec site says this process is part of the Adware.WebSearch virus.

I ran a Symantec scan (in Safe mode) and it found nothing. (?!?!)

I can't find the "Golden Palace Casino PT" program in Add/Remove Programs, (Symantec says to remove it from there) so it must be doing something under the covers.

Anyway, in the Symantec "manual" instructions for removing the Casino virus, it says to go into regedit to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run and remove version.exe and keyhost.exe and HKEY_LOCAL_MACHINE\SOFTWARE\Redirectkey.

But none of these were there.

HOWEVER, there were all sorts of suspicious keys, like:

- adcomplusanalytic.exe
- exp.exe
- mmxp2passion.exe
- playandwin.exe
- Setup2-71.exe.exe

Can I remove these without worrying?

She's got dozens (maybe 45) executables being kicked off in this "Run" registry folder. This is excessive, isn't it.

I understand that if you can run hijackthis, you can get a list of running processes to show experts. But that computer is so overwhelmed that I can't get to IE, Mozilla, or Windows Explorer to download/transfer the hijackthis program.

Do you think restoring an earlier version of the system (via System Restore in Safe mode) might improve the situation?

Or would that probably not affect these viruses?

Thanks for any advice you can give,

- Willie Williams
Reply With Quote

  #5  
Old 10-16-2005, 01:40 PM
yoni5002's Avatar
yoni5002 Offline
Registered User
 
Join Date: Oct 2005
Posts: 923
Why dont you better try an Antispyware first??/
About the:
adcomplusanalytic.exe
- exp.exe
- mmxp2passion.exe
- playandwin.exe
- Setup2-71.exe.exe

You can erase them all is not gonna afect you at all... ( It is posible that you'll receive a message of error after windows starts up... thats gonna be fixed later by any antispyware)

Yoni5002º
________
Reply With Quote
Reply




Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Connecting to the Internet Basic question micro_learner Internet 3 05-31-2005 12:32 AM
Problem Displaying contents using File -> Open Alphabeticaly from Z to A Stith16 Windows XP 6 04-26-2005 09:31 AM
Stop Folders from showing contents! Kishen Windows XP 4 01-09-2004 07:37 AM
Folder settings, cant view contents. blowndeadline Windows XP 0 10-11-2003 12:13 PM
how do you set up a table of contents in Word tuccokeith Software Problems and Useful Utilities 1 05-21-2003 12:39 AM



All times are GMT -5. The time now is 03:55 AM.


Designed by eXtremepixels. Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 2.3.2 © 2005, Crawlability, Inc.