Image
Interordi Menu
Unknown
Deleted account
Quote

Post redacted

Sage
All Business.
Offline
1762 posts
Quote

What are you doing with a kazaa file anyways? p2pnetworking.exe isn\'t really a worm.*cough* You MAY have to remove it from registry. If you gave me the full name if there is one, I could give you a fix tool.

EDIT: Its not a worm, its spyware and adware combined ACTING like a worm, I\'ve found it, it coems along with kazaa...ALL VERSIONS. Right, do you have hijackthis.exe? If so, run it save the log and send it to me VIA msn. Theres about 6-7 things you MAY need to remove. Because, its in your regsitry too as

HKLM\\..\\RunServices: [p2pnetworking] p2pnetworking.exe

do a ctr/alt/del and in taskmanager stop this process if running.


ap9h4qmo.exe


have hijack this fix these entries. close all browsers and programmes before
clicking FIX.

4 - HKLM\\..\\Run: [ViewMgr] C:\\Program Files\\Viewpoint\\Viewpoint Manager\\ViewMgr.exe
O4 - HKLM\\..\\Run: [winupdate] C:\\Program Files\\winupdate\\winupdate.exe /auto
O4 - HKLM\\..\\Run: [MSConfig] C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\MSConfig.exe /auto
O4 - HKLM\\..\\Run: [ap9h4qmo] C:\\WINDOWS\\system32\\ap9h4qmo.exe
O4 - HKLM\\..\\Run: [Media Access] C:\\Program Files\\Media Access\\MediaAccK.exe
O4 - HKLM\\..\\RunServices: [p2pnetworking] p2pnetworking.exe

http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.af.html

^Found it, easy removal.

And...

http://securityresponse.symantec.com/avcenter/venc/data/adware.p2pnetworking.html


[Edited on 6/12/05 by Sage]

[Edited on 6/12/05 by Sage]


Fight, Megaman! For everlasting peace! ~ :o

Unknown
Deleted account
Quote

Post redacted

Sage
All Business.
Offline
1762 posts
Quote

Kill these


O4 - HKLM\\..\\Run: [p2pnetworking] p2pnetworking.exe
O4 - HKLM\\..\\RunServices: [p2pnetworking] p2pnetworking.exe


UE will tell the rest


Fight, Megaman! For everlasting peace! ~ :o

Staff Unknown_Entity
Moderator
Minecraft op
Contributor
634% more 1337
Offline
463 posts
Squid beaker
Squid beaker
Earned all 150 original CL achievements
Acquired on 17 January 2016
Princess Celestia
Princess Celestia
Got all items in the AFD2012 event!
Acquired on 2 April 2012
Zenny
Zenny
Unlock all of the main forum features!
Acquired on 2 April 2014
Hisao Nakai
Hisao Nakai
Acquired on 2 April 2012
Lilly Satou
Lilly Satou
Acquired on 2 April 2012

... and 24 more
Quote

Processes to Kill:
C:\\Program Files\\Common files\\SearchUpgrader\\SearchUpgrader.exe

Have HJT fix:
R1 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Search Page = http://www.couldnotfind.com/search_page.html?&account_id=139479
R1 - HKCU\\Software\\Microsoft\\Internet Explorer\\Search,SearchAssistant = http://www.couldnotfind.com/search_page.html?&account_id=139479
^You sure you set these?

R3 - URLSearchHook: (no name) - {00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file)
O2 - BHO: {92E1B3F7-0546-421E-9835-904D25B7BA66} - {C4F147D7-BF25-488E-A12B-EFD43E7029BF} - C:\\WINNT\\System32\\winvbie.dll
O3 - Toolbar: VisuExplorer - {92E1B3F7-0546-421E-9835-904D25B7BA66} - C:\\WINNT\\System32\\msiev32.dll
O4 - HKLM\\..\\Run: [winupdate] C:\\Program Files\\winupdate\\winupdate.exe /auto
O4 - HKLM\\..\\Run: [p2pnetworking] p2pnetworking.exe
O4 - HKLM\\..\\RunServices: [p2pnetworking] p2pnetworking.exe

O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\\Program Files\\AIM\\aim.exe (file missing)
^You sure you have AIM installed?
If so kill this too:
O4 - HKCU\\..\\Run: [AIM] C:\\Program Files\\AIM\\aim.exe -cnetwait.odl
--

O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\\PROGRA~1\\AWS\\WEATHE~1\\Weather.exe (file missing) (HKCU)
^You sure you have Weatherbug installed?

O16 - DPF: {11111111-1111-1111-1111-111111113457} - file://c:\\ied_s7.cab
/> O16 - DPF: {11111111-1111-1111-1111-111191113457} - file://c:\\ied_s7.cab
/> O16 - DPF: {11111111-1111-1111-1111-511111113457} - file://c:\\x.cab
O16 - DPF: {11111111-1111-1111-1111-511111113458} - file://c:\\x.cab
O16 - DPF: {11111111-1111-1111-1111-511111193457} - file://c:\\x.cab
O16 - DPF: {11111111-1111-1111-1111-511111193458} - file://c:\\x.cab
O16 - DPF: {23232323-2323-2323-2323-232323291122} - file://c:\\x.cab
O16 - DPF: {4418DD4D-7265-4C32-BC0A-3FDB3C2DA938} (Protecter Class) - http://www.xxxtoolbar.com/ist/softwares/v3.0/protect_regular.cab
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - file://C:\\TempEI4\\EI40_\\msxml4.cab
O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - C:\\WINNT\\System32\\vbsys2 (file missing)

[Edited on 6/12/2005 by Unknown_Entity]

[Edited on 6/12/2005 by Unknown_Entity]


Spammers make Doc this face > :mad:

Chatz

[14:33:35] <Lost_To_Apathy> STZ...what the feck is that? Sexually Transmitted Zit?

Noobs can click here for all the Gameshark codes and roms they need

Unknown
Deleted account
Quote

Post redacted