BetaONE will rise again!


Reply
  #1  
Old 5th Jun 04, 11:24 PM
wire2wire18 wire2wire18 is offline
New Member
 
Join Date: Jun 2004
Posts: 2
wire2wire18
Hey all-

I did a search on Yahoo for a taskmgr.exe problem I have. There was one thread on this board where one guy had the exact same problem I had...2 taskmgr.exe were on my computer.

1 is the normal one...taskmgr.exe in System32.

Then I have the problem one...TASKMGR.EXE-06144C13.pf. It is the obvious reason why when I press Ctrl+Alt+Del my system usage comes up, not the task manager.

So, I tried to delete that file, which it allowed me to do, then I clear it from the Recycle Bin. I reboot my computer and it's still there. I right clicked it and ran Norton on it, and there was no virus found....

How can I get rid of this file for good? Any info appriciated.
Reply With Quote
  #2  
Old 6th Jun 04, 01:49 AM
richardc2000 richardc2000 is offline
Retired
 
Join Date: Jul 2001
Location: vancouver
Posts: 803
richardc2000 is on a distinguished road
when you do delete it as you say - be sure to turn off the system restore
Reply With Quote
  #3  
Old 6th Jun 04, 02:12 AM
wire2wire18 wire2wire18 is offline
New Member
 
Join Date: Jun 2004
Posts: 2
wire2wire18
Sorry, Richard, I am not that computer saavy. What does that mean?
Reply With Quote
  #4  
Old 6th Jun 04, 03:01 AM
~*McoreD*~'s Avatar
~*McoreD*~ ~*McoreD*~ is offline
Super Moderator
 
Join Date: Jul 2002
Location: Australia
Posts: 2,902
~*McoreD*~ is an unknown quantity at this point
Provided that you have Widows XP:

My Computer > Right Click > Properties > System Restore > Turn off System Restore.
Reply With Quote
  #5  
Old 6th Jun 04, 04:56 AM
KingCobra's Avatar
KingCobra KingCobra is offline
Senior Member
 
Join Date: Dec 2001
Location: Illinois
Posts: 2,409
KingCobra is on a distinguished road
Send a message via Yahoo to KingCobra
If you do not currently run anti spyware like adaware, I'd run a scan ASAP!

Code:
http://download.com.com/3000-8022-10214379.html?tag=lst-0-2
Install and then update the def before you do a scan. Please post your results.
__________________
Reply With Quote
  #6  
Old 9th Jun 04, 01:04 AM
Jupiter2k Jupiter2k is offline
Member
 
Join Date: Oct 2001
Posts: 93
Jupiter2k
read this it's possible?

CoolWebSearch is a trojan that hijacks Internet Explorer start and search settings to one of several different web sites (see below). Most of these web sites appear to have an affiliate relationship with coolwebsearch.com in which coolwebsearch pays them for every visitor they refer. There could be other domains involved in the future.

This hijack is similar to the datanotary.com hijack discovered within the last couple of months. As with datanotary, the CoolWebSearch hijack sets Internet Explorer to use a custom style sheet containing javascript that opens a pop up window. In fact, it is believed that: the trojan involved with CoolWebSearch is an updated version of the same malware involved with datanotary.

In the original variant, the start and search settings were changed to an address in which the letters are converted into an unreadable mess of numbers and % symbols to hide the domain name from the user. It also made it difficult to blacklist the domain. Internet Explorer is able to translate the symbols and load the hijacker's web site.

An executable file named bootconf.exe is copied to the \windows\system32\ folder and set to load at startup. Even if you fix the hijack, this file will reinstall it the next time it is loaded.

More current variants also install a small web server, contained in a file named svchost32.exe. It adds several google addresses (google.de, google.ch, google.ca, etc) search.yahoo.com, and search.msn.com to the HOSTS file, telling windows that the IP addresses for those sites is 127.0.0.1, and that's where it's webserver is listening.

Yet another variant hijacks Internet Explorer's SearchHook setting with a file named dnsrelay.dll. This redirects all search and start page settings to allhyperlinks.com.

Finally, CoolWebSearch lists the hijacker's web site in Internet Explorer's trusted security zone. Domains listed in the trusted security zone have no restrictions on what they can do. This allows that web site to have virtually unlimited access to the infected computer's file system.

The source of the infections might be activex drive by installers located on pornographic web sites, or possibly trojan programs pretending to be illegal serial number generators. Unfortunately, this is just speculation for now.


Best Bet:

1. Back up your personal files.

2. Do a complete format (not quick) on your hard drive.
.
some useful info here
Code:
www.spywareinfo.com/~merijn/downloads.html
hope it helps ?
Reply With Quote
  #7  
Old 9th Jun 04, 03:12 AM
SlickVic78's Avatar
SlickVic78 SlickVic78 is offline
Senior Member
 
Join Date: Sep 2001
Location: New York, USA
Posts: 515
SlickVic78 is an unknown quantity at this point
I personally would only resort to what Jupiter2k stated, which was to format your hard drive and start over, only as a last resort. I would agree with what KC said - download some free spyware removal tools such as SpyBot and Ad-Aware and see if they help you out.

Believe me, I had 2 computers crazy infected with all sorts of spyware/adware junk, and with a little time, and patience, was able to completely clean out both systems without formatting either one.

Good luck,
-SlickVic78
__________________
  • Pentium 4 3.20GHz Processor
  • 1 Gig DDR 400MHz RAM
  • 100 Gig 7200 RPM Western Digital HDD
  • 80 Gig 7200 RPM Western Digital HDD
  • Lite-On LTR-52327S CD-RW Burner
  • Lite-On SOHW-1633S DVD Burner
  • ATI Radeon 9700 Pro
  • Sound Blaster Audigy
  • Microsoft Windows XP Pro SP-2
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Quick Thinking Hunted The Funny Forum 0 2nd Nov 04 01:08 PM
ECS K7S5A motherboard problem Ishy Hardware Support 2 18th Mar 02 07:49 PM
Floppy Drive problem on Win2K Crowdirt Hardware Support 0 28th Sep 01 11:31 AM
Sidewinder Problem robintodd Hardware Support 0 26th Aug 01 09:17 PM


All times are GMT +1. The time now is 10:30 AM.


Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.