Forum     

Go Back   Digit Technology Discussion Forum > Software > Software Q&A
Register FAQ Calendar Mark Forums Read

Software Q&A Having trouble with software? Find solutions here


Closed Thread
 
LinkBack Thread Tools Display Modes
Old 23-08-2005, 08:13 PM   #1 (permalink)
Right Off the Assembly Line
 
Join Date: Feb 2004
Location: Pune
Posts: 9
Default SOme kinda virus


I use WinXP professional
Recently a file cald p2pnetwork.exe pops up during startup and tries to connect to the net.
Many system programs lik taskmon, regedit, etc v stopped workin
wen i type regedit in the run dialog, it gives a 16 bit msdos subsystem error.
n for task manager, it says dat it is being used by some other program
i tried using the process viewer with visual studio to kill the p2p process, but it says it cant open the processes
CTRL+ALT+DEL also doesnt work
i searched using norton and ad-aware, but no results
also i cant find the p2pnetwork.exe on my disk, though it returns every time i remove it frm the startup list using msconfig

WHat DO I DO???
__________________
i want to be buried with my head down in the sand,
so that people who hate me,
can kiss my a ss
chetan331 is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 23-08-2005, 08:20 PM   #2 (permalink)
In The Zone
 
Join Date: Oct 2004
Location: Chennai
Posts: 400
Default

Yikes!! you got a Backdoor W32.Alcra.A update your virus definitions and adware definitions scan your pc.

See here for detailed information on removing this virus.
__________________
Intel Pentium 4 2.40C @ 800 Mhz FSB,On Asrock P4i65GV, 1 GB Transcend DDR 400 Mhz,160 GB Seagate SATA,120 GB Samsung PATA
GeForce FX5500 256MB,LG GCE-8525B,52x32x52x,Lite-On SOHW-1633S DVD Burner
Creative 2.1 Inspire Series,Syncmaster 17\" 793MB
shivaranjan.b is offline  
Old 23-08-2005, 08:56 PM   #3 (permalink)
Human Spambot
 
swatkat's Avatar
 
Join Date: Mar 2004
Location: India
Posts: 2,033
Default

Download HijackThis and unzip it to dedicated folder (like C:\HijackThisFolder\hijackthis.exe).
Then run it and click the button Do a System scan and save log file. HijackThis will perform a scan and saves the log file as hijackthis.log in the same folder where it is installed and it also opens the file automatically.
Copy the entire contents of the file and post it here.
__________________
http://swatrant.blogspot.com/
swatkat is offline  
Old 24-08-2005, 01:02 PM   #4 (permalink)
In The Zone
 
anomit's Avatar
 
Join Date: Mar 2005
Location: Kharagpur
Posts: 252
Default

Well swatkat, I am just joking. How many times have you posted the same lines ??!! 8)

Do you have these lines copied in a text file from where you copy and paste it here ??
__________________
Don\'t SYN me, I'll SYN you. :p
anomit is offline  
Old 24-08-2005, 01:11 PM   #5 (permalink)
Just Do It
 
Charley's Avatar
 
Join Date: Feb 2005
Location: Bangalore
Posts: 2,126
Default

[EDITED=ctrl_alt_del]No personal attacks.
Charley is offline  
Old 24-08-2005, 01:17 PM   #6 (permalink)
Microsoft MVP
 
Vishal Gupta's Avatar
 
Join Date: Jul 2005
Location: AskVG.com
Posts: 5,173
Default

I think this thread was started for getting the solution to the problem, not for personal talk.

well chetan331,
Do what swatcat suggested...
and post the result.
__________________
:arrow: http://www.AskVG.com/
Vishal Gupta is offline  
Old 24-08-2005, 03:40 PM   #7 (permalink)
Right Off the Assembly Line
 
Join Date: Feb 2004
Location: Pune
Posts: 9
Default

yeah, it was the w32.alcra.a virus. but my liveupdate subscription has expired, and couldnt update my vir defn using the symantec site

What i did was open the registry in safe mode. searched and deleted all instances of "p2pnetwork.exe" and "msconfigs.exe" also deleted the temp files created by the virus in the system folder

this stopped the virus from starting itself automatically at startup. my task manger also started showing up, but the cmd console doesnt work still. i cant use sfc too... maybe i'll take the command.com, ping, tracert, and other affected files from a friend's machine.

THanks Shivranjan for the help
__________________
i want to be buried with my head down in the sand,
so that people who hate me,
can kiss my a ss
chetan331 is offline  
Old 24-08-2005, 03:45 PM   #8 (permalink)
String Phreak
 
mediator's Avatar
 
Join Date: Mar 2005
Location: In ur Evil Mind!
Posts: 2,457
Default

Hmm...
1. First of all there are lots of threads on 16bit subsytem search them to find ut soln.
2. Go Install some startup managing program like startup platinum and remove the p2pnetwork.exe!
Its neither a virus nor a trojan! But a program u recently installed like kazaa, shareaza,bareshare or limewire.
U can alternately configure the installed program not to connect at startup!
Or use spysweeper it monitors the unwanted startup progs like p2pnetwork.exe besides being an antispyware!
__________________
Bad Bad server.....No candy for u!
mediator is offline  
Old 24-08-2005, 04:39 PM   #9 (permalink)
I am Optimus Prime
 
navjotjsingh's Avatar
 
Join Date: Feb 2005
Location: Delhi, India
Posts: 1,919
Default

sfc might be disabled. Use Tweaker like X-Setup or Fresh UI to enable it again.
navjotjsingh is offline  
Old 24-08-2005, 05:49 PM   #10 (permalink)
Distinguished Member
 
anandk's Avatar
 
Join Date: Mar 2005
Location: Pune
Posts: 3,783
Default

p2pnetwork.exe is added by the w32/rbot-acz worm. when started this infection will connect to a remote irc server where it will wait for commands.
http://www.bleepingcomputer.com/star....exe-9645.html

use pestpatrol or ewido security suite to remove it, if u dont want to do it manually. www.download.com

ya, u have some p2p program like kaazaa, warez, etc installed ? also if ur norton subscription has expired, dump it and go for avast or avg. having a non-updated anti-virus is like not having one at all !
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
anandk is offline  
Old 24-08-2005, 08:08 PM   #11 (permalink)
In The Zone
 
Join Date: Oct 2004
Location: Chennai
Posts: 400
Default

@anandk

Hey the ewido security suite is really good thanks for your suggestion the other day.........
__________________
Intel Pentium 4 2.40C @ 800 Mhz FSB,On Asrock P4i65GV, 1 GB Transcend DDR 400 Mhz,160 GB Seagate SATA,120 GB Samsung PATA
GeForce FX5500 256MB,LG GCE-8525B,52x32x52x,Lite-On SOHW-1633S DVD Burner
Creative 2.1 Inspire Series,Syncmaster 17\" 793MB
shivaranjan.b is offline  
Old 25-08-2005, 12:58 PM   #12 (permalink)
In The Zone
 
anomit's Avatar
 
Join Date: Mar 2005
Location: Kharagpur
Posts: 252
Default

[EDITED=ctrl_alt_del]No personal attacks.
__________________
Don\'t SYN me, I'll SYN you. :p
anomit is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


 
Latest Threads
- by clinton
- by Niilesh
- by chris
- by abhidev
- by gforz
- by Anorion
- by Tenida
- by tkin

Advertisement




All times are GMT +5.5. The time now is 02:17 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2