Jump to content

libupd~1.exe


Guest ellas
 Share

Recommended Posts

  • Replies 181
  • Created
  • Last Reply

Top Posters In This Topic

Top Posters In This Topic

Posted Images

These 2 are a result of virus infection

Systray = c:\windows\system32\kernel32.exe

netcode = C:\WINDOWS\System32\kernel32.dlI, tkBell is a nag screen for realplayer and can be disabled on start up possibly a few more in there that you can start from programs rather than have them running in the background all the time

Link to comment
Share on other sites

Wait for the scan to finish then run Spybot S& D (updated 1st) followed by Hijackthis and then we can have another look at the start up list log from hijack this.

Be aware tho that anything that needs the spyware will not run after running Spybot but there are freeware versions of most

Link to comment
Share on other sites

it is xp you are using is'nt it,you dont need dos commands,if you click on the start button and put regedit in RUN you can then follow the symantec instuctions,if you want to start in safe mode type msconfig in run and click on BOOT INI then chose safe mode.

Link to comment
Share on other sites

Have you done this stage 1st

Windows NT/2000/XP

To stop the Trojan process:

1. Press Ctrl+Alt+Delete one time.

2. Click Task Manager.

3. Click the Processes tab.

4. Double-click the Image Name column header to sort the processes alphabetically.

5. The Task Manager truncates the process name so that only 15 characters are displayed. Therefore, look for Yahoo updater.c by scrolling through the list.

6. If you find the file, click it, and then click End Process.

7. Exit the Task Manager.

Link to comment
Share on other sites

That perhaps suggests that it is no longer active,

Run regedit then just double check for

HKEY_LOCAL_MACHINE\SOFTWARE\EES once more if it isn't there do the next step

go to

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders

Windows NT/2000/XP: In the right pane, update the value

Common Startup

with the following data:

%ALLUSERSPROFILE%\Start Menu\Programs\Startup

Thanks for popping in gladiator need a lot of help here :o

Link to comment
Share on other sites

Guest Gladiator

Ahyes... and post her here the scan report --> AND THE PACKER INFO (tabulator runtime packed) AND the warnings.

Means all 4 pages from the scan report - You can do that with Copy + Paste

Link to comment
Share on other sites

Guest CalamityJane

Looking at the screen shot p2ccolo posted a page or two back, you need to disable system restore in Win XP while trying to get rid of the infected files. Did you do that?

I am glad to see Gladiator in here helping :D

Link to comment
Share on other sites

Guest Gladiator

And please delete the Backdoor "Netdevil.15" too - i see him without a AV Software :)

Because i am just including him in GAV - it's the File kernel32.dlI <--- I instand of L

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share


×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy