-
Are they spying on me?
Hello my comp is lately very very slow, and there are automaticly starting a browser and 2 notepaths.
When i look into the properties of the browser, it says:
res://C:\WINDOWS\System32\shdoclc.dll/navcancl.htm#http://www.tampabaymart.com/vb/chann...ktopSearch.asp
What is this and how do i get my comp back to normal.
Tnx for all support.
-
try using ad-aware it will show you and you can delete all the spy-ware installed in your computer .
its available at: http://www.lavasoftusa.com/
-
Tnx i ave dowloaded it an t's checking now.
In the notepaths that are openin when starting up are these senteces:
[.ShellClassInfo]
LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21787
mmm didn't help a thing. I removed all what was suspecious. But it is still he same.
-
MMM i think i found something:
I found a desktop.ini file in my programfiles.
When i deleted it, it multiplied like a cockroache. Now i have like 75 of them.....
Please please help me with this......
-
Desktop.ini is a feature of microsoft as fas as I know It enhances the layout of the directory. You should check your registery to. Local_machine/software/microsoft/windows/run runservices etc. for things you don't need to be started. Be carefull tho you don't delete important things, you can't just delete all. Also check current_user/software/microsoft/windows/run.
Hope that helps...
-
do not wory about desktop.ini or yu will worse the condition ,but run yur antivirus .
REMEMBER :- to run ADAWARE SW after accessing internet .
it serches for that cookies ,which ar making yur clicks ,even pasword public or to another
AVOID using KAAZA ,it sends yur password to a serevre
THANK YU
IF THE RED LIGHT OF HARD DISK IS GOING ON THEN YU HAVE A VIRUS OR A TORJAN
SOMETIMES SOME APPLICATION START LOGGING YUR INTERNET CONNECTION .
CHECK NEWLY INSTALL APPLICATION .
REMMEMBER HAVE A GOOD ANTI VIRUS & ALSO UPDATED
REMOVE FILE FROM start-up folder ,they slow down the computer
& also run scandisk & defrgment yur HD
-
I dont care about 1 desktop.ini, but now i have about 75.....how come?
I have Norton antivirus running with liveupdate.
-
What makes me suspicous is this entry:
[.ShellClassInfo]
LocalizedResourceName=@%SystemRoot%\system32\shell
32.dll,-21787 <--is this a server listening on a high port number?
Is this a trojan server? Get The Cleaner to see if it is... here is a link: www.moosoft.com
-
tnx for that prog, it found 10 of them.....
I also got this message
FILE: C:\hiberfil.sys
PROBLEM: I could not scan this file. Error Code 5: "Toegang geweigerd."(acces dienied)
SOLUTION: A common reason for this error is that Windows has locked the file for
SOLUTION: exclusive access. A swap file is a common example. Also, an antivirus
SOLUTION: program might be denying access to the file. In that case, you can
SOLUTION: temporarily disable the anti-virus to clean the trojan.
FILE: C:\pagefile.sys
PROBLEM: I could not scan this file. Error Code 5: "Toegang geweigerd."(acces dienied)
SOLUTION: A common reason for this error is that Windows has locked the file for
SOLUTION: exclusive access. A swap file is a common example. Also, an antivirus
SOLUTION: program might be denying access to the file. In that case, you can
SOLUTION: temporarily disable the anti-virus to clean the trojan.
Are those files ok or not?
-
Pagefile.sys is your Windows Pagefile (known as swap file in Win9x). Don't worry about that. The hiberfil.sys, I'm not really sure about, but is probably a hibernation file where all of your memory is stored when you computer goes into hibernation mode. You should be fine not being able to scan those two files.
AJ
Edit: Also, because of the Trojans you had, you may want to think about installing a software firewall which will let you filter out-going traffic so that you can ensure that you won't have any Trojan's accessing the 'net without your permission any more.