1
   

Nasty virus!

 
 
stuh505
 
Reply Fri 6 May, 2005 08:58 pm
I've never really had a problem with viruses before (I've had trojans etc of course but they just never really did anything bothersome)...but today I downloaded a file and had the sudden doubt that perhaps it was infected. My computer scans what I download automatically usually but I didn't recall seeing the scanner pop up. So I scanned it manually. Nothing found. I ran the program...and all of a sudden there were 600 rar files in that folder...what a blatant virus attack? I deleted them...but then realized another side-effect...I can no longer access my windows Task Manager! Windows is pretty much useless to me without that because I can't kill tasks and monitor my performance...I've run ad AdAware scan which killed some tracker trojans but did nothing to solve my current problem...does anyone have any knowledge of this specific virus and how to deal with it? I'm not interested in trying a million different trojan scanning programs I'm just wondering if anyone knows anything about this specific virus.

edit: this virus seems to have a lot of other nasty features which I won't go into now...but it seems to run under the guise of p2pnetwork.exe, although this file does not seem to exist anywhere
  • Topic Stats
  • Top Replies
  • Link to this Topic
Type: Discussion • Score: 1 • Views: 2,948 • Replies: 8
No top replies

 
bubba nis
 
  1  
Reply Mon 9 May, 2005 09:12 am
p2pnetwork.exe is nomore
Try this

goto http://www.mlin.net/StartupCPL.shtml and get the startup control panel

it installs into the control panel

log back into windows in safe mode and run the startup control in the HKLM/run tab and hkcu/run tab delete the p2pnetwork.exe entry then goto the deleted tab adn permenantly delete them

restart and hopefully all is well
0 Replies
 
marchitect nc
 
  1  
Reply Mon 9 May, 2005 03:15 pm
buba_nis:
the suggestion you gave doesn't seem to work. The p2pnetwork.exe comes back when you reboot, even after deleting it using the downloaded control panel. Any additional help would be appreciated. I cannot access my Task Manager and this program tries to log on every time I restart my computer. It even disables ZoneAlarm (whom I would love to call about this but they seem to be inaccessable for anything but software sales, no after the sale contact allowed, it seems).
0 Replies
 
marchitect nc
 
  1  
Reply Mon 9 May, 2005 03:46 pm
I found this and it seems to work even after rebooting...
At download.com there is a program called Security Task Manager 1.6e that found the P2Pnetwork.exe file. I click on the p2pnetwork.exe name, and select delete. A box comes up that gives you the option to delete the file or quarantine it. If you delete it it says the file may come back, but not if you quarantine it. So I quarantined it, exited, rebooted and now my Task Manager comes up. Yeah...so far.
Hope this helps.
0 Replies
 
xtreme628
 
  1  
Reply Mon 9 May, 2005 07:35 pm
Hijack This
I was having the exact same prob the tips on this page finally resolved it for me:
http://www.pcguide.com/vb/showthread.php?t=37182&goto=nextnewest

First, from Add/Remove Programs, uninstall newnet If there is no entry for it, an uninstaller can be found on the newnet website. http://www.newdotnet.com/removal.html


Download Hijack This http://files4.majorgeeks.com/files/2e626277f946a25463ebae27f7cac1d5/spyware/hijackthis.zip

Have Hijack This fix all of the following by placing a check in the appropriate boxes and hitting fix checked. Make sure all browser and all Windows Explorer windows are closed before fixing.

O4 - HKLM\..\Run: [MsConfigs] C:\Program Files\MsConfigs\MsConfigs.exe
O4 - HKLM\..\Run: [p2pnetwork] p2pnetwork.exe
O4 - HKLM\..\RunServices: [p2pnetwork] p2pnetwork.exe
O4 - HKCU\..\Run: [p2pnetwork] p2pnetwork.exe
O4 - HKCU\..\RunServices: [p2pnetwork] p2pnetwork.exe

Reboot and delete

files
p2pnetwork.exe

folders
C:\Program Files\MsConfigs

hope that helps
0 Replies
 
stuh505
 
  1  
Reply Mon 9 May, 2005 07:36 pm
Hello,

I wasn't reading this post but yes, the problem file is p2pnetwork.exe as well as msconfigs.exe

I have cleaned the problems.

First some things to do to help:

Download Registry Mechanic and Security Task Manager, Ad-Aware and AVG Virus Scanner. Those will all help clean things up. You should use them while in diagnositc or safe mode afte you've downloaded them.

Now onto this specific problem:

p2pnetwork.exe is visible in msconfig through Start->Run, however, the location it shows there is false...there is another flag that it sets up as a false locatoin! haha

anyway, it is located at these locations in the registry:


HKEY_CURRENT_USER\System\CurrentControlSet\Control\Lsa
HKEY_CURRENT_USERS\Software\Microsoft\Windows\CurrentVersion\RunServices
HKEY_LOCAL_MACHINE\Software\Microsoft\Ole

The Ole folder contains a whole bunch of other restrictions on your machine startup and use which you should delete

Finally, also delete this folder

HKEY_LOCAL_MACHINE\Software\Microsoft\Shared Tools\MsConfig\startupreg\p2pnetwork

whch contains the copy of p2pnetwork that shows up in msconfig, as well as it's false flags for it's location

To delete these things you usually use Start->Run->Regedit but for me, I think these progs disabled that, so download a different registry editor.

Yes, you need to do it manually. In the registry you may be able to notice a lot of folders for old programs and stuff. You should run Registry Cleaner first to help clean them up. While you're in here, you can also delete registry entries for old programs etc or anything else you know you dont need.
0 Replies
 
marchitect nc
 
  1  
Reply Mon 9 May, 2005 10:11 pm
stuh-505: you wrote: "so download a different registry editor." I just bought Registry Mechanic but it doesn't allow editing of the individual registry files. Regedit also doesn't work on my machine. Is there another registry editor? Download.com had one that I downloaded but I didn't know how to tell it where to find the registry files. Regedit knows where they are but this program didn't. I don't have that kind of computer knowledge.
What other registry editing program is there? (hopefully free since I just wasted $30 on Registry Mechanic.)
Thanks.
0 Replies
 
Everdarkangel
 
  1  
Reply Tue 17 May, 2005 09:52 am
I found out that if you get service pack 2 for xp, it upgrades the firewall and blocks the p2pnetwork.exe so you can access task manager and regedit, i'm not a regular member but i'm trying to get rid of that damn thing so i thought i'd post my own little contribution Smile
I know its not a fix but at least with task manager and regedit, you can get rid of the damn thing.
0 Replies
 
Glassman
 
  1  
Reply Tue 17 May, 2005 11:40 pm
Was having the same problem with p2pnetwork.exe and msconfigs.exe preventing task manager from working. I followed the directions given by xtreme628 and it worked. No worries.
Thanx Extreme
0 Replies
 
 

Related Topics

Clone of Micosoft Office - Question by Advocate
Do You Turn Off Your Computer at Night? - Discussion by Phoenix32890
The "Death" of the Computer Mouse - Discussion by Phoenix32890
Windows 10... - Discussion by Region Philbis
Surface Pro 3: What do you think? - Question by neologist
Windows 8 tips thread - Discussion by Wilso
GOOGLE CHROME - Question by Setanta
.Net and Firefox... - Discussion by gungasnake
Hacking a computer and remote access - Discussion by trying2learn
 
  1. Forums
  2. » Nasty virus!
Copyright © 2024 MadLab, LLC :: Terms of Service :: Privacy Policy :: Page generated in 0.03 seconds on 05/04/2024 at 06:32:56