Forum Home
Press F1
 
Thread ID: 57856 2005-05-14 11:10:00 p2pnetwork hacker/virus help jamesyboi (6579) Press F1
Post ID Timestamp Content User
355132 2005-05-14 11:10:00 brother used computer, closed zonealarm when playing counter-strike source probably and somehow this thing got in. Its called 'p2pnetwork' in msconfig's startup tab, and 'Sploa5c' in services. Also has a temp file in C:\

It wont let me run 'regedit' and it keeps adding itself to the startup.
ive scanned with AVG7, crap cleaner, spybot, adaware, regmech, sysmech, spyware doctor, and microsoft anti spyware and nothing has worked.

Any ideas?
james
jamesyboi (6579)
355133 2005-05-14 11:20:00 Reboot in safemode and then rerun the cleaners
this may stop it from loading and the scanners and cleaners should be more successful
EX-WESTY (221)
355134 2005-05-14 11:22:00 brother used computer, closed zonealarm when playing counter-strike source probably and somehow this thing got in. Its called 'p2pnetwork' in msconfig's startup tab, and 'Sploa5c' in services. Also has a temp file in C:\

It wont let me run 'regedit' and it keeps adding itself to the startup.
ive scanned with AVG7, crap cleaner, spybot, adaware, regmech, sysmech, spyware doctor, and microsoft anti spyware and nothing has worked.

Any ideas?
james
First you hate em', then you get used to em'. After time you learn to depend on em, = Virus'
jamesyboi (6579)
355135 2005-05-14 11:23:00 um, i think i got rid of it, but regedits still dead jamesyboi (6579)
355136 2005-05-14 11:47:00 um, i think i got rid of it, but regedits still dead
Have you try the solution EX-WESTY mentioned?
Renmoo (66)
355137 2005-05-14 11:49:00 Is there a Newnet or Newdotnet entry in Add/remove programs??

And this p2pnetwork is it p2pnetwork.exe??

And is there a msconfigs.exe as well?
Speedy Gonzales (78)
355138 2005-05-15 02:27:00 To enable registry:

Start -> Run -> copy and paste the following and press enter:


REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Pol icies\System /v DisableRegistryTools /t REG_DWORD /d 0 /f
wintertide (1306)
355139 2005-05-15 06:39:00 YES!, thank you. it is p2pnetwork.exe and there was msconfig.exe. i think i got rid of msconfig.exe though.

there is nothing in ad/remove programs under N except nvidia drivers.

thanks for help. whoever posted above (i can't see while typin here) it seems like you know what is wrong. so help is appreciated thanx
jamesyboi (6579)
355140 2005-05-15 06:40:00 And pasting:
REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Pol icies\System /v DisableRegistryTools /t REG_DWORD /d 0 /f

doesn't work either.
jamesyboi (6579)
355141 2005-05-15 07:23:00 Hmm looks like this might be the culprit

WIN32.ALCAN.A WORM

And it looks like Trojan remover may remove it.

dl.filekicker.com

From here www.simplysup.com

Its in its database as Worm.P2P.Alcan

Get this (and hopefully it installs and runs). Make sure trojan remover is up to date and click on scan.

And then go to the utils menu, select the 3/4/5/6 and 7th option.
Speedy Gonzales (78)
1