Forum Home
Press F1
 
Thread ID: 70756 2006-07-15 03:29:00 Altnet cowboy stu (7021) Press F1
Post ID Timestamp Content User
470990 2006-07-15 03:29:00 Is Altnet a problem ? Spybot can't get rid of it as it is in use .. safe mode also.
Other progs have same result.
Computer boots to system32 window for whatever reason. Found a trjan lurking there but still persists to open here. Any help appreciated.
cowboy stu (7021)
470991 2006-07-15 03:49:00 Suggest Google Altnet FrankS (257)
470992 2006-07-15 03:54:00 done.. all freeprograms to rid want money once they tell you how bad it all is..
suspicious ???
cowboy stu (7021)
470993 2006-07-15 04:10:00 Use Spybot (www.spybot.info) to remove it.

Download it, download the latest detection updates, install both, then scan.
Speedy Gonzales (78)
470994 2006-07-15 04:51:00 Ran Spybot again.. still doesn't like Altnet ??


SpywareBOT: Settings (Registry key, fixed)
HKEY_USERS\S-1-5-21-375612493-951796526-1614765859-1006\Software\SpywareBot

SpywareBOT: Program directory (Directory, fixed)
C:\Program Files\SpywareBot\

SpywareBOT: Program directory (Directory, fixed)
C:\Program Files\SpywareBot\Log\

SpywareBOT: Program directory (Directory, fixed)
C:\Program Files\SpywareBot\Quarantine\

SpywareBOT: Program directory (Directory, fixed)
C:\Program Files\SpywareBot\Registry Backups\

SpywareBOT: Program directory (Directory, fixed)
C:\Program Files\SpywareBot\Settings\

SpywareBOT: Data (File, fixed)
C:\Program Files\SpywareBot\DataBaseNew.ref

Vcodec.eMedia: Root class (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AVZipEnchancer .Chl

Vcodec.eMedia: Root class (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VSEnchancer.Ch l

Vcodec.eMedia: Uninstall settings (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\ZipCodec

Vcodec.eMedia: Program directory (Directory, fixed)
C:\Program Files\ZipCodec\

Windows Security Center.FirewallOverride: Settings (Registry change, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallOverride!=dword:0

Altnet: Settings (Registry key, fixing failed)
HKEY_LOCAL_MACHINE\SOFTWARE\Altnet


--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---

2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2006-07-15 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2006-02-06 advcheck.dll (1.0.2.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2006-02-20 Tools.dll (2.0.0.2)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2006-07-14 Includes\Cookies.sbi (*)
2006-07-14 Includes\Dialer.sbi (*)
2006-07-14 Includes\Hijackers.sbi (*)
2006-07-14 Includes\Keyloggers.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2006-07-14 Includes\Malware.sbi (*)
2003-03-16 Includes\plugin-ignore.ini
2006-07-14 Includes\PUPS.sbi (*)
2006-07-14 Includes\Revision.sbi (*)
2006-07-14 Includes\Security.sbi (*)
2006-07-14 Includes\Spybots.sbi (*)
2003-03-16 Includes\Temporary.sbi (*)
2005-02-17 Includes\Tracks.uti
2006-07-14 Includes\Trojans.sbi (*)
cowboy stu (7021)
470995 2006-07-15 09:11:00 Spybot identifies a line in registry but can't delete it. Is it okay to go in and delete manually? It is in Hkey local_machine\ software\ altnet cowboy stu (7021)
470996 2006-07-15 21:12:00 Run spybot in safe mode, with the latest detection updates, and do another scan. See if it removes it.

Also see if there's an Altnet entry in Add/remove programs. If there is, uninstall it.
Speedy Gonzales (78)
470997 2006-07-16 02:21:00 Thanks Speedy. Done all that .. it found no issues. Same with CCleaner & AVG & Adaware all updated.
Everything seems okay except it boots to an open system32 window !!

Never used to do this.. any ideas Thanks
cowboy stu (7021)
470998 2006-07-16 02:30:00 get ccleaner run it, click on tools/startup .

Tell us whats here it'll be in here somewhere take a snapshot of whats here and post it .

Or use msconfig .
Speedy Gonzales (78)
470999 2006-07-16 02:51:00 Fishing around found following

www.viruslist.com

Suggest on completion of Speedys run have a look in above for alternative names if necessary.
FrankS (257)
1 2 3