PC Review


Reply
Thread Tools Rate Thread

anyone heard of "Geoclean.bat" to be a mal/spyware?

 
 
jacob
Guest
Posts: n/a
 
      13th Mar 2007
Hi,
I found it as a new entry in my Startup programs. the date&time of
the file exactly matches yesterday's time, after logging in a certain
site. from that moment i experienced some BSOD's and restarts,
and couldn't get that page again(Error 404).
i found the file 'Geoclean.bat' at-
"... \Documents and Settings\user\Local Settings\temp\".
also found a new directory by the name of 'Geography' with one
empty subdir called 'setup', at-
"...\Program Files\Common files\Ms shared\".
i scanned the registry with a tool that found out some more classes
and interfaces with that name, that pointed to nothing, and can be
safely removed. i did so, and then deleted the above.
i can now get that page on the site that caused me troubles,
not logging in of course.
any comments?

------
thanks
jacob


 
Reply With Quote
 
 
 
 
Will Denny
Guest
Posts: n/a
 
      13th Mar 2007
Hi

Try searching for any spyware you may have on your system with the following
programs:

Spybot - http://www.safer-networking.org/
CWShredder - http://aumha.org/downloads/cwshredder.zip
Spy Sweeper - www.webroot.com
Ad-Aware - www.lavasoftusa.com

Try SpyWareBlaster to stop intrusions:

http://www.javacoolsoftware.com/spywareblaster.html

Also see the following links:

http://aumha.org/a/parasite.htm
http://mvps.org/winhelp2002/unwanted.htm

Also run a virus-check on your system with the latest definitions for your
anti virus program.

--


Will Denny

MS MVP Shell/User
Please Reply to the News Groups


"jacob" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> Hi,
> I found it as a new entry in my Startup programs. the date&time of
> the file exactly matches yesterday's time, after logging in a certain
> site. from that moment i experienced some BSOD's and restarts,
> and couldn't get that page again(Error 404).
> i found the file 'Geoclean.bat' at-
> "... \Documents and Settings\user\Local Settings\temp\".
> also found a new directory by the name of 'Geography' with one
> empty subdir called 'setup', at-
> "...\Program Files\Common files\Ms shared\".
> i scanned the registry with a tool that found out some more classes
> and interfaces with that name, that pointed to nothing, and can be
> safely removed. i did so, and then deleted the above.
> i can now get that page on the site that caused me troubles,
> not logging in of course.
> any comments?
>
> ------
> thanks
> jacob
>



 
Reply With Quote
 
jacob
Guest
Posts: n/a
 
      13th Mar 2007
Thank you Will,
i've already ran NAV 2007 and Spybot, both of which i have already,
and all came out clean.
i'm now going to install Ad-Aware Se and IE-Spyad.
a question though- are NAV 2007+Ad-Aware+IE-Spyad live
in peace together on the machine?
----
jacob

"Will Denny" <(E-Mail Removed)> כתב
בהודעה:Oqkg$(E-Mail Removed)...
> Hi
>
> Try searching for any spyware you may have on your system with the
> following
> programs:
>
> Spybot - http://www.safer-networking.org/
> CWShredder - http://aumha.org/downloads/cwshredder.zip
> Spy Sweeper - www.webroot.com
> Ad-Aware - www.lavasoftusa.com
>
> Try SpyWareBlaster to stop intrusions:
>
> http://www.javacoolsoftware.com/spywareblaster.html
>
> Also see the following links:
>
> http://aumha.org/a/parasite.htm
> http://mvps.org/winhelp2002/unwanted.htm
>
> Also run a virus-check on your system with the latest definitions for your
> anti virus program.
>
> --
>
>
> Will Denny
>
> MS MVP Shell/User
> Please Reply to the News Groups
>
>
> "jacob" <(E-Mail Removed)> wrote in message
> news:(E-Mail Removed)...
>> Hi,
>> I found it as a new entry in my Startup programs. the date&time of
>> the file exactly matches yesterday's time, after logging in a certain
>> site. from that moment i experienced some BSOD's and restarts,
>> and couldn't get that page again(Error 404).
>> i found the file 'Geoclean.bat' at-
>> "... \Documents and Settings\user\Local Settings\temp\".
>> also found a new directory by the name of 'Geography' with one
>> empty subdir called 'setup', at-
>> "...\Program Files\Common files\Ms shared\".
>> i scanned the registry with a tool that found out some more classes
>> and interfaces with that name, that pointed to nothing, and can be
>> safely removed. i did so, and then deleted the above.
>> i can now get that page on the site that caused me troubles,
>> not logging in of course.
>> any comments?
>>
>> ------
>> thanks
>> jacob
>>

>
>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Data Robotics "Drobo". Anyone ever heard of this? Gary Seven Storage Devices 4 12th Aug 2007 06:25 AM
Multiple "clicks" heard when clicking on links in Internet Explorer rollinginownfilth@hotmail.com Windows XP General 5 9th Mar 2006 04:26 AM
"Default Beep" (Windows XP Ding.wav) Heard At Shutdown John C. Altvater Windows XP Performance 1 7th Jan 2004 01:27 AM
Has anyone ever heard of a "PC Chips" M851LU Motherboard ? Al Dykes DIY PC 14 8th Nov 2003 02:58 PM
Anyone heard of the trojan, "BackDoor.Niova.B" ? Bill UK Anti-Virus 1 28th Jun 2003 11:46 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 12:28 PM.