Virus ? Bug ? Help !

A

Arkady

Hello !

A friend of my father's gave me a computer with a problem
to fix :
When trying to run programs, Windows would claim that the
executable isn't found and wouldn't run the program. But
if you were to right click the file, and choose "run as",
and run it as the same user, the file would work. That
happens with all the applications, including MSIE,
everything in Program Files, all the installed programs,
and so on.

First of all, I googled the problem(on my computer, not
that one), and most pages said that I have the DarkSky(?)
virus, but when I tried to ensure that, it didn't match.
That's bacause I couldn't find any "kernel32.exe"
processes running on the machine. Anyways.

Later on I discovered that there is an AntiVirus on the
system, but it wouldn't run. It had a few quarantined
files, though. All having the "Backdoor.OptixPro.12"
virus. I deleted them, and tried to ensure that it is,
infact, the optixpro12 virus. But it didn't match either,
butcause the :
HKEY_CLASSES_ROOT\exefile\shell\open\command
had a very different value from the one listed in the
antivirus' site.
I have " Winampw.exe ""%1"%*" " there, by the way.


To make sure there is no virus, I connected it's HD to a
third computer I have, with Norton Antivirus with the
latest update, made a full scan and found no viruses.

When I connected the HD back, the problem was still there.
It's also there when I try to run in safe mode.





So right now I'm not sure what to do. The symptoms fit a
virus, but the Antivirus said there are none. And the
problem is still there.
Any ideas ?

Thanks !

Best Regards,
Arkady Freidman
 
G

Guest

Backup (Export") that registry key (teh "execfile") so you can recover it if necessary
Then: delete that "Winampw.exe" value - this does not belong there
Then highlight (select) "My Computer" at the top of the tree (you're still in "Regedit") and do search for "Winampw". You should be able to find all references to this executable (I assume that you tried to uninstall it - and if not then do it!) and remove them (to include Class ID's) AFTER you backup ("export" from Regedit) each and everyone of them
Also - check your COM/DCOM for that particular executable (or its Class ID) and kill it there

These are just some of the steps you can take

Gregg.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top