IPB

Welcome Guest ( Log In | Register )

 
Reply to this topicStart new topicStart Poll

Outline · [ Standard ] · Linear+

> Security Warning...

Awai
post Jun 25 2004, 09:55 AM
Post #1


Waiting For...
****

Group: Moderator
Posts: 382
Joined: 18-March 04
From: ~beyond the sea
Member No.: 19



Hiya all,

A little heads up here as i've spent the last 2hours cleansing my system of a little fucker that was slowing the system to a crawl and also killing my web browsing - amongst other things...

it appears to be something that is currently slipping under the protection of norton, spybot s&d, spysweeper, adaware and spyware blaster - all of which are running on my comp.

The file in question is called SYSTEMNT.exe - no its not a system process and has nothing to do with windows. it resides in the c:/windows/system32 directory and is a hidden, read-only system file. you'll be needing to make hidden-system files visable to see the actual file but if you do a ctrl-alt-del key press it'll be sat in your "running processes" menu.

you need to drop into safe mode with command prompt to get rid of it as it'll take advantage of your admin/power user status to reinstall itself on reboot otherwise.

in safemode-command prompt type the following:
QUOTE

cd c:\windows\system32\
attrib -s -h -r systemnt.exe
del systemnt.exe


reboot and log in as normal then do a regedit search for systemnt.exe and delete all the keys you find (i had 3) - it claims to be part of the windows update thing in the registry but this is bollocks...

:angry:

Awai.

This post has been edited by Awai: Jun 25 2004, 09:55 AM


--------------------
"You look into her eyes
and it’s more than your heart will allow
And in August and Everything After
you get a little less than you expected somehow."
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Bearsland
post Jun 25 2004, 10:55 AM
Post #2
Lightning Pool Champion! Midi Golf Champion! Pepsi Pinball Champion! Pool Jam Champion!

Grumpy Old Man
****

Group: VIP Member
Posts: 494
Joined: 17-March 04
Tournaments Won: 2

From: London. UK
Member No.: 4



Maybe something to do with this: http://news.com.com/Corporate+Web+servers+...ml?tag=nefd.top

or maybe this: http://bink.nu/DesktopModules/ArticleDetai...?ArticleID=2073

Some crap going on on the net right now. :(
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

Reply to this topicTopic OptionsStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:
 

Lo-Fi Version Time is now: 2nd May 2024 - 03:59 PM