Gnutella Forums  

Go Back   Gnutella Forums > Current Gnutella Client Forums > LimeWire+WireShare (Cross-platform) > Technical Support > General Windows Support
Register FAQ The Twelve Commandments Members List Calendar Arcade Find the Best VPN Today's Posts

General Windows Support For questions about Windows issues regarding LimeWire or WireShare or related questions


Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old April 4th, 2007
Novicius
 
Join Date: April 4th, 2007
Posts: 1
Proco is flying high
Exclamation Limewire Popping & Lack of Task Manager

Hello,

Yesterday i purchased Limewire Pro and installed it and proceeded to downloading ****** and it was a .zip

Now when i close Limewire it will not stay closed but instead open itself back up a few moments later and i can also no longer access my Task Manager.

I use Windows XP and I have read the thread on this particular subject.

I scanned my computer with the McAfee free scan and it did infact find 25 copies of the same worm.

I followed the suggestions mentioned in the above threads including the BFU removel tool, and these steps...

Quote:
Originally Posted by
I had this exact same problem, and after literally 24 hours of analyzing every inch of my computer, I solved the problem. I suspect that based on your descriptions of the problem (which I had as well), you are infected with a virus. It's unbelievable that none of my AntiVirus packages picked up this infection.

For me, everytime I restarted my computer, Limewire would automatically load up. Even if I closed it, it would just open back up again. On top of this, I could not even access the Task Manager in Windows XP to allow me to force a shutdown of Limewire. I hit CTRL-ALT-DEL and nothing would happen.

Anyways, here are the steps that need to be taken.

1) Uninstall Limewire. You can reinstall it at the end of these steps.

2) Disable System Restore in Windows. This can be done by right clicking on My Computer, selecting Properties, and then clicking on the System Restore tab. Then check the box Turn Off System Restore. Hit Apply, and then OK. If you are prompted to restart Windows, do so.

3) Now we need to fool the virus into allowing us to open the Task Manager. This can be done by copying the Task Manager executable file from the Windows directory. To do this, go to c:\windows\system32, select the file taskmgr.exe, right click on it, and select Copy. Go to the desktop, and click on an empty part of the desktop. Then right click on the desktop, and select Paste.

4) Double click on the taskmgr.exe file on your desktop. This should open the Task Manager. Click on the Performance tab. If you are in fact infected with a virus, you will likely (although not necessarily) see close to 100% CPU usage!! Now click on the Processes tab, followed by clicking twice on the CPU column header. What this does is order the files running on your computer based on the amount of CPU resources they are consuming in real time. If there is a process, other than System Idle Process, that is consuming close to 100% of the CPU, then it is this process (or file) that is infecting your computer. For me, and likely for a lot of you, that file will be winupdates.exe. Don't be tricked. This is not a Microsoft program. It's a virus masking itself as a legitimate file. Please remember the exact name of this process, because you will need it in a later step.

5) Click on this process to highlight it, then click the button End Process. A warning prompt should pop up. Click on Yes.

6) Now that this process is killed, we need to remove any references to it from the Registry. Once again, because this virus is blocking us from opening the Registry Editor, we need to trick the virus by copying the file to the desktop. Follow the same steps as in number 3, except this time, copy the following two files from their respective directories, and paste them on the desktop.

c:\windows\regedit.exe
c:\windows\system32\cmd.exe

7) Open regedit from the desktop. In the left window, click on My Computer so that it is highlighted. Now select Edit from the menu, followed by Find. In the Find box, type the name of the process that you ended from the Task Manager. If you recall, mine was winupdates. Do not include the .exe, just winupdates. Then click Find.

8) For the item that it found in the right window, click it to highlight it if it isn't highlighted already, and then right click on it, and select Delete. If a prompt pops up, select Yes or OK to confirm the delete.

9) Now, hit the F3 button once. This will find the next reference to that bad file. Follow step 8 again to delete the reference. Repeat steps 9 and 8 until the editor indicates that there are no more references to this file. Then exit the editor.

10) Finally, click on cmd.exe which you copied to the desktop. It will open the Command Prompt (which looks like DOS). Type the following commands in order, and hit Enter after each line:

cd c:\
cd program files
rd /s /q winupdates

11) Now restart your computer. Reinstall Limewire.

This should hopefully fix your problem.

Bobby Naini
except for in the above steps, if someone could please clear this up for me, i get to the step where you stort the processes running on your computer in real time CPU usage. cept when i sort mine i find nothing out of the ordinary.

I do not find winupdate.exe or anything for that matter that is using more then 01 or 00 CPU usage other than my System Idle Process which is using 99, everything else is using hardly any. In fact on performance my CPU usage is rather low, staying at a constant 2% ~ 4%.

I do notice that when i use the link to download the copy of Limewire Pro i purchased from their site, that after launching it i see TONS of saved files and files in the shared folder, keep in mind i just started using Limewire Pro yesterday and had only downloaded one file, the .zip for ******* and nothing more. So none of these files are mine, they came with the installation of Limewire Pro.

So to recap if someone could please further explain the above steps to clearing up this issue.

thank you


__________________________________________________

Edited to comply with the House Rules.
Warez, copyright violation, or any other illegal activity may NOT be linked or expressed in any form.
Reply With Quote
  #2 (permalink)  
Old April 4th, 2007
wondering why's Avatar
You caught my eye
 
Join Date: September 11th, 2005
Location: Brisbane, Australia
Posts: 6,677
wondering why is just really nice
Default

They didn't come with your Pro, they are duplicates of the zip file that you downloaded and because that virus spreads via duplication that's where they have come from...
I have never actually had a virus, hence I cannot explain exactly what you need to do with the BFU fix except that it has worked for just about everyone that has used it...
Your best bet is to do a highjack this log and go to one of these site's and get advice from there....They know exactly what to do in these circumstances....
http://www.bleepingcomputer.com/
http://forums.spywareinfo.com/index.php?showtopic=79038
http://www.castlecops.com/HijackThis.html
__________________


If you dont live for something...
You die for nothing...
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Limewire disabled XP task manager Tdub General Windows Support 1 March 13th, 2007 09:09 PM
Can't open task manager co87 General Windows Support 1 November 9th, 2006 06:46 AM
i can't open task manager dave101 General Windows Support 10 February 14th, 2006 09:22 PM
Task manager disabled by administrator torleiv General Windows Support 2 May 29th, 2005 02:17 AM
gnut, lack of documentation, lack of connections DougTheSlug.ca General Gnutella / Gnutella Network Discussion 1 September 7th, 2003 07:45 PM


All times are GMT -7. The time now is 12:07 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 ©2011, Crawlability, Inc.

Copyright © 2020 Gnutella Forums.
All Rights Reserved.