Gnutella Forums  

Go Back   Gnutella Forums > Off Topic Discussion > Tips & Tricks
Register FAQ The Twelve Commandments Members List Calendar Arcade Find the Best VPN Today's Posts

Tips & Tricks For help with file formats, viruses, security, etc. This section is not for questions about problems with Gnutella program clients, downloading, connecting, etc.


 
 
LinkBack Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #6 (permalink)  
Old August 2nd, 2005
Novicius
 
Join Date: August 2nd, 2005
Posts: 3
erikinlongbeach is flying high
Lightbulb

I remember I had this file in the Windows system directory once. I
didn't download the file directly. It was wrapped into a Nullsoft
installer file, or so I thought. I thought it was a Winamp plug-in.
They just stole the icon. Ad-aware would detect it, but it would
reappear at startup. I scanned the original file when I realized
where it came from. Nothing was detected. I spend hours trying to
manually get rid of the program. It would eventually come back,
depending upon how long I left the computer on.

This program had two processes, and when one or both were killed,
they would reappear. One process was Nail.exe, and the other was a
random name. It would place itself in the registry at
HKLM\Software\Microsoft\Windows\CurrentVersion\Run with the same
random name. It would always make an additional copy of itself in
the system directory. I had several stale versions of it after I
killed them in the system directory xxx:\WINDOWS.

I think Nail.exe facilitates either downloading malicious code from
the internet or installing it. The randomly named programs were
smaller.

Lavasoft Ad-Aware was never able to fully eradicate it. It is some
sort of VX2 variant. I even downloaded the VX2 plug-in for Ad-Aware.
Unfortunately, you get what you pay for. The malware was eradicated
finally when I installed Microsoft Anti-Spyware. I was surprised
that a Microsoft product worked that well. Usually, Microsoft
creates their own kind of spyware, in my opinion. Also, I've heard
that commericially available programs are better than either
Lavasoft's or Microsoft's anti-spyware programs. That's just what
I've heard so far.

Erik
Reply With Quote
 


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
DL file with virus!! pallet Getting Started Using LimeWire + WireShare 2 March 20th, 2007 01:23 PM
Every .zip file Contains a WORM virus Gaara Download/Upload Problems 1 March 15th, 2006 11:15 AM
Virus 851.7 file size jondamage General Gnutella / Gnutella Network Discussion 0 November 16th, 2005 11:01 PM
Possible Virus containing File Grandpa Open Discussion topics 2 June 27th, 2005 02:53 AM
Virus in a file manutd Support: General 1 October 19th, 2001 12:17 PM


All times are GMT -7. The time now is 11:42 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 ©2011, Crawlability, Inc.

Copyright © 2020 Gnutella Forums.
All Rights Reserved.