Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Can't remove strange bad site "app"

Status
Not open for further replies.

avmva

Technical User
Nov 12, 2002
6
US
My boss, who has Win XP, has apparently been carousing on the web. Embarassingly enough for him, he now has an app that we can not get rid of. It appears as a small red heart in the task tray on startup and opens as a black box with what look like links. I haven't tried any of the links for fear of making things worse. It opens right in the middle of the screen, blocking whatever else is there, and will not allow itself to be minimized. Since it's clever designers disabled any right mouse key functionality, we can't get any "Properties" info, i.e., a file name. We can't find anything recognizable in any start folders, in the system startup configuration, in the registry, via a search, etc. While we have figured out how to close it during the current session, we can't uninstall it. We can't make it go away by closing any running "tasks." I have searched the web and while I can find the sites associated with the apparently Polish (sorry for the smear if I'm wrong) terms available to us, i.e., Najlepsze strony erotyczne, appearing when I hover the mouse over the cute little red heart, I can't find anything in English that I can follow to get rid of the thing for good. It must be in the registry or elsewhere under an "assumed" file name. I hope someone can supply one to search for. Or give us suggestions. Thanks for your time and consideration.
 
Yeah, I've searched for all the text that's available to me. As part of file names or as text. By date? Since my boss can't remember when he did whatever he did that resulted in this app, I can't really search by date. There must be something, though. In all my years of computing, I've never run across something like this that I couldn't find evenutally. It's just got me stumped.
Thanks for your suggestions.
 
Did you run the System Configuration Utility , MSCONFIG ?
You will probably find a pirate program in Services or Startup. As the name of the pirate program is unknown, you may have to compare the names of the startup programs of the infected computer with the names in another machine running XP. From MSCONFIG, you can uncheck or disable one or more programs.
 
It is certainly polish because a friend of mine who's polish says it is.

If the designers of the program were clever enough, they could have made it a virtual driver, in which case it is not trivial to find it or shut it down. Maybe a spy killer could do the job because many spy programs are implemented as virtual drivers. A search on Google for vxd spy killer generates lots of results.

Also, anti-virus software such as McAfee VirusScan may be able to detect and remove it.
 
Ad-aware? Have you tried the key on the left of the right Ctrl key on most keyboards (it will often let you into a contect menu when right mouse click has been disabled).
You've probably looked here - but just check all files in root of C:
 
Great suggestions! I won't be at work again until next Monday but will definitely try these.
I'll post back here with results.
Thank you!
 
Everything that runs needs a process.. one way to kill it .. is to open Taskmgr and kill its process.

Then look into the start up section in the start menu -- to see if its there.

THEN...

Look inside this following folder:

C:\winnt\prefetch
(or whatever drive the winnt folder resides)

See if there is anything in that folder that looks remotely like the offending app. These pain-in-the-arse apps tend to put crap in that folder so that the app launches at startup. Delete it, if it's there.

Alshrim
System Administrator
MCSE, MCP+Internet
 
The file is called MD.EXE if that helps.

Ash.
 
If I were you, I'd bother your boss endlessly with this. Anyway, ad-aware should take care of this. Try looking in the Dr. Watson snapshot file. Hopefully the file did not attach itself to another exe on startup; if it did not, then it'll have a task and a startup item in msconfig. -God Bless
 
Go into the registry and look in the HKLM\Software\Microsoft\Windows\CurrentVersion\Run key... you may find your offending app there... debonairOne

"I look in the mirror and what do I see..."
dboneanime.gif
 
Use a good virus-cleaning program ..it is probably a variant of the nimda worm..


[profile]
 
Take a screenshot and send it to his wife!

ok, sorry... not very helpful, but i could not resist. -God Bless
 
Jesuspower,
Problem is, he doesn't have one.
Thanks.
 
Update - I didn't get in to work today. Will go tomorrow. I've printed all out for use.

Thank you to all contributors!

I'll report back.

Anne
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top