Am i in deep doodoo?

  • Two Factor Authentication is now available on BeyondUnreal Forums. To configure it, visit your Profile and look for the "Two Step Verification" option on the left side. We can send codes via email (may be slower) or you can set up any TOTP Authenticator app on your phone (Authy, Google Authenticator, etc) to deliver codes. It is highly recommended that you configure this to keep your account safe.

Goat Fucker

No Future!
Aug 18, 2000
2,625
0
0
Denmark
Visit site
The last month or so, my connection has been doing strange stuff, it seems its sending something every now and then, im afraid i may have a Trojan problem.

How do i find out if this is indeed true, is there any way to reveal the little f<b></b>ucker if it is indeed present?

Allso, more disturbingly, often when i access a page with anti EU or UN material, my system locks up for no apparent reason, even Ctrl+Alt+Del wont work, i dont like this one bit!

Stuff that displays in my Ctrl+Alt+Del screen:

Explorer (duh)
Lgevntrt
Point 32 (my mouse)
Mswheel (more mouse stuff)
Autochk
Aptezbp
Systray (duh)
Rnaapp

Allot of this i have no clue what is, Rnaapp i'we had for some time, but Autochk, Lgevntrt and Aptezbp are new :eek:
 

DarkBls

Inf Ex-admin
Mar 5, 2000
4,551
0
36
France
You can add process under any Win9x OS (Don't ask why I know that).

So ctrl+alt+del may cannot help you.

The best you can do is to install a firewall.

Take a look at all run run once etc microsoft resitry keys too. It may help.

But there are so many way to start a program everytime you start your os...
 

Goat Fucker

No Future!
Aug 18, 2000
2,625
0
0
Denmark
Visit site
Many of thease things now attaches themselves to common programs, witch means we are all in trouble, without hax0ring youre entire system, you may never find them, and even if you do, theres no seartainty that you will find them.

I hope this is nothing more than my modem beeing an old POS, and Winblows just beeing winblows, but i want to be sure.
 

RogueLeader

Tama-chan says, "aurf aurf aurf!"
Oct 19, 2000
5,314
0
0
Indiana. Kill me please.
First of all try a virus scanner they detect trojans. If you don't want to do that, goto Run and type "regedit"
Goto HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion

Under that you will find 3 folders, Run, RunOnce, RunOnceEx.
Anything in there runs on startup and will run trojans. Some, like Netbus, will simply say, Netbus, so they are easy to find. But Back Orifice can change its name. You should delete anything you don't recognize or arn't sure about to be on the same side.
Then reboot.
 

Goat Fucker

No Future!
Aug 18, 2000
2,625
0
0
Denmark
Visit site
Problem is Rogue, i know Jack and S<b></b>hit about what should be in there, and Jack was just run over by a bus.

Does anyone know where to find a list of what should be there and what shouldent?

I hope this doesent mean that i will have to reinstall everything, i dont have a CD-R drive, so i will loose so much good stuff :(
 

Goat Fucker

No Future!
Aug 18, 2000
2,625
0
0
Denmark
Visit site
Ok, heres the list of "RUN".

(Standard)
AEZBProc
Configsafe
ESSolo
job-oversigt
LEGVENTRT
Loadpowerprofile
POINTER
Skan-Registreringsdatabase
SystemTray
TIPS

Heres whats in RUNonce\Dialer

(Standard)
Maindir
PRODUCT TITLE
TEMP

And heres the contents of RunonceEX

(Standard)
 

DarkBls

Inf Ex-admin
Mar 5, 2000
4,551
0
36
France
Best dynamic firewall for me is the ore of @guard known nown as Internet personal firewall (norton).

Of course if you use only some port you can install a static one...
 

AtomicAxis

PHD in keeping it REAL!!
Mar 13, 2001
237
0
0
116
Dont get nervous goat but you could also have a bot. They are used as dumb programs that sit on your machine and when the bots master wants to he can get it to ping a server. They usually have thousands of these sitting on different PCs. These are used for DOS attacks. They dont do anything to the host machine tho they just ping large packets.

To see if you have a bot type this in a DOS window:

netstat -an | find ":6667"

if nothing is displayed then you dont have an IRC bot. If something similar to this is displayed

TCP 192.168.1.101:1026 70.13.215.89:6667 ESTABLISHED

You have one.

Try this one as well.

netstat -an | find ":113 "
blank line indicates nothing.

Just make sure that IRC is NOT running when you do these.

These commands are only for IRC Zombies/Bots. I posted this link about 2 months ago but this is where I got this info from and it is a very interesting read.....

www.grc.com

Just something to check. Probably unlikely that you will have a Zombie/Bot
 

EndlessInfinity

Where is your god now?
dude if your really worried about someone fookin with your system if you get a virus checker (this is if the guy says that he will toast your system if you get a virus checker/firewall) just do the most logical thing. Pester a friend to get a virus checker on a disc, then unhook your system from the net. Just hunt for the virus/worm/troj offline. Sorry if this doesn't apply to you, but you never know - in certain situations you might not think of the most reasonable path of action.
 

funkstylz

I CLEAN TEH LATRINE
Mar 15, 2000
1,455
0
0
48
Bris. QLD, Oz
www.funkstylz.com
Explorer (duh) - Yes
Lgevntrt - Dunno...third part stuff. Do you have any LG hardware?
Point 32 (my mouse) - Yes
Mswheel (more mouse stuff) - Obvious
Autochk - Windows stuff...it's both harmless and useless
Aptezbp - Aptiva EZ buttons Software...Harmless
Systray (duh) - Yup
Rnaapp - Your Dialup software.

You have an Aptiva...or an Aptiva Keyboard. Good for you old chap, what model?! Have you run a virus checker that was updated 60 years before??
 

Hadmar

Queen Bitch of the Universe
Jan 29, 2001
5,558
42
48
Nerdpole
Mswheel (more mouse stuff) - Obvious

Maybe to obvious... I have a Intellymouse Explorer and the Point32 is normal but I don't have the Mswheel...

However, it's not so hard to hide a prog from the CTRL-ALT-DEL window so I doubt that this is the problem. BTW, I suggest the use of Sinfo. It's much better then the wannabee Task Manager from 9x

Maybe you have a Spyware problem, try Ad-aware.

And Rogue, I don't have any problems with ZoneAlarm. It works fine.