PDA

View Full Version : XP users... I NEED your help!!!



Kaji
06-08-2003, 06:35 AM
Okay, apparently KaZaA put some kind of worm on my comp and the only way I guess I could save it was to delete my system32.exe file. I NEED someone to send me a replacement copy like right NOW. I think my dad was trying to fix it and I just went in and messed with it. Please contact me on AIM if you can help me. I'm AllenMan03. PLEASE don't f with me, I'm already stressed out and tired as it is.

crono_logical
06-08-2003, 06:44 AM
No, no-one is going to send you anything, and they'd better not either.

Why? System32.exe is the virus itself (variant of Klez, probably), WinXP does not have a System32.exe. Viruses often name themselves to look like their part of Windows to make it less suspecting, and to make novice users more wary of wanting to delete them. You should have run a virus scan, let it delete the file, and stop worrying over it from the start :p Alternatively, don't use the evil file sharing network accessible through Kazaa/Kazaa Lite :D

Kaji
06-08-2003, 06:54 AM
SWEETNESS!!!!!! But how do I get rid of the error message that pops up saying that it is missing? What should I use instead of Kazaa/Kazaa Lite? All this and more hopefully on.. THE NEXT POST!!!!

Oh yeah, and don't IM me cause I don't need the file...

crono_logical
06-08-2003, 07:06 AM
The errors are because it's hooked itself into the startup keys in the registry and/or Start Menu, to make sure that it's run every time you reboot the computer - basically an attempt to make it harder to remove. Since it's gone but the keys haven't, Windows is still trying to run it even though it no longer exists. You really should have used a virus scanner to remove it cleanly, unless you don't mind registry editing :p

Kaji
06-08-2003, 01:13 PM
Thanks so much for kinda helping me out chrono! I really appreciate it! My dad actually had a site up saying what values to delete in the registry from Norton (the site not values). Now I guess my computer's in good health, but since the worm's "gone" can I still use Kazaa or will it put it back on? I wanna make sure before I run it ever again, cause if it will put it back on, I guess I'll have to find another program to download stuff with....

crono_logical
06-08-2003, 04:00 PM
Kazaa itself doesn't put the worm on, it's just that Kazaa has a huge number of infected files and mislabelled files on it's network that makes it so bad. Basically just be careful with what you download over Kazaa, e.g. never download or run anything that's .exe from Kazaa, since they're the highest source of viruses there.

Killy
06-08-2003, 04:34 PM
Just dont download weird files like that look like this:

Final_Fantasy_10_Full_game+Ps2 Emu_super_Compression.exe (size: 300k)

Dont laugh, I actually found this file while searching for FF-Related stuff.

Dr Unne
06-08-2003, 05:16 PM
.exe, .com, .scr, .pif, .bat, assume anything like that is a virus. Even a real program that legitimately works can be infected with viruses the person you got it from doesn't even know about.

Kaji
06-08-2003, 06:21 PM
Okay, thanks for the tips guys. At least now I have Kazaa Lite and DivX, I don't think I'll need to download any more programs and if I do, I'll try and be more careful....

Citizen Bleys
06-08-2003, 07:11 PM
KaZaA is perfectly safe as long as you're only downloading data files and not program files. i.e., games can be infected. MP3s can only sound bad.

Endless
06-08-2003, 07:52 PM
Word, Excel, Access, PowerPoint, Amipro and Visio can carry macro virii.
.hlp files can carry virii
.dll files (included in an archive for example) can hold trojans/virii/...
vbs and html files can carry scripts.

So, a general rule of thumb is to run an av on everything you receive (and as far as I'm concerned, it's running in the background, all the time).

Citizen Bleys
06-09-2003, 12:32 AM
.dlls are basically program files. All that's missing is main().

.vbs is an executable format on most computers (Although I've got mine set up to open in notepad instead), so I count that as a program file as well.

Endless
06-09-2003, 03:38 PM
What I meant is that these two (vbs and dll) don't require YOU to launch them. vbs can be run from an email, dlls called by a program.
Keyloggers, for example, love to go in dlls, that way a modified program (clean, just the real blak.dll renamed in blah2.dll with blah.dll loading blah2.dll) will load the keylogger in memory.

Erdrick Holmes
06-10-2003, 09:51 PM
I think this might fix it, just uninstall Kazaa and delete evrything but move all of your downlaod files to a different folder and then Reinstall Kazaa (this solved my kazaa lite problem a while ago) then reinstall Kazaa. Lemmie know if it helps.

Citizen Bleys
06-10-2003, 10:48 PM
Just don't download anything off of KaZaA that has an extention other than .mp3, .avi, .jpg, .gif, .mov, .smc, .nes, or .png

That gives you mp3s, anime, ROMs, and porn. What more could you ask for?

MecaKane
06-11-2003, 12:53 PM
I've only gotten one virus from Kazaa, and that was my own damn, stupid, greedy falut. Warcraft III bnet keygen, INDEED. :cry:
But I have norton always running, so it fixed that all nice and spiffy.

Peegee
06-18-2003, 07:36 AM
I often have to download executables from kazaa, because well...I just do.

just have to be careful. I never run kazaa unless I have an antivirus set up.