New User? Need help? Click here to register for free! Registering removes the advertisements.

Computer Cops
image image image image image image image image
Donations
If you found this site helpful, please donate to help keep it online
Don't want to use PayPal? Try our physical address
image
Prime Choice
· Head Lines
· Advisories (All)
· Dnld of the Week!
· CCSP News Ltrs
· Find a Cure!

· Ian T's (AR 23)
· Marcia's (CO8)
· Bill G's (CO11)
· Paul's (AR 5)
· Robin's (AR 2)

· Ian T's Archive
· Marcia's Archive
· Bill G's Archive
· Paul's Archive
· Robin's Archive
image
Security Central
· Home
· Wireless
· Bookmarks
· CLSID
· Columbia
· Community
· Downloads
· Encyclopedia
· Feedback (send)
· Forums
· Gallery
· Giveaways
· HijackThis
· Journal
· Members List
· My Downloads
· PremChat
· Premium
· Private Messages
· Proxomitron
· Quizz
· RegChat
· Reviews
· Google Search
· Sections
· Software
· Statistics
· Stories Archive
· Submit News
· Surveys
· Top
· Topics
· Web Links
· Your Account
image
CCSP Toolkit
· Email Virus Scan
· UDP Port Scanner
· TCP Port Scanner
· Trojan TCP Scan
· Reveal Your IP
· Algorithms
· Whois
· nmap port scanner
· IPs Banned [?]
image
Survey
How much can you give to keep Computer Cops online?

$10 up to $25 per year?
$25 up to $50 per year?
$10 up to $25 per month?
$25 up to $50 per month?
More than $50 per year?
More than $50 per month?
One time only?
Other (please comment)



Results
Polls

Votes: 940
Comments: 19
image
Translate
English German French
Italian Portuguese Spanish
Chinese Greek Russian
image
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Login to check your private messagesLogin to check your private messages   LoginLogin 

CASPROG
Goto page 1, 2, 3, 4  Next
 
Post new topic   Reply to topic       Computer Cops Forum Index -> Security - Guests
View previous topic :: View next topic  
Author Message
Barty

Guest






PostPosted: Sun Mar 14, 2004 6:13 pm    Post subject: CASPROG
Reply with quote

Hi,

I have just had a system32 dialog box pop up stating the above file has been sucessfully removed.

Any Ideas? Have i been hacked?
Back to top
Jaden

Guest






PostPosted: Wed Mar 17, 2004 7:53 am    Post subject:
Reply with quote

Same thing here...Anyone know what this means?????
Back to top
Nick

Guest






PostPosted: Wed Mar 17, 2004 11:24 am    Post subject:
Reply with quote

i dunno but i was cleaning my programs and i found it and i removed it myself, now i was searching on the web to see if i could find anything on it but no luck. oh well i dont think it was anything helpful.
Back to top
sadsadface

Guest






PostPosted: Wed Mar 17, 2004 8:11 pm    Post subject:
Reply with quote

that happened to me too anybody else....
Back to top
Fussen

Guest






PostPosted: Thu Mar 18, 2004 12:42 am    Post subject: Answers
Reply with quote

Heads up,

it's a casino program.

it's malware.

it's infectious.

delete it.

the last attempt at it staying on your computer is in a file called uninst_cp.exe located in your windows\system32 folder.

it will continue to bore itself into your registry's "run" section.

So don't choose the Uinstall option from your icons because you'll just be doing exactly what the program wants you to do.

Delete these files manually or use Ad-Aware (free) from lavasoftusa.com

I ran ad-aware and it cleaned it all up. EXCEPT for the c:\windows\system32\uninst_cp.exe

cp stands for CASINO PROGRAM.

the uninst_cp.exe has no details on a publisher, a file name, a version , or even who made it. It is a deviant program.

INSIDE the uinst_cp.exe is:

CasProg Software\Microsoft\Windows\CurrentVersion Software\Microsoft\Windows\CurrentVersion\Run Rebooting after uninstall Do not forget to reboot your computer. You must restart your computer in order to finish uninstalling %s.

If you have this file, don't run it. But you can see for yourself that it has this code simply by DRAGGING it into a blank Notepad window.
you can search for "casprog" and tada, there it is.

This casprog means Casino program, and it's intentions are to bore itself into your currentversion\run section of your registry (making it forever load on startup)

I would have never noticed it except for one tactic which I use sometimes. I scan my computer for EXE files that were modified/created within the last.. week or so . This file showed up. I never had any recolection of putting such a file there, and Uninstall programs are NOT NOT NOT suppossed to be in the system32 folder. They are suppossed to stay within the folder of the parent program.


I have no idea if anybody will ever read this post or not but if you do, hopefully this helped.

Cheers,

-Fussen
Back to top
Guest








PostPosted: Thu Mar 18, 2004 4:36 am    Post subject:
Reply with quote

If you go into your regedit you will also find a Golden Palace file
Back to top
AndyG

Guest






PostPosted: Thu Mar 18, 2004 10:26 am    Post subject: very, very tricky
Reply with quote

I was at a loss for how this program came to be on my computer, but it was a nasty one to get rid of. I think it was also launching a weirdly named process, because now that problem has gone away. Did anyone else see a process: zqanyech.exe?

Either way, I hope that after removing that file and registry key it is gone for good.

Thanks!
Back to top
rirvin

Guest






PostPosted: Fri Mar 19, 2004 12:33 pm    Post subject: yes this is very sticky, hard to get rid of
Reply with quote

I cleaned this up yesterday and today it's back. I used spybot and manually. I'm working on it now again. A lot of little things get loaded; internet optimizer, play live poker, vvlqkyjv.exe (note in code say it sends you to www.flingstone.com). Somebody needs to compile all the steps for cleaning this up.
Back to top
Barty

Guest






PostPosted: Fri Mar 19, 2004 2:04 pm    Post subject:
Reply with quote

Cheers boys n girls Smile info was much appreciated

system seems ok now
Back to top
christine

Guest






PostPosted: Fri Mar 19, 2004 2:43 pm    Post subject:
Reply with quote

yeah, how do you get rid of it??

i thought ad-aware got it, but then later when i started my computer up again it said that CasProg was successfully unistalled. I think im screwed... any suggestions??

is my computer gonna get all messed up now?
Back to top
I_Hate_Casinos

Guest






PostPosted: Sat Mar 20, 2004 8:20 am    Post subject: The Fix
Reply with quote

http://www.servenet.com/ipiboard/messages/7465.html
Subject: Re: Golden Palace Casino

There are three ways of removing the software, try each one in order.

1. Click the following link for instruction on how to remove the software: http://remove.monsterserve.com/remove/toolbar/index.html

2. Go to http://www.jraun.com and click the uninstall download at the
bottom.

3. In some cases, you may also have to remove the software from
your computer index directory. This is easy if you follow these steps:

1. Double click the 'My Computer'icon on your desktop to open
it.

2. Double click the 'Local Disk (C)' icon to open it.

3. Find the folder named 'Casino' then right-click ONCE on it-this will open a drop-down menu.

4. Hold down the SHIFT Key and click DELETE in the drop-down
menu simultaneously.

5. Be sure to wait for the final Delete message - you must
click YES, then the software will be deleted from your index directory.

For further assistance with the removal of the software, contact support at Golden Palace Casino toll free number 1-888-217-5648.

Call this phone number and threaten and harrass them
I am going to do this once a day, If you all do the same it will hurt thier
business, Lets take these jerks out!

Take Aim, Fire!
Back to top
Casinos_Suck_CALL_THEM

Guest






PostPosted: Sat Mar 20, 2004 8:23 am    Post subject:
Reply with quote

In case you didnt notice in my last post :

For further assistance with the removal of the software, contact support at Golden Palace Casino toll free number 1-888-217-5648.

I wanted to put extra emphasis on this...

People might just procede from the top and begin fixing and not see the
most important part on the bottom
Back to top
MrPlotz

Guest






PostPosted: Sat Mar 20, 2004 1:44 pm    Post subject: Right-o!
Reply with quote

Hi,
Back to top
MrPlotz

Guest






PostPosted: Sat Mar 20, 2004 1:47 pm    Post subject: ignore the above
Reply with quote

Hi,

I had a little problem posting so please ignore that earlier message heh. Anyway, just wanted to say thx for all the info! I am in the process of getting rid of Casprog and everything looks pretty good so far.

As for that casino company, I hope you all call them up and b*tch about this crap as much as you can Smile .

Thanks again,

Plotz
Back to top
Meese

Guest






PostPosted: Sat Mar 20, 2004 9:52 pm    Post subject:
Reply with quote

Thanks so much re "CasProg". It was driving me crazy!! So, yes you did help a lot Fussen!! I figured that's what it was, but there were some strange things, ie.. Adware didn't catch it!! How is that?

Plus I've got this nasty eAnthology Station garbage on my PC,
1. not downloaded
2. no uninstall AT all anywhere, AND
3. even when Adware caught it there is stuff left behind - anyone know how to get rid of ALL of it?

Thanks,
Meese
Back to top
Display posts from previous:   
Post new topic   Reply to topic       Computer Cops Forum Index -> Security - Guests All times are GMT - 5 Hours
Goto page 1, 2, 3, 4  Next
Page 1 of 4

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
Jump to:  
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB 2.0.8a © 2001 phpBB Group

Version 2.0.6 of PHP-Nuke Port by Tom Nitzschner © 2002 www.toms-home.com
Version 2.2 by Paul Laudanski © 2003-2004 Computer Cops