New User? Need help? Click here to register for free! Registering removes the advertisements.

Computer Cops
image image image image image image image image
Donations
If you found this site helpful, please donate to help keep it online
Don't want to use PayPal? Try our physical address
image
Prime Choice
· Head Lines
· Advisories (All)
· Dnld of the Week!
· CCSP News Ltrs
· Find a Cure!

· Ian T's (AR 24)
· Marcia's (CO8)
· Bill G's (CO12)
· Paul's (AR 5)
· Robin's (AR 2)

· Ian T's Archive
· Marcia's Archive
· Bill G's Archive
· Paul's Archive
· Robin's Archive
image
Security Central
· Home
· Wireless
· Bookmarks
· CLSID
· Columbia
· Community
· Downloads
· Encyclopedia
· Feedback (send)
· Forums
· Gallery
· Giveaways
· HijackThis
· Journal
· Members List
· My Downloads
· PremChat
· Premium
· Private Messages
· Proxomitron
· Quizz
· RegChat
· Reviews
· Google Search
· Sections
· Software
· Statistics
· Stories Archive
· Submit News
· Surveys
· Top
· Topics
· Web Links
· Your Account
image
CCSP Toolkit
· Email Virus Scan
· UDP Port Scanner
· TCP Port Scanner
· Trojan TCP Scan
· Reveal Your IP
· Algorithms
· Whois
· nmap port scanner
· IPs Banned [?]
image
Survey
How much can you give to keep Computer Cops online?

$10 up to $25 per year?
$25 up to $50 per year?
$10 up to $25 per month?
$25 up to $50 per month?
More than $50 per year?
More than $50 per month?
One time only?
Other (please comment)



Results
Polls

Votes: 1211
Comments: 21
image
Translate
English German French
Italian Portuguese Spanish
Chinese Greek Russian
image
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Login to check your private messagesLogin to check your private messages   LoginLogin   Your Favorite ForumsFavForums 

Nictech NEW spyware alert.

 
Post new topic   Reply to topic       All -> FavForums -> Spyware - Guests
View previous topic :: View next topic  
Author Message
markw007

Guest






PostPosted: Tue May 11, 2004 7:29 pm    Post subject: Nictech NEW spyware alert.
Reply with quote

AsTIVEDS.DLL is another new spyware dated 5/9/2004. It also drops a randomly named .dll also dated 5/9/2004 into your \system32 directory and adds the HKEY_LOCAL_MACHINE\SOFTWARE\WindowsNT\GuardianXXXX registry entry onto your system. It's removal seems to be the same as AkTIVEDS so do a search on that for help. I just wanted to post this new threat because I could not find it specifically anywhere YET!
Back to top
Gadgets

Cadet
Cadet



Joined: May 11, 2004
Posts: 2
Location: USA

PostPosted: Wed May 12, 2004 5:23 pm    Post subject:
Reply with quote

i do tech support for a company and i currently have three w2k computers(out of ~80) on this network with problems thanks to nictech. adaware hasn't caught them and i do not have the "permissions" option available in regedit so that i can disable the reg key these files are attached to, per dj van's suggestion in the other topic concerning nictech.

my observations concerning these files:
currently, it appears that the files are generated with similar names to legitimate files in the winnt\system32 folder. however all the questionable files are 310 kb in length and will have an identical creation date. one can rename and even remove all but one(or two) of the .dlls directly. the one(or two) that cannot be removed is the one that is listed in the registry.

please pardon(and inform me of) any faux pas in this post.

gadgets.
Back to top
View users profile Send private message AIM Address
Guest








PostPosted: Wed May 12, 2004 6:43 pm    Post subject:
Reply with quote

http://www.tek-tips.com/gviewthread.cfm/pid/760/qid/834037
Back to top
Gadgets

Cadet
Cadet



Joined: May 11, 2004
Posts: 2
Location: USA

PostPosted: Wed May 12, 2004 7:15 pm    Post subject:
Reply with quote

Gadgets wrote:
i do not have the "permissions" option available in regedit so that i can disable the reg key these files are attached to, per dj van's suggestion in the other topic concerning nictech.


my apologies. i should have been using regedt32, which DOES have the security>permissions option available.

gadgets.
Back to top
View users profile Send private message AIM Address
WyeKnottMe

Guest






PostPosted: Wed May 26, 2004 1:12 am    Post subject: NICTech Rubbish
Reply with quote

I used regedt32 and I deleted the GUARDIAN key and I watched it pop back up immediately after deletion.

What does it take to make this junk go away permanently?
Do I have to re-install Windows 2000?

I've been at this for 12 hours now and it's lost its appeal!
Evil or Very Mad
Back to top
WyeKnottMe

Guest






PostPosted: Wed May 26, 2004 1:15 am    Post subject: NICTech Rubbish
Reply with quote

I used regedt32 and I deleted the GUARDIAN key and I watched it pop back up immediately after deletion.

What does it take to make this junk go away permanently?
Do I have to re-install Windows 2000?

I've been at this for 12 hours now and it's lost its appeal!
Evil or Very Mad
Back to top
Stephanyr

Guest






PostPosted: Fri May 28, 2004 1:04 pm    Post subject: Have you....
Reply with quote

tried this within safe mode too? Perhaps there is another dll lurking.
Back to top
guest

Guest






PostPosted: Mon May 31, 2004 9:41 am    Post subject: astiveds.dll
Reply with quote

This file may be related to the VX2 spyware. I had the same problem with astiveds.dll and it eventually disappeared, but other files took its place. These files attached themselves to an unknown application and could not be deleted by AdAware or Norton Antivirus while this application was running. I ggogled VX2 and found a removal tool "VX2Finder.exe", which elimnated all of these problems. Hope this helps.
Back to top
DanR

Guest






PostPosted: Mon Jun 14, 2004 10:01 pm    Post subject:
Reply with quote

I have this same problem too. I have Win 98 and I have no idea where this thing came from. Its messing with Adaware and spy bot search and destroy. there is DLL files in my windows/system directory with ILFARED.DLL or other similar name FARED DLLs. Each one was placed by NicTech. I had no idea it was even there untill EXPLORER starting crashing on start up. The only way to use my computer is to move the error message off the edge of the screen. Everytime I boot up its allways saying "windows is updating files" etc even though i havent changed anything.
Back to top
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Spyware - Guests All times are GMT - 5 Hours
Page 1 of 1

 
 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
Jump to:  
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB 2.0.8a © 2001 phpBB Group

Version 2.0.6 of PHP-Nuke Port by Tom Nitzschner © 2002 www.toms-home.com
Version 2.2 by Paul Laudanski © 2003-2004 Computer Cops