View previous topic :: View next topic |
Author |
Message |
markw007
Guest
|
Posted: Tue May 11, 2004 7:29 pm Post subject: Nictech NEW spyware alert. |
|
|
AsTIVEDS.DLL is another new spyware dated 5/9/2004. It also drops a randomly named .dll also dated 5/9/2004 into your \system32 directory and adds the HKEY_LOCAL_MACHINE\SOFTWARE\WindowsNT\GuardianXXXX registry entry onto your system. It's removal seems to be the same as AkTIVEDS so do a search on that for help. I just wanted to post this new threat because I could not find it specifically anywhere YET! |
|
Back to top |
|
|
Gadgets
Cadet
Joined: May 11, 2004
Posts: 2
Location: USA
|
Posted: Wed May 12, 2004 5:23 pm Post subject: |
|
|
i do tech support for a company and i currently have three w2k computers(out of ~80) on this network with problems thanks to nictech. adaware hasn't caught them and i do not have the "permissions" option available in regedit so that i can disable the reg key these files are attached to, per dj van's suggestion in the other topic concerning nictech.
my observations concerning these files:
currently, it appears that the files are generated with similar names to legitimate files in the winnt\system32 folder. however all the questionable files are 310 kb in length and will have an identical creation date. one can rename and even remove all but one(or two) of the .dlls directly. the one(or two) that cannot be removed is the one that is listed in the registry.
please pardon(and inform me of) any faux pas in this post.
gadgets. |
|
Back to top |
|
|
Guest
|
Posted: Wed May 12, 2004 6:43 pm Post subject: |
|
|
http://www.tek-tips.com/gviewthread.cfm/pid/760/qid/834037 |
|
Back to top |
|
|
Gadgets
Cadet
Joined: May 11, 2004
Posts: 2
Location: USA
|
Posted: Wed May 12, 2004 7:15 pm Post subject: |
|
|
Gadgets wrote: |
i do not have the "permissions" option available in regedit so that i can disable the reg key these files are attached to, per dj van's suggestion in the other topic concerning nictech.
|
my apologies. i should have been using regedt32, which DOES have the security>permissions option available.
gadgets.
|
|
Back to top |
|
|
WyeKnottMe
Guest
|
Posted: Wed May 26, 2004 1:12 am Post subject: NICTech Rubbish |
|
|
I used regedt32 and I deleted the GUARDIAN key and I watched it pop back up immediately after deletion.
What does it take to make this junk go away permanently?
Do I have to re-install Windows 2000?
I've been at this for 12 hours now and it's lost its appeal!
|
|
Back to top |
|
|
WyeKnottMe
Guest
|
Posted: Wed May 26, 2004 1:15 am Post subject: NICTech Rubbish |
|
|
I used regedt32 and I deleted the GUARDIAN key and I watched it pop back up immediately after deletion.
What does it take to make this junk go away permanently?
Do I have to re-install Windows 2000?
I've been at this for 12 hours now and it's lost its appeal!
|
|
Back to top |
|
|
Stephanyr
Guest
|
Posted: Fri May 28, 2004 1:04 pm Post subject: Have you.... |
|
|
tried this within safe mode too? Perhaps there is another dll lurking. |
|
Back to top |
|
|
guest
Guest
|
Posted: Mon May 31, 2004 9:41 am Post subject: astiveds.dll |
|
|
This file may be related to the VX2 spyware. I had the same problem with astiveds.dll and it eventually disappeared, but other files took its place. These files attached themselves to an unknown application and could not be deleted by AdAware or Norton Antivirus while this application was running. I ggogled VX2 and found a removal tool "VX2Finder.exe", which elimnated all of these problems. Hope this helps. |
|
Back to top |
|
|
DanR
Guest
|
Posted: Mon Jun 14, 2004 10:01 pm Post subject: |
|
|
I have this same problem too. I have Win 98 and I have no idea where this thing came from. Its messing with Adaware and spy bot search and destroy. there is DLL files in my windows/system directory with ILFARED.DLL or other similar name FARED DLLs. Each one was placed by NicTech. I had no idea it was even there untill EXPLORER starting crashing on start up. The only way to use my computer is to move the error message off the edge of the screen. Everytime I boot up its allways saying "windows is updating files" etc even though i havent changed anything. |
|
Back to top |
|
|
|