cexx.org - Support Forums
Home
Help
Search
Login
Register
News
: Cexx forums, with volunteers dedicated to helping you remove malware and stay protected
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
May 18, 2013, 06:00:14
cexx.org - Support Forums
>
Spyware-Related Stuff
>
Report New Spyware Here
Topic: new spyware wincfg.scr ?
Pages: [
1
]
Go Down
« previous
next »
Print
Topic: new spyware wincfg.scr ? (Read 5261 times)
0 Members and 1 Guest are viewing this topic.
new spyware wincfg.scr ?
« on: July 26, 2003, 04:43:10 »
yellowfan
Newbie
Karma: 0
Posts: 1
This is my personal experience
I got it probably via usenet
It installed a program "wincfg.scr" in my c:\windows\system (Windows98 user)
I search the web but got no answer.
This file attemp to access the net by my firewall (ZA) detected it
The problam was to remove it as it blocked the use of the following commands :
regedit
msconfig
Of course the programm was used by windows so the delete key was not in use...
So I fixed the problem like that :
- I shutdown my computer
- I connect an additional harddrive and boot with this one as "primary master", the other one being secondary master now
- Then I run my computer under Windows95 in safe mode and renade the wincfg.scr
Now my computer is running well
I got regedit and msconfig in us again
So I found in the "startup" panel an item called Winsock2 driver that launch it
If you got any info please reply
Logged
new spyware wincfg.scr ?
« Reply #1 on: July 26, 2003, 05:07:01 »
Tony Klein
Global Moderator
Karma: 2
Posts: 1638
No spyware, but very likely a W32/Spybot worm variant.
Cheers,
Logged
Tony
CLSID List
-
A Collection of Autostart Locations
new spyware wincfg.scr ?
« Reply #2 on: July 26, 2003, 05:12:46 »
Metallica
Global Moderator
Karma: 4
Posts: 4840
Most likely yes, regarding the Winsock2 driver.
You can verify this by checking if you have a \WINDOWS\SYSTEM32\kazaabackupfiles\ folder all of a sudden.
Regards,
Pieter
Logged
Remove and prevent spyware
MVP Windows Security 2003-2008
RE:wincfg.scr
« Reply #3 on: July 31, 2003, 04:18:10 »
Ghostman046
Guest
You can boot to dos and go to the windows\system dir. Run attrib wincfg.scr -h. The file will show up and can be deleted. After rebooting back in windows run regedit and remove all wincfg.scr from there. Should be in two locations
Logged
wincfg.scr
« Reply #4 on: July 31, 2003, 21:11:39 »
Neill
Guest
Here's another board thread:
http://forums.techguy.org/showthread.php?s=226fe5e2ecd79aa1b3fa84ee76a7f5df&threadid=149985&pagenumber=2
Logged
new spyware wincfg.scr ?
« Reply #5 on: August 02, 2003, 14:29:05 »
nesbot
Guest
Something killed my soundcard. It was always in use and so not available for any ap to call it. Did the usual with no fix. I can't say wincfg.scr was the problem but that's why I was searching. I knew something out of the ordinary was running.
I loaded a trial copy of StartUp Manager (http://www.rayslab.com/startup_manager/startup_manager.html)
and saw the winsock2 (several) and that led me to wincfg.scr. I couldn't delete or rename.
I came here, found out it wasn't a normal windows file and had SM disable it. Per some other post I did a safe mode boot, deleted it in regedit and renamed the file to wincfg.scr.virus. In my case it appeared in the register THREE times.
That seemed to fix things. I did a fresh live update to Norton AV. When I went in the C:/window/system directory, it caught the renamed file and I had it delete it.
Side note, I do occationally use Kazaa as Metallica noted, but I did NOT have the WINDOWS\SYSTEM32\kazaabackupfiles\ directory.
Thanks a million everyone for the info.
Logged
wincfg.scr
« Reply #6 on: August 03, 2003, 01:37:42 »
bigmac6
Newbie
Karma: 0
Posts: 1
I managed to delete
wincfg.scr
(backdoor sdbot) using a product called "East Tech Eraser" free trial visit tucows, allowed me then to access registry and delete WINCFG.SCR here
Quote
Logged
new spyware wincfg.scr ?
« Reply #7 on: August 27, 2003, 20:51:54 »
Anonymous
Guest
I just booted into Safe Mode and deleted the file, then used regedit and found all the little pieces.
Logged
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Spyware-Related Stuff
-----------------------------
=> Spyware - Help!
=> Security Related Updates
=> Spyware - General
=> Report New Spyware Here
=> Class-Action Heroes
-----------------------------
Everything Else
-----------------------------
=> Free Webpage Providers
=> Culture Jamming
=> Site Comments & Feedback
=> Tech Talk
=> Bitch Board
=> General Discussion