3843 Files created

Dan

Distinguished
Dec 31, 2007
2,208
0
19,780
Archived from groups: microsoft.public.win95.general.discussion (More info?)

I am using Win95 and IE 5.5.
On 11/12/2004 some 3843 files were created in C:\Windows
SYSMAP.exe was created in C:\ and install.exe was created
in C:\Windows\Temp.
All files except install.exe were 7KB. Examples from A thru V, all 3
letters are:

Aaa.exe
Aab.exe
Bac.exe
Bae.exe
Bvf.exe
Rnb.exe
Rvq.exe
Vvo.exe

Is this from an Adware or Spyware exe. ? I removed a Windows Adcontrol exe.
around that
date and I'm not sure if this is a remainder or new stuff on the HD.
My puter has been running very slow since that time period
and the modem isn't doing much better.

Any help would be appreciated.
 
G

Guest

Guest
Archived from groups: microsoft.public.win95.general.discussion (More info?)

SYSMAP.exe is added as a result of the MAPSY virus:
http://securityresponse.symantec.com/avcenter/venc/data/backdoor.mapsy.html
http://vil.nai.com/vil/content/v_99783.htm

I do not find a reference to a file named "adcontrol.exe", but "WinAdCtl.exe" is
known as Windows AdControl, and is a Windupdates adware variant.
CastleCops Windows AdControl WinAdCtl.exe:
http://computercops.biz/startuplist-6126.html

See here for more info and check your system for the enties listed:
http://www.spynet.com/spyware/spyware-WindUpdates.aspx

aaa.exe appears to be part of Downloader-DK, a trojan downloader:
http://vil.mcafeesecurity.com/vil/content/v_100512.htm

Bac.exe may be W32/Backterra-D:
http://www.sophos.com/virusinfo/analyses/w32backterrad.html

The random-letter-named exe's may also be just that....random-generated names for
trojan downloaders.

Bottom line is that the system seems to be infested with trojans and adware. Do you
have an updated anti-virus installed?

Update your anti-virus app and then run a full-system virus scan.

Use CWShredder, the CoolWeb removal tool, available here:
http://www.majorgeeks.com/downloads31.html
http://www.zerosrealm.com/downloads/CWShredder.zip
http://aumha.org/downloads/cwshredder.zip
Close all browser windows and open apps, start CWShredder and click the Fix button.

In addition, install Ad-Aware SE free edition (if possible...it does not install
successfully on all Win95 systems), start it, click its 'Check for Updates' link in
the app to install updates, then use it to scan your system, and remove what it
finds.
Ad-Aware:
http://www.lavasoftusa.com/support/download/

Install SpywareBlaster:
http://www.majorgeeks.com/download2859.html
Click the link in the app to check for and install updates, then click to 'Enable
all protection'.
Update at least weekly.

Post back with your results.
--
Glen Ventura, MS MVP W95/98 Systems
http://dts-l.org/goodpost.htm


"dan" <4dsf@NoSpaM.com> wrote in message
news:ObLHyFH4EHA.3596@TK2MSFTNGP12.phx.gbl...
> I am using Win95 and IE 5.5.
> On 11/12/2004 some 3843 files were created in C:\Windows
> SYSMAP.exe was created in C:\ and install.exe was created
> in C:\Windows\Temp.
> All files except install.exe were 7KB. Examples from A thru V, all 3
> letters are:
>
> Aaa.exe
> Aab.exe
> Bac.exe
> Bae.exe
> Bvf.exe
> Rnb.exe
> Rvq.exe
> Vvo.exe
>
> Is this from an Adware or Spyware exe. ? I removed a Windows Adcontrol exe.
> around that
> date and I'm not sure if this is a remainder or new stuff on the HD.
> My puter has been running very slow since that time period
> and the modem isn't doing much better.
>
> Any help would be appreciated.
>
>
 

Dan

Distinguished
Dec 31, 2007
2,208
0
19,780
Archived from groups: microsoft.public.win95.general.discussion (More info?)

Thank you Glen for all that info. Question please ?

I started removing those files before I posted here. They
are in Recycle Bin, not yet removed.
Can I continue to remove them to the Bin and then Delete
them all ? I'm not having any trouble doing that, so far.

Shredder says I'm clean ????

Will goto sites and start DL those aps. you mentioned.
 
G

Guest

Guest
Archived from groups: microsoft.public.win95.general.discussion (More info?)

I don't think it will matter that you put some of those files in the Bin, but before
deleting any more, run Ad-Aware, and update your anti-virus and run a full system
scan. What anti-virus do you have installed, and what is the date of the virus
definition updates?

If trouble persists, do this:
Download, unzip, and run Hijack This from one of these locations:
http://computercops.biz/downloads-cat-14.html
http://www.majorgeeks.com/downloads31.html
http://www.spywareinfo.com/downloads/tools/HijackThis.exe
Unzip to a folder other than your Desktop or the Temp folder, doubleclick
HijackThis.exe, and hit "Scan".

When the scan is finished, the "Scan" button will change into a "Save Log"
button.
Press that, save the log somewhere you can find it (Desktop, My Documents, or
similar).
Most of what it lists will be harmless or even required, so do NOT fix anything yet.

Copy the log files and paste them into a new post at this forum:
http://forum.aumha.org/viewforum.php?f=30

In your post, please state your problem clearly and what you've done so far to fix
it.

The folks there will tell you what to remove.

See the "housekeeping" you should complete before you post your log:
http://aumha.org/forum/viewtopic.php?t=4075

A tutorial for using Hijack This is located here:
http://tomcoyote.com/hjt/
--
Glen Ventura, MS MVP W95/98 Systems
http://dts-l.org/goodpost.htm


"dan" <4dsf@NoSpaM.com> wrote in message
news:uKaHNvH4EHA.4028@TK2MSFTNGP15.phx.gbl...
> Thank you Glen for all that info. Question please ?
>
> I started removing those files before I posted here. They
> are in Recycle Bin, not yet removed.
> Can I continue to remove them to the Bin and then Delete
> them all ? I'm not having any trouble doing that, so far.
>
> Shredder says I'm clean ????
>
> Will goto sites and start DL those aps. you mentioned.
>
>
 
G

Guest

Guest
Archived from groups: microsoft.public.win95.general.discussion (More info?)

?? I see all your posts, at least all that I know about. I don't have any way to
delete your posts, anyway. What do you see as missing?
--
Glen Ventura, MS MVP W95/98 Systems
http://dts-l.org/goodpost.htm

"dan" <4dsf@NoSpaM.com> wrote in message
news:%230fDP2d4EHA.3120@TK2MSFTNGP12.phx.gbl...
> Curious. Did you delete my last post ?
>
>
 
G

Guest

Guest
Archived from groups: microsoft.public.win95.general.discussion (More info?)

? I see all your posts. Try deleting and re-downloading this group in Outlook
Express, on the Tools menu> Options> Maintenance tab> Clean Up Now.
--
Glen Ventura, MS MVP W95/98 Systems
http://dts-l.org/goodpost.htm

"dan" <4dsf@NoSpaM.com> wrote in message
news:OyQdwpy4EHA.2568@TK2MSFTNGP11.phx.gbl...
> I give up ???
>
>