den: (Default)
[personal profile] den
I found the file giving me problems. AdAware, Spychecker and OptOut didn't pick up the program, but I found it! In /winapps there was a small exe called emylthro.exe which had a date that matched the day I started having problems. This is how I reckon it worked:

When windows is started emylthro.exe is executed and resides in mem. All it does is set the homepage on IE to a porn site, and create in /windows/temp a .tmp file with a random name like hxvc7391.TMP They were always llllnnn.TMP Emylthro.exe stayed resident in mem but did nothing after it executed the .TMP. This .tmp created an icon in the systray called Music Search Online, but actually linked to a hard-core porn site. I connected once to see where it took me, but hit the LOCK switch on ZoneAlarm as soon as it started asking to upload some more s/ware. I set the firewall to deny the Music Search Online access to all networks. Proxomitron killed all the popups and ads so I don't know how many there were, but I expect the site is popoup central.

anyway. That's the story. I'll run regclean again to clean up the mess.

Next step is to remove the programs listed in add/remove programs that don't have an attachment to anything.

The kid who installed this mongrel bastard thing has had all his PC priveliges revoked. I was so pissed off with him I told his mum exactly what he'd been doing:

Surfing the 'net for hard core lesbian porn.
This account has disabled anonymous posting.
If you don't have an account you can create one now.
HTML doesn't work in the subject.
More info about formatting

Profile

den: (Default)
den

April 2023

S M T W T F S
      1
2345678
9101112131415
16171819202122
23242526 272829
30      

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated 31 December 2025 17:35
Powered by Dreamwidth Studios