redwolfe_98
December 9th, 2003, 01:23 PM
when i run the "process-kill demo", it shuts down vettray.exe. i would like some help to try to set things so that it cannot be killed. also, i would like some help with the settings in pg: should either of the two options in "pg/protection/general protection options" be checked?.. i don't know much about how to gather and post whatever information could be used for diagnosis.. here is the log from asviewer: DiamondCS Autostart Viewer (www.diamondcs.com.au) - Report for Tom@TOMS-PC, 12-09-2003
c:\windows\system32\autoexec.nt
C:\WINDOWS\system32\mscdexnt.exe
C:\WINDOWS\system32\redir.exe
C:\WINDOWS\system32\dosx.exe
c:\windows\system32\config.nt
C:\WINDOWS\system32\himem.sys
c:\windows\system.ini [drivers]
timer=timer.drv
c:\windows\system.ini [boot]\shell
C:\WINDOWS\Explorer.exe
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
C:\WINDOWS\Explorer.exe
HKCR\htafile\shell\open\command\
C:\Program Files\AnalogX\Script Defender\sdefend.exe %1 %*
HKCR\vbsfile\shell\open\command\
C:\Program Files\AnalogX\Script Defender\sdefend.exe %1 %*
HKCR\vbefile\shell\open\command\
C:\Program Files\AnalogX\Script Defender\sdefend.exe %1 %*
HKCR\jsfile\shell\open\command\
C:\Program Files\AnalogX\Script Defender\sdefend.exe %1 %*
HKCR\jsefile\shell\open\command\
C:\Program Files\AnalogX\Script Defender\sdefend.exe %1 %*
HKCR\wshfile\shell\open\command\
C:\Program Files\AnalogX\Script Defender\sdefend.exe %1 %*
HKCR\wsffile\shell\open\command\
C:\Program Files\AnalogX\Script Defender\sdefend.exe %1 %*
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\POINTER
point32.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\IntelliType
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\VetTray
C:\PROGRA~1\CA\ETRUST~1\ETRUST~1\VetTray.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\THGuard
C:\Program Files\TrojanHunter 3.7\THGuard.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\RegProt
c:\program files\regprot\regprot.exe /start
HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\
C:\WINDOWS\system32\SHELL32.dll
C:\WINDOWS\system32\SHELL32.dll
C:\WINDOWS\System32\webcheck.dll
C:\WINDOWS\System32\stobject.dll
HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute
autocheck autochk *
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit
C:\WINDOWS\system32\userinit.exe
HKLM\System\CurrentControlSet\Control\WOW\cmdline
C:\WINDOWS\system32\ntvdm.exe
HKLM\System\CurrentControlSet\Control\WOW\wowcmdline
C:\WINDOWS\system32\ntvdm.exe -a %SystemRoot%\system32\krnl386
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\rsvpsp.dll
HKLM\System\CurrentControlSet\Services\VxD\JAVASUP\
C:\WINDOWS\system32\JAVASUP.VXD
thanks, :) (p.s. something seems peculiar about the point32.exe entry. spybot flags it, but when it "fixes" it, point32.exe no longer runs) also note the "dos" attributes in "HKLM\Software\Microsoft\Windows\CurrentVersion\Run\VetTray
C:\PROGRA~1\CA\ETRUST~1\ETRUST~1\VetTray.exe"
c:\windows\system32\autoexec.nt
C:\WINDOWS\system32\mscdexnt.exe
C:\WINDOWS\system32\redir.exe
C:\WINDOWS\system32\dosx.exe
c:\windows\system32\config.nt
C:\WINDOWS\system32\himem.sys
c:\windows\system.ini [drivers]
timer=timer.drv
c:\windows\system.ini [boot]\shell
C:\WINDOWS\Explorer.exe
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
C:\WINDOWS\Explorer.exe
HKCR\htafile\shell\open\command\
C:\Program Files\AnalogX\Script Defender\sdefend.exe %1 %*
HKCR\vbsfile\shell\open\command\
C:\Program Files\AnalogX\Script Defender\sdefend.exe %1 %*
HKCR\vbefile\shell\open\command\
C:\Program Files\AnalogX\Script Defender\sdefend.exe %1 %*
HKCR\jsfile\shell\open\command\
C:\Program Files\AnalogX\Script Defender\sdefend.exe %1 %*
HKCR\jsefile\shell\open\command\
C:\Program Files\AnalogX\Script Defender\sdefend.exe %1 %*
HKCR\wshfile\shell\open\command\
C:\Program Files\AnalogX\Script Defender\sdefend.exe %1 %*
HKCR\wsffile\shell\open\command\
C:\Program Files\AnalogX\Script Defender\sdefend.exe %1 %*
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\POINTER
point32.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\IntelliType
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\VetTray
C:\PROGRA~1\CA\ETRUST~1\ETRUST~1\VetTray.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\THGuard
C:\Program Files\TrojanHunter 3.7\THGuard.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\RegProt
c:\program files\regprot\regprot.exe /start
HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\
C:\WINDOWS\system32\SHELL32.dll
C:\WINDOWS\system32\SHELL32.dll
C:\WINDOWS\System32\webcheck.dll
C:\WINDOWS\System32\stobject.dll
HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute
autocheck autochk *
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit
C:\WINDOWS\system32\userinit.exe
HKLM\System\CurrentControlSet\Control\WOW\cmdline
C:\WINDOWS\system32\ntvdm.exe
HKLM\System\CurrentControlSet\Control\WOW\wowcmdline
C:\WINDOWS\system32\ntvdm.exe -a %SystemRoot%\system32\krnl386
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\rsvpsp.dll
HKLM\System\CurrentControlSet\Services\VxD\JAVASUP\
C:\WINDOWS\system32\JAVASUP.VXD
thanks, :) (p.s. something seems peculiar about the point32.exe entry. spybot flags it, but when it "fixes" it, point32.exe no longer runs) also note the "dos" attributes in "HKLM\Software\Microsoft\Windows\CurrentVersion\Run\VetTray
C:\PROGRA~1\CA\ETRUST~1\ETRUST~1\VetTray.exe"