Problems Removing Kazaa

Discussion in 'other security issues & news' started by aishuu, Sep 14, 2002.

Thread Status:
Not open for further replies.
  1. aishuu

    aishuu Registered Member

    Joined:
    Sep 14, 2002
    Posts:
    10
    Location:
    somewhere slightly north of reality
    My computer skills? I know enough to be dangerous, as I like to say. I am very good at file management (run a company of 50's organizational system), can make the Microsoft programs dance, and am a quick study with most other informational programs- in other words, I'm a user, not a programmer.

    I manually removed those kazaa files I could find, but for some reason, my system didn't have the same organizational system. Don't ask why- I think it may be because my uncle is a programmer and he set it up. Unfortnately, he's out of contact at the moment. I did a find, and nothing else came up kazaa.

    Here's my current run list and I don't see kazaa but that purple thing is still there... Any more ideas, or should I just call it quits? I can track down and mannual delete anything that looks like it doesn't belong, but... that kinda scares me. For some reason, Adalert and spybot didn't grab kazaa for me, so I'm wondering what ELSE they missed.

    Running processes:

    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\AVPCC.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\PROGRAM FILES\DELFIN\PROMULGATE\PGMONITR.EXE
    C:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\AVPCC.EXE
    C:\PROGRAM FILES\CHECKIT\UTILITIES\TOOLBOX.EXE
    C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE
    C:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\AVPM.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
    C:\WINDOWS\SYSTEM\RNAAPP.EXE
    C:\WINDOWS\SYSTEM\TAPISRV.EXE
    C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\WINWORD.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
    C:\MY DOCUMENTS\DOWNLOAD\STARTUPLIST13\STARTUPLIST.EXE

    ~ Aishuu
     
  2. Jooske

    Jooske Registered Member

    Joined:
    Feb 12, 2002
    Posts:
    9,713
    Location:
    Netherlands, EU near the sea
    Good you found the regkey already John and description about the find and delete there.

    And with all you've been trying, is the system still slow?

    No other trojans, TDS or other found nothing of the like?

    Sometimes a program mixes with another program which it has nothing to do with at all and forces us to uninstall the other and after uninstalling the one we really want to be rid of, we have to reinstall the second one we want to keep. Could be something like that has happened.
    So if the regcleaning and finding files does not help, ...

    I always like to look deeper with Faber Toys (free) www.faberbox.com to all what is running and dll's and all that belonging to each process. Might give light in the situation?

    Did you initially remove the files manually, and not use the uninstall option or add/remove first? Then there can be still be files left everywhere with names you don't recognize immediately, and entries in sys.ini and win.ini maybe even.
    (see explanation how to handle with those in the other posting above)
    In some cases to have everything it can help to install the program again, and after uninstall in the proper way via uninstall or add/remove and after go through the registry and files hunting. How about that option?
     
  3. Checkout

    Checkout Security Rhinoceros

    Joined:
    Feb 11, 2002
    Posts:
    1,226
    Ah, if only! I hope it helps you eradicate this beast.
     
  4. aishuu

    aishuu Registered Member

    Joined:
    Sep 14, 2002
    Posts:
    10
    Location:
    somewhere slightly north of reality
    *sighs* I'm actually getting kind of amused by this- if it's stumping you guys, it means it's not because I'm simple.

    No, I tried to uninstalled kazaa properly. I never manually remove anything except word docs, txt files, Quark files, jpegs, or other things I create personally. Messing with the system is best left to people who know what each file DOES rather than people like me, who use those files to create things. Then I tried to kill it with ad alert, then spybot, before I got the kazaa killer working, and none of them has come through.

    My system is connect to a 56K, so I'm not sure if it's slow or not, though it was finicky in word yesterday until I restarted after I performed a scan. I think one of the new programs (possibly Kaspersky since it's SLOW and seems to have a long running time- I'm not fond of that virus scan- I'm think of investing in Norton's since apparently it's the best-known and most people I know use it) glitches word- it freezes it, then types in lwhatever I entered later- it's only a few seconds delay that most people would shrug off, like an AIM delay, but since I need to do so much Word processing, I can't tolerate ANY Word malfunctions.

    Aside from that, everything is ok. I just have that purple thing on the bar- it's not sucking up my connection anymore, and even if it were, I'd put up a better firewall. I'll be getting a cable modem later this month (live in the middle of nowhere so it took forever for them to wire this area or whatever they had to do) so that should compensate.

    Still, I'll download that fabertoys and see what it does. I think I know enough to follow it, though it looks for serious users- which I am not. I'm a dabbler.

    ~ Aishuu
     
  5. eyespy

    eyespy Registered Member

    Joined:
    Feb 20, 2002
    Posts:
    490
    Location:
    Oh Canada !!
    I've never seen that one before. Are you running a firewall ?
    If so, check the "apps" that are running or are connected while online ! Look for something unfamiliar !
    Hope this helps !!
    bill ;)
     
  6. Bethrezen

    Bethrezen Registered Member

    Joined:
    Apr 16, 2002
    Posts:
    546
    hi

    sorry to hear about ya troubles i got an idea that migth help try this

    http://www.karenware.com/powertools/ptbrowse.asp

    its a free lil app that shows ya every file on ya comp when it was created what created it and and what app it belongs to and why it was created

    also if ya want to run a striped out crapware free version of kazaa kazaa lite here is where it can be found

    ADMIN edit The link has been removed. I don't mean to be a jerk, spyware does suck, but if you don't like spyware then don't use Kazaa. This board cannot condone the use of software in such a way that it violates its EULA or any laws.


    juging from ya screen shot it looks like ya got some sort of bogus dialer software installed happens to me all the time all

    have ya tryed lookin at internet options/conections tab and in my computer/dialup networking folder

    if all eles fails and its really buggin ya that much reformat ya harddrive and reinstall ya os and this will undo everything thats gone wrong on ya comp and set it back to factory settings

    let me know how ya get on
     
  7. aishuu

    aishuu Registered Member

    Joined:
    Sep 14, 2002
    Posts:
    10
    Location:
    somewhere slightly north of reality
    o_O Re:problems Removing Kazaa

    I've looked through everything, current programs that are up... yadda yadda... and according to it, it SHOULDN'T be there.

    I'm stumped.

    I think that... getting mixed in with someone else suggested is most likely.

    Well, I'm getting a BRAND NEW computer in January. I won't be transfering any of my hardware (just a few word files... which I save on disk, anyway!) so as long as this doesn't crash until then....

    I think I must conceed defeat. Though it IS annoying. I think I'll head over to the... Ten Forward...? is that the random chat?? around early December and see what people recommend to start of right. New System... should set up right!

    Though it is against my nature to give up, I refuse to bang my head into the wall on this anymore. I've spent at least... 10 hours trying to debug this.

    ~ Aishuu
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.