Welcome to SecurityForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

Executables Stop, PendingFileRenameOperations written

 
   Security Forums (Home) -> General Discussions RSS
Next:  Help! - part 2, please  
Author Message
news.rsvl.unisys.com

External


Since: Sep 15, 2004
Posts: 1



(Msg. 1) Posted: Wed Sep 15, 2004 10:32 am
Post subject: Executables Stop, PendingFileRenameOperations written
Archived from groups: alt>comp>virus (more info?)

Greetings,

I have a virus that Norton can't find. It has chosen to disable a set of
executables that I happened to be using.

When you double-click, or open, these executables, they appear to do
nothing. I searched the registry and found that they were writing entries
into
HKLM\System\CurrentControlSet\Control\SessionManager\PendingFileRenameOperat
ions

The value was \??\pathtofile and sometimes @\??\pathtofile.

The excutables were odd. eclipse, java.exe, adaware's install exe. Others
seem to be working OK. Eventually, the files disappear.

I can't reinstall the files. It has their names somewhere infects them as
soon as they appear.

I've run the anti-goner tool, and it says I have nothing.

It appears to be riched20.dll based. If I try to delete riched20.dll, it
says I need a password.

I tried going into safe mode and deleting riched20.dll. That worked, but
when I reinstalled it, everything came back. In fact, I saw riched20 in
the RenameFile... registry setting.

Any guesses or help.

Thanks

 >> Stay informed about: Executables Stop, PendingFileRenameOperations written 
Back to top
Login to vote
Bill

External


Since: Sep 12, 2004
Posts: 28



(Msg. 2) Posted: Wed Sep 15, 2004 4:15 pm
Post subject: Re: Executables Stop, PendingFileRenameOperations written [Login to view extended thread Info.]
Imported from groups: per prev. post (more info?)

This message is not archived

 >> Stay informed about: Executables Stop, PendingFileRenameOperations written 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
Over written MBR - Hi all Is there a virus going round that over writes the mbr (NTFS) I know 2 people that have been hit with something that does this, I was hit last night! TIA

Is Swen ever going to stop? - Is it ever going to stop? I get 80 in about 8 hours. I hate deleting them.

Want to stop viruses and Trojans? - Install Linux.

W32.Swen...Help Make it STOP!!! - Does anybody out there know how to make the infected emails STOP coming to me. I've tried blocking, filtering, Spaminating, I even contacted my server to see if they could block all my email for a while. NAV only tells me how to clean the worm from...

W32.Swen...Help Make it STOP!!! - ----- Original Message ----- From: "DebLeppard" <debleppard@frontiernet.net> Newsgroups: alt.comp.virus Sent: Thursday, September 25, 2003 12:19 AM Subject: W32.Swen...Help Make it STOP!!! > Does anybody out there know how to make t...
   Security Forums (Home) -> General Discussions All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]