Two Plus Two Newer Archives  

Go Back   Two Plus Two Newer Archives > General Poker Discussion > Poker Beats, Brags, and Variance
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #131  
Old 06-19-2007, 10:50 PM
medaugh medaugh is offline
Senior Member
 
Join Date: Feb 2005
Posts: 172
Default Re: DON\'T CLICK ON THE LINK IN THE \"is this 4 real...\" THREAD

OK another question. I used system restore and went back a week. Now when I use regedit I have nothing showing up. Did this fix it or do I really have to reformat. dont have any money online but do have online banking ect.
Reply With Quote
  #132  
Old 06-19-2007, 10:50 PM
GrannyMae GrannyMae is offline
Senior Member
 
Join Date: Sep 2002
Posts: 11,677
Default Re: DON\'T CLICK ON THE LINK IN THE \"is this 4 real...\" THREAD

edit


nevermind
Reply With Quote
  #133  
Old 06-19-2007, 10:51 PM
Neuge Neuge is offline
Senior Member
 
Join Date: Jul 2004
Posts: 784
Default Re: DON\'T CLICK ON THE LINK IN THE \"is this 4 real...\" THREAD

[ QUOTE ]
What I have on mine is svcholt not svchost

[/ QUOTE ]
Ok. This a really crappy trojan. It should be okay to just delete the svcholt.exe from your Program Files directory. I would also delete any eMondo entries from my registry, but if you're not comfortable doing that (if you're not sure, you're not comfortable) it'll still probably be okay. I'd also keep an eye on task manager for a couple weeks to see if any instances of svcholt recur.
Reply With Quote
  #134  
Old 06-19-2007, 10:52 PM
tercet tercet is offline
Senior Member
 
Join Date: Mar 2006
Location: Kingston ON
Posts: 522
Default Re: DON\'T CLICK ON THE LINK IN THE \"is this 4 real...\" THREAD

[ QUOTE ]
i have
1 under AIM 6 and
1 under C:\I386 and
1 under c:\program files\common files\AOL\1149599630\ee

[/ QUOTE ]

I think ur infected, but not from this website.
Reply With Quote
  #135  
Old 06-19-2007, 10:53 PM
medaugh medaugh is offline
Senior Member
 
Join Date: Feb 2005
Posts: 172
Default Re: DON\'T CLICK ON THE LINK IN THE \"is this 4 real...\" THREAD

I did this also before using system resto.
Reply With Quote
  #136  
Old 06-19-2007, 10:53 PM
Neuge Neuge is offline
Senior Member
 
Join Date: Jul 2004
Posts: 784
Default Re: DON\'T CLICK ON THE LINK IN THE \"is this 4 real...\" THREAD

[ QUOTE ]
OK another question. I used system restore and went back a week. Now when I use regedit I have nothing showing up. Did this fix it or do I really have to reformat. dont have any money online but do have online banking ect.

[/ QUOTE ]
You should be fine. Keep checking your registry periodically for the next few weeks to see if the entries recur. If they don't, I wouldn't worry about it.
Reply With Quote
  #137  
Old 06-19-2007, 10:53 PM
danzasmack danzasmack is offline
Senior Member
 
Join Date: May 2005
Location: DYNAMO HARSHBART
Posts: 7,370
Default Re: DON\'T CLICK ON THE LINK IN THE \"is this 4 real...\" THREAD

[ QUOTE ]
[ QUOTE ]
i have
1 under AIM 6 and
1 under C:\I386 and
1 under c:\program files\common files\AOL\1149599630\ee

[/ QUOTE ]

I think ur infected, but not from this website.

[/ QUOTE ]

i have symantec and scanned and nothing came up. any idea what i should do?

btw thanks so much everyone this is awesome
Reply With Quote
  #138  
Old 06-19-2007, 10:54 PM
tercet tercet is offline
Senior Member
 
Join Date: Mar 2006
Location: Kingston ON
Posts: 522
Default Re: DON\'T CLICK ON THE LINK IN THE \"is this 4 real...\" THREAD

Everyone just download this prog if u think your infected
http://www.download.com/SnoopFree-Pr...ml?tag=lst-0-1

If you log onto any keylogging progs(pokerstars,full tilt, aim,msn etc) it will prompt you with files that are trying to track your login information. If the file looks suspicious you can just block it until the desired file(s) are gone.
Reply With Quote
  #139  
Old 06-19-2007, 10:55 PM
number007 number007 is offline
Junior Member
 
Join Date: Jun 2007
Posts: 15
Default Re: DON\'T CLICK ON THE LINK IN THE \"is this 4 real...\" THREAD

i have a file named svcholt under my program files, when i open it this is what is displayed - <RemoteSettings>
- <Appearance>
<Title>svcholt</Title>
<FileName>svcholt.exe</FileName>
</Appearance>
- <Behavior>
<Mode>Service</Mode>
<EnableListener>true</EnableListener>
<ListenPort>8551</ListenPort>
<AllowSimplifyUI>false</AllowSimplifyUI>
<SilentInstall>false</SilentInstall>
<EnableLogging>false</EnableLogging>
<CheckForUpdates>false</CheckForUpdates>
</Behavior>
- <Sessions>
- <Session Name="Default">
- <Connection>
<AccountName>morti</AccountName>
<StaticHost>false</StaticHost>
<Switchboard>http://www.emando.net/services/switc...witchboard>
<Host />
<Port>8550</Port>
</Connection>
<DisplayName />
<Group />
</Session>
</Sessions>
- <General>
<MachineId>4edecd7b-d3f4-4aff-ac71-25edaf49e123</MachineId>
<ControllerServerPort>8552</ControllerServerPort>
</General>
</RemoteSettings>
tercet what do i need to go to get rid of this
Reply With Quote
  #140  
Old 06-19-2007, 10:57 PM
Neuge Neuge is offline
Senior Member
 
Join Date: Jul 2004
Posts: 784
Default Re: DON\'T CLICK ON THE LINK IN THE \"is this 4 real...\" THREAD

[ QUOTE ]
i have a file named svcholt under my program files, when i open it this is what is displayed - <RemoteSettings>
- <Appearance>
<Title>svcholt</Title>
<FileName>svcholt.exe</FileName>
</Appearance>
- <Behavior>
<Mode>Service</Mode>
<EnableListener>true</EnableListener>
<ListenPort>8551</ListenPort>
<AllowSimplifyUI>false</AllowSimplifyUI>
<SilentInstall>false</SilentInstall>
<EnableLogging>false</EnableLogging>
<CheckForUpdates>false</CheckForUpdates>
</Behavior>
- <Sessions>
- <Session Name="Default">
- <Connection>
<AccountName>morti</AccountName>
<StaticHost>false</StaticHost>
<Switchboard>http://www.emando.net/services/switc...witchboard>
<Host />
<Port>8550</Port>
</Connection>
<DisplayName />
<Group />
</Session>
</Sessions>
- <General>
<MachineId>4edecd7b-d3f4-4aff-ac71-25edaf49e123</MachineId>
<ControllerServerPort>8552</ControllerServerPort>
</General>
</RemoteSettings>
tercet what do i need to go to get rid of this

[/ QUOTE ]
Open task manager, under the processes tab find svcholt.exe, kill it. Delete this file from you Program Files directory.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 04:51 PM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.