|
|
#1 (permalink) |
|
New Member
![]() Join Date: Nov 2004
Posts: 4
|
My conputer gets extremely slow and cant do anything so I open the task manager and my cpu is at 100%. There is a process called wavevb.exe and there is nothing on google about it. I ran ad aware, norton antivirus, spybot and that doesnt detroy it. Also when I end the process it coms back again. I search for it on my computer and just comes up in the prefetch folder. Then I go to msconfig and it is not in the startup configuration. Then I went to Hkey\Current Version\run and it was in there but there is a * by it and it was under the folder name C:\Winnt\addins\java\packages, so I went to that and it wasnt there. I deleted it Hkey but it came back. So does anyone have any ideas??
|
|
|
|
|
|
#2 (permalink) |
|
Administrator
![]() Join Date: Jul 2004
Location: Canada
Age: 25
Posts: 19,954
|
Well i dunno about specifics but a good firewall can nail it for ya
(have a look at Kerio)
__________________
ASUS P5K Premium WiFi-AP, Q6600@3.7 / ASUS P5ND, E6400@3.8 4GB OCz Platinum XTC 8500 / 4GB CorsairXMS2 6400 5x500GB Seagate 7200.10 / 2x500 Seagate 7200.10 OCz 8800GTX 768MB @ 630/800 / 2x Galaxy 8800GT SLI |
|
|
|
|
|
#3 (permalink) |
|
New Member
![]() Join Date: Dec 2004
Location: Netherlands
Age: 23
Posts: 19
|
first try to locate it by searching ur harddrives.
a trick ive done with result is when u locate the file, kill the service and delete the file. than create an file named exactly the same in the same dir. on properties tab set security on no acces for all. its not the cleanest way to fix but it worked u can always try running the adware progs in safemode
__________________
Dont take life 2 serious, u wont come out of it alive anyway !!! :eek: |
|
|
|
|
|
#4 (permalink) |
|
New Member
![]() Join Date: Dec 2004
Posts: 12
|
I had this same problem with my machine. If its what I'm thinking about, you can do a search on it but nothing comes up. The file of this such is super hidden, and cannot even be located in DOS. I had to use the sysinternals process explorer, avaliable at http://www.sysinternals.com/files/procexpnt.zip and find where the exe file was running from. Do this by opening process expolorer, right-clicking the file and going to properties. If the exe file is in a location where the entire directory can be deleted, you can just delete the folder the file is in. At my luck, it was in system32, so I had to get a boot CD rom (i.e. knoppix, ERD commander, the XP boot disk may work if you boot to the recovery console but I've never tried this) and delete the file there. You may get an error message saying path cannot be found when you log in from now on, but at least you dont have that stupid process running. I suppose this is the new type of trojan or something, but I dont understand why none of my virus programs gets it. Hope this helps!
|
|
|
|
![]() |
| Bookmarks |
| Thread Tools | |
| Display Modes | |
|
|