Computing.Net > Forums > Security and Virus > Suspicious Script has been......

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Suspicious Script has been......

Reply to Message Icon

Name: tommy o
Date: April 13, 2004 at 17:41:15 Pacific
OS: Win XP home
CPU/Ram: 256 MB
Comment:

Hello all; I have no idea what this means. I clicked on system restore, not intending on restoring, but to see what I had for restore points available; this is the first time in almost a year I checked this.
My McAfee immediatelt flagged, what is worded like this....." C:\windows\system32\RSTRUI.exe....contains suspicious script activity."
It also says " activity : the script is attempting to call the RUN method within the IWshShell3 object "
Man, I'm lost on this one; does anyone have any idea if I have some sort of problem here? I should add, that my computer is running fine. I only went to check the restore points because I'll probably install the Microsoft critical updates tomorrow; as the server is very busy and slow tonight. Thanks very much !
~Tommyo



Sponsored Link
Ads by Google

Response Number 1
Name: Dog
Date: April 13, 2004 at 18:00:33 Pacific
Reply:

tommyo,
http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=RSTRUI.EXE


It works for me

D4


0

Response Number 2
Name: tommy o
Date: April 13, 2004 at 18:13:46 Pacific
Reply:

Thanks, Dog, very much....I've got quite a bit to read here, as I've never had to use system restore before, so I'm not very familiar with it. I don't even know how long that bad script has been there. I just noticed it tonight by clicking to see what my restore points were set to.
I didn't even get into system restore, as McAfee flagged it right away.
Thanks again; I'll read up on it and see how to delete this thing, what ever it is.


0

Response Number 3
Name: tommy o
Date: April 13, 2004 at 19:37:02 Pacific
Reply:

Hi Dog...I've been reading non-stop here, and tried a few things, but I guess I'm not doing the right things here. Because in my event viewer, I recieve a (yellow exclamation mark) warning every day, about
event 36, W32 time. So, I must be looking in the wrong places here.
As I scanned the events in event viewer, I notice a warning every day for the same thing....event 36; W32 time....."the time service has not been able to sinchronize the time for 49,152 seconds because none of the time providers has been able to provide a usable time stamp. The system clock is un-synchronized. "
That is strange, as my clock seems to keep good time, at least it appears it does to me. Well, enough for tonight....my eyes are gettin' heavy here. I'll add some more info Wed. morning when I delve into this again. I just wanted to keep ypu posted on how I was making out. Thanks very much, Dog.
~Tommyo


0

Response Number 4
Name: Dog
Date: April 13, 2004 at 22:26:18 Pacific
Reply:

tommyo,
Have a look at this also

http://forums.eyo.com.au/arc/t-36015

It works for me

D4


0

Response Number 5
Name: tommy o
Date: April 14, 2004 at 07:18:34 Pacific
Reply:

Hi Dog..thanks for the additional info. I did search everywhere for the "ipstack" virus, and I can't locate it anywhere; so at this point I don't know if I've got some hidden virus, or a synchronization problem with my clock. I don't know why I show a (yellow) warning, for every day, in my event viewer. I've got to try and determine what
"event 36; W32TIME" refers to.
Thanks again for your help...I'll be reading all day long here to try and decipher this mess.
~Tommyo


0

Related Posts

See More



Response Number 6
Name: tommy o
Date: April 14, 2004 at 07:20:43 Pacific
Reply:

I forgot to ask....can someone advise if I should hold off with the install of the new Microsoft critical updates, until I can figure out this problem??? Thanks!


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Suspicious Script has been......

My background has been hijacked! www.computing.net/answers/security/my-background-has-been-hijacked/23170.html

a virus has been found www.computing.net/answers/security/a-virus-has-been-found/19720.html

My BIOS has been flashed!! www.computing.net/answers/security/my-bios-has-been-flashed/6208.html