Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
I recently bought a k7 ultra motherboard, with 256mb ddr ram, and an athlon 2000+ processor, however i use WIN 98, i recently had a "stop-sign" virus scanner pop up whenever i run an application, i try so hard to go through all my files do delete the files associated with it and it still pops up, this is a spyware program, i used adaware to try to get rid of it and it finds the files, deletes them , then they show back up again, i have deleted them out of my temporary directory, and many other files, ,i need help really bad with this, this think annoys me, it also came with a a program called eanthology which i took care of, any help would be nice, thanks, also please email if you have a solution to this problem, please make the subject of the email something to the extent of where i do not think it is spam mail and delete it, thank you all :)

Installation may also include the eAcceleration Download Receiver or other Provider
free software. End Users also agree to allow Provider to display online advertising for
our own products, if they are not paid subscribers.
see the rest at eanthology servive agreement
1st try add/remove in control panel, to remove any of their software entries.
you might need to use something like regcleaner to remove the registry entries for it.

start-run-type in msconfig-click ok-
check msconfig startup tab, to see if it is listed there, if so uncheck it,click apply-click ok.also check your startup folder
in programs and delete any of their entries.
right click start-click open-doubleclick programs-doubleclick start up folder,etc.

http://www.webcelerator.com/products/webcelerator/install.htm
Defender antivirus is a SCUMWARE program! It fully opens your system to any popup
they wish you to have.The main program connects to the web accessing: www6.buttonware.net and goes to
download all it's .DAT files to infiltrate your system. These are:www6.buttonware.net\dr_popup\settings2.ini
www6.buttonware.net\dr_popup\entercasino9.dat
www6.buttonware.net\dr_popup\omnicasino10.dat
www6.buttonware.net\dr_popup\t4c12.dat
www6.buttonware.net\dr_popup\webscan5.dat[Thank GOD for packet sniffers!!!!]
You have NO protection of your system and port 80 AND 8080 are locked open! Allowing
ALL port 80/8080 Trojans to leave your system at any time you're online AND, may be
capable of initiating your dial up, depending oon your system configuration!!!The popups are timed to appear every hour you're online and, AT LEAST once a week -
Hence the auto dial out exploit!!!I accidently had it installed on my server, and had a nightmare to find all it's components,
splayed out all over my XP Pro system! The damn program was hidden inside a popup
killer from eAccelerator Software Corp.The files you nedd to remove are as follows [This is after doing an install!!!]
ANY folder by EADownloads
ANY folder with eAccelerator in the name
\Windows\System32\Prefetch\Canary.exe-XXXXXXXX.pf [Whatever the system has called
it]
can_temp.exe
canary.exe
dr_temp.exe
wren.exe
wren_temp.exe
C:\Program Files\Common Files\eAcceleration\systimer.exe
[Systimer.exe process will have to be killed, as it remains running in the background,
then delete the file from the directory within 30 seconds - The process will restart then
you'll be unable to delete it!!! - I recommend Process Viewer by Symantec included in
Norton SystemWorks to do this job effectively]
If you decide to use Windows task manager to do this job, then DO NOT click the "Notify"
button - just kill it!!!
With those removed, next the registry.....HKEY_CURRENT_USER\software\acceleration software international corporation\
HKEY_LOCAL_MACHINE\software\acceleration software international
DELETE THEM BOTH!!! Use Ad-Aware from www.lavasoft.nu for that job, makes it far
easier :-) [And a Freebie!]PLEASE NOTE: THIS REGISTRY UNINSTALL WILL ONLY WORK IF THE PREFETCH
FILE IS ALREADY DELETED AND, REMOVED FROM THE RECYCLE BIN!!! So I found out
to my cost!! :-(Do all that in the order listed and you'll be free of the accursed program -

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |