Computing.Net > Forums > Windows 95/98 > readme.exe virus?

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

readme.exe virus?

Reply to Message Icon

Name: Pete20033
Date: August 8, 2005 at 08:05:28 Pacific
OS: Win98
CPU/Ram: p150
Comment:

I was surfing the net when my Windows explorer popped up and somthing was installing or did install on my hd. My Norton firewall popped up asking whether or not to allow "readme.exe" in my C drive root directory to access the internet. I clicked no. I then deleted the "readme.exe" file from my hd. When I started up my browser (Internet Explorer 5.5) I was directed to this page on my hd:

res://C:\WINDOWS\system32\shdocsv.dll/API32.htm#ID=347;065D

It basically lists my personal information (IP, country of origin, OS, etc) and says my activities are being monitored and advises me to click on a link to download privacy protection software; the link is "javascript:redirector.dll" which when I tried to right-click to copy to post here showed up as "evidence-eliminator.com." I am running an older PC right now which, for some reason, will not let me use hijack this (it says I am missing MSVBM60.DLL) but msinfo32 does not show any unusual processes running since I stopped "readme.exe" and deleted it and my firewall does not show any odd connections. Does anyone know if this could be some type of virus or keylogger that is now in my system? Is there anyway to find out?

Thanks



Sponsored Link
Ads by Google

Response Number 1
Name: jboy
Date: August 8, 2005 at 08:40:49 Pacific
Reply:

Visual Basic 6.0 Run-time Files

Computers in the future may have only 1,000 vacuum tubes and perhaps only weigh 1 1/2 tons.


- Popular Mechanics, 1949


0

Response Number 2
Name: Rimfire
Date: August 8, 2005 at 14:17:03 Pacific
Reply:

This sounds more like a scam than a virus. You will notice that the address where the information is located is on your hard drive. The aim is to goad you into buying a sham program which won't really do much.

I'm not sure that shdocsv.dll is a valid file. I'm not using win98 at the moment, perhaps someone else can check.

A similar problem was solved on another forum by deleting
C:\WINDOWS\SYSTEM32\SVCNT.exe while in safe mode.


0

Response Number 3
Name: jboy
Date: August 8, 2005 at 17:36:43 Pacific
Reply:

Doesn't appear to be part of 98SE/IE5.5 anyhow. Results from Google are decidedly shady, and may even involve (the vile) Smitfraud

Computers in the future may have only 1,000 vacuum tubes and perhaps only weigh 1 1/2 tons.


- Popular Mechanics, 1949


0

Response Number 4
Name: Pete20033
Date: August 9, 2005 at 19:26:19 Pacific
Reply:

Thanks. I should have waited to post the above message. I found a rule in my Norton firewall that wasn't there before for "loadnew.exe." I did an online virus scan with Panda and it found in my c:\windows\system dktibs.exe (a dialer.bb), paydial.exe (a dialer.xc), systime.exe (adware). All of these have 0kbs. Does this mean they are just empty files?

Panda virus scan also found in my C:\WINDOWS\SYSTEM32\ svcnt.exe (spyware/Smitfraud), shdocsv.dll (Adware/E-eliminator) and it also found C:\WINDOWS\TEMP\pavE321.TMP (Adware:Adware/E-eliminator). The loadnew.exe was a virus which Panda disinfected. The svnct file was actually set to load as a start-up program in msconfig, which I unchecked. As stated above, I can try delete svcnt in safe mode but with the other files, would adaware and spybot search and destroy work or do I have to manually get rid of them?


0

Response Number 5
Name: Rimfire
Date: August 10, 2005 at 05:45:35 Pacific
Reply:

I think that they should be able to get rid of at least most of them. Check them off the list after each scan.

Make sure that you have the latest definitions. Also, run the scans again in safe mode to be sure.

Should you have problems finding them and updating. Decisive use of task manager might help. The only program that you need running is explorer.exe. You might also leave your AV running and of course taskman is the task manager program.


0

Related Posts

See More



Response Number 6
Name: BrunoB
Date: September 2, 2005 at 11:30:35 Pacific
Reply:

I don't think loadnew.exe is a real virus. But if you want to get rid of all of its "friends" look here:
http://www.computerhilfen.de/hilfen-17-36803-0.html

BrunoB

Denmark


0

Sponsored Link
Ads by Google
Reply to Message Icon

USB HDD format Firefox Homepage keeps co...



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows 95/98 Forum Home


Sponsored links

Ads by Google


Results for: readme.exe virus?

Monkey.avi.exe virus www.computing.net/answers/windows-95/monkeyaviexe-virus/71300.html

help to remove scrvsr.exe virus www.computing.net/answers/windows-95/help-to-remove-scrvsrexe-virus/128949.html

anti-exe virus www.computing.net/answers/windows-95/antiexe-virus/44609.html