Re: Help! Spyware on boot up

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



"Rue" wrote
When I start up Windows XP Pro the program umonit.exe tries to open. Have
used msconfig to examine boot.ini , start up etc but can see the file listed.
When I do a search there are two entries, one in Windows Prefetch, the other
in Windows System 32. Since the file umonit.exe has an unknown publisher is
it safe to assume that I can just delete the two entries?

Umonit.exe is _not_ a windows file. It could be legitimate, installed by a 3rd party app, or it could be malware masquerading as a legit file. You should know if you installed anything right before this problem started. It's interesting that you can't find it on msconfig, since when legit it should appear there. Download Autoruns for MS to see if you can find where it's loading from.

http://www.microsoft.com/technet/sysinternals/utilities/Autoruns.mspx

In any event I would not just let it be. Even if legit it's not needed. Here are some links for dealing with malware. I suggest you do a thorough scan for malware.

Malware Removal
http://www.elephantboycomputers.com/page2.html#Removing_Malware

THE PARASITE FIGHT
Finding, Removing & Protecting Yourself From Scumware
http://aumha.org/a/parasite.htm

Richard Harper’s Guide to Cleaning Pests
http://rgharper.mvps.org/cleanit.htm

--
Rock [MS-MVP User/Shell]

.



Relevant Pages

  • Re: backdoor.afcore.bb HELL
    ... I'll read up on MSCONFIG. ... > malware as soon as it detects the other is deleted, ... >> the registry and deleted the entries. ... But I can remote into the PC. ...
    (microsoft.public.security)
  • Re: boot.ini disappears on restart or startup XP Pro
    ... boot.ini tab disappeared from msconfig. ... I have 11 files in the root directory of c:\ plus 17 folders. ... It isn't the number of files of folders in the root causing your ... sounds like malware to me. ...
    (microsoft.public.windowsxp.general)
  • Re: boot.ini disappears on restart or startup XP Pro
    ... boot.ini tab disappeared from msconfig. ... I have 11 files in the root directory of c:\ plus 17 folders. ... It isn't the number of files of folders in the root causing your ... sounds like malware to me. ...
    (microsoft.public.windowsxp.general)
  • Re: ContraVirus v2.0
    ... Is *what* a "legit. ... Either go to the link I gave the OP or go through the following general malware removal steps: ... Scroll all the way down to almost the bottom of the page and you'll see a box titled "Infos Zum Download - Multi-AV Scanning Tool". ... If the procedures look too complex - and there is no shame in admitting this isn't your cup of tea - take the machine to a professional computer repair shop. ...
    (microsoft.public.security.virus)
  • Re: backdoor.afcore.bb HELL
    ... free Firewall.With secure dll authentication enabled,by ... >the classic malware, the other is a monitoring service ... using registry entries and MSCONFIG itself ...
    (microsoft.public.security)