Re: adminamok

From: Rick \ (rick_at_mvps.org)
Date: 02/10/05


Date: Thu, 10 Feb 2005 18:06:37 -0500

Hi,

Can you say "trojan"? I knew that you could <g>. Seriously though, this a
trojan variant, a sort of virus. Follow these "relatively" simple removal
steps:

Restart in Safe mode by hitting F8 as Windows first begins to load on boot.
Logon as administrator. As this can be tricky, you will find help in doing
this here:
http://www.rickrogers.org/fixes.htm#Safe%20mode

Start/search/files and folders, look for <filename> and delete it wherever
it is found (hopefully it is not found if your antivirus software is doing
its job).

Click start/run, type regedit and click ok. Expand the plus (+) signs to
look under these keys:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg

Look in the right hand pane for the string or strings that load that file.
Delete just those strings that contain the reference. Do not delete other
strings or the keys from the left pane. Close the registry editor when
completed, make sure you check all strings.

Go to the Control Panel/System/System Restore tab. Check the box to "Turn
off system restore on all drives". Click apply/ok. This will remove all
restore points, however you don't want them back as some or all of them will
contain the virus depending upon how recently you got infected.

Restart the system normally. Go back to the Control Panel/System and restart
System Restore.

Update your antivirus software, run a full system scan.

-- 
Best of Luck,
Rick Rogers, aka "Nutcase" - Microsoft MVP
http://mvp.support.microsoft.com/
Associate Expert - WindowsXP Expert Zone
www.microsoft.com/windowsxp/expertzone
Windows help - www.rickrogers.org
"boab jay" <robert_cassie@hotmail.com> wrote in message 
news:uFAc2b7DFHA.1296@TK2MSFTNGP10.phx.gbl...
>I keep getting a error pop up on my PC which says "adminamok.exe is
> encountering a problem..blah blah please tell microsoft.....This pops up
> every thirty seconds or so and I keep clicking it away with "don`t send".
> I searched for it on my pc and found it in the prefetch folder. I deleted 
> it
> and another similar file but when the pop up comes back so do the files. I
> thought it may be returning from the recycle bin but there were multiple
> copies in the bin. Anyone know how I can get rid of it????
> PS Pop up Time scale is now down to every 15 secs!!!!
>
> 


Relevant Pages

  • Re: LIBVGA.EXE???
    ... Restart in Safe mode by hitting F8 as Windows first begins to load on boot. ... Look in the right hand pane for the string or strings that load that file. ... off system restore on all drives". ...
    (microsoft.public.windowsxp.general)
  • Re: obqhs.exe
    ... Restart in Safe mode by hitting F8 as Windows first begins to load on boot. ... Look in the right hand pane for the string or strings that load that file. ... off system restore on all drives". ...
    (microsoft.public.windowsxp.general)
  • Re: jrjptru.exe
    ... Restart in Safe mode by hitting F8 as Windows first begins to load on boot. ... Look in the right hand pane for the string or strings that load that file. ... off system restore on all drives". ...
    (microsoft.public.windowsxp.general)
  • Re: Msconfig Startup list unusual item
    ... Restart in Safe mode by hitting F8 as Windows first begins to load on boot. ... Look in the right hand pane for the string or strings that load that file. ... off system restore on all drives". ...
    (microsoft.public.windowsxp.general)
  • Re: Ipey32.exe error, what is it
    ... Restart in Safe mode by hitting F8 as Windows first begins to load on boot. ... Look in the right hand pane for the string or strings that load that file. ... off system restore on all drives". ...
    (microsoft.public.windowsxp.newusers)