<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: How do I tell what program inserted a registry entry?</title>
	<link>http://ask.metafilter.com/8796/How-do-I-tell-what-program-inserted-a-registry-entry/</link>
	<description>Comments on Ask MetaFilter post How do I tell what program inserted a registry entry?</description>
	<pubDate>Sun, 18 Jul 2004 07:20:51 -0800</pubDate>
	<lastBuildDate>Sun, 18 Jul 2004 07:20:51 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>Question: How do I tell what program inserted a registry entry?</title>
		<link>http://ask.metafilter.com/8796/How-do-I-tell-what-program-inserted-a-registry-entry</link>	
		<description>PCFilter : Is there any way to tell what program inserted something into the registry?&lt;br&gt;
&lt;small&gt;I&apos;ve been attacked by four seperate virii that sophos claims don&apos;t exist in the wild. One of them (netclnc.exe) keeps reappearing in my registry and the system32, and I want to know what&apos;s putting it there so I can kill it. Ideas?&lt;/small&gt;</description>
		<guid isPermaLink="false">post:ask.metafilter.com,2004:site.8796</guid>
		<pubDate>Sun, 18 Jul 2004 07:05:52 -0800</pubDate>
		<dc:creator>twine42</dc:creator>
		
			<category>windows</category>
		
			<category>windowsxp</category>
		
			<category>registry</category>
		
			<category>windowsregistry</category>
		
			<category>registrycleaner</category>
		
			<category>virus</category>
		
			<category>viruses</category>
		
			<category>virii</category>
		
			<category>trojans</category>
		
			<category>system32</category>
		
			<category>microsoft</category>
		
	</item> <item>
		<title>By: triv</title>
		<link>http://ask.metafilter.com/8796/How-do-I-tell-what-program-inserted-a-registry-entry#167578</link>	
		<description>hi, after a quick google check, i came up with &lt;a href=&quot;http://www.viruslist.com/eng/?id=1614140&amp;forum=1&amp;repl=1857520&quot;&gt;this&lt;/a&gt;, which seems to be a solution to your problem. i hope.&lt;br&gt;
&lt;br&gt;
if all else fails - hijack this.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.8796-167578</guid>
		<pubDate>Sun, 18 Jul 2004 07:20:51 -0800</pubDate>
		<dc:creator>triv</dc:creator>
	</item><item>
		<title>By: ed\26h</title>
		<link>http://ask.metafilter.com/8796/How-do-I-tell-what-program-inserted-a-registry-entry#167579</link>	
		<description>&lt;a href=&quot;http://www.sysinternals.com/ntw2k/source/regmon.shtml&quot;&gt;RegMon&lt;/a&gt; will do too.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.8796-167579</guid>
		<pubDate>Sun, 18 Jul 2004 07:34:55 -0800</pubDate>
		<dc:creator>ed\26h</dc:creator>
	</item><item>
		<title>By: twine42</title>
		<link>http://ask.metafilter.com/8796/How-do-I-tell-what-program-inserted-a-registry-entry#167580</link>	
		<description>I&apos;ll check out RegMon.&lt;br&gt;
&lt;br&gt;
I&apos;ve seen that page for netclnc, and done as instructed several times now, but the bastard comes back. I think it reappears after a reboot, but I don&apos;t think it&apos;s starting the process on startup, which is annoying me somewhat. I&apos;m not sure if something is reinfecting me (inwhichcase it must be either Felix or Viktoria (pcs)) or it&apos;s smarter than people think and it&apos;s reinfecting itself.&lt;br&gt;
&lt;br&gt;
My firewall is healthy enough to annoy my ISP when they&apos;re pinging me, so I assume it&apos;s not coming in that way...</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.8796-167580</guid>
		<pubDate>Sun, 18 Jul 2004 07:45:05 -0800</pubDate>
		<dc:creator>twine42</dc:creator>
	</item><item>
		<title>By: twine42</title>
		<link>http://ask.metafilter.com/8796/How-do-I-tell-what-program-inserted-a-registry-entry#167582</link>	
		<description>missed out a thanks in there. *sigh*&lt;br&gt;
&lt;br&gt;
Also, how did you find that? My googling returned so much noise I couldn&apos;t find anything worthwhile.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.8796-167582</guid>
		<pubDate>Sun, 18 Jul 2004 07:54:04 -0800</pubDate>
		<dc:creator>twine42</dc:creator>
	</item><item>
		<title>By: Daddio</title>
		<link>http://ask.metafilter.com/8796/How-do-I-tell-what-program-inserted-a-registry-entry#167586</link>	
		<description>twine42: Please &lt;strong&gt;do&lt;/strong&gt; let us know when you figure it out. It sounds nasty....</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.8796-167586</guid>
		<pubDate>Sun, 18 Jul 2004 08:07:52 -0800</pubDate>
		<dc:creator>Daddio</dc:creator>
	</item><item>
		<title>By: twine42</title>
		<link>http://ask.metafilter.com/8796/How-do-I-tell-what-program-inserted-a-registry-entry#167594</link>	
		<description>&lt;small&gt;For Daddio, in case I forget, the files I eradicated so far are...&lt;br&gt;
&lt;br&gt;
ifa32.exe and wingx32.exe -  (W32/Rbot-BU) - one and the same virus it appears. Kill one and the other respawns it, kill both and they die. Sophos claims one copy in the wild but ignored my offer to email them a copy. ;)&lt;br&gt;
&lt;br&gt;
netclnc.exe - the one that kept respawning. No word I can find from any of the anti-virus companies. It seems to be opening up lots of ports and wrecking my net connection.&lt;br&gt;
&lt;br&gt;
csmss.exe - (Troj/Dedler-D) -  this one infected my own personal laptop. It travels by ICQ (which I don&apos;t have). Again, Sophos has just one report of it in the wild.&lt;br&gt;
&lt;br&gt;
I don&apos;t understand how these virii got us, considering we&apos;re firewalled, use Thunderbird and Fire(fox|bird), don&apos;t use p2p. The first seems to be a worm, so it&apos;s possible it snuck in and gave us the rest, but it&apos;s not returned to do the job again, so...&lt;br&gt;
&lt;br&gt;
I&apos;ll keep you guys informed though.&lt;/small&gt;</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.8796-167594</guid>
		<pubDate>Sun, 18 Jul 2004 08:36:21 -0800</pubDate>
		<dc:creator>twine42</dc:creator>
	</item><item>
		<title>By: jmd82</title>
		<link>http://ask.metafilter.com/8796/How-do-I-tell-what-program-inserted-a-registry-entry#167613</link>	
		<description>Also be warry of unkown virsuses inserting themselves into one of the startup *.ini files.  This happened to me a few years back and the virus propogation name was command.exe- not to be confused with command.com.  That bastardly program would run on startup through one of the ini files and managed to reinstall the virus program and prevented deletion except by some trickery on my part (namely restarting the computer in DOS mode so the command.exe file wouldn&apos;t start and delete the file.  Then, when windows started, I got one of those &quot;cannot find command.exe file&quot; messages and I figured out where the launching command was from there).  For whatever reason, I&apos;ve found regular virus programs suck at finding those type of viruses.&lt;br&gt;
Another roundabout trick I&apos;ve learned is use Administartive Tools.  I forget which program to use, but its the one that holds all the regular windows processes.  Sometimes a program/virus will insert itself into this either under a regular windows process such as messaging- ripe for annoying spyware- or create a completely new one.  You can usually right-click on the process to see its startup path.  You can disable its startup from the given tool, too.&lt;br&gt;
&lt;br&gt;
I have no idea if that&apos;ll help, but good luck!</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.8796-167613</guid>
		<pubDate>Sun, 18 Jul 2004 09:58:11 -0800</pubDate>
		<dc:creator>jmd82</dc:creator>
	</item><item>
		<title>By: baylink</title>
		<link>http://ask.metafilter.com/8796/How-do-I-tell-what-program-inserted-a-registry-entry#167624</link>	
		<description>Spybot 1.3 will install teatimer.exe, a realtime registry modification monitor.  I *think* it tells you what&apos;s doing the modification, but I&apos;m not positive.&lt;br&gt;
&lt;br&gt;
FYI, folks: that&apos;s what teatimer is, should you run across it in a task list.  ;-)</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.8796-167624</guid>
		<pubDate>Sun, 18 Jul 2004 11:01:08 -0800</pubDate>
		<dc:creator>baylink</dc:creator>
	</item><item>
		<title>By: jmd82</title>
		<link>http://ask.metafilter.com/8796/How-do-I-tell-what-program-inserted-a-registry-entry#167633</link>	
		<description>On a side note, using XP, does anyone know how to end those processees Windows won&apos;t let you end or delete files that won&apos;t let themselves be deleted?</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.8796-167633</guid>
		<pubDate>Sun, 18 Jul 2004 12:03:40 -0800</pubDate>
		<dc:creator>jmd82</dc:creator>
	</item><item>
		<title>By: andrew cooke</title>
		<link>http://ask.metafilter.com/8796/How-do-I-tell-what-program-inserted-a-registry-entry#167652</link>	
		<description>ms office?  a user bringing in floppies?  (for the source).</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.8796-167652</guid>
		<pubDate>Sun, 18 Jul 2004 13:20:13 -0800</pubDate>
		<dc:creator>andrew cooke</dc:creator>
	</item><item>
		<title>By: punilux</title>
		<link>http://ask.metafilter.com/8796/How-do-I-tell-what-program-inserted-a-registry-entry#167658</link>	
		<description>jmd82: Previously mentioned on here, &lt;a href=&quot;http://www.sysinternals.com/ntw2k/freeware/procexp.shtml&quot;&gt;Process Explorer&lt;/a&gt; is the bee&apos;s.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.8796-167658</guid>
		<pubDate>Sun, 18 Jul 2004 14:13:50 -0800</pubDate>
		<dc:creator>punilux</dc:creator>
	</item><item>
		<title>By: twine42</title>
		<link>http://ask.metafilter.com/8796/How-do-I-tell-what-program-inserted-a-registry-entry#167673</link>	
		<description>ansdrew: users would be myself or my wife, I don&apos;t use floppies and she shuns Office. ;)&lt;br&gt;
&lt;br&gt;
I&apos;m seriously at a loss here. Our only contact with the world is via the Internet. God that sounds pathetic. You know what I mean.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.8796-167673</guid>
		<pubDate>Sun, 18 Jul 2004 15:21:17 -0800</pubDate>
		<dc:creator>twine42</dc:creator>
	</item><item>
		<title>By: jopreacher</title>
		<link>http://ask.metafilter.com/8796/How-do-I-tell-what-program-inserted-a-registry-entry#167703</link>	
		<description>Where exactly are you looking in the registry? &lt;br&gt;
&lt;br&gt;
H_KEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\run ?&lt;br&gt;
runServices?&lt;br&gt;
&lt;br&gt;
HijackThis is good stuff...</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.8796-167703</guid>
		<pubDate>Sun, 18 Jul 2004 18:08:22 -0800</pubDate>
		<dc:creator>jopreacher</dc:creator>
	</item><item>
		<title>By: twine42</title>
		<link>http://ask.metafilter.com/8796/How-do-I-tell-what-program-inserted-a-registry-entry#167758</link>	
		<description>I&apos;m searching the reg in general, but yeah, that was one of the main area things seemed to appear. That and the user specific areas f the reg.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.8796-167758</guid>
		<pubDate>Mon, 19 Jul 2004 01:51:19 -0800</pubDate>
		<dc:creator>twine42</dc:creator>
	</item>
	</channel>
</rss>
