Cheat Engine Forum Index Cheat Engine
The Official Site of Cheat Engine
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 


is DAT297B.tmp.exe system process
Goto page 1, 2, 3  Next
 
Post new topic   Reply to topic    Cheat Engine Forum Index -> Computer Talk
View previous topic :: View next topic  
Author Message
paupav
Master Cheater
Reputation: 13

Joined: 15 Apr 2011
Posts: 314
Location: P. Sherman 42, Wallaby Way, Sydney

PostPosted: Sat Jul 14, 2012 8:15 am    Post subject: is DAT297B.tmp.exe system process Reply with quote

because i noticed it is running and uses a lot of ram and lot of processor...
P.S im using win 7
Back to top
View user's profile Send private message
Dark Byte
Site Admin
Reputation: 471

Joined: 09 May 2003
Posts: 25832
Location: The netherlands

PostPosted: Sat Jul 14, 2012 8:22 am    Post subject: Reply with quote

it's most likely a backdoor trojan or adware
_________________
Do not ask me about online cheats. I don't know any and wont help finding them.

Like my help? Join me on Patreon so i can keep helping
Back to top
View user's profile Send private message MSN Messenger
paupav
Master Cheater
Reputation: 13

Joined: 15 Apr 2011
Posts: 314
Location: P. Sherman 42, Wallaby Way, Sydney

PostPosted: Sat Jul 14, 2012 11:13 am    Post subject: Reply with quote

:O ok, thanks. My pc is verry slow and i cant run any flash..
Back to top
View user's profile Send private message
SF
I'm a spammer
Reputation: 119

Joined: 19 Mar 2007
Posts: 6028

PostPosted: Sat Jul 14, 2012 12:32 pm    Post subject: Reply with quote

You should consider just formatting it.
Oh, and change your passwords to sites you access (Use another PC to do this!)

_________________
Back to top
View user's profile Send private message
Hero
I'm a spammer
Reputation: 79

Joined: 16 Sep 2006
Posts: 7154

PostPosted: Sat Jul 14, 2012 12:34 pm    Post subject: Reply with quote

Its funny that this thread is one of the only 3 results on google for this virus. Just reformat like SF said, its not worth it. Considering it seems like it is unheard of.
Back to top
View user's profile Send private message
paupav
Master Cheater
Reputation: 13

Joined: 15 Apr 2011
Posts: 314
Location: P. Sherman 42, Wallaby Way, Sydney

PostPosted: Sat Jul 14, 2012 3:04 pm    Post subject: Reply with quote

SF wrote:
You should consider just formatting it.
Oh, and change your passwords to sites you access (Use another PC to do this!)

How do you mean format... format virus lol? I wont format my hard drive. Any alternative solution?
Back to top
View user's profile Send private message
SF
I'm a spammer
Reputation: 119

Joined: 19 Mar 2007
Posts: 6028

PostPosted: Sat Jul 14, 2012 10:57 pm    Post subject: Reply with quote

paupav wrote:
SF wrote:
You should consider just formatting it.
Oh, and change your passwords to sites you access (Use another PC to do this!)

How do you mean format... format virus lol? I wont format my hard drive. Any alternative solution?


manually remove the source of the infection and any files infected?

_________________
Back to top
View user's profile Send private message
paupav
Master Cheater
Reputation: 13

Joined: 15 Apr 2011
Posts: 314
Location: P. Sherman 42, Wallaby Way, Sydney

PostPosted: Sun Jul 15, 2012 7:59 am    Post subject: Reply with quote

SF wrote:
paupav wrote:
SF wrote:
You should consider just formatting it.
Oh, and change your passwords to sites you access (Use another PC to do this!)

How do you mean format... format virus lol? I wont format my hard drive. Any alternative solution?


manually remove the source of the infection and any files infected?

How can i know witch files are infected?
Back to top
View user's profile Send private message
Gniarf
Grandmaster Cheater Supreme
Reputation: 43

Joined: 12 Mar 2012
Posts: 1285

PostPosted: Sun Jul 15, 2012 9:31 am    Post subject: This post has 1 review(s) Reply with quote

To be useful to an attacker, an infected file has to be executed even after rebooting, preferably without you noticing it.

In windows registry, check every Run/RunOnce key and look of odd stuff (files with a randomly generated name, names containing tmp,.bat,.com, extensions that are unusual for executables...).
Also check C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup and C:\users\%username%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup for similar stuff.

And there is also the possibility that it crazily infected all your .exe files to be sure to be executed. Haven't seen such a virus in 7 years, so dump that as very unlikely and forget it, or run an AV scan if it reassures you.


Last edited by Gniarf on Sun Jul 15, 2012 7:25 pm; edited 1 time in total
Back to top
View user's profile Send private message
paupav
Master Cheater
Reputation: 13

Joined: 15 Apr 2011
Posts: 314
Location: P. Sherman 42, Wallaby Way, Sydney

PostPosted: Sun Jul 15, 2012 1:52 pm    Post subject: Reply with quote

Gniarf wrote:
To be useful to an attacker, an infected file has to be executed even after rebooting, preferably without you noticing it.

In windows registry, check every Run/RunOnce key and look of odd stuff (files with a randomly generated name, names containing tmp,.bat,.com, extensions that are unusual for executables...).
Also check C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup and C:\users\%username%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup for similar stuff.

And there is also the possibility that is crazily infected all your .exe files to be sure to be executed. Haven't seen such a virus in 7 years, so dump that as very unlikely and forget it, or run an AV scan if it reassures you.


im not sure but this is only 1 that doesnt seems legit

P.S why is here registry of uninstalled apps
Back to top
View user's profile Send private message
Gniarf
Grandmaster Cheater Supreme
Reputation: 43

Joined: 12 Mar 2012
Posts: 1285

PostPosted: Sun Jul 15, 2012 3:02 pm    Post subject: Reply with quote

-Datamngr is an adware, remove it. I recommend using Hijackthis and check what they describe here
-facemood. I ain't a fecebook user so idk if you use that one. If you don't wipe this away.
-Imminent.Notifier: dunno if you really wanted it installed, but it can be removed through add/remove programs.
-SweetIM: same as above.

As to why there are remnants of applications you deleted, well, uninstallers are not very thorough. All that matters to guys who write crapbars like sweetIM is that you INSTALL their poop. They don't give a damn about removal.
Normally a CCleaner run should fix that anyway.

Also beware that there are several "Run" keys you should inspect (I had a funny freak once in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run).
If you don't find a reference to "DAT297B.tmp.exe" somewhere, we've got a problem.
Back to top
View user's profile Send private message
paupav
Master Cheater
Reputation: 13

Joined: 15 Apr 2011
Posts: 314
Location: P. Sherman 42, Wallaby Way, Sydney

PostPosted: Sun Jul 15, 2012 3:44 pm    Post subject: Reply with quote

Gniarf wrote:
-Datamngr is an adware, remove it. I recommend using Hijackthis and check what they describe here
-facemood. I ain't a fecebook user so idk if you use that one. If you don't wipe this away.
-Imminent.Notifier: dunno if you really wanted it installed, but it can be removed through add/remove programs.
-SweetIM: same as above.

As to why there are remnants of applications you deleted, well, uninstallers are not very thorough. All that matters to guys who write crapbars like sweetIM is that you INSTALL their poop. They don't give a damn about removal.
Normally a CCleaner run should fix that anyway.

Also beware that there are several "Run" keys you should inspect (I had a funny freak once in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run).
If you don't find a reference to "DAT297B.tmp.exe" somewhere, we've got a problem.


i did it... is searchsetting system process?
Back to top
View user's profile Send private message
Gniarf
Grandmaster Cheater Supreme
Reputation: 43

Joined: 12 Mar 2012
Posts: 1285

PostPosted: Sun Jul 15, 2012 3:53 pm    Post subject: This post has 1 review(s) Reply with quote

Whoops, no it ain't http://www.spigot.com/remove-search-settings.html .

But I want a clear answer to that question: did you find a reference to "DAT297B.tmp.exe" in your registry?
Back to top
View user's profile Send private message
paupav
Master Cheater
Reputation: 13

Joined: 15 Apr 2011
Posts: 314
Location: P. Sherman 42, Wallaby Way, Sydney

PostPosted: Mon Jul 16, 2012 4:19 am    Post subject: Reply with quote

Gniarf wrote:
Whoops, no it ain't http://www.spigot.com/remove-search-settings.html .

But I want a clear answer to that question: did you find a reference to "DAT297B.tmp.exe" in your registry?

just found it ... Very Happy
Back to top
View user's profile Send private message
valent89
Newbie cheater
Reputation: 0

Joined: 12 Jul 2012
Posts: 17

PostPosted: Mon Jul 16, 2012 6:37 am    Post subject: Reply with quote

Just format the danm PC. It's less effort to do so after all this. The Windows 7 Key is legit? That's fine too. Now you can download a legit Windows 7 with any version, have to be same as yours of cause, as long as you checked and knew your W7 Genuine Key. Use 'KeyFinder' for that. Use 'Windows 7 USB DVD Download Tool' to burn it into your USB (preferably new one and format it into NTCS first) or DVD for the installation after format. Backup all your personal files: Musics, Videos, Pictures, etc...
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Cheat Engine Forum Index -> Computer Talk All times are GMT - 6 Hours
Goto page 1, 2, 3  Next
Page 1 of 3

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group

CE Wiki   IRC (#CEF)   Twitter
Third party websites