View Single Post
  #1 (permalink)  
Old 10-07-2004, 02:13 PM
imotic imotic is offline
Junior Member
 

Join Date: Oct 2004
Location: USA.
Posts: 4
imotic is on a distinguished road (10)
Send a message via AIM to imotic
I think I have an AIM virus?

Recently I tried installing an old version of AIM (5.5.3572) as well as DeadAIM 4.5, which I downloaded from www.aimthings.com . The DeadAIM process complained about a missing or invalid file "comdlg32.ocx". After that, when I would run AIM, AIM would run invisibly, without a Sign On dialog popping up. Instead, I could see the process running in the Task Manager (in the Processes tab, not in the Applications tab), but I couldn't see it running anywhere else.

Before all of this happened, I could successfully run the new version of AIM (5.9) on this laptop. Now, no amount of uninstalling, reinstalling, re-downloading or deleting items in the registry that pertain to "AIM" will make this work.

This is a brand new laptop, I just got it on Monday. I installed McAfee virus scanner and AdAware after this whole thing happened, they detect nothing.

After this happened, I tried installing again while running Ethereal, a packet sniffer. I don't see anything too crazy when running the AIM install... I see a lot of requests being sent to the WildTangent website, but I expect that seeing as how AIM uses WildTangent for its games stuff.

The really weird thing, however, is that when AIM is running, I see things like "Offgoing Buddy: Schleve23" and "Oncoming Buddy: MESoRb82". Neither of those two users are on my buddy list.

I looked into comdlg32.ocx... the last modified date is last monday, right around when I upgraded to XP SP2, and the version is "6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)". The version on my desktop machine (which works fine) is "6.00.8418" with a last-modified date of 1999... and that's running WinXP SP2 as well. This could be because I'm running Windows XP Tablet edition on my laptop, though.

I'm thinking that something is fishy.
Reply With Quote