What could this program be?

Discussion in 'Malware Help (A Specialist Will Reply)' started by claptrap, Feb 13, 2011.

  1. claptrap

    claptrap Private First Class

    My firewall has been asking me regularly about this program, should I allow it run or not:

    [FONT=&quot]S24EvMon.exe could not be recognised and it is about to modify the protected registry key HKLM/SYSTEM/ControlSet001/Control/Class/{4D36E972-E325-11CE-BFC1-08002bE10318}/0012/Application/AdapterHWRadioState. You must make sure S24EvMon.exe is a safe application before allowing this request.

    So far I have blocked it, without asking it to remember my answer (just in case it is legitimate). It is then followed by few other requests to modify the registry key, all linked to S24EvMon.exe. Sadly, I don't have the information of those requests as when I finally have the time and internet connection my firewall stops reporting them. Perhaps I ticked the remember my answer by accident?

    I am also worried that the virus I had in my flash drive [/FONT][FONT=&quot](win32 I think, or something like that) [/FONT][FONT=&quot]has infected my machine when I opened the files in Win Word 2000. The virus came originally from a hacked Windows XP that was so badly infected it needed a complete re-install - but whoever installed the copy into my boss' machine, used the same, infected copy.

    I have XP 2005 media edition and I have noticed that my machine is getting slower by day, and I worry it's not just because my HDD is getting rather full, with just over 7GB left. (I run CCleaner regularly and occasionally Tune Up Utilities 2007)

    I have run Hijack this and by quick look there are things I don't recognise - but then there are so many programs in my machine I practically never use these days; I just keep them because I don't have an installation disks any more so if I wanted to use them again...

    Also, I see a reference to Spybot Search and Destroy, which I am desperate to get rid of but can't by usual means. How can I use Hijack this to remove it - or is it safe? I mean, are any of the files used by other programs or something like that?
    [/FONT]
     
  2. claptrap

    claptrap Private First Class

    I just remembered, I downloaded a new version of AVG and also bought a new mobile broadband modem around the same time... Could S2EvMon.exe be related to these programs? (I did also surf a lot at the time, having suffered from lack of connection for a LONG time.)
     
  3. claptrap

    claptrap Private First Class

    Here is the Hijack this log, silly me, I forgot - me thinks I'm getting old.

    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 16:23:59, on 13/02/2011
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Edit by chaslang: Inline HJT log removed. READ & RUN ME FIRST. Malware Removal Guide sticky not followed.
     
    Last edited by a moderator: Feb 13, 2011
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    s24evmon.exe is an application that gives access to your wireless network interface devices configurations and diagnostics. The full name is IntelĀ® PROSet/Wireless Service. It is not a problem and you should not be blocking it.

    If you had or have malware problems, a HijackThis log is not good enough for us to provide you proper support. Thus if you wish to properly check your PC ( and I advise you to do so based on a couple observations in the limited HJT log ) then follow the instructions in the below:

    READ & RUN ME FIRST. Malware Removal Guide
     
  5. claptrap

    claptrap Private First Class

    Fair enough. My main worry is infecting other computers when opening files created in mine.. but I won't have enough hours to go through all the steps until Easter - so I was hoping Hijack would show if there is something AVG might have missed.

    When I have time to go through the steps in Malware Removal Guide, I hope I can get rid of Spybot Search & Destroy at the same time.

    Thanks for the quick reply.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    HijackThis is not an antivirus nor an antispyware program and is very limited in what it shows which is basically just an extremely small subset of registry keys and a currently running process list and most of the time what is being shown are normal. HijackThis does not make any statement about whether items being shown are good/bad or normal/abnormal Basically with the state of malware these days, a HijackThis log alone is almost useless which is why our sticky threads state not to post them. ;)

    Spybot can just be uninstalled anytime you wish by using Add/Remove Programs.


    Do note that if you have infections, the longer you wait the worse it can get. And if you have any serious infections, you could be having personal data stolen. It is not a good idea to wait ( especially several months ) and allow an infection to do what it wants. The time spent now could be a lot less than you would have to spend later if serious malware is present.
     
  7. claptrap

    claptrap Private First Class

    "Do note that if you have infections, the longer you wait the worse it can get."

    I do understand the problem but I just don't have the time at the moment - I go to work at 7 am and I finish at 7.30 pm earliest (often at midnight) and then I'll have to start cooking, maybe go to market first... Which is why I was hoping that someone might spot a rogue file and tell me what to to. I fear I might have told AVG to ignore malware in certain files, to avoid them being deleted entirely - the last time AVG did this, it made my flash drive useless and I lost all the data in it: the malware had attached itself to some essential system file and could not be deleted without destroying the file. None of the virus checkers could quarantine the virus.

    "Spybot can just be uninstalled anytime you wish by using Add/Remove Programs."

    This is where the problem lies: with some files being corrupted from the start Spybot never installed properly, none of my utility programs could get rid of it any better than windows Add/Remove facility, and It keeps popping up sort of times and I'm afraid it is eating my precious memory, at best of times. In any case, it all adds to the junk in my HDD, which is already struggling under the weight of a full drive,
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can either try reinstalling the same version and then uninstall it or you can try using the below tool to remove it

    Revo Uninstaller
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds