Last week I installed the software Antiporn! While i was installing, i didn't get any installation process and i thougt there appeared some erro or sth and I throwed the installation file in the trash!

Afterwards I noticed that it has cearly been installed but not in the c:\program~ directory but in the C:\Documents and Settings\Sems\Local Settings\Temp\IXP000.TMP. There I clicked the uninstall file and I installed it, but...

When I restart I see that it's installed again. In the task manager i noticed that the process eaglesvr doensn't show up, while it's actually running and it makes my system really slow.

Now I use Security task Manager with to take process eaglesvr in quarantine to stop it, but I see that in this case the program is installed in C:\Documents and Settings\...\Temp\IXP001.TMP and so in ........IXP002.TMP in the next restart.

I tried different programs to uninstall it but nothing positive happens!


Please help me out of this shit program!

btw, i use McAfee 2007 Suite as protection program but it doesn't give any sign of danger because of this eaglesvr shit!


Please..........

Dani AI

Generated

As described, the Antiporn dropper is extracting itself into Internet Explorer temp folders (IXP000.TMP, IXP001.TMP) and recreating a new copy with each boot; 's suggestion to clear temp files is a good first step but won't stop whatever is re-launching the file on startup. The usual cause is a persistent autorun entry, service or scheduled task that points to the temp copy, so removal requires both killing the running component and deleting the persistence points.

A practical, ordered cleanup (do these from Safe Mode when possible):

  1. Boot Safe Mode (F8).
  2. Stop the running malware with a process-killer tool so scanners can work (RKill-style tools or Process Explorer).
  3. Run a current on-demand scanner (Malwarebytes or another second-opinion scanner) and remove detections.
  4. Use Sysinternals Autoruns (or msconfig) to find and disable any entries that reference eaglesvr or IXP*.TMP. Check these registry locations for suspicious entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
  1. Remove matching files from the Temp folders (the IXP*.TMP directories) and delete any scheduled tasks that reference the file. Empty Temporary Internet Files and the Recycle Bin.

Back up the registry before editing and make or note a System Restore point; after cleanup, disable and then re-enable System Restore (or delete old restore points) so an infected restore snapshot cannot reinfect the system. If the process still respawns, consider an offline rescue/CD scanner or full reinstall—persistent droppers sometimes hide in drivers or sealed restore points. Note that single AV products (McAfee in this case) can miss rogues; use multiple reputable scanners and manual inspection (Autoruns/HijackThis logs) for verification.

Recommended Answers

All 3 Replies

Thanks a lot, man! But It did not help! I'm gonna drive crazy because of that! I don't know anymore what to do!

This program reinstall self again with each restart, no matter what i do to remove it!


pleaaaseeeeeeeeeeeeeeeeeeeeeeeeeee help me!

you need to go to our spyware and other nasties section and follow instructings to posting there at the top of page when you get there ,use this link .
http://www.daniweb.com/forums/forum64.html

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.