To register for an Internet.com membership to receive newsletters and white papers, use the Register button ABOVE.
To participate in the message forums BELOW, click here


Virtual DR   Earthweb  
Events Premium Services Media Kit E-mail Offers Whitepapers Vendor Showcases

Go Back   Virtual Dr Forums-Computer Tech Support > Windows Operating Systems > Windows 95/98/ME

Windows 95/98/ME Discussion and Technical Support for the Windows 95, 98 and Millenium operating systems.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old November 30th, 2001, 05:40 AM
duveyduv duveyduv is offline
Virtual Med Student
 
Join Date: Nov 2001
Location: oceanside,ca,us
Posts: 1
ptsnoop

how can i obtain an updated version of ptsnoop. my computer said it is outdated
Reply With Quote
  #2  
Old November 30th, 2001, 05:54 AM
Spiny's Avatar
Spiny Spiny is offline
Senior Irritant
 
Join Date: May 2001
Location: Somewhere in the UK
Posts: 309
Are you sure you want it?
Some people say it's a trojan, some says it's legitimate and is part of a modem's driver.

The best thing to do is to check for viruses.
__________________
Only dead fish float with the stream.
Reply With Quote
  #3  
Old November 30th, 2001, 05:56 AM
AnnMarie's Avatar
AnnMarie AnnMarie is offline
Deco Annie
 
Join Date: Sep 2001
Location: New Zealand
Posts: 2,869
Hi duveyduv - Welcome to the VirtualDr Forum. I really dont think you want one - see link ptsnoop. Follow the instructions and delete all relevant files.
__________________
Microsoft MVP Windows - Shell/User
Reply With Quote
  #4  
Old November 30th, 2001, 06:09 AM
Spiny's Avatar
Spiny Spiny is offline
Senior Irritant
 
Join Date: May 2001
Location: Somewhere in the UK
Posts: 309
Educated guess:
There is a legitimate ptsnoop and a trojan with the same name.

PCTel modems install the legitimate one, but it can be removed without wrecking anything.

The point is:
KILL IT!

It won't hurt and it might help.
__________________
Only dead fish float with the stream.
Reply With Quote
  #5  
Old November 30th, 2001, 06:30 AM
AnnMarie's Avatar
AnnMarie AnnMarie is offline
Deco Annie
 
Join Date: Sep 2001
Location: New Zealand
Posts: 2,869
hmmm. Spiny, you are right. It looks like the Anti Virus folk cannot work this one out. From Symantec:
"PTSNOOP is a token program that waits for a program to request the COM port to be opened. Then it makes sure that the modem drivers get loaded if they are not.

PTSNOOP can be found with several different modems, such as the MICOM HSP PCTEL and EPS Technology COMM WAVE PCMCIA modems. It is not mandatory for proper operation, and the manufacturers list removal of PTSNOOP in various steps of their troubleshooting procedures."




[This message has been edited by AnnMarie (edited 11-30-2001).]
__________________
Microsoft MVP Windows - Shell/User
Reply With Quote
  #6  
Old November 30th, 2001, 06:32 AM
Spiny's Avatar
Spiny Spiny is offline
Senior Irritant
 
Join Date: May 2001
Location: Somewhere in the UK
Posts: 309
On the other hand, Sophos says:

{Troj/Ptsnoop

Infects: Trojan horse
Memory resident: Yes

This is a backdoor Trojan. It copies itself to \windows\system\ptsnoop.exe and changes win.ini adding "c:\windows\system\ptsnoop.exe" to "load = ".

First reported in March 2001.}

I still think you should kill it, just to be sure.

[This message has been edited by Spiny (edited 11-30-2001).]
__________________
Only dead fish float with the stream.
Reply With Quote
  #7  
Old December 1st, 2001, 08:52 AM
nlday nlday is offline
Virtual Intern
 
Join Date: Jun 2001
Location: wi,usa
Posts: 476
is it good enough to remove ptsnoop fron sys config utility-startup tab, and uncheck it? or is there a registry hack needed... i'll 'go in' and do it with a little trepidation and some good directions, or visa/versa.
and is it ok to do in win 98se also?

[This message has been edited by nlday (edited 12-01-2001).]
__________________
the more you make...
the more they take.
Reply With Quote
  #8  
Old December 2nd, 2001, 05:35 AM
AnnMarie's Avatar
AnnMarie AnnMarie is offline
Deco Annie
 
Join Date: Sep 2001
Location: New Zealand
Posts: 2,869
Hi nlday - I found the following instructions on the Driver Forum:

"To Remove ptsnoop (very quick & easy)
1)Click on START,then RUN
2)Type in sysedit,then click OK
3)Click on Win.ini tab/page
4)Look for(it's often listed very first)
load=ptsnoop.exe
run=C:\WINDOWS\SYSTEM\cmmpu.exe
NullPort=None
5)Delete all that,so it shows only the following;
load=
run=
NullPort=None
(simply click and drag over what needs removing,that will "Blue" it/Select it,,then click Backspace)
6)At top of the SysEdit page,click on File & Save.
Restart your 'puter,either now or later,and upon restart ptsnoop will be permanently gone."

Also check the Windows Registry by selecting Start,Run, typing RegEdit, and pressing Enter. NB Always backup your Registry before making any changes.

Navigate to HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run.
If you see a reference to Ptsnoop in the right window, simply highlight that reference and press Delete.Close the Registry. Restart Windows and you're finished.


If you are not confident in doing this, removing it from your startup routine should be sufficient to disable it.



[This message has been edited by AnnMarie (edited 12-02-2001).]
__________________
Microsoft MVP Windows - Shell/User
Reply With Quote
  #9  
Old December 2nd, 2001, 11:40 AM
nlday nlday is offline
Virtual Intern
 
Join Date: Jun 2001
Location: wi,usa
Posts: 476
thanks annmarie and happy monday to ya! i unchecked both ptsnoops on the startup tab, but after reboot, one of them comes back. so i'll follow your directions after i back up the registry.{i've got those directions around here somewhere}...or will it be disabled if only one is unchecked? (i have the hsp pc-tel modem.)
just one more question? is this registry hack the same on win 98se? i'll be doing it on that 'puter also.

[This message has been edited by nlday (edited 12-02-2001).]
__________________
the more you make...
the more they take.
Reply With Quote
  #10  
Old December 2nd, 2001, 07:01 PM
AnnMarie's Avatar
AnnMarie AnnMarie is offline
Deco Annie
 
Join Date: Sep 2001
Location: New Zealand
Posts: 2,869
Hmmm. Dont know why you have two ptsnoops nlday. Maybe it would be better if you ran a Trojan Scanner first before you do anything else. You can download a good free one - Ants v2 English Version from here Wilders. The some of the dialogue is still in German but you can download the translations from here Ants English Translation
__________________
Microsoft MVP Windows - Shell/User
Reply With Quote
  #11  
Old December 2nd, 2001, 07:26 PM
nlday nlday is offline
Virtual Intern
 
Join Date: Jun 2001
Location: wi,usa
Posts: 476
ok heading over there. i've had norton internet security 2001 since feb. not having trouble. but let's take a look.
__________________
the more you make...
the more they take.
Reply With Quote
  #12  
Old December 2nd, 2001, 07:37 PM
nlday nlday is offline
Virtual Intern
 
Join Date: Jun 2001
Location: wi,usa
Posts: 476
annmarie-i find trojan hunter v 2.0 nothing that says 'ants' so is trojan hunter the correct one?
__________________
the more you make...
the more they take.
Reply With Quote
  #13  
Old December 2nd, 2001, 08:08 PM
AnnMarie's Avatar
AnnMarie AnnMarie is offline
Deco Annie
 
Join Date: Sep 2001
Location: New Zealand
Posts: 2,869
Nope - had problems installing that one - it kept reporting a missing file - Ants is on the link below. Most AV's are not that good at picking up trojans nlday, its a good idea to run a dedicated trojan detection program as well as your AV. http://www.wilders.org/downloads.htm
__________________
Microsoft MVP Windows - Shell/User
Reply With Quote
  #14  
Old December 2nd, 2001, 08:41 PM
nlday nlday is offline
Virtual Intern
 
Join Date: Jun 2001
Location: wi,usa
Posts: 476
i found it and dl'd it. ran the scan of c: and then rescanned windows folder...no trojans found. so could it be--the 2 pt snoops-- is from an aborted DL of hsptel modem driver from windows update site. it told me it was available,tried twice but got a tan error box. this was actually on the win 98 puter.... discussion with triple 7...decided to leave well enough alone since modem is working well. then one more? the directions for removing ptsnoop will work on win98se as well? ps this trojan program is very nice-classy!
__________________
the more you make...
the more they take.
Reply With Quote
  #15  
Old December 3rd, 2001, 02:25 AM
AnnMarie's Avatar
AnnMarie AnnMarie is offline
Deco Annie
 
Join Date: Sep 2001
Location: New Zealand
Posts: 2,869
Hi again nlday - sorry, had to dash off to work and didnt see your last post. If you decide to remove PTSNOOP, I have posted this link which gives you full information on editing your registry Win98/ME Editing The Windows Registry. I guess I have a reservation in view of the conflicting reports on PTSNOOP. Like Triple 7's, I think if its working well, its best to leave it alone. Yes Ants is a great program, I'm pleased that you like it however neither Nav or Ants detected PTSNOOP as a trojan, so it may have been misdiagnosed.
__________________
Microsoft MVP Windows - Shell/User
Reply With Quote
Reply

Bookmarks
Go Back   Virtual Dr Forums-Computer Tech Support > Windows Operating Systems > Windows 95/98/ME



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 09:31 AM.









Acceptable Use Policy


The Network for Technology Professionals

Search:

About Internet.com

Legal Notices, Licensing, Permissions, Privacy Policy.
Advertise | Newsletters | E-mail Offers

Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.