| Windows 95/98/ME Discussion and Technical Support for the Windows 95, 98 and Millenium operating systems. |

November 30th, 2001, 05:40 AM
|
|
Virtual Med Student
|
|
Join Date: Nov 2001
Location: oceanside,ca,us
Posts: 1
|
|
|
ptsnoop
how can i obtain an updated version of ptsnoop. my computer said it is outdated
|

November 30th, 2001, 05:54 AM
|
 |
Senior Irritant
|
|
Join Date: May 2001
Location: Somewhere in the UK
Posts: 309
|
|
|
Are you sure you want it?
Some people say it's a trojan, some says it's legitimate and is part of a modem's driver.
The best thing to do is to check for viruses.
__________________
Only dead fish float with the stream.
|

November 30th, 2001, 05:56 AM
|
 |
Deco Annie
|
|
Join Date: Sep 2001
Location: New Zealand
Posts: 2,869
|
|
Hi duveyduv - Welcome to the VirtualDr Forum. I really dont think you want one - see link ptsnoop. Follow the instructions and delete all relevant files.
__________________
Microsoft MVP Windows - Shell/User
|

November 30th, 2001, 06:09 AM
|
 |
Senior Irritant
|
|
Join Date: May 2001
Location: Somewhere in the UK
Posts: 309
|
|
|
Educated guess:
There is a legitimate ptsnoop and a trojan with the same name.
PCTel modems install the legitimate one, but it can be removed without wrecking anything.
The point is:
KILL IT!
It won't hurt and it might help.
__________________
Only dead fish float with the stream.
|

November 30th, 2001, 06:30 AM
|
 |
Deco Annie
|
|
Join Date: Sep 2001
Location: New Zealand
Posts: 2,869
|
|
|
hmmm. Spiny, you are right. It looks like the Anti Virus folk cannot work this one out. From Symantec:
"PTSNOOP is a token program that waits for a program to request the COM port to be opened. Then it makes sure that the modem drivers get loaded if they are not.
PTSNOOP can be found with several different modems, such as the MICOM HSP PCTEL and EPS Technology COMM WAVE PCMCIA modems. It is not mandatory for proper operation, and the manufacturers list removal of PTSNOOP in various steps of their troubleshooting procedures."
[This message has been edited by AnnMarie (edited 11-30-2001).]
__________________
Microsoft MVP Windows - Shell/User
|

November 30th, 2001, 06:32 AM
|
 |
Senior Irritant
|
|
Join Date: May 2001
Location: Somewhere in the UK
Posts: 309
|
|
|
On the other hand, Sophos says:
{Troj/Ptsnoop
Infects: Trojan horse
Memory resident: Yes
This is a backdoor Trojan. It copies itself to \windows\system\ptsnoop.exe and changes win.ini adding "c:\windows\system\ptsnoop.exe" to "load = ".
First reported in March 2001.}
I still think you should kill it, just to be sure.
[This message has been edited by Spiny (edited 11-30-2001).]
__________________
Only dead fish float with the stream.
|

December 1st, 2001, 08:52 AM
|
|
Virtual Intern
|
|
Join Date: Jun 2001
Location: wi,usa
Posts: 476
|
|
|
is it good enough to remove ptsnoop fron sys config utility-startup tab, and uncheck it? or is there a registry hack needed... i'll 'go in' and do it with a little trepidation and some good directions, or visa/versa.
and is it ok to do in win 98se also?
[This message has been edited by nlday (edited 12-01-2001).]
__________________
the more you make...
the more they take.
|

December 2nd, 2001, 05:35 AM
|
 |
Deco Annie
|
|
Join Date: Sep 2001
Location: New Zealand
Posts: 2,869
|
|
|
Hi nlday - I found the following instructions on the Driver Forum:
"To Remove ptsnoop (very quick & easy)
1)Click on START,then RUN
2)Type in sysedit,then click OK
3)Click on Win.ini tab/page
4)Look for(it's often listed very first)
load=ptsnoop.exe
run=C:\WINDOWS\SYSTEM\cmmpu.exe
NullPort=None
5)Delete all that,so it shows only the following;
load=
run=
NullPort=None
(simply click and drag over what needs removing,that will "Blue" it/Select it,,then click Backspace)
6)At top of the SysEdit page,click on File & Save.
Restart your 'puter,either now or later,and upon restart ptsnoop will be permanently gone."
Also check the Windows Registry by selecting Start,Run, typing RegEdit, and pressing Enter. NB Always backup your Registry before making any changes.
Navigate to HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run.
If you see a reference to Ptsnoop in the right window, simply highlight that reference and press Delete.Close the Registry. Restart Windows and you're finished.
If you are not confident in doing this, removing it from your startup routine should be sufficient to disable it.
[This message has been edited by AnnMarie (edited 12-02-2001).]
__________________
Microsoft MVP Windows - Shell/User
|

December 2nd, 2001, 11:40 AM
|
|
Virtual Intern
|
|
Join Date: Jun 2001
Location: wi,usa
Posts: 476
|
|
|
thanks annmarie and happy monday to ya! i unchecked both ptsnoops on the startup tab, but after reboot, one of them comes back. so i'll follow your directions after i back up the registry.{i've got those directions around here somewhere}...or will it be disabled if only one is unchecked? (i have the hsp pc-tel modem.)
just one more question? is this registry hack the same on win 98se? i'll be doing it on that 'puter also.
[This message has been edited by nlday (edited 12-02-2001).]
__________________
the more you make...
the more they take.
|

December 2nd, 2001, 07:01 PM
|
 |
Deco Annie
|
|
Join Date: Sep 2001
Location: New Zealand
Posts: 2,869
|
|
Hmmm. Dont know why you have two ptsnoops nlday. Maybe it would be better if you ran a Trojan Scanner first before you do anything else. You can download a good free one - Ants v2 English Version from here Wilders. The some of the dialogue is still in German but you can download the translations from here Ants English Translation
__________________
Microsoft MVP Windows - Shell/User
|

December 2nd, 2001, 07:26 PM
|
|
Virtual Intern
|
|
Join Date: Jun 2001
Location: wi,usa
Posts: 476
|
|
|
ok heading over there. i've had norton internet security 2001 since feb. not having trouble. but let's take a look.
__________________
the more you make...
the more they take.
|

December 2nd, 2001, 07:37 PM
|
|
Virtual Intern
|
|
Join Date: Jun 2001
Location: wi,usa
Posts: 476
|
|
|
annmarie-i find trojan hunter v 2.0 nothing that says 'ants' so is trojan hunter the correct one?
__________________
the more you make...
the more they take.
|

December 2nd, 2001, 08:08 PM
|
 |
Deco Annie
|
|
Join Date: Sep 2001
Location: New Zealand
Posts: 2,869
|
|
Nope - had problems installing that one - it kept reporting a missing file - Ants is on the link below. Most AV's are not that good at picking up trojans nlday, its a good idea to run a dedicated trojan detection program as well as your AV. http://www.wilders.org/downloads.htm
__________________
Microsoft MVP Windows - Shell/User
|

December 2nd, 2001, 08:41 PM
|
|
Virtual Intern
|
|
Join Date: Jun 2001
Location: wi,usa
Posts: 476
|
|
|
i found it and dl'd it. ran the scan of c: and then rescanned windows folder...no trojans found. so could it be--the 2 pt snoops-- is from an aborted DL of hsptel modem driver from windows update site. it told me it was available,tried twice but got a tan error box. this was actually on the win 98 puter.... discussion with triple 7...decided to leave well enough alone since modem is working well. then one more? the directions for removing ptsnoop will work on win98se as well? ps this trojan program is very nice-classy!
__________________
the more you make...
the more they take.
|

December 3rd, 2001, 02:25 AM
|
 |
Deco Annie
|
|
Join Date: Sep 2001
Location: New Zealand
Posts: 2,869
|
|
Hi again nlday - sorry, had to dash off to work and didnt see your last post. If you decide to remove PTSNOOP, I have posted this link which gives you full information on editing your registry Win98/ME Editing The Windows Registry. I guess I have a reservation in view of the conflicting reports on PTSNOOP. Like Triple 7's, I think if its working well, its best to leave it alone. Yes Ants is a great program, I'm pleased that you like it however neither Nav or Ants detected PTSNOOP as a trojan, so it may have been misdiagnosed.
__________________
Microsoft MVP Windows - Shell/User
|
|
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
|
|
|
| Thread Tools |
Search this Thread |
|
|
|
| Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT -4. The time now is 09:31 AM.
|
|
| |