Our new Indie Games subforum is now open for business in G&T. Go and check it out, you might land a code for a free game. If you're developing an indie game and want to post about it, follow these directions. If you don't, he'll break your legs! Hahaha! Seriously though.
Our rules have been updated and given their own forum. Go and look at them! They are nice, and there may be new ones that you didn't know about! Hooray for rules! Hooray for The System! Hooray for Conforming!

AUX registry key

WingedWeaselWingedWeasel Registered User regular
Hello all,

This may be suited better to the tech forum but I wanted to check here first. I have been searching for an answer to this but I can't find a suitable resolution. Basically I have some PC's that are having a registry key modified, specifically:

hkey_local_machine\software\micrsoft\windows nt\current version\drivers32

aux

I don't have the foggiest what is changing (it changes the key to point to a random temp file under the current lgoged in user's local profile) it but it has happened on a few computers and it causes all kinds of strange symptoms such as regedit not opening, command lines not opening, AV not running, network/internet connections crapping out etc. I was able to find a "fix" that says to modify the data for the aux key back to:

wdmaud.drv

It corrects the symptoms and scans haven't turned up a virus on the affected machines after the fact...but I can't for the life of me find out what is triggering it and that kinda worries me. Anyone ever come across this before? I am continuing to try and research what the root cause is but any leads would be much appreciated!

WingedWeasel on

XBL GT: Winged Weasel

Posts

  • acidlacedpenguinacidlacedpenguin Registered User regular
    sounds like your AV is compromised. What AV have you used to check the machines?

    GT: Acidboogie PSNid: AcidLacedPenguiN
  • WingedWeaselWingedWeasel Registered User regular
    sounds like your AV is compromised. What AV have you used to check the machines?

    eTrust, off the top of my head I am not positive on the version. The only logical conclusion I can draw is some virus disabling everything but as I mentioned nothing is being turned up in scans. Well the scans I run after modifying the registry anyway (can't scan before that).


    XBL GT: Winged Weasel
  • RuckusRuckus Registered User regular
    I'd recommend that you try a few free scan tools,

    McAfee Stinger, for example. It just scans for a small subset of the nastiest nasties.

    Raneados wrote: »
    so what SPECIFICALLY is the problem with my hole?
  • WingedWeaselWingedWeasel Registered User regular
    The original problem (of many) was that I did not get to see many of the PC's first hand and someone else got to them first using the registry fix. I was able to finally get my hands on one that wasn't stripped of problems already. After going through the logs and searching CA it seems to be a newer virus that literally was released May of this year. Seekwel B. Thankfully the AV seems to be purging it when it comes up but we shall see.

    Mods feel free to close/lock this or leave it open for people to comment in. Thanks everyone.


    XBL GT: Winged Weasel
Sign In or Register to comment.