PDA

View Full Version : ptsnoop



Ozo
01-11-2002, 05:57 AM
In Win98 on my Compaq 'puter I have a background program running after boot called'ptsnoop.exe'.
Anyone know what it is?

7ate9
01-11-2002, 06:10 AM
Hmmm, I get conflicting reports when I look it up. Some say its a backdoor trojan or virus, some say its harmless modem software. Check for yourself.

http://www.europe.f-secure.com/v-descs/ptsnoop.shtml (http://)

http://pub3.ezboard.com/ftotalseminarsfrm6.showMessage?topicID=126.topic (http://)

http://www.computeruser.com/articles/1908,5,21,1,0801,00.html (http://)

If anyone has a definative answer, I'd like to know too. Hehe.

~ 7ate9

coolsights2000
01-11-2002, 01:16 PM
I don't have the file but if you go start explore

find the file---- right click on it and select properties it might give you a company name and version ... if it is valid file... might give a lead...

I also found this on a q/a

Q. OK, I read that article about the ptsnoop.exe file. Is there a way to get the file back? Because my antivirus software detected a virus on it, I deleted the file. Now I get an error message, but instead of just editing the win.ini, like someone suggested in a previous article, is there away to get that file back?

A. There seems to be a lot of confusion about this famous ptsnoop.exe file. The ptsnoop.exe file is installed with certain modems. The file watches the COM ports for activity and allocates system resources to open the port.

It is a Terminate and Stay Resident (TSR) program that uses roughly 1 MB of resources to run. The problem here is that Norton Antivirus misdiagnoses this file to have a Trojan virus in it. This has caused many people to become frightened of this file, as if it were the Black Plague itself. It isn't a virus. The file is safe, and if you deleted it, you can reinstall the drivers that came with your modem to restore it.


Thanks
Mac!!!

This Is just my opinion
So if it stinks wait for another one
Cause I'm no expert

reghakr
01-13-2002, 12:22 AM
Ozo

Bottom line is...the file is not neccessary:

Ptsnoop.exe is a program installed with some modems that monitors the COM ports for the modem driver. It's not actually necessary for using your modem.

To stop the error message, you can open C:\WINDOWS\WIN.INI with a text editor such as Notepad or Word Pad. Locate and delete the reference to Ptsnoop in either the LOAD= or RUN= lines at the top of the file, and save the file. (Leave the LOAD= and RUN= references.)

Check the Windows Registry by selecting Start*Run, typing RegEdit, and pressing Enter. Navigate to HKEY_ LOCAL_ MACHINE\Software\Microsoft\ Windows\CurrentVersion\Run. If you see a reference to Ptsnoop in the right window, simply highlight that reference and press Del, then close the Registry. Restart Windows and you're done.

reghakr