Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Trojans,virii, and scans. Yikes!

0 views
Skip to first unread message

Molly

unread,
Jul 4, 2008, 9:12:10 PM7/4/08
to
Got a program aboard with an associated trojan. Loaded it was eating
memory... grinding, grinding, always 97% memory usage. In addition to
which IE would take FOREVER to load. And when I ran defrag, etc.
there were always two messages, one says it cannot locate the recycle
(not sure if this problem is related.) While the second message was
that the cache for IE was missing or otherwise not accessible. So I
removed one trojan and an IE cache rider that was seriously malicious.
Then, when dumping the above,a program purporting to be from XP
hijacked IE and started what appeaed to be an official virus scan.When
I tried to click the site and figure out what was going on, it
suddenly closed. I then ran Spy Doc and found the scan had planted
changes in my registry. Spyware got some out, after which I did a
google on the critter and found a program called FixIEDef. I hit run
and it scanned my registry and came up with the following:

!!! Files that have been deleted !!!

C:\WINDOWS\hosts

--------------------------------------------------------------------------------

!!! Directories that have been removed !!!

No malicious directories to be removed

--------------------------------------------------------------------------------

!!! Registry entries that have been removed !!!

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
"NoDispBackgroundPage"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
"NoDispScrSavPage"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4937D5D1-2039-409A-BD83-FEC9B39B2356}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CAF9D798-C659-4B9B-8E19-EE27C3D04EE7}

Four different infections from one trojan. Ah, next stop is to leave
a message for those enabling the d/l that set the whole thing off.

Molly

0 new messages