<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: problem with Trojan DomCom again in Operating System - Microsoft</title>
    <link>https://community.hpe.com/t5/operating-system-microsoft/problem-with-trojan-domcom-again/m-p/4906265#M10400</link>
    <description>I tried to follow the above instructions before  and again, but when I arrive at the "run" key, nothing about the loader32 shows in the right hand panel or anywhere else for that matter.</description>
    <pubDate>Fri, 10 Jun 2005 09:54:07 GMT</pubDate>
    <dc:creator>Joe van Raamt</dc:creator>
    <dc:date>2005-06-10T09:54:07Z</dc:date>
    <item>
      <title>problem with Trojan DomCom again</title>
      <link>https://community.hpe.com/t5/operating-system-microsoft/problem-with-trojan-domcom-again/m-p/4906257#M10392</link>
      <description>I have the same problem, I followed the steps provided by Norton, but it does not show in in the right hand panel as per attachment in previous post. It is apparently hiding in Source: ipreg32.dll &lt;BR /&gt;Description: The compressed file ipreg32.dll within C:\Documents and Settings\Joe\Local Settings\Temporary Internet Files\Content.IE5\666N6D4H\ipreg32[1].cab is infected with the Trojan.Domcom virus. &lt;BR /&gt;Click for more information about this threat : Trojan.Domcom but Norton can not delete the trojan. I have tried to remove it in safe mode as well. When I check the contents of the internet files, it comes up empty, but when I click on properties it shows five files  in there (see attachment)</description>
      <pubDate>Wed, 08 Jun 2005 08:16:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-microsoft/problem-with-trojan-domcom-again/m-p/4906257#M10392</guid>
      <dc:creator>Joe van Raamt</dc:creator>
      <dc:date>2005-06-08T08:16:11Z</dc:date>
    </item>
    <item>
      <title>Re: problem with Trojan DomCom again</title>
      <link>https://community.hpe.com/t5/operating-system-microsoft/problem-with-trojan-domcom-again/m-p/4906258#M10393</link>
      <description>Hi Joe,&lt;BR /&gt;&lt;BR /&gt;as the name suggests, trojans "hide" themselves anywhere on the local system or the networked machines. removing files once from a certain location is usually not an accurate solution, you shopuld use some other pathes or trojan cleaning antiviruses, as well as some better firewall security packs/ antispywares etc to properly protect your system. you should update the OS with latest SP and security patches ( windows updates if it's a windows OS) to block the holes on your OS.</description>
      <pubDate>Thu, 09 Jun 2005 01:23:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-microsoft/problem-with-trojan-domcom-again/m-p/4906258#M10393</guid>
      <dc:creator>kcpant</dc:creator>
      <dc:date>2005-06-09T01:23:34Z</dc:date>
    </item>
    <item>
      <title>Re: problem with Trojan DomCom again</title>
      <link>https://community.hpe.com/t5/operating-system-microsoft/problem-with-trojan-domcom-again/m-p/4906259#M10394</link>
      <description>Also, do not log on as an administrator. &lt;BR /&gt;Or remove the user you use to log on with from the administrators group.&lt;BR /&gt;&lt;BR /&gt;See this:&lt;BR /&gt;&lt;A href="http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/windows_security_whynot_admin.mspx" target="_blank"&gt;www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/windows_security_whynot_admin.mspx&lt;/A&gt; &lt;BR /&gt;&lt;BR /&gt;regards.</description>
      <pubDate>Thu, 09 Jun 2005 01:58:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-microsoft/problem-with-trojan-domcom-again/m-p/4906259#M10394</guid>
      <dc:creator>Edgar Zapata</dc:creator>
      <dc:date>2005-06-09T01:58:38Z</dc:date>
    </item>
    <item>
      <title>Re: problem with Trojan DomCom again</title>
      <link>https://community.hpe.com/t5/operating-system-microsoft/problem-with-trojan-domcom-again/m-p/4906260#M10395</link>
      <description>Here's a guy that had a problem with same trojan couple of weeks ago.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums1.itrc.hp.com/service/forums/questionanswer.do?admit=716493758+1118301660905+28353475&amp;amp;threadId=888955" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/questionanswer.do?admit=716493758+1118301660905+28353475&amp;amp;threadId=888955&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;hope it helps.&lt;BR /&gt;regards.&lt;BR /&gt;</description>
      <pubDate>Thu, 09 Jun 2005 02:23:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-microsoft/problem-with-trojan-domcom-again/m-p/4906260#M10395</guid>
      <dc:creator>Edgar Zapata</dc:creator>
      <dc:date>2005-06-09T02:23:06Z</dc:date>
    </item>
    <item>
      <title>Re: problem with Trojan DomCom again</title>
      <link>https://community.hpe.com/t5/operating-system-microsoft/problem-with-trojan-domcom-again/m-p/4906261#M10396</link>
      <description>Hi Kcpant, I have done all that, to no avail. I have 4 different types of spy-ware detector programs and none detects the trojan. (Norton does detect, but can not delete it).&lt;BR /&gt;---------------------------------------------&lt;BR /&gt;Edgar, I am automatically logged in when I start the computer and there is no other user listed. I tried that url, but it did not work. I will try again by modifying the url. The las link was to my previous post about this. I thought that I had the system clean at that time. I believe that this trojan was re-installed from the same web site (my son forgot to clear the history log)where it came from to begin with. However, this time I could not get rid of it.</description>
      <pubDate>Thu, 09 Jun 2005 08:28:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-microsoft/problem-with-trojan-domcom-again/m-p/4906261#M10396</guid>
      <dc:creator>Joe van Raamt</dc:creator>
      <dc:date>2005-06-09T08:28:37Z</dc:date>
    </item>
    <item>
      <title>Re: problem with Trojan DomCom again</title>
      <link>https://community.hpe.com/t5/operating-system-microsoft/problem-with-trojan-domcom-again/m-p/4906262#M10397</link>
      <description>Joe, &lt;BR /&gt;I would run this free on-demand AV solution:&lt;BR /&gt;&lt;BR /&gt;Follow instructions here (under Recovery tab):&lt;BR /&gt;&lt;A href="http://www.sophos.com/virusinfo/analyses/trojdomcomc.html" target="_blank"&gt;http://www.sophos.com/virusinfo/analyses/trojdomcomc.html&lt;/A&gt;&lt;BR /&gt;regards.&lt;BR /&gt;&lt;BR /&gt;---&lt;BR /&gt;McAfee Stinger might also help.&lt;BR /&gt;&lt;A href="http://vil.nai.com/vil/stinger" target="_blank"&gt;http://vil.nai.com/vil/stinger&lt;/A&gt;&lt;BR /&gt;This is a very usefull tool.&lt;BR /&gt;DomCom is not listed under stinger though.&lt;BR /&gt;</description>
      <pubDate>Thu, 09 Jun 2005 09:04:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-microsoft/problem-with-trojan-domcom-again/m-p/4906262#M10397</guid>
      <dc:creator>Edgar Zapata</dc:creator>
      <dc:date>2005-06-09T09:04:19Z</dc:date>
    </item>
    <item>
      <title>Re: problem with Trojan DomCom again</title>
      <link>https://community.hpe.com/t5/operating-system-microsoft/problem-with-trojan-domcom-again/m-p/4906263#M10398</link>
      <description>I tried the sophos web site, but there does not seem to be a trial version. Would you know of any where I could get one? The stinger did not find the trojan.</description>
      <pubDate>Fri, 10 Jun 2005 00:59:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-microsoft/problem-with-trojan-domcom-again/m-p/4906263#M10398</guid>
      <dc:creator>Joe van Raamt</dc:creator>
      <dc:date>2005-06-10T00:59:33Z</dc:date>
    </item>
    <item>
      <title>Re: problem with Trojan DomCom again</title>
      <link>https://community.hpe.com/t5/operating-system-microsoft/problem-with-trojan-domcom-again/m-p/4906264#M10399</link>
      <description>Hi Joe,&lt;BR /&gt;&lt;BR /&gt;You can try cleaning registry entries following this procedure:&lt;BR /&gt;&lt;BR /&gt;" To delete the value from the registry&lt;BR /&gt;Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified subkeys only. For instructions refer to the document: How to make a backup of the Windows registry.&lt;BR /&gt;&lt;BR /&gt;   1. Click Start &amp;gt; Run.&lt;BR /&gt;   2. Type regedit&lt;BR /&gt;   3. Click OK.&lt;BR /&gt;&lt;BR /&gt;   4. Navigate to the subkey:&lt;BR /&gt;&lt;BR /&gt;      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;BR /&gt;&lt;BR /&gt;   5. In the right pane, delete the value:&lt;BR /&gt;&lt;BR /&gt;      "loader32 " = "%AppData%\SysDown\sys[5 random numbers].exe"&lt;BR /&gt;&lt;BR /&gt;   6. Navigate to and delete the following registry subkeys:&lt;BR /&gt;&lt;BR /&gt;      HKEY_CLASS_ROOT\CLSID\{031B6D43-CBC4-46A5-8E46-CF8B407C1A33}&lt;BR /&gt;      HKEY_CLASS_ROOT\TypeLib\{4A31E565-08CB-4272-8817-7BF729B6A96F}&lt;BR /&gt;      HKEY_CLASS_ROOT\Interface\{CC1725CD-1EFA-4D88-8987-5EBF66347856}&lt;BR /&gt;      HKEY_CLASS_ROOT\DownCom.CDownCom.1&lt;BR /&gt;      HKEY_CLASS_ROOT\DownCom.CDownCom&lt;BR /&gt;&lt;BR /&gt;   7. Exit the Registry Editor."&lt;BR /&gt;&lt;BR /&gt;You should not login as administrator, make a separate standard user for normal use. If you  are using WinXP, go to control panel &amp;gt; user accounts &amp;gt; change the way users log in /off, and de-select " use the welcome screen". before doing this, note down the password for current user (administrator), or reset the password if you don't know. now, create a new user, and give him " standard user" access. you can login now by typing this user name and password. you can copy the data from old user's profile to the new one by logging in as administrator.</description>
      <pubDate>Fri, 10 Jun 2005 01:57:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-microsoft/problem-with-trojan-domcom-again/m-p/4906264#M10399</guid>
      <dc:creator>kcpant</dc:creator>
      <dc:date>2005-06-10T01:57:07Z</dc:date>
    </item>
    <item>
      <title>Re: problem with Trojan DomCom again</title>
      <link>https://community.hpe.com/t5/operating-system-microsoft/problem-with-trojan-domcom-again/m-p/4906265#M10400</link>
      <description>I tried to follow the above instructions before  and again, but when I arrive at the "run" key, nothing about the loader32 shows in the right hand panel or anywhere else for that matter.</description>
      <pubDate>Fri, 10 Jun 2005 09:54:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-microsoft/problem-with-trojan-domcom-again/m-p/4906265#M10400</guid>
      <dc:creator>Joe van Raamt</dc:creator>
      <dc:date>2005-06-10T09:54:07Z</dc:date>
    </item>
    <item>
      <title>Re: problem with Trojan DomCom again</title>
      <link>https://community.hpe.com/t5/operating-system-microsoft/problem-with-trojan-domcom-again/m-p/4906266#M10401</link>
      <description>The trojan was deleted with the Killbox program. URL was provided by Mr. Venkatesh on the "windows" page.</description>
      <pubDate>Mon, 13 Jun 2005 23:13:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-microsoft/problem-with-trojan-domcom-again/m-p/4906266#M10401</guid>
      <dc:creator>Joe van Raamt</dc:creator>
      <dc:date>2005-06-13T23:13:19Z</dc:date>
    </item>
  </channel>
</rss>

