- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - Microsoft
- >
- Re: spybot warning
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-27-2005 02:14 PM
тАО05-27-2005 02:14 PM
Re: spybot warning
Then I started in safe mode and did the HJT scan (could find no reference to the trojan).
Then I run Norton again and the trojan was still there. For some reason Norton can not delete the virus, It says could not repair, computer is still infected.
See pic of add ons, i could not find it in Netscape.
Should I download the program you mentioned below?
http://www.superadblocker.com/I/IPREG32.DLL-2157.html
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-27-2005 02:15 PM
тАО05-27-2005 02:15 PM
Re: spybot warning
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-27-2005 02:37 PM
тАО05-27-2005 02:37 PM
Re: spybot warning
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-27-2005 03:53 PM
тАО05-27-2005 03:53 PM
Re: spybot warning
I'm just now looking at the Hijack File, so that may take a few moments and it's almost 11:00p.m. I may not get back to you until tomorrow.
Ron Kinner's the "Old Pro" at reading Hijack files.
Pat
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-27-2005 04:24 PM
тАО05-27-2005 04:24 PM
Re: spybot warning
http://www.daniweb.com/techtalkforums/thread5425.html
but I understand it comes with RealPlayer and downloads patches/updates. It's been described as Malware.
DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/31c65bb9aec318606800/netzip/RdxIE601.cab
Did you look for the Registry Values to Delete the Trojan?
Click Start > Run.
Type regedit
Click OK.
Navigate to the subkey:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"loader32 " = "%AppData%\SysDown\sys[5 random numbers].exe"
Navigate to and delete the following registry subkeys:
HKEY_CLASS_ROOT\CLSID\{031B6D43-CBC4-46A5-8E46-CF8B407C1A33}
HKEY_CLASS_ROOT\TypeLib\{4A31E565-08CB-4272-8817-7BF729B6A96F}
HKEY_CLASS_ROOT\Interface\{CC1725CD-1EFA-4D88-8987-5EBF66347856}
HKEY_CLASS_ROOT\DownCom.CDownCom.1
HKEY_CLASS_ROOT\DownCom.CDownCom
Exit the Registry Editor.
When Norton continued to Scan a virus on my unit, I located the file in Quarantine and deleted. Once I'd dont that, it did not show up in scans. Other scanners had not detected it at all. You might start a search for the Norton Files and see if you can locate and delete it there.
Pat
- « Previous
- Next »