Anyone got any idea why this little lot is hiding in the registry??? [Archive] - SpeedGuide.net Broadband Community

View Full Version : Anyone got any idea why this little lot is hiding in the registry???


caveman
03-05-02, 05:33 PM
gator
regload
back orifice
trojan
cydoor
subseven and last bvut not least back door????

Help as I now shatting meself!!!:( :(

TonyT
03-05-02, 06:43 PM
gator SPYWARE
regload
back orifice TROJAN
trojan OBVIOUS
cydoor SPYWARE
subseven TROJAN
back door???? TROJAN

You need ADAWARE and a FULL system scan w/ an anti-virus app

Norm
03-05-02, 06:46 PM
Well I must say you're living up to your nic
You must be living in the past with all those installed lol
Sorry, this isn't really funny :D

Someone, or something has more control over your PC than you do.
Get a Trojan Scanner, a Virus scanner, and Adaware to remove all those. Then get a good firewall to keep them out for good.

Adaware - www.lavasoftusa.com
Virus Scanner www.grisoft.com
Trojan Scanner - The Cleaner is a good one http://tucows.tierranet.com/system/trojanscan95.html
Firewall - www.zonelabs.com

Unplug from the net once you download what you need, clean up your system, then plug back in.

You can then cleanup your registry with System Mechanic from www.iolo.com

Good Luck, keep in touch, let us know how things work out.

greEd
03-05-02, 06:47 PM
Umm .... I hope you are kidding.

blebs
03-05-02, 06:52 PM
That's a nice little assortment of nasties.

Go to http://www.lurkhere.com/~nicefiles/index.html and get a free copy of Ad Aware 5.62 AND the latest reference list update.
Install it and run it. Get rid of Gator and Cydoor. Reboot and run it again to be sure all spyware is removed.

Next go to http://www.moosoft.com/download.php and get a free trial of "The Cleaner", update it to the newest update, run it and have it set to scan "All files including archives" if that is an option. This should get rid of the rest of the trojans.

Get yourself a good AV program at www.grisoft.com. AVG AntiVirus
Update it and run it, then keep it!

Do all that and then let us know where you stand.

The other option is to reformat, if you'd rather do that.

blebs
03-05-02, 06:53 PM
Man, I'm gettin slow or else Norm and greEd are getting faster! :confused: Heck, TonyT too!

Norm
03-05-02, 06:54 PM
Originally posted by blebs99
That's a nice little assortment of nasties.

Go to http://www.lurkhere.com/~nicefiles/index.html and get a free copy of Ad Aware 5.62 AND the latest reference list update.
Install it and run it. Get rid of Gator and Cydoor. Reboot and run it again to be sure all spyware is removed.

Next go to http://www.moosoft.com/download.php and get a free trial of "The Cleaner", update it to the newest update, run it and have it set to scan "All files including archives" if that is an option. This should get rid of the rest of the trojans.

Get yourself a good AV program at www.grisoft.com. AVG AntiVirus
Update it and run it, then keep it!

Do all that and then let us know where you stand.

The other option is to reformat, if you'd rather do that. Hey, you stole my post lol :D
You a slow typist Blebbs ?
Well, at least we're on the same page eh? :)

greEd
03-05-02, 06:56 PM
Damn, You gotta enough links there to lock down your computer for good.
:rotfl:

blebs
03-05-02, 06:57 PM
Originally posted by Norm
Hey, you stole my post lol :D
You a slow typist Blebbs ?
Well, at least we're on the same page eh? :)
I just crawled out from under my rock and I'm still shaking the dirt off!;)
Same page? Yeap, except I'm moving at the speed of molases in winter. :D

Norm
03-05-02, 07:12 PM
I meant we offer about the same advice and programs when I said "same page" ,
and we are on the same page in here too :D kewl.

Next time, start typing as soon as you see the post
Hang around refreshing the security forum main page till a new post comes in
lol
Good to see you're in good spirits bud :)

TonyT
03-05-02, 07:29 PM
Well I must say you're living up to your nic
You must be living in the past with all those installed lol
Sorry, this isn't really funny

Someone, or something has more control over your PC than you do.
Get a Trojan Scanner, a Virus scanner, and Adaware to remove all those. Then get a good firewall to keep them out for good.

Adaware - www.lavasoftusa.com
Virus Scanner www.grisoft.com
Trojan Scanner - The Cleaner is a good one http://tucows.tierranet.com/system/trojanscan95.html
Firewall - www.zonelabs.com

Unplug from the net once you download what you need, clean up your system, then plug back in.

You can then cleanup your registry with System Mechanic from www.iolo.com

Good Luck, keep in touch, let us know how things work out.

caveman
03-05-02, 07:32 PM
Well this is worrying as I`ve already run adaware and I`m behind a firewall already well I`m hanging off a router (Netgear RP-114)so I would`ve thought I was impervious to any outside bollox:( :(

caveman
03-05-02, 07:46 PM
Right I`ve done all of the above except "Trojanscan95" coz when I try to install it it gets to 80% and says there`s a file access problem or something and nothing has come up with anything my AVG (which I use anyway) is up to date and that didn`t even find anything wrong so I dunno whether I should still be worried or not????

Any more pointers are MORE than welcome:( :D :( :D

greEd
03-05-02, 07:48 PM
Being behind a router does not make you impervious to attack. To detect the installed trojans on your system you would need to have virus detection software installed. If you have some type of firewall and are behind a router then chances are know one has accessed your system, unless you allowed one of these applications access and forwarded the underlaying port from your router, then yes you would be screwed. If you see any instance at all of netcat however then you are in trouble. If the right person get's netcat activated on your system then it can be told to listen on stealthed ports.
Be sure you get a virus detection utility and get that stuff removed.

regards,
greEd

caveman
03-06-02, 04:17 AM
I`ve already done avirus scan, twice in fact (AVG Anti-Virus) and it hasn`t come up with anything:(

Also what is this netcat that you mention? and as far as opening ports go there are none opened in the routers settings so I think I`m ok there:rolleyes:

caveman
03-06-02, 05:33 AM
AHA I`ve just been told that this littlte list of goodies could be the `manual` for the antivirus which tells the av what is what. Does this sound like a convincing explanation??

blebs
03-06-02, 05:45 AM
Exactly what key or keys did you find this in the registry?

caveman
03-06-02, 05:53 AM
I don`t know where they were as I just did a search in the edit -->find option in the main regedit window so I am unsure as to where they were located. Al I can remember is that down the lefthand side of the window was a list of numbers 000-->015 I think and down the righthand side of the window were all these names (plus others that didn`t seem anything to worry about) If it will help I`ll have another look tonite when I get home from work and post here with the details.

Hopefully what my mate told me is about right about this list being the `rules` for the AV !?!?!?!?!

blebs
03-06-02, 06:01 AM
It might be a list, but check it out when you get home and post the key. These are usually found under Run and Run Services, but let us know. You might just be right and were all jumping the gun. ;)

caveman
03-06-02, 06:05 AM
OK Blebs, thanx for your time;)

blebs
03-06-02, 06:09 AM
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run or Run services

Don't know why, but I went brain dead in the other post. Take a hard look at these 2 keys. See Ya tonight.

Croc
03-06-02, 09:06 AM
The only reference I could find at Trend was to do with Melissa.
See the link and go to the very bottom line.

Oh, and I changed the spelling to "mahatma" as well, in case there was an error in the spelling. With the word "mahatama" it semed logical to try.

http://www.antivirus.com/vinfo/virusencyclo/default5.asp?VName=W97M_MELISSA.AK&VSect=T

Hard to know what you found without the filename, OS you use and a few other details.

Croc.

fredra
03-06-02, 07:46 PM
hey caveman
Don't come near me....j/k
All the advice you have been receiving is fantastic and correct.
I will add my two cents worth here (jeez..Norm, Gred and Tony are fast)
-Sometimes you HAVE to bite the bullet
-Change your Internet habits (not meant as a flame)
-If you are using Win9x, get a boot disk, write protect it, and blow away your HD partitions with FDISK and reformat.
-Re-install your software including
An Antivirus which has an email module, The Cleaner (it has a TACTIVE module, which will block incoming trojans) and Ad-Aware, of course.
When I said change your Internet habits, someone must have opened an email attachment, or downloaded something to have infected you like that (maybe before you installed the router).
I use the theory that "I can't close the barn door after the horse has escaped".... so I err on the side of caution.

JMO

caveman
03-07-02, 06:40 AM
Right I`ve managed to find where this list is located,it`s in....

_HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\FilesNamedMRU

And this list including other stuff is here too

Any ideas Blebs99 ???

blebs
03-07-02, 07:42 AM
Had you maybe searched those terms from the search bar?
MRU=Most Recently Used

I don't think it's anything to be worried about, but I do question why the entries are there. I don't have that particular key in my registry.

caveman
03-07-02, 07:57 AM
Ermmm.... Yes I may well have done at some point in the past (fairly recently) as I was going through a holy-****-there-might-be-some-sort-of-nasties-on-my-computer stage;) :D :p So yes that may well be the case, thank God!!LOL

But hey everyone, thanx for all your time and effort
:D much appreciated

obi womp kenuzi
03-07-02, 01:15 PM
of course all this hasnt been in vein , i have read and cleaned up my system too ... good advice guys ...
:D