G
Gary Adams Lsu Edu
Guest
Virus or trojan in my Windows XP desktop.
Live care found ; renos.y
This XP Professional Compaq Evo has a trojan or virus.
It was cleaned with;
1. Ad Aware
2. Spy Bot Search and Destroy
3. Microsoft Live One Care
Somewhere in the registry there is a startup or run command that created an
excutable file in the c:\Windows\Temp directory. But I cannot find it.
i TRIED aUTORUNS BUT i CANNOT find the startup command.\fg
Here is the registry info relating to the new file found in the Temp folder
after each restart.
The filename changes at each restaRT.
PendingFileRenameOperations
\??\C:\WINDOWS\TEMP\E1167036.exe
Pending Rename Operations
CurrentControlSet\Control\Session Manager\PendingFileRenameOperations
Session Manager
PendingFileRenameOperations
\??\C:\WINDOWS\TEMP\E1167036.exe
ControlSet003
BackupRestore
KeysNotToRestore
Pending Rename Operations
CurrentControlSet\Control\Session Manager\PendingFileRenameOperations
ControlSet same as above
SessionMangeger
PendingFileRenameOperations
\??\C:\WINDOWS\TEMP\E1167036.exe
It is somwhere in the autostart area of the registry ?
Live care found ; renos.y
This XP Professional Compaq Evo has a trojan or virus.
It was cleaned with;
1. Ad Aware
2. Spy Bot Search and Destroy
3. Microsoft Live One Care
Somewhere in the registry there is a startup or run command that created an
excutable file in the c:\Windows\Temp directory. But I cannot find it.
i TRIED aUTORUNS BUT i CANNOT find the startup command.\fg
Here is the registry info relating to the new file found in the Temp folder
after each restart.
The filename changes at each restaRT.
PendingFileRenameOperations
\??\C:\WINDOWS\TEMP\E1167036.exe
Pending Rename Operations
CurrentControlSet\Control\Session Manager\PendingFileRenameOperations
Session Manager
PendingFileRenameOperations
\??\C:\WINDOWS\TEMP\E1167036.exe
ControlSet003
BackupRestore
KeysNotToRestore
Pending Rename Operations
CurrentControlSet\Control\Session Manager\PendingFileRenameOperations
ControlSet same as above
SessionMangeger
PendingFileRenameOperations
\??\C:\WINDOWS\TEMP\E1167036.exe
It is somwhere in the autostart area of the registry ?