|
Posted by Leythos on June 17, 2007, 10:34 pm
If you were Registered and logged in, you could reply and use other advanced thread options ToddAndMargo@invalid.com says...
> Leythos wrote:
>
> > ToddAndMargo@invalid.com says...
> >> Hi All,
> >>
> >> I was at a customer site who was infected with
> >> what Kaspersky calls: Trojan-downloader.win32.Agent.bkd.
> >> Kaspersky had no trouble removing it.
> >>
> >> Before I let Kaspersky do its thing, I looked through
> >> the registry for the DLL's (eeuydc.dll) start point.
> >> I did not find it: not is Run; not is Winlogon.
> >> I tried renaming the winlogin/notify keys and nothing
> >> protected itself. (This, while the virus' icon in the task
> >> bar kept flashing with fake security problems.)
> >>
> >> Anyone have any idea where this thing starts up?
> >
> > Don't worry about where it starts, use Multi_AV and run all of the
> > scanners, then use SBS&D and AdAware and you'll be happy again
>
> I want to know where it starts because I just think it is
> capital fun to defeat them by hand. Yes, I am easily amused.
>
> Do you know where this virus is started?
Sorry, I don't even try any more, it doesn't amuse me any more, use to a
long time ago, but now I just take an updated Multi-AV and start it
running and walk away :)
--
Leythos
- Igitur qui desiderat pacem, praeparet bellum.
- Calling an illegal alien an "undocumented worker" is like calling a
drug dealer an "unlicensed pharmacist"
spam999free@rrohio.com (remove 999 for proper email address)
|