TheGrandHooHa
Technical User
I have a weird one here...at least, weird in that I have never seen it before:
A computer running Windows ME (I know, I know, but it's not mine...) has been infected with a virus that neither Norton AntiVirus, AVG, AdAware, or Spybot are able to detect.
Upon loading Windows, this trojan adds anywhere from 5-500 bogus entries to the StartUp folder in the Start Menu. The computer tries to execute these bogus entries, which means that one must click OK about 500 times. These entries appear to be named randomly; example names include "QU01C9NK.lnk" and "M7GK4FHL.lnk" The programs they point to are supposed to be in the Windows directory, but the actual executables are not there.
Also, there are a few strange processes running in the background as well. These are, again, randomly named, but include "53ystfe3c" and "ANXC6EZ0". I did find a registry entry for 53ystfe3c and deleted it, but the problem with the StartUp items still remains.
I originally suspected the Dr.Peper trojan, but the removal instructions I tried did not work as this does not have the same registry entries as Dr.Peper. I don't believe it is one of the new worms because Norton did not get it, nor did AVG or any spyware detector. I will try to get a HiJackThis log later tonight, but if anyone has heard of this let me know, thanks!
A computer running Windows ME (I know, I know, but it's not mine...) has been infected with a virus that neither Norton AntiVirus, AVG, AdAware, or Spybot are able to detect.
Upon loading Windows, this trojan adds anywhere from 5-500 bogus entries to the StartUp folder in the Start Menu. The computer tries to execute these bogus entries, which means that one must click OK about 500 times. These entries appear to be named randomly; example names include "QU01C9NK.lnk" and "M7GK4FHL.lnk" The programs they point to are supposed to be in the Windows directory, but the actual executables are not there.
Also, there are a few strange processes running in the background as well. These are, again, randomly named, but include "53ystfe3c" and "ANXC6EZ0". I did find a registry entry for 53ystfe3c and deleted it, but the problem with the StartUp items still remains.
I originally suspected the Dr.Peper trojan, but the removal instructions I tried did not work as this does not have the same registry entries as Dr.Peper. I don't believe it is one of the new worms because Norton did not get it, nor did AVG or any spyware detector. I will try to get a HiJackThis log later tonight, but if anyone has heard of this let me know, thanks!