| |
Antivirus World Forum
Re: Can not Rid my "Downloader - YH" or "nipt.exe"
Posted By: Snerd O'Reilly In Response To: Re: Can not Rid my "Downloader - YH" or "nipt.exe" (Christine Jackowski)
Date: Tuesday, 12 April 2005, at 12:42 a.m.
Its back... this is what Microsoft found and the reason for my optimism.
Unclassified.ActiveX.Trojan.A Hostile ActiveX Control more information...
Details: Unclassified ActiveX Trojan A was identified by SpyNet as hostile. Currently research is under way to classify this threat and complete a risk assessment.
Status: Removed
Severe threat - Severe-risk items have an extreme potential for harm, such as a security exploit, and should be removed.Infected files detected
C:\WINDOWS\Downloaded Program Files\Information.INFInfected registry keys/values detected
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{11111111-1111-1111-1111-111111113456}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{11111111-1111-1111-1111-111111113456}\DownloadInformation CODEBASE file://c:\info6.cab
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{11111111-1111-1111-1111-111111113456}\DownloadInformation INF C:\WINDOWS\Downloaded Program Files\Information.INF
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{11111111-1111-1111-1111-111111113456}\InstalledVersion 0,0,0,1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{11111111-1111-1111-1111-111111113456} SystemComponent 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{11111111-1111-1111-1111-111111113456} Installer MSICD
But McAfee is still finding those 2 files i286.exe and tp7543.exe on my computer. If it deletes i286.exe, it is immediately replaced with i286(1).exe. Progress????
| |
Antivirus World Forum is maintained by Administrator with WebBBS 5.12.