| Onega's profileOnegaBlogListsNetwork | Help |
|
|
December 27 iget.vbeI just found a virus like file under c:\, the content is: Set xPost = CreateObject("Microsoft.XMLHTTP") December 05 mravsc32.exeThis worm created a lot of TCP connection and affected normal internet usage. It will spawn another process once it is killed. Well, I can suspend it and then google a solution. August 04 sddriver.exesddriver.exe seems to be a worm, it initialed a lot of connections (can be seen in TCPView.exe) and affected normal use of web browser. It is found in the following registry entries, but the file is not found in disk. HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run Call Function System32=C:\WINDOWS\system32\Com\sddriver.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List C:\WINDOWS\system32\Com\sddriver.exe=C:\WINDOWS\system32\Com\sddriver.exe:*:Enabled:Call Function System32 July 16 Firefox displays blank page for many urlsToday when I am surfing internet, suddenly Firefox can't open new pages correctly -- just be blank. After launching TCPView.exe I found rundll.exe (PID=4848) making lots of connection attempts, much like a virus/worm, so I killed it and firefox resumed to work correctly. The sad thing was that my virus protection software failed to protect my system. June 21 wishs.exe -- virus or worm?Wishs.exe is found in the following registry [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] Microsoft=wishs.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices] Microsoft=wishs.exe [HKEY_USERS\.DEFAULT\Software\ASProtect] Microsoft=wishs.exe |
|
|