Computing.Net > Forums > Security and Virus > Don't have reg key needed

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

Don't have reg key needed

Reply to Message Icon

Original Message
Name: missmuffet
Date: May 12, 2005 at 00:16:04 Pacific
Subject: Don't have reg key needed
OS: XP Pro
CPU/Ram: 3.4Ghz/1 gig
Comment:

When i restarted my comp PC Cillin come up saying I have the virus TROJ_DLOADER.LE (Win32.Chisyne)(Downloader-ZM (McAfee)

It said the quarantine was unsuccessful, so I went to the site to see how to remove it. http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_DLOADER.LE

It says to delete it at HKEY_LOCAL_MACHINE>Software>Microsoft>Windows>
CurrentVersion>Winlogon>Notify>{name of malicious (.DLL)}

I'm running WinXP Pro and I don't have the winlogin folder in my registry, it also says to delete it at:

HKEY_CURRENT_USER>Software>Microsoft>
Windows>CurrentVersion>Browser Helper Objects
In the left panel, locate and delete the key:
{8E13DDE1-E013-47ec-9C4C-27C2F78BDD26}

which I do have, but is it safe to delete it from the 2nd key if I can't find the 1st?
And would it be in another folder other then winlogin? My comp has been running slugish for the speed it used to run at, programs used to open instantly, now it takes about 3 x longer.


P4 3.4 ghz
1 gb ram
Asus P4P800 se motherboard
ATI All In Wonder 9600 XT video card
40 GB Western Digital hard drive
150 GB Western Digital 2nd hard drive
LG DVD Rom
LG DVD Ram bu


Report Offensive Message For Removal


Response Number 1
Name: missmuffet
Date: May 12, 2005 at 00:43:49 Pacific
Reply: (edit)

Should I just delete the infected file?


P4 3.4 ghz
1 gb ram
Asus P4P800 se motherboard
ATI All In Wonder 9600 XT video card
40 GB Western Digital hard drive
150 GB Western Digital 2nd hard drive
LG DVD Rom
LG DVD Ram bu


Report Offensive Follow Up For Removal

Response Number 2
Name: smifff
Date: May 12, 2005 at 09:21:02 Pacific
Reply: (edit)

Trend micro says you can also do an online scan
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ%5FDLOADER%2ELE&VSect=Sn

First download microsoft antispyware,
http://www.microsoft.com/downloads/details.aspx?FamilyID=321CD7A2-6A57-4C57-A8BD-DBF62EDA9671&displaylang=en
update it, and then run it, it found a trojan downloader on my system i didnt know i had, and i believe i have good security

Then try the online scan from trendmicro
http://housecall.antivirus.com/housecall/start_corp.asp

Also checkout the undo.zip on this page
http://vil.nai.com/vil/averttools.asp

If any advice helps, please post back as it might help others.


Report Offensive Follow Up For Removal







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home








Do you have your own blog?

Yes
No
I did before
I will soon


View Results

Poll Finishes In 5 Days.
Discuss in The Lounge
Poll History




Data Recovery Software