Re: Downloader-VA trojan??????

From: David (ddtraveller_at_yahoo.com)
Date: 02/13/05

  • Next message: SGLM821: "MSN Messenger and Microsoft AntiSpyware"
    Date: 13 Feb 2005 07:01:59 -0800
    
    

    I have the same virus. I'm using Firefox now which doesn't seem to be
    affected.

    I tried that knowledge base article and was able to remove the .sys
    files but the .exe files weren't there and so I have the same problem.
    I searched my system for the exes but couldn't find them.

    When I start IE I get an error from
    c:\windows\system32\drivers\ungylsqv.sys

    McAfee's says it's deleting it but when I start up again it says the
    virus is coming from there again so I suspect that an exe somewhere is
    creating that file to kick things off everytime IE starts.

    I found it in my registry at
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ungylsqv

    I found the exes referenced at
    HKEY_CURRENT_USER\Software\Microsoft\Search Assistant\ACMru\5603

    Looks like this virus is coming from search assistant. It's already
    been uninstalled but I can't keep this virus from popping back up.

    Deleting those reg keys didn't help at all...

    Maybe I just need to reboot now...

    Argh!

    I will post back if I can find some way to get rid of this thing.

    Dave

    hostsearch.com

    "SG" <sorry@nomail.com> wrote in message news:<eXoq8HREFHA.3972@TK2MSFTNGP15.phx.gbl>...
    > See this KB Article...
    > http://support.microsoft.com/?scid=kb;en-us;894278
    >
    > All the best,
    > --
    > George Aker aka SG
    > Google is your friend www.google.com
    > Anything else is just a search engine
    > "Wouter" <Wouter@home> wrote in message
    > news:exkaCGIEFHA.3592@TK2MSFTNGP15.phx.gbl...
    > > I used all solutions, but nothing helped.
    > > Ad-aware found 43 infected files.
    > > Stinger found nothing.
    > > The problem stays. Please, do you have more suggestions?
    > > (When I start Internet, the scanner found this trojan, deletes it, so I
    > can
    > > not submit it.)
    > >
    > > "Wouter" <Wouter@home> wrote in message
    > > news:#j610UGEFHA.3648@TK2MSFTNGP10.phx.gbl...
    > > > Hello,
    > > > Since a few days I get a warning from my virusscanner McAfee that the
    > > file:
    > > > D:\Windows\system\drivers\hlmsfrd.sys was infected bij the downloader-VA
    > > > trojan. It occurs everytime I start my internet or my mailprogram.
    > > > I could not find where it comes from. Please, does anyone know a
    > solution
    > > > for me? Where can i remove it permentley?
    > > >
    > > >
    > >
    > >


  • Next message: SGLM821: "MSN Messenger and Microsoft AntiSpyware"

    Relevant Pages

    • Re: registry? virus? help!
      ... I found it interesting that you mentioned Itunes. ... launch anti-virus software which returned no results that indicate a virus. ... then whenever i open any .EXE files, ... but i cant use any of them cuz they are all EXE files.. ...
      (microsoft.public.windowsxp.general)
    • RE: registry? virus? help!
      ... I found it interesting that you mentioned Itunes. ... launch anti-virus software which returned no results that indicate a virus. ... then whenever i open any .EXE files, ... but i cant use any of them cuz they are all EXE files.. ...
      (microsoft.public.windowsxp.general)
    • Re: registry? virus? help!
      ... I found it interesting that you mentioned Itunes. ... then whenever i open any .EXE files, ... therefore i've looked around the internet and i came across this virus ... but i cant use any of them cuz they are all EXE files.. ...
      (microsoft.public.windowsxp.general)
    • RE: New Virus?
      ... unknown files. ... Subject: New Virus? ... when opened contains an .EXE file that is attempting to ... <SAMPLE WEB PAGE> ...
      (Incidents)
    • backdoor.trojan
      ... I do get virus alert windows popped up once in awhile saying a .exe ... But I do not see anything was registered in my registry, win.ini, and ... I've Symantec Antivirus installed in my computer and the real-time scan ...
      (microsoft.public.security.virus)

    Loading