CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Strange Files in Startup list

 
Post new topic   Reply to topic       All -> FavForums -> Startup Programs [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Buruchi

Cadet
Cadet


Joined: Dec 23, 2004
Posts: 7
Location: Australia

PostPosted: Mon Dec 27, 2004 10:12 pm    Post subject: Strange Files in Startup list
Reply with quote

I have been having problems with some trojan virus's that continually reload themselves even after being detected with AVG 7.0 and deleted....I have posted on another forum but have yet had an answer....but checking out registries and using the msconfig on xp sp1..i have noticed that two suspicious files exist:-

Kmed.dat
80LPBT.exe

both are set to run in the startup list and both search the C:\Documents and Settings\(nyname)\Local Settings\Temp directory.......

also when i check the registry for HKEY_LOCAL_MACHINE>SOFTWARE>MICROSOFT>WINDOWS>CURRENTVERSION>RUN

the Kmed.dat is refered to by a file called Cyberfree.exe which is cannot find on my machine.....i did notice this was listed on the startup list page as not required........but the other file 80LPBT.exe is not......

Is it safe for me to just delete these entries from the startup list and registry? and are these causing the re-occurance of the trojan viruses...

Thanks

Back to top
View users profile Send private message
TonyKlein

Site Moderator
Microsoft MVP

Joined: Oct 15, 2002
Posts: 13120
Location: Netherlands
MIRT Moderators MVP Premium Security Experts

PostPosted: Tue Dec 28, 2004 10:42 am    Post subject:
Reply with quote

Wiithout details about your configuration it's impossible to say what's what; I suggest you proceed as follows:

Go to our downloads section, and download Hijack This.

Unzip, doubleclick HijackThis.exe, and hit "Scan".

When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that, and save the log somewhere.

NOTE: Most of what Hijack This lists will be harmless or even required, so do NOT fix anything yet.

Next, go to the Hijackthis - Spyware, Viruses, Worms, Trojans section of this board.

Press "New Topic", explain your problem, and copy and paste the contents of the Hijack This log into your new message.

Reply to this topic including a link to the new topic you posted, and we'll have a look!

Cheers


_________________
Tony image CLSID List
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Startup Programs All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer