Virus Help
Posted: Fri Jul 14, 2006 9:52 am
A co-worker of mine was just hit with the QQlaid Trojan and just as it is designed to do she started getting nailed with pop-ups and other crap. Our IT, to some extent has made enough fixes to her pc that allows her to continue to work with interruption, however there is still a sliver of it left as she got one single pop-up. I've gone into her IE properties and have disabled several oddball Add-ons and have taken a look at her registry and found the following under HKey_Current_ User / Software / Microsoft / Windows / Current Version / Run:
Axgxxij ( C:\DOCUME~1\TERRI~1.ROM\APPLIC~1\DOBE~1\HKNTFS~1.EXE )
irssyncd ( C:\WINDOWS\system32\irssyncd.exe
rasiav ( C:\WINDOWS\system32\rasiav.exe
Tair ( "C:\PROGRA~1\YMANTE~1\services.exe" -vt ndrv )
xxldg ( C:\WINDOWS\system32\cjakfq.exe reg_run )
I also checked her System32 folder and sorted everything by date modified and found about 30 entries at the time of her trojan attack. Do these need to be deleted? Any thoughts about what we can do about the above registry entries? Please remember that she cannot load any 3rd party software on her computer, because it is a company pc and they frown on that here.
Thanks,
Razorbacx
Axgxxij ( C:\DOCUME~1\TERRI~1.ROM\APPLIC~1\DOBE~1\HKNTFS~1.EXE )
irssyncd ( C:\WINDOWS\system32\irssyncd.exe
rasiav ( C:\WINDOWS\system32\rasiav.exe
Tair ( "C:\PROGRA~1\YMANTE~1\services.exe" -vt ndrv )
xxldg ( C:\WINDOWS\system32\cjakfq.exe reg_run )
I also checked her System32 folder and sorted everything by date modified and found about 30 entries at the time of her trojan attack. Do these need to be deleted? Any thoughts about what we can do about the above registry entries? Please remember that she cannot load any 3rd party software on her computer, because it is a company pc and they frown on that here.
Thanks,
Razorbacx