
Signature
Mike Maltby MS-MVP
mike.maltby@gmail.com
> That's already checked (or unchecked, as the case may be). Scanning
> with the products I mentioned show the directories and registry
> entries. Looking at the directories listings doesn't. (I can see
> the "hidden" files and directories, but not these strange ones.)
> Same with the registry entries - they show up on the scan, but not
> when I use Regedit.
Thanks for your patience, Mike.
On Tuesday, I clicked on a link in an e-mail message from an insurance
company that I thought was OK. WRONG! I got a Trojan called
"Downloader.Mediket" installed on my machine. VERY nasty. It installs
long-distance porn dialers on your machine, and will hijack your home page.
(I don't do porn, by the way.) Love that spam!
I scanned my computer with two programs, XoftSpy and NoAdWare to find where
the culprit was lodged on my computer. During the XoftSpy scan of the
Registry, some porn-related names went flying by. But when I go to look for
them to delete them, Regedit doesn't find them.
During the NoAdWare scan, a couple directories came flying by as well, at
least one Windows subdirectory, and another listed as %Program Files% (with
the percent signs). But looking for these rascals with Explorer comes up
empty.
These situations can be reproduced at will with these two programs.
The Trojan's been disabled, but I'd like to get rid of the garbage it left
behind.
Thanks for your help.
Chris
> If I knew what your problem was I would try and help but as it is I'm
> sorry but I don't really have a clue as to the actual problem you are
[quoted text clipped - 10 lines]
> > Same with the registry entries - they show up on the scan, but not
> > when I use Regedit.
Mike M - 18 Feb 2005 00:18 GMT
Neither NoAdware nor XoftSpy have much of a reputation as suitable tools
for such tasks. In fact what reputation they have on the whole stinks.
You would be much better served sticking to more reputable products such
as AdAware, SpyBot Search & Destroy and PestPatrol.
If Regedit didn't find the entries then they aren't there and you are
seeing false positives, something for which both of the products you
mention are renowned, especially NoAdware.
%Program Files% is, by default, your C:\Program Files folder, in the same
way %WinDir% is the C:\Windows folder and %winsys% the C:\Windows\System
folder. Similarly %Temp% is by default C:\Windows\Temp, %CommonFiles% is
C:\Program Files\Common Files, %personaldocuments% what ever name you have
given the My Documents object (folder) and %internetcache% your Temporary
Internet cache, by default the C:\Windows\Temporary Internet Files folder.

Signature
Mike Maltby MS-MVP
mike.maltby@gmail.com
> Thanks for your patience, Mike.
>
[quoted text clipped - 20 lines]
>
> Thanks for your help.
Jack E Martinelli - 20 Feb 2005 21:20 GMT
Here is the best site I know for tracking bad choices in antiparasite
software:
http://www.spywarewarrior.com/rogue_anti-spyware.htm

Signature
Jim Eshelman, MS-MVP Windows/Security
Windows Support Center: http://aumha.org/
AumHa Forums: http://aumha.net/
Jan 2005
------
--
Jack E. Martinelli 2002-05 MS MVP for Shell/User / DTS
Help us help you: http://www.dts-L.org/goodpost.htm
http://www.microsoft.com/athome/security/protect/default.aspx
Your cooperation is very appreciated.
------
> Thanks for your patience, Mike.
>
[quoted text clipped - 37 lines]
> > > Same with the registry entries - they show up on the scan, but not
> > > when I use Regedit.