If Harry0 is about would be interested in your views.
I followed the links listed on a thread here to get a MyDoom virus removal tool, so d/l it and ran it.
Then got a txt file with following in it:
-------------------------------------------------------------------------------
Norman MydoomFix (C) 2004 Norman ASA
Norman engine version:
Checking processes.
Scanning files on disk. This may take some time.
Scanning drive: c:
Scanning drive: d:
Scanning drive: e:
Cleaning the registry
Setting reg key: HKCRCLSID{E6FB5E20-DE35-11CF-9C87-00AA005127ED}InprocServer32 to
Deleted registry key: HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunDisc Detector
Deleted registry key: HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunCTStartup
Deleted registry key: HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunJet Detection
Deleted registry key: HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunATIPTA
Deleted registry key: HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunShare-to-Web Namespace Daemon
Infected processes killed: 0
Files scanned: 45737
Infected files: 0 deleted, 0 repaired
Done!
---------------------------------------------------------------------------------
My question is why would it delete those registery keys?
Oh by the way, just as two wrongs don't make a right .... just because I understand the word 'registry' and the word 'key' it don't mean understand 'registry key' lol!
One of your usual 'cut throght' posts would be appreciated lol
Hi Griffin,
Re. our chat in the SH Chatroom I would advise you get the full AVG anti virus programme its well worth it.
Harry0
Feenix
Changing The Class Identifier is a protection measure against backdoor processes that can be running in a stealth mode and the default should be
Removing run registry keys are because code inside them was suspect because the keys had been changed at some point. There will be less things running on your taskbar in the background now but to me that is not a bad thing! The share to web one is a dangerous one to leave running at the best of times. I think you have cd writing software installed which has a disc detector process running. This has been stopped along with several other processes like a graphics card one and print services one. If everything is running as before then you have no problems.
The good news is - you were not infected!
Fred
Many thanks Fred for the update
LOL it actually makes sense!
I'm in that dangerous state of knowing a little bit about this stuff and therefore likely to meddle