G
Guest
Microsoft Antispyware and Grisoft's AVG were disabled and being prevented
from running and/or re-installing. Although I was unable to save the
infected files as I was "fighting" it, I can tell you that there were two
files running in Task Manager and also had registry settings (there were
actually two instances of each running at the same time). They were:
ANTIAV_EXE.EXE / AUTO_ANTIAV_KEY
HLOADER_EXE.EXE / AUTO_HLOADER_KEY
I performed a search for these files, renamed them and then I was able to
"End Task" each of them, without them recreating themselves again and again.
I also found a bogus subdirectory under Windows filled with about eight EXE's
containing numeric filenames. I'm assuming this was a holding queue or cache
for HLOADER.
This problem was discovered and resolved on November 2, 2005.
I hope this helps. Again, I'm sorry I was unable to isolate any of these
files for your examination.
from running and/or re-installing. Although I was unable to save the
infected files as I was "fighting" it, I can tell you that there were two
files running in Task Manager and also had registry settings (there were
actually two instances of each running at the same time). They were:
ANTIAV_EXE.EXE / AUTO_ANTIAV_KEY
HLOADER_EXE.EXE / AUTO_HLOADER_KEY
I performed a search for these files, renamed them and then I was able to
"End Task" each of them, without them recreating themselves again and again.
I also found a bogus subdirectory under Windows filled with about eight EXE's
containing numeric filenames. I'm assuming this was a holding queue or cache
for HLOADER.
This problem was discovered and resolved on November 2, 2005.
I hope this helps. Again, I'm sorry I was unable to isolate any of these
files for your examination.