XP: Registry Keys, Malware

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



What role do registry keys play in malware? Is a registry key sufficient or
does there need to be a malware program on my computer?

Details.

I run Ad-Aware 2008 Free every week and on Aug 5 if found Virtumonde.
According to Lavasoft, this is in the top 5 of threats going around now.

File name: yacscom.dll in C:\Program Files\Yahoo!\Messenger

My notes do not mention that I checked to see if Ad-Aware also found
registry keys.

Before removing it, I tested AVG-Free, Spybot, and Yahoo Anti Spy and they
did not find Virtumonde. Microsoft Malicious Software Removal Tool did not
find anything with the July and August updates

Yahoo Anti Spy, however, did find 4 registry keys it identified as
hijackers.

One is ISTbar from a company called Internet Search Technologies:

hkey_local_machine \software\microsoft\windows\currentversion\internet
settings\zonemap\domains\contentmatch.net

Three were from Mirar. They had the exact form above but with different
domain names at the end: mirarseach.com, netnucleus.com, getmirar.com

Thanks for any info

Scott

Los Angeles


.



Relevant Pages

  • Re: Virtumonde, Registry Keys, User Accounts, Microsoft
    ... They may only identify they are realted to the malware itself/ ... | Would a user account prevent Virtumonde from installing? ... | Yahoo Anti Spy found four registry keys it called hijackers. ...
    (microsoft.public.security.virus)
  • Re: Virtumonde, Registry Keys, User Accounts, Microsoft
    ... They may only identify they are realted to the malware itself/ ... | Would a user account prevent Virtumonde from installing? ... | Yahoo Anti Spy found four registry keys it called hijackers. ...
    (microsoft.public.security.virus)
  • Virtumonde, Registry Keys, User Accounts, Microsoft
    ... Would a user account prevent Virtumonde from installing? ... I exchange files using the ... Yahoo Anti Spy found four registry keys it called hijackers. ...
    (microsoft.public.security.virus)