A Windows Vista forum. Vista Banter

Welcome to Vista Banter.

You are currently viewing our boards as a guest which gives you limited access to view most discussions, articles and access our other FREE features. By joining our free community you will have access to ask questions and reply to others posts, upload your own photos and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact contact support.

Go Back   Home » Vista Banter forum » Microsoft Windows Vista » Performance and Maintainance of Windows Vista
Site Map Home Register Authors List Search Today's Posts Mark Forums Read Web Partners

Performance and Maintainance of Windows Vista A forum for performance and maintenance tasks in Windows Vista. (microsoft.public.windows.vista.performance_maintainance)

worm?



 
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old July 4th 08, 04:56 PM posted to microsoft.public.windows.vista.performance_maintenance
Maggie
external usenet poster
 
Posts: 41
Default worm?

I believe my computer was affected by some virus.
Somehow program called 'mirc.exe' has been installed. I tried to unistall
it, however problem exists. Every time after turning on my computer, the
winsow pops -up with the message:
COULD NOT LOAD OR RUN 'C:\WINDOWS\SYSTEM32\SETUP\DRONA\MIRC.EXE' SPECIFIED
IN THE REGISTRY. MAKE SURE FILE EXISTS ON YOUR COMPUTER OR REMOVE THE
REFERENCE TO IT IN THE REGISTRY

Is there a way to get rid of it? please, help.
thank you

  #2 (permalink)  
Old July 4th 08, 05:04 PM posted to microsoft.public.windows.vista.performance_maintenance
Malke[_2_]
external usenet poster
 
Posts: 4,230
Default worm?

Maggie wrote:

I believe my computer was affected by some virus.
Somehow program called 'mirc.exe' has been installed. I tried to unistall
it, however problem exists. Every time after turning on my computer, the
winsow pops -up with the message:
COULD NOT LOAD OR RUN 'C:\WINDOWS\SYSTEM32\SETUP\DRONA\MIRC.EXE' SPECIFIED
IN THE REGISTRY. MAKE SURE FILE EXISTS ON YOUR COMPUTER OR REMOVE THE
REFERENCE TO IT IN THE REGISTRY

Is there a way to get rid of it? please, help.
thank you


First make sure the computer is really virus/malware-free:
http://www.elephantboycomputers.com/...moving_Malware

Only after you've determined this, manage your startup:

Start OrbStart Search boxmsconfig [enter]

If you are prompted for an administrator password or for a confirmation,
type the password, or click Continue. Then see what is on the Startup tab.
You don't need to restart immediately, but the next time you do you'll get
a dialog saying you've used the Utility. Usually in Vista this will be
blocked by Windows Defender and you'll need to allow it so you can then
tick the box that says in effect, "don't bother me about this again".

Important - Do not use the System Configuration Utility to stop processes.
Instead, use StartRunservices.msc [enter] and do not stop any services
unless you really, really know what you're doing.

The free Autoruns program is very useful for managing your Startup -
http://www.microsoft.com/technet/sys...s/default.mspx - Autoruns

Malke
--
MS-MVP
Elephant Boy Computers - Don't Panic!
FAQ - http://www.elephantboycomputers.com/#FAQ

  #3 (permalink)  
Old July 4th 08, 05:29 PM posted to microsoft.public.windows.vista.performance_maintenance
Charlie Tame
external usenet poster
 
Posts: 2,383
Default worm?

Maggie wrote:
I believe my computer was affected by some virus.
Somehow program called 'mirc.exe' has been installed. I tried to unistall
it, however problem exists. Every time after turning on my computer, the
winsow pops -up with the message:
COULD NOT LOAD OR RUN 'C:\WINDOWS\SYSTEM32\SETUP\DRONA\MIRC.EXE' SPECIFIED
IN THE REGISTRY. MAKE SURE FILE EXISTS ON YOUR COMPUTER OR REMOVE THE
REFERENCE TO IT IN THE REGISTRY

Is there a way to get rid of it? please, help.
thank you


I found this which looks interesting, as does the product that goes with
it (Link on page).

http://www.threatexpert.com/files/mirc.exe.html

There is a legitimate mirc executable, but be aware that internet relay
chat is also a good way to get people to infect themselves with trojans
etc, so look on that page about 15 lines down and you will see your
critter is clearly identified by the "DRONA" in the path name.

It's gone, you nailed it, but the registry entry that tries to run it is
still there. It won't do anything, the error message tells you that it
cannot find the file you removed, but you need to edit the registry to
stop that message.

See if anything Malke suggested gets it first.
 




Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 01:05 PM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.Search Engine Optimization by vBSEO 3.0.0 RC6
Copyright ©2004-2012 Vista Banter.
The comments are property of their posters.