About two week ago a FreeFixer user added prnet.tmp to the online file database. I've not had the chance to analyze this file myself, but from the large number the searches it must be a major problem right now.
This file is dropped in C:\WINDOWS\system32\ and adds itself to the registry under HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, prnet, which starts the prnet.tmp process every time a user logs on to the machine. Those infected by this malware reports a large numbe of unwanted pop-up windows.
If you need assistance to remove prnet.tmp, please post a FreeFixer log at the FreeFixer User Group.
Showing posts with label trojan. Show all posts
Showing posts with label trojan. Show all posts
Wednesday, 6 May 2009
Wednesday, 1 April 2009
Tuesday, 31 March 2009
reader_s.exe
reader_s.exe seems to be the major infection out there right now. More than 30% of all users entering freefixer.com from a search engine are looking for information about this Virut variant.
Subscribe to:
Posts (Atom)