Results 1 to 3 of 3
  1. #1
    Member
    Join Date
    Jul 2006
    Posts
    2
    Points
    0

    Default Trojan.Downloader.Druser

    Hello,

    Just signed on to give some advice with Trojan.Downloader.Druser

    The spyware software that detected this gave the following message:

    Trojan.Downloader.Druser infects the users machine by downloading randomly named files in the system folder and hijacking the web browser to rogue antispyware advertisement sites.

    and the following registry key for the spyware:

    HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows##run

    It was a trail version and to remove the problem you had to buy the software.

    Now, I compared the key to that on a healthy pc and the value "run" wasn't there so I believe that all you have to do is delete the value "run". This is what I have done and the spyware software no longer finds a problem.

    I hope this can be of help.

    Gear贸id

  2. #2
    Member Oddjob's Avatar
    Join Date
    May 2004
    Location
    London, U.K.
    Posts
    1,981
    Points
    248

    Default

    Thanks for the tip, Gear贸id. All help is welcome here.

    OJ
    PLEASE DONATE. Help keep our site alive without ads.

    Help keep your computer protected. Read this > http://www.help2go.com/article152.html

  3. #3
    Member
    Join Date
    Jul 2006
    Posts
    2
    Points
    0

    Default Re: Trojan.Downloader.Druser

    Quote Originally Posted by Gear贸id
    Hello,

    Just signed on to give some advice with Trojan.Downloader.Druser

    The spyware software that detected this gave the following message:

    Trojan.Downloader.Druser infects the users machine by downloading randomly named files in the system folder and hijacking the web browser to rogue antispyware advertisement sites.

    and the following registry key for the spyware:

    HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows##run

    It was a trail version and to remove the problem you had to buy the software.

    Now, I compared the key to that on a healthy pc and the subkey "run" wasn't there so I believe that all you have to do is delete the subkey "run". This is what I have done and the spyware software no longer finds a problem.

    I hope this can be of help.

    Gear贸id