The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    Anyone come across this xrg1.exe, xrg2.exe

    Discussion in 'Security and Anti-Virus Software' started by Full-English, Nov 26, 2008.

  1. Full-English

    Full-English Notebook Deity

    Reputations:
    1,227
    Messages:
    1,512
    Likes Received:
    8
    Trophy Points:
    56
    I've just been doing a virus scan with avira and it's come up with xrg1.exe in my sisters user profile.

    Avira reports this:

    Virus or unwanted program 'TR/BHO.Gen [trojan]'
    detected in file 'C:\Users\Claire\AppData\Local\Temp\xrg1.exe.
    Action performed: Move file to quarantine.

    I've gone to the folder it was contained in and there is also an xrg2.exe which avira hasn't picked up, anyhow, found this out about it:

    http://www.prevx.com/filenames/103078361981903688-1681525813/XRG1.EXE.html

    Anyone come across this before, anyone maybe know the origin or where it could have been picked up from, i.e. toolbar etc????

    Edit: Used Malwarebytes which picked up a few things, basically, the trojan by the looks of it just dumped 4 shortcuts in the pictures, video, muioc and documents folder directing to some sites, nothing harmfull, plus it got rid of the files and some entries into the registry. Also it put a shortcut into the favourites folder in IE7, for an antispyware program. Hopefully, this has rid it all, but i'm gonna use a couple of other programs to scan the system and see if anything else comes up.
     
  2. Baserk

    Baserk Notebook user

    Reputations:
    2,503
    Messages:
    1,794
    Likes Received:
    1
    Trophy Points:
    56
    Also make sure to check the 'Trusted Domain' settings in Internet Explorer as PrevX warns about in the link you posted.
     
  3. Full-English

    Full-English Notebook Deity

    Reputations:
    1,227
    Messages:
    1,512
    Likes Received:
    8
    Trophy Points:
    56
    All checked and results are good. I'm pretty baffled as to where it came from though.
     
  4. entropy.cz

    entropy.cz Notebook Evangelist

    Reputations:
    110
    Messages:
    386
    Likes Received:
    0
    Trophy Points:
    30
    well what does virustotal.com say about it? try to scan the files there to get aliases - other names used by other antivirus vendors... and you'll get more keywords for google