Jump to content
The mkiv Supra Owners Club

**msn Virus**


RobSheffield

Recommended Posts

Even if you click that link, it'll point you to the page where it asks you to download the file. I would recommend against clicking the link, unless you're using firefox. i have no idea how Internet Explorer would handle it, nor do i want to find out!

 

It drops a file called "svshost" into a hidden directory in the system32 folder. It blocks (at least) task manager and regedit, and sends itself to all the users on your list. To clean it i took it out of the run keys in HKCU and HKLM in safe mode, then deleted it from the prefetch and system32

 

Anyone got a step by step guide how to do this?

Link to comment
Share on other sites

You need to boot in safe mode for a start (F8 whilst the system is loading I think).

Then look in C:\WINDOWS\system32\

in 'tools\folder options' you should click view and make sure that it is set to show hidden files and folders. Then find a folder that has an odd name (or you might need to look in them to find the file called svshost).

Just delete the file if you find it, if the virus software has got rid of the problem then you shouldn't need to worry about the registry entries.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. You might also be interested in our Guidelines, Privacy Policy and Terms of Use.