Wednesday, June 20, 2007

Folder.exe virus

S
tep by step instructions
1.) you have to be quick on this step: in Task Manager end task on DC, FUN and SVIQ...I used the End Process Tree

2.) look for the following files(extension is usually EXE but not always)
fun
dc
sviq
repair
DataV
Other
win
winsit
cviq
They can be located in one or more of the following directories:
C:\windows\system
C:\windows\system32
C:\windows
C:\windows\inf
C:\windows\config
C:\windows\system32\config
C:\windows\system\config

3.) In regedit clean these keys:
HKEY_CURRENT_USER\Software\Microsoft\windows\current\version\run
HKEY_LOCAL_MACHINE\Software\Microsoft\windows\current\version\run
HKEY_LOCAL_MACHINE\software\microsoft\windows NT\currentVersion\winlogon
subkeys: Useinit --> set Useinit to Blank
Shell to Explorer.exe

HKEY_CURRENT_USER\software\microsoft\windowsNT\currentVersion\windows
delete subkeys: load=other.exe
run=win.exe

4.) run MSCONFIG and look to see if anything else is starting or loading
that looks weird and remove it...of course be careful because you can destroy
your system if you remove the wrong things
5.) reboot and make sure the virus is gone (it should be)

No comments: