RE: is this a virus?
Indeed it is.
Even if you click that link, it'll point you to the page where it asks you to download the file. (I would recommend against clicking the link, unless you're using Firefox. I have no idea how Internet Explorer would handle it, nor do I want to find out!)
It drops a file called "svshost" into a hidden directory in the system32 folder. It blocks (at least) task manager and regedit, and sends itself to all the users on your list.
What I suggest is to close down and delete a file called svshost.exe (not to be confused with svchost.exe)...
1) Go Start > Run > cmd
2) Type taskkill /f /im svshost.exe
3) Go to WINDOWS\system32
4) Click Tools > Folder Options > View
5) Click Show hidden files and folders and uncheck Hide protected operating system files
6) Find the random lettered folder
7) Delete
... and run a full virus/adware/spyware scan.
This post was edited on 10-24-2005 at 10:47 AM by hexel.
|