O.P. RE: MSN Messenger Worm Removal
[/color][color=black][/color][color=yellow][/color][color=green][/color][color=purple][/color][color=beige][color=brown][/color][color=teal]It is part of the worm!
3. Configures itself to run each time an .exe file runs, by changing the default value of the registry key:
HKEY_LOCAL_MACHINE\Software\Classes\exefile\shell\open\command
to:
C:\%System%\Nav32_loader.exe"%1 %*
5. Attempts to end the antivirus and firewall processes. The worm inventories the active processes, and if the name of the process contains one of the following, it attempts to end the process:
This post was edited on 03-18-2005 at 06:30 PM by vn2k5.
|