|
Description of virus: When I am on MSN-IM a program from one of my contacts sends random comments like "this is my dream house. WOW" and immediately prompts a compressed file waiting to be accepted. The contact denys sending you the text and file because the program (virus) is responsible for it.
These are the steps I took to remove the MSN virus that’s going around:
I have an XP version of windows. This process involves playing around with start up applications and may be dangerous to your computer if you disable certain start up items. Be forewarned.
Open the start menu and hit run. Type in “msconfig” and hit enter. A window saying “System Configuration Utility” should open. Go to the very last tab- startup. From my understanding, this tab shows all the programs that open when you start up the computer.
I went down the list and looked up each and every series of words to find which programs (all of these in the list are applications, in other words .exe files) were viruses using the internet as a tool to judge whether an .exe was “valid”.
For example, there was one called "igfxtray". I looked up igfxtray.exe in google and it was a "valid program".
Once you encounter a threat, the way to remove it is to disable the application by unchecking the box on the left, hitting apply, and then using the directory on the right to locate the source where the file resides. I unchecked two boxes in total (pressed apply) and deleted two files located in C:\WINDOWS\system32. The two files appeared like JPEG files but were definitely .exe when I looked up its properties. One was named “wkwcrphp.exe”. I forgot the name of the other one. However, the names may vary.
In other words (different phrasing), the right side of the “System Configuration Utility” window shows you the location of the file so if you encounter one as a virus, uncheck the box next to the name and apply to disable it and then find the file using the directory (locate it) and delete it... from my understanding, you can't delete a file that is running so you must disable it first.
I restarted the computer for the actions to take effect.
Again, please be careful not to disable vital programs such as your power supply, keyboard or monitor functions.
If you accidently lose track of which progams you unchecked you can revert back to the old settings in the “System Configuration Utility” under the “General” tab where it says “Launch System Restore”.
Hope it's useful info ^^
P.S. Whoever made this virus should be hunted down.
|