H-Net* Fw: Virus - Red Alert! Name ---NAVIDAD--
- Original Message - Sent: Thursday, November 16, 2000 4:38 PM Subject: Virus - Red Alert! Name ---NAVIDAD-- DO NOT TRY TO OPEN THE ATTACHMENT NAVIDAD.EXE If you already open it..no worried..you already infected..do the following below.. Symptoms : Windows pop up looking for WINSVRC.EXE..cannot find programs .. Click on Start|Programs|MS-DOS Prompt. Type the DOS command below then press "ENTER"Ren regedit.exe regedit.com(Note: This renaming is only temporary and is necessary to be able to run Regedit) Type exit, then press "ENTER" to return to Windows. Click on Start|Run, type regedit, then press ENTER. In the left panel of the Registry Editor, click on the + at left of the names to go to the registry below:HKEY_CLASSES_ROOT\exefile\shell\open\command In the right panel, double-click on the entry with the data(Default) = %systemdir%\WINSVRC.EXE%1%* where %systemdir% is the Windows system directory; i.e., \WINDOWS\SYSTEM for Win 9x, and \WINNT\SYSTEM32 for NT/2K. In the Edit window that appears, delete the entire first part of the string, leaving behind %1%*. As in step 5, go to the registry entry below: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run Click on the entry below, then press "DELETE"Win32BaseServiceMOD = %systemdir%\WINSVRC.EXE Click on Start|Programs|MS-DOS Prompt Type the DOS command below then press "ENTER"Ren regedit.com regedit.exe Scan your system with Nortonor go to http://housecall.antivirus.com/pc_housecall/and delete all files detected as TROJ_NAVIDAD.A. Thank you!
H-Net* Fw: Virus - Red Alert! Name ---NAVIDAD--
utk makluman warga hizbi yg terkena virus tsbt... - Original Message - Sent: Thursday, November 16, 2000 4:38 PM Subject: Virus - Red Alert! Name ---NAVIDAD-- DO NOT TRY TO OPEN THE ATTACHMENT NAVIDAD.EXE If you already open it..no worried..you already infected..do the following below.. Symptoms : Windows pop up looking for WINSVRC.EXE..cannot find programs .. Click on Start|Programs|MS-DOS Prompt. Type the DOS command below then press "ENTER"Ren regedit.exe regedit.com(Note: This renaming is only temporary and is necessary to be able to run Regedit) Type exit, then press "ENTER" to return to Windows. Click on Start|Run, type regedit, then press ENTER. In the left panel of the Registry Editor, click on the + at left of the names to go to the registry below:HKEY_CLASSES_ROOT\exefile\shell\open\command In the right panel, double-click on the entry with the data(Default) = %systemdir%\WINSVRC.EXE%1%* where %systemdir% is the Windows system directory; i.e., \WINDOWS\SYSTEM for Win 9x, and \WINNT\SYSTEM32 for NT/2K. In the Edit window that appears, delete the entire first part of the string, leaving behind %1%*. As in step 5, go to the registry entry below: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run Click on the entry below, then press "DELETE"Win32BaseServiceMOD = %systemdir%\WINSVRC.EXE Click on Start|Programs|MS-DOS Prompt Type the DOS command below then press "ENTER"Ren regedit.com regedit.exe Scan your system with Nortonor go to http://housecall.antivirus.com/pc_housecall/and delete all files detected as TROJ_NAVIDAD.A. Thank you!