Wkssvc.exe trojan horse sheur.ARTJ

Kay84 -  
 Kay84 -
Bonjour,
et voila, jai finalement decouvert mon fameux bug sur msn.. cest un trojan T_T
d'habitude cest mon frere qui s'occupe de cela mais moi je fais quoi pour m'en debarrasser
ya une merveilleuse application deja dans mon start up.. je dois me debarrasser de ça aussi non? et comment?
est ce que cest bien d'aller shredder l'application manuellement avec tune up shredder? comment je procede?
merci...
A voir également:

4 réponses

Kay84
 
deuxieme trojan sur mon ordi... -.-"
PIC006.JPG-www.photoshare.com un trojan du meme type.. (sHeur.ARTJ)
au secours? D:
0
Kay84
 
bon un troiseme trojan...
A0098602.com
ils sont dans la voute maintenant mais jaime pas du tout ca!!!! :(
0
Foarl
 
Mon frencais n'est pas parfait... mais j'ai decouvert le methode de tuer cette problem. Les instructions son dans englais, mais je nais pas asser to temps pour faire un translation. Je M'excuse.

Ok guys, so apparently this stupid MSN virus hit a bunch of people through me. It took me 3 hours but I’ve figured out how to kill it. This one is a bastard because it disables your Anti-Virus updating abilities.

Step 1 – Getting your updates back

In a folder, paste this into the top (like a website for the non geeks lol )
C:\WINDOWS\system32\drivers\etc

In there you will see a file Titled “Hosts” Open it using the program Notepad. Now there are two things you will see. Mine looks like this:

# Copyright (c) 1993-1999 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

This is what you SHOULD see. But After this the virus pastes in a bun ch of web addresses (of all the most common antivirals actually, which stops them from updating). Now there should be a gap between them and the hosts you will actually see. Delete all of these and then resave the file. Now your antivirus will be able to update.

***Some people don’t have the big message like I do. Don’t worry it’s just instructions. Just delete the list of websites and don’t worry about it.

Step 2 – Killing the virus
Now update your Anti-Virus and run it. If it’s a decent quality one it should find the Trojan. If not I suggest installing the free AVG from https://www.avg.com/en-ww/homepage
0
Kay84
 
ok so hold on.. youre telling me this has something to do with the "shell32.dll" and "hosts" problem too?
thats been showing up in my avg for a while but it doesnt see it as a threat (...????)
my avg found these 3 trojans today but it says theyre not "healable"
isnt there a simpler way for me to get rid of them? like thru my msconfig or tune up??
thanks!
0