The virus is being typically transported by some bots/people as: DIVX_3e.exe (Remember installing those drivers?) PSXCOPY.ZIP (bleh n64 r00lz) CDRWIN3.8f (cracked) If you've installed these lately , you're probably running the srvcp daemon (do a ctrl-alt-del task manager and look!) and you'll find srvcp.exe in/windows/system and gus.ini (gravis ultrasound rules! hehe) in/windows/system. remove the files. run regedit.exe and remove the service profile for srvcp (find srvcp, delete the entry for service_profile) reboot trojan is gone. The bot will download files to your system, connect to efnet irc servers and will attack others and you'll eventually get our ip banned for running drones. bleh. lamers. rigor-http://sam.bytebandits.com
The virus is being typically transported by some bots/people as: DIVX_3e.exe (Remember installing those drivers?) PSXCOPY.ZIP (bleh n64 r00lz) CDRWIN3.8f (cracked) If you've installed these lately , you're probably running the srvcp daemon (do a ctrl-alt-del task manager and look!) and you'll find srvcp.exe in /windows/system and gus.ini (gravis ultrasound rules! hehe) in /windows/system. remove the files. run regedit.exe and remove the service profile for srvcp (find srvcp, delete the entry for service_profile) reboot trojan is gone. The bot will download files to your system, connect to efnet irc servers and will attack others and you'll eventually get our ip banned for running drones. bleh. lamers. rigor-http://sam.bytebandits.com