Replicator
New Member
AAG got the worst virus I have ever seen on one of our computers this morning.
it was called SMSS32.EXE, only I didn't know that because it disguised itself as WORM.WIN32.SPYNET and it
disabled the TaskMgr, the Regedit and all other spyware tools to try and remove it . . . I really thought it had me beat.
I couldn't boot into SafeMode either and if I attemped to launch ComboFix the system froze . . . I was truly ready to give up.
I tried re-enabling the TaskMgr through several command line options that were unsuccessful and then I found
a great utility called : xp_emergencyutil.exe (http://www.dougknox.com/xp/utils/xp_emergencyutil.zip) which places copies of the TaskMgr, Regedit and MSConfig
in a C: directory folder. The virus doesn't know to block those copies, so I finally gained access.
I found the running app SMSS32.EXE and also found a second virus on it's coat tails called IS2010.EXE which is
a fake internet security 2010 app that is also hard to abolish, but once I had access to those exe's I was able to
shut them down and begin the removal process using MalwareBytes.
It took a long time, but there has never been a virus that I could not defeat, so I'm glad my record stands at 100%.
NOTE : Apparently AVG vanished off of the computer somehow
I have since put Microsoft Security Essentials on this machine which I have found to be a very dependable program.
it was called SMSS32.EXE, only I didn't know that because it disguised itself as WORM.WIN32.SPYNET and it
disabled the TaskMgr, the Regedit and all other spyware tools to try and remove it . . . I really thought it had me beat.
I couldn't boot into SafeMode either and if I attemped to launch ComboFix the system froze . . . I was truly ready to give up.
I tried re-enabling the TaskMgr through several command line options that were unsuccessful and then I found
a great utility called : xp_emergencyutil.exe (http://www.dougknox.com/xp/utils/xp_emergencyutil.zip) which places copies of the TaskMgr, Regedit and MSConfig
in a C: directory folder. The virus doesn't know to block those copies, so I finally gained access.
I found the running app SMSS32.EXE and also found a second virus on it's coat tails called IS2010.EXE which is
a fake internet security 2010 app that is also hard to abolish, but once I had access to those exe's I was able to
shut them down and begin the removal process using MalwareBytes.
It took a long time, but there has never been a virus that I could not defeat, so I'm glad my record stands at 100%.
NOTE : Apparently AVG vanished off of the computer somehow
I have since put Microsoft Security Essentials on this machine which I have found to be a very dependable program.