Re: ms32.sys

From: David H. Lipman (DLipman~nospam~_at_Verizon.Net)
Date: 10/24/05


Date: Mon, 24 Oct 2005 07:45:47 -0400

From: "Jnthn" <n@yahoo.com>

| David H. Lipman wrote:
>> Sophos will now catch this as; Troj/DNSBust-C
>>
>> So the Sophos module of the Multi AV Scanning Too
>> can be used as well.
|
| I downloaded Multi AV.
|
| Two files (DNSChanger, trojan.downloader) with similar names were found
| in system32. After going to http://195.95.218.100 to see what it was, I
| noticed a c.vbs file in the root folder. This file and ms32.sys (I had
| put it back in the root dir) were also found and deleted.
|
| I rebooted one hour ago and the computer hasn't shut down by itself
| yet.
|
| Thank you very much for your help.
|

Jnthn:

C O O L !

I am glad to hear that. Thanx for updating the thread.

-- 
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm