-
February 26th, 2002, 11:22 AM
#1
sub7 removal
I've read much about this sub7.....now I'm taking noted on the removal. I found this one site that has a download and is supposed to automatically remove it. I know there are many experts here and I was wondering if someone would check out this site and tell me what you think. Also, if this is not a reliable way to remove it.....what is? Thank you....
www.europe.f-secure.com/v-descs/subseven.shtml
-
February 26th, 2002, 02:34 PM
#2
I told you in your last thread how to completely remove it from your harddrive. Guess you didnt pay attention or you were more concerned with how to send it out and infect some little kids. But I am not going to tell you that.If you dont know then i guess your going to have to find another place to get that info. Now that you have been infected yourself you want it out. SO LISTEN UP!
When the server is executed, the name of the file is changed from what ever it was when you downloaded it.To a random name.(Usually) Example: ksjdhfiuh.exe
The default Server settings tell the server to run in the Win.ini file, and tell to start up @ Windows startup. find it like this.
START>FIND>win.ini>FIND NOW
open the win.ini file and you should see this, on the first few lines.
[windows]
load=
run=ksjdhfiuh.exe
NullPort=None
device=HP LaserJet 2200 Series PCL 6,HPBF3220,\\EVNET6\HPLaserJ2200
You must delete this file from the win.ini file and restart your computer.Just hilight it and select cut. At this point , as windows starts back up, do this.
START>FIND>ksjdhfiuh.exe>FIND NOW
It should find the file. Go-ahead and try to delete it. If that doesnt work, if you cant delete it,
then the program is still running. In this case you should run MSCONFIG.
START>RUN>msconfig
(this is your computers start up utility) Look for the ksjdhfiuh.exe make sure its not set to run at startup.ANYWHERE! Then restart. I would advise checking registry aswell, but I'm not real sure YOU should be poking around there.
Haraam, this is going to be my last reply to your sub7 questions. I have twice now replied with usfull info, and your asking the same questions. Copy this to a txt file, if you can't remember.
It is better to be HATED for who you are, than LOVED for who you are NOT.
THC/IP Version 4.2
-
February 26th, 2002, 03:01 PM
#3
also, there are these things i heard about called antivirus software. some damn new fangled technology those crazy young whipper snappers created. you might want to give that a try. most updated virus sig files can find the piece of shite sub7.
-
February 27th, 2002, 12:38 AM
#4
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|