|
ACID SHIVERS Acid shiver is a pretty bad trojan to become infected with , it has a lot of damaging abilities and should be removed immediately if found The port opened by acid shiver is dynamic , meaning it changes every time the victim comes online and sends the victims ip number and what port has been opened to the hacker by email. Removal instructions : Fortunately removing this trojan is fairly simple. It adds two lines to your registry, both identical. Using regedit, go to the key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and delete the line which reads: Explorer = "C:\WINDOWS\MSGSVR16.EXE" Also go to the key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices and delete the same line above. (Explorer = "C:\WINDOWS\MSGSVR16.EXE") Reboot your computer, and use windows explorer to go to C:\windows\ and delete the file MSGSVR16.EXE Be careful however, as in C:\windows\system\ there are a few files with similar names, which are needed by windows to run. Do NOT delete anything in C:\windows\system\ for this trojan
|
|