Einzelnen Beitrag anzeigen
Alt 31.08.2001, 00:23   #2
g17
Elite
 
Registriert seit: 13.07.2001
Beiträge: 1.339


Standard

Das erfährst Du auf fast jeder Antivirenseite:
__________________________________________________ __________
To remove this Trojan from your system please follow the following steps:

Look for SKA.EXE and SKA.DLL then delete the two files. They are known as TROJ_SKA and TROJ_SKA.DLL respectively. Also, look for HAPPY99.EXE and/or HAPPY00.EXE, or any other file that is detected by our product as TROJ_SKA.
Look for WSOCK32.SKA and WSOCK32.DLL. These two files are normally located in the Windows System directory. Set the attributes of the files from READ-ONLY. This can be achieved by using ATTRIB.EXE or any tool that can manipulate the attributes of the file. Delete WSOCK32.DLL and rename WSOCK32.SKA to WSOCK32.DLL. When the worm executes, it modifies WSOCK32.DLL. The original WSOCK32.DLL is saved in the system directory as WSOCK32.SKA. If WSOCK32.DLL cannot be deleted because it is being used by other programs then restart the computer in DOS mode and then execute the necessary steps.
Run RegEdit. Find SKA.EXE and then delete the key. It is normally located at \\HKEY_CURRENT_USER\Software\Microsoft\Windows\
CurrentVersion\RunOnce. This step should be taken when the PC is not yet rebooted.
__________________________________________________ __________

HTH
g17
g17 ist offline   Mit Zitat antworten