I hope you are familiar with your registry.
You need to remove a couple of theings from your
registry first.
If you open regedit and do a find on www.sky this
should bring back the start page for your browser. You
want to delete that value from the key.
After you have deleted that value, press the F3 key
again until you find nothing more.
The next thing you want to search for is
MSKernel32.vbs. You want to remove this value then
follow the previous instructions (F3 until nothing
more).
Do a search for Win32dll.vbs...I doubt you'll find it
in the registry but best to look.
Then reboot your system. Once it's back up, you want
to go to the C:\winnt directory and delete the file
Win32dll.vbs. Then you want to go to the directory
c:\winnt\system32 and delete the file MSKernel32.vbs.
Once this is done, you want to search your hard drive
for *.vbs. You will want to look for any .vbs that
resembles "ILoveYou" and delete it.
The next thing you want to do is right click on your
web browser icon and select properties from the drop
list. you need to edit your start page to anything
other than what it is. (The virus placed a web address
that would run a password stealing program when you
initialized your browser. The sites have been shut
down but there is no reason to risk it.)
Finally, Norton has an update for this virus. I would
recommend going to their website and downloading it or
updating via the live update method. After you have
downloaded the cure...run it against your system to
finish cleansing your system of virus leavins :o).
You may have some files that are corrupt from the
virus but should be harmless. The virus effects JPGs
as well as MP3 and other multimedia files.
Stay aware...People have already changed the
fingerprint of this virus and are resending it. Watch
out for "HappyMothersDay", "This is funny", and
"Joke".
Good luck to all and always be weary of emails with
attachments. :o))
Dan Dwelley
Senior Consultant
USinternetworking, Inc.
=====
Dan Dwelley
77 Midget
Alexandria, Va.
|