Originally posted by ndmmxiaomayi:The dog can't find both temp1 and temp2.
Can you do a search of temp1 and temp2?[*]Go to Start > Search.
Repeat for temp2.exe[/b]
[*]When the dog asks [b]What do you want to search for?, click All files and folders.
[*]In All or part of the file name, copy and paste temp1.exe in.
[*]Click More advanced options. Check (tick) these boxes:[*]Search system folders
[*]Click Search.
[*]Search hidden files and folders
[*]Search subfolders
Originally posted by Conner MacDermott:can't find both Existenz.exe and Dtreg.exe.
You have quite a few things to do.
First, you need to stop the worm from running. Else, all your efforts at recovery will be undone by the worm.
To [b]STOP the worm,
Log off internet connection
Task Manager -> Processes
Find Existenz.exe and terminate it.
Find Dtreg.exe and terminate it.
If you can't find the EXE, that means it is not running and you can proceed. Now, to destroy the worm..
1) Delete this directory
%windir%\Mirky
2) Delete all these files
Mirc.ini *
%windir%\Mirky\Moni.zip
%windir%\Mirky\Nick.txt
%windir%\Mirky\Dtreg.exe
Remote.ini *
Script.ini *
%windir%\Mirky\Servers.ini
Aliases.ini *
Perform.ini *
Existenz.exe *
* means that they are found where you installed your mIRC.
3) Delete this registry value
Start Menu -> Run -> Type "regedit" -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run -> delete the value for mirky
Your computer should be okay liao..
But, to be on the safe side, scan with your antivirus program.
I'm assuming that you don't have one at the moment so this is a good time to download and scan. The worm is too crippled to do anything so you can go internet now.[/b]
okOriginally posted by Conner MacDermott:Try rebooting your computer.
It will load back svchost.exe
i don't have to do anything to the registry too?Originally posted by Conner MacDermott:You ran a Norton scan?
It should remove and repair any bad stuff already.
You do not need to do anything further.
Vista don't have many compatible drivers yet.Originally posted by boka:I load vista and did a full system scan using norton.they found the trojans and removed it.
i'm not sure if temp2.exe eror are caused by these trojans.
I'm not even sure if it has been resolved.
now i load in to vista and there's not more temp2.exe error but now there's this msg that says svchost.exe cannot be foud.
WTF?
and becuz my notebook has dual chip intel 950 and nvdia 7400,those kids ca't even install those drivers for me!
my programs in xp are lagging so badly!
I do not know where is the xp being installed,is there anyway i can locate it?Originally posted by ndmmxiaomayi:Norton killed your svchost and never replaced it back.
Log in to Vista, go the drive where XP is installed. Find the i386 folder or dllcache folder. Copy and paste svchost back into the system32 folder.
OK, I go step by step.Originally posted by boka:I do not know where is the xp being installed,is there anyway i can locate it?
now i can't even remember how do i go to the partition thingy.