Originally posted by bladez87:
cant delete svchost cause it is in use.
cant find explorer only got iexplorer
totally cant find ravmond
all done in safe mode
btw how to switch to safe mode? i did the crude method of powering off during boot up.
what is Winpcap?
didnt do the rest. can advice?
You are not supposed to delete svchost because this is a good file. The one you should delete is this: svch
0st. The virus has replaced O with zero (0).
Looks like Symantec managed to keep it in check, none managed to affect you,
The only method to switch to Safe Mode is to off the computer, press F8 and select Safe Mode.
Winpcap is a remote packet capture utility. It captures packets and are widely used by attackers for sniffing. If you didn't install this, you have to uninstall Winpcap.
Go to Start > Control Panel. Double click on Add/Remove Programs. Scroll all the way down and find Winpcap from the list of programs and uninstall it.