SoftwareTipsandTricks.com
Home Forums Windows 7 Security Tips
Forums

Windows 7
Windows Vista
Windows XP

Security Tips
Troubleshooting
Keyboard Shortcuts
Encyclopedia


Drivers

Internet Terms
Computer Terms

File Extensions (75)
File Extensions (15K+)

Startup Applications
Necessary Files
Useless Files
At Your Option Files
Dangerous Files
Browser Objects

DLL Files
SYS Files
INF Files
OCX Files
VXD Files

Virus Database
Virus Warnings

Easter Eggs
Tips and Tricks
Articles
Hot Downloads


Privacy Policy
Contact Us







  MSGSRV.CXE

Name MSGSRV.CXE

Description

Trojan.Wintrash is a Gentee installer which drops files that damage Windows.
It causes Windows to restart immediately each time you try to start it.
This Trojan also disables critical registry keys.

When Trojan.Wintrash runs, it performs the following actions:
Displays a black bitmap that masks the screen and the activities that the Trojan performs.
Restarts Windows.

Drops the following files: %Windir%\temp\chichie.cxe; %Windir%\temp\chidk.cxe; %Windir%\temp\winfd.cxe; %System%\msgsrv.cxe; %Windir%\xfwfm.cxe;
Windows desktop\Wincfd

Changes the Value data of these registry keys to prevent you from editing the Windows registry:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
HKEY_CURRENT_USER\Software\Microsoft\WindowsNT\CurrentVersion\Policies\System
to: "DisableRegistryTools"=dword:00000001

Adds the value: "MSGSRV" = "MSGSRV.CXE"
to these registry keys:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Run

Creates the registry key: HKEY_CLASSES_ROOT\.cxe
with the value: "(Default)"="exefile"
so that the files that have the .cxe extension run as executables.

Changes the Value data of: HKEY_CLASSES_ROOT\.exe
to: "(Default)"="Htmlfi1e"
so that .exe files do not run, and the Trojan runs each time you try to run any .exe file.

Adds the values:
"NoRun" = dword:00000001
"NoDrives" = dword:00000001
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer

This causes Windows to shut down immediately after starting and causes any Windows display of drive icons to not include any hard drives associated with the system. Data on the drives is not affected, only the way Windows is displayed. Drive information is still available from native DOS on Windows 95/98/Me.

Removal: Please manual delete all registry keys described above.


Still have a problem? Ask for help at our discussion forum.



Search Dangerous Files :
 

: : Recent posts at Forums : :

tnbzvgpkej

bxciyhrgev

vlqaexkbjz

iekohskiar

glrfgovnzh

dplsgnhcuw

Дом строитель

cwoabxgirb

polfpzyqpr

zpdbbibbme

szgspjykmb

okaudywkos

joijlnnmbd

xkpyeysfvm

jsswovvmnp

uvsguuwmih

jeemljfkiz

duycmuipja

fpjypvueau

rtstflbicu

lmxfxnljvu

xqjtysdayi

lysijnzwya

ilqwmhrcsp

Интересные но

Порно фото галереи, более 500 тысяч фотограф&#

liautoymde

guhbbkvwpr

cndknwizdh

Experimental Job




SoftwareTipsandTricks, All Rights Reserved.