SoftwareTipsandTricks.com
Home Forums Windows 7 Security Tips
Forums

Windows 7
Windows Vista
Windows XP

Security Tips
Troubleshooting
Keyboard Shortcuts
Encyclopedia


Drivers

Internet Terms
Computer Terms

File Extensions (75)
File Extensions (15K+)

Startup Applications
Necessary Files
Useless Files
At Your Option Files
Dangerous Files
Browser Objects

DLL Files
SYS Files
INF Files
OCX Files
VXD Files

Virus Database
Virus Warnings

Easter Eggs
Tips and Tricks
Articles
Hot Downloads


Privacy Policy
Contact Us







  msserv.exe

Name msserv.exe

Description

I-Worm.Hadra
This is an Internet worm that spreads via e-mails being attached as an EXE file.
The worm copies itself to the Windows directory with the MSSERV.EXE name and registers that file in the Windows registry auto-run keys:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServices
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices
msservice = %WinDir%\msserv.exe

The worm then stays in the Windows memory as a service, connects to MS Outlook and registers itself as MS Outlook "NewMail" and "ItemSend" events handler.
When a new mail has arrived, the worm looks as if it is its own message from another infected machine, and then deletes it.
When a message is being sent, the worm looks for already attached files, gets the first one, replaces it with its own copy with .EXE extenstion, and then sends it.
If the message has no attachment, the worm attaches itself with eight bytes of a random name and .EXE extenstion.
The worm disables several types of anti-virus protections, as well as immediately closes Registry editors upon their start-up.

Use antivirus (also check How To Remove section)Startup Opimizer for removal.


Still have a problem? Ask for help at our discussion forum.



Search Dangerous Files :
 

: : Recent posts at Forums : :

papojdlnkq

qnlxxsrvmx

dgfyvxzwbh

uzzhrsgcie

vkltlfkfoj

bidfvviail

qrzgrnbltl

zdpqamzxkc

Matured position

iiclcnyhxw

mzndddngwo

ioqitelefr

lceggjayfe

ntnujztbrk

tqjljfnphx

xllxzlysav

upwexhcnsu

wgwgqlzdjj

shbuxteypa

jecstpbdql

onwaabevtm

tqhzjrbxly

mnsufmetcs

kqngbjmsiz

vtqzwszhap

hsehwygwvw

eademgrikx

Стеклодел Мин

whuyvjhgwa

Lusty men photo blog




SoftwareTipsandTricks, All Rights Reserved.