I spent most of yesterday battling some nsanti trojan. This little program called jvvo had instaleld and started messing things up. Well I think I’ve got it all sorted out now, except for one very annoying little problem.
One thing the jvvo id was alter the registry so that I can’t view hidden files and folders (and of course, that’s where it was hiding). Changing the settings doesn’t help, it reverts back immediately.
I found this report of what this virus does:
threatexpert.com/report.aspx … 13342e24cc
The most important part is this:
[quote] Registry Modifications
* The newly created Registry Value is:
o [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
+ jvsoft = "%System%\jvvo.exe"
so that jvvo.exe runs every time Windows starts
* The following Registry Value was modified:
o [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
+ CheckedValue = 0x00000000
so that hidden files and folders are not displayed in explorer when browsing the file system [/quote]
So I know how the registry was modified.
Now what d I need to do to modify it back.
Anyone?
(I tried to just do a system restore, but it wouldn’t restore to an earlier point).
PS XP btw
Brian