I spent most of yesterday battling some nsanti trojan. This little program called jvvo had instaleld and started messing things up. Well I think I’ve got it all sorted out now, except for one very annoying little problem.
One thing the jvvo id was alter the registry so that I can’t view hidden files and folders (and of course, that’s where it was hiding). Changing the settings doesn’t help, it reverts back immediately.
I found this report of what this virus does:
The most important part is this:
[quote] Registry Modifications
* The newly created Registry Value is: o [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] + jvsoft = "%System%\jvvo.exe" so that jvvo.exe runs every time Windows starts * The following Registry Value was modified: o [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] + CheckedValue = 0x00000000 so that hidden files and folders are not displayed in explorer when browsing the file system [/quote]
So I know how the registry was modified.
Now what d I need to do to modify it back.
(I tried to just do a system restore, but it wouldn’t restore to an earlier point).
PS XP btw