| O GOD.. YOU GUYS FOUND A DIAMOND IN THE DIRT THAT AINT BEEN FOUND! AS OF THIS POST, no minor/major ANTIVIRUS company has a product to delete W32/Suij.c ! This virus has barely been caught less than 300 times! GIVE ME THE URL TO WHERE I CAN DOWNLOAD IT AND THEN I'LL RUN IT ON MY P.C., see its symptons, and play around with it...
I haven't tested this Virus hands on yet(nor can i find it as hard as i try), so You Probably don't want to use these instructions.
But I'm almost positive this would be how to delete it.
W32/Suij.c virus hides in
C:\Device\harddisk\volume1 \Program files\commonfiles\updmgr\updmgr.exe or
C:\Program Files\Common Files\updmgr\updmgr.exe
and can't be deleted...
NOW WHATS REALLY NEAT ABOUT THIS 'VIRUS' IS THAT WELL, USUALLY
Common Files\updmgr\updmgr.exe IS SUPPOSE TO BE KEENVALUE ADWARE/SPYWARE
distributed by eU.. But I guess they are stepping up their game and now using viruses.
Now In this particular case, to delete W32/Suij.c virus,
use this particular online virus scanner ->
and if for some reason its still there...
Next, Turn off system restore / Restart in Safe mode
Start the registry editor. This is done by clicking Start then Run. (The Run dialog will appear.) Type REGEDIT , CLICK OK
Browse to the key: 'HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run'
In the right panel, delete the value called 'updmgr'
Exit the registry editor.
Start Windows Explorer and delete: %ProgramsDir%\Common Files\updmgr\
And if found delete
rvupdmgr.exe simgr.exe fsg.exe or fsg_4104.exe or any fsg...exe files Note: %ProgramsDir% is a variable ( ?). By default, this is C:\Program Files.
Restart your computer to default mode
CHECK IF ITS STILL THERE, if it is proceed to
open a DOS command prompt window (from Start->Programs->Accessories) and enter the following commands:
cd "%WinDir%\System" regsvr32 /u "\Program Files\Incredifind\BHO\BHO.dll" regsvr32 /u "\Program Files\PowerSearch\Toolbar\pwrs0rbi.dll"
Next, for either variant, open the registry (click 'Start', choose 'Run' and enter 'regedit') and find the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run. Remove the 'KeenValue' entry. Also Delete
HKEY_CURRENT_USER\Software\Visicom Media\PWRS0RBI HKEY_LOCAL_MACHINE\SOFTWARE\eUniverse HKEY_LOCAL_MACHINE\SOFTWARE\KeenValue Delete the 'KeenValue' and 'PowerSearch' keys from HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall can be deleted if you still have them.)
Next, restart your computer and you should be able to delete the 'KeenValue' folder inside the Program Files\Common Files folder. For the Incredifind variant you can also delete the Program Files folders 'PowerSearch', 'Incredifind' and 'Dynamic Toolbar\PWRS0RBI'.
|