A virus is using Yahoo Messenger (ym) or MSN messenger to spread itself.
It sends out messages like
(Don't try any of these links !!!)
* damn, she is so cute http:// nsl-school.org?id=miss_world
* oh my god , i've won a 20000 usd lottery http:// nsl-school.org/?id=winning_list . Come to my house tonight for a party !!
* Just check out my new personal website : http:// mytermex.com c0ol !!!
* check this link for me : http:// nsl-school.org?id=forum . Why I cannot surf this site ???
1. Start>Run>Regedit
From the below locations in Regedit chage your default home page to google.com or other.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main
HKEY_ LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main
HKEY_USERS\Default\Software\Microsoft\Internet Explorer\Main
Just replace the attacker site with google.com or set it to blank page.
2: Now we need to kill the process from back end. Press Ctrl + Alt + Del
Kill the process svhost32.exe . ( may be more than one process is running.. check properly)
3: Delete svhost32.exe , svhost.exe files from Windows/ & temp/ directories. Or just search for svhost in your comp.. delete those files.
( Svchost.exe is a generic host process name for services that run from dynamic-link libraries (DLLs).( meaning there is an original svchost.exe that is part of Windows - http://support.microsoft.com/kb/314056 )
4: Go to regedit search for svhost and delete all the results you get. ( Be careful )
Start menu > Run > Regedit >
5: Restart the computer.
6:It's so simple,as A,B, C ^_^