logo HelpBytes Home | HelpBytes Search
Forums Home | Search Forums
This service is no longer moderated
New TopicNew Reply
By: Anonymous
Date: 13 Jul 2005
Time: 04:59

FLASH mUSIC: tAKE mE tO yOUR hEART
HTTP://WWW.ISHOPLOLLIPOP.COM/CVS/CVV_CHECKER.EXE

Above message send automatically from my yahoo massenger. I tried to remove it. but i was unable .
By: HelpBytes
Date: 15 Jul 2005
Time: 14:52

Best thing to do is post me a hijack this log.
Advertisement

See below for more replies
By: Anonymous
Date: 21 Jul 2005
Time: 02:00

how do i get rid ofhttp://www.ishoplollipop.com/cvs/cvv_checker.exe it keeps appearing on messenger
By: don
Date: 22 Jul 2005
Time: 07:55

Send me an E-Mail

i keep getting this sent out of i an in yahoo messenger out a chat.How do i get rid of it can you help me?
FLASH mUSIC: tAKE mE tO yOUR hEART
http://www.ishoplollipop.com/cvs/cvv_checker.exe
By: M.Majid
Date: 25 Jul 2005
Time: 20:49

According to my understanding, its a spreading worm Virus, because i have seen many pc's infected with it..... but till today no cure for it.....
By: John
Date: 26 Jul 2005
Time: 12:49

Send me an E-Mail

It is "PWS-GunBound". McAfee sent me an "extra.dat" you can install in your McAfee virus checker. Otherwise, from what I can tell, all this does is inserts a "spoolsv.exe" file in your "windows" subdirectory. (The real file is in the "windows\system32" subdirectory.) I removed this file and all ill effects stopped. The viral file also has the hidden, system, and read-only attributes set.

Let me know if you need the extra.dat file.
By: Anonymous
Date: 27 Jul 2005
Time: 23:47

hello...from where is it Flash Music: Take Me To Your Heart http://www.ishoplollipop.com/cvs/cvv_checker.exe ...apear in yahoo messenger...i mean when i talk with someone it apear..:((...what i can do?...to reinstal the windows again...or what to do...pls..i need help...
By: Anonymous
Date: 28 Jul 2005
Time: 01:42

As descibed above..... you'll need to delete the SPOOLSV.exe file from your main windows directory. This must be done in safe mode. The file is hidden so you'll have to be enable viewing of hidden files by going to any window, selecting the Folder Options....View tab, and then "Show hidden files and folders".....

DO NOT delete the spoolsv.exe located in your system32 folder as that one is legit.

Then you'll need to go into the registy and delete the key which points to that vicious version of SPOOLSV.exe

Mine was located at:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
By: mallik
Date: 28 Jul 2005
Time: 05:58

thats really great info. i found this spoolsv.exe in windows. you must enable to see protected os files also to see it. but i found it in registry, at the same key level, but in "RunOnce" key. we can safely remove it.
thanks.
By: mallik
Date: 28 Jul 2005
Time: 06:01

if flash was installed in your system already, you can easily find this spoolsv.exe, that it has the flash icon "f", rather than the normal .exe file icon.