M
Mitch Evans
We got hit with some type of virus on 4/13/04. It is on
all our XP machines. We have the latest patches and
virus updates. A file named msmscfg.exe is dropped in
the c:\windows\system32 directory as well as in the
registry. All the major virus scanners will not detect
this either. Once dropped the hosts file is modified,
and redirects all requests to the major virus software
vendors back to the local machine. It also will not
allow regedit to be run. It will also disable the real
time virus scanners for Norton, Mcaffee, Computer
Associates etc. If you delete it from the registry and
hard drive, it will come right back, usually after you
see three dos screens flas accros the screen. We have
reported this and have no luck in a solution at this
time. It has infected over 100 of our Windows XP and
2000 machines, and all are patched with the latest
patches.
all our XP machines. We have the latest patches and
virus updates. A file named msmscfg.exe is dropped in
the c:\windows\system32 directory as well as in the
registry. All the major virus scanners will not detect
this either. Once dropped the hosts file is modified,
and redirects all requests to the major virus software
vendors back to the local machine. It also will not
allow regedit to be run. It will also disable the real
time virus scanners for Norton, Mcaffee, Computer
Associates etc. If you delete it from the registry and
hard drive, it will come right back, usually after you
see three dos screens flas accros the screen. We have
reported this and have no luck in a solution at this
time. It has infected over 100 of our Windows XP and
2000 machines, and all are patched with the latest
patches.