Requires Free Membership to View
HKEY_CLASSES_ROOT\exefile\shell\open\command
is set to
C:\recycled\sirc32.exe "%1" %*" This change to the registry ensures that the virus runs first each time you try to run any executable. If the removal process used eliminates the sirc32.exe file but does not correct the registry, then no executables will be able to run, as the file no longer exists. To get around this, the file regedit.exe will need to be renamed to regedit.com and the key corrected to read:
@= "%1" %*" There is a batch file that will make this fix available here.
This was first published in July 2001
Security Management Strategies for the CIO
Join the conversationComment
Share
Comments
Results
Contribute to the conversation