Swen query

  • Thread starter Thread starter Ron McDowell
  • Start date Start date
R

Ron McDowell

I have been following the steps from Symantec to remove any traces of Swen
worm which appeared over the weekend.They mention a 'random set of letters'
which the worm generates and uses in various contexts. My virus definitions
are now uptodate, no virus is now detected. However I have a question
regarding deleting any remaining values from the registry.
I have no idea what the random set of letters that were generated-the only
file I can find in
HKEY_LOCAL_MACHHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run is of the
form SiSUSBRG. Is this a recognised system file?
I've ran task manager and the only unrecogniseable file I can see is
MsPMSPSv.exe, which is of course of a different form. Does anyone recognise
it?
PC seems to be fine but I'm just wanting to be sure!
Thanks for any info
Ron
 
Ron McDowell said:
I have no idea what the random set of letters that were generated-the only
file I can find in
HKEY_LOCAL_MACHHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run is of the
form SiSUSBRG. Is this a recognised system file?

SiS Corporation sound card driver
I've ran task manager and the only unrecogniseable file I can see is
MsPMSPSv.exe, which is of course of a different form. Does anyone recognise
it?

Process File: mspmspsv or mspmspsv.exe
Process Name: WMDM PMSP Service
Description: Helper Service needed installed by Windows Media Player 7


--

~~~~~~~~~~~~~~~~~~
Dave McAuliffe
<Central Mass> USA
Remove X from address
~~~~~~~~~~~~~~~~~~
 
HKEY_LOCAL_MACHHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run is of the
form SiSUSBRG. Is this a recognised system file?

Video driver patch.
I've ran task manager and the only unrecogniseable file I can see is
MsPMSPSv.exe, which is of course of a different form. Does anyone recognise
it?

Windows Media Player 7 service.
PC seems to be fine but I'm just wanting to be sure!
Thanks for any info

When you're looking for info on a program like the above, it's
usefull to run a google search, without the .exe on the end.

Regards, Dave Hodgins
 
Back
Top