tasklist.org
A comprehensive list of processes running in your computer
tasklist
|
attachlist
bookmark this website!
total tasks: 16297
AttachList is a list of email attachment files that viruses usually send in email. It contains the attached file names, typical subjects and messages, the name of the viruses that send them, and instruction on how to remove these viruses.
search
most requested
ISUSPM.exe
ctfmon.exe
svchost.exe
AresLite.exe
alg.exe
gcasDtServ.exe
csrss.exe
ccApp.exe
jusched.exe
csrss.exe
Browse
attach
list
by file name
:
|
a
|
b
|
c
|
d
|
e
|
f
|
g
|
h
|
i
|
j
|
k
|
l
|
m
|
n
|
o
|
p
|
q
|
r
|
s
|
t
|
u
|
v
|
w
|
x
|
y
|
z
|
Name:
W32.HLLW.Merkur
Sender:
Varies.
Subject:
Update your Anti-virus Software
Message:
Here is a patch for your AV software, it will cover all the latest out breaks of worms ect (worms as in virus not earth worms! lol)
Attachment:
Taskman.exe
Comments:
A mass-mailing worm that uses Microsoft Outlook to send itself to all contacts in the Outlook Address Book. It also attempts to spread through the KaZaA, Bearshare and eDonkey file-sharing networks, as well as through mIRC
Symptoms:
Copies itself as the following: C:Autoexec.exe C:WindowsScreensaver.exe C:WindowsSystemAvupdate.exe C:Program FilesUninstall.exe C:Program FilesKazaaMy Shared FolderIpspoofer.exe C:Program FilesKazaaMy Shared FolderVirtual Sex Simulator.exe C:Program FilesBearshareSharedIpspoofer.exe C:Program FilesBearshareSharedVirtual Sex Simulator.exe C:Program FilesEdonkey2000IncomingIpspoofer.exe C:Program FilesEdonkey2000IncomingVirtual Sex Simulator.exe NOTE: It can copy itself into the KaZaA, Bearshare, or eDonkey folders only if the folder already exists. Also overwrites the following files with a copy of itself: C:WindowsTaskman.exe C:WindowsNotepad.exe Adds the value AVupdate C:WindowsSystemAVupdate.exe to the registry key HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun
Recommended Cleanup Software:
We found that
Easy SpyRemover
is the most effective tool for removing this file.
Manual Removal Instructions:
Update the virus definitions.
Restart the computer in Safe mode.
Run a full system scan, and delete all files that are detected as W32.HLLW.Merkur@mm.
Remove the valueAVupdate C:\Windows\System\AVupdate.exefrom the registry keyHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
Restore C:\Windows\Taskman.exe and C:\Windows\Notepad.exe, if necessary.
© Copyright 2004, TaskList.org. All rights reserved. Portions copyright by
Paul Collins
(Pacs Portal).
Disclaimer
.
Links