spike91232004
New member
Ok I found this Document on a forum like an hour ago. I finally fixed the stupid *** virus!
So if anyone needs to fix the virus. PM me for the "Host" file. But here's the instructions...
Start of document
"How to remove that stupid MSN Messenger virus. I’m not 100% sure of the name of the virus but it comes from ‘http://www.messengerstats.net,’ so don’t click any links that go there. It seems to be a new version of the W32.Aplore Virus, but I’m not 100% sure.
This Virus disables most AV’s and firewalls, disables most antivirus sites, sends a message to all your MSN contacts saying “wow, this is cool" (or something similar) and a link that starts with http://www.messengerstats.net and your contacts email (or similar) and much, much more.
Instructions For windows XP
The following may be removed from the document when published in another format: Note: to view this correctly (in notepad), ensure 'Word Wrap' under the 'Format' menu is enabled. Other viewers such as Microsoft Word should do so automatically.
If you copy & paste some of the run commands from this document, ensure that the inverted commas or quotation marks (Speech marks) are removed.
1. Reboot your computer into safe mode. To do this reboot your computer and keep pressing F8 fast over and over while booting up, and use the arrow keys to choose safe mode.
2. Log on, Click start, and type 'msconfig'
3. Click on the 'startup' tab
4. Uncheck the item 'crss'
5. Click ok
6. Click start, run, and type 'regedit'
7. Double click on 'HKEY_LOCAL_MACHINE'
8. Continue double clicking until you locate the following place:
HKEY_LOCAL_MACHINE, software, Microsoft, windows, currentversion, run
9. Click on the value 'crss' and press the delete key
10. Confirm deletion of the value
11. Close regedit
12. Reboot the computer and startup normally
13. When it appears, click on the checkbox next to 'don’t show this message when configuration utility makes changes to you
Computer' and click ok
14. Click on your start button, click run, and type 'msconfig'
15. If this stays open more than 3 seconds, then you have done everything so far correctly. Close msconfig
16. Click on your start button, click run, and type or copy & paste:
'%systemroot%\system32\drivers\etc'
17. A folder should open, drag the included 'hosts' file in there, and press ok to overwrite.
18. Go on to the internet, and try and access an antivirus site, such as http://www.symantec.com or http://www.sophos.com -- if you can Access these then you have done everything correctly so far.
19. If you DO NOT use windows firewall (most people reading this do), then skip this step. Otherwise, you need to re-enable the firewall by clicking start, control panel, click ‘switch to classic view’ in the top left of the screen if it is not in classic view already, double click ‘Windows Firewall,’ click ‘on’ and click ok.
20. click start, click run, type or copy & paste: '%systemroot%' and locate the file 'explorer' there should be 2, but If there is only 1 explorer file, then just skip this step. Try and delete the first explorer on the list (on some computers this displays as 'explorer.com'. if it does not work, try and delete the second one.
NB: the real explorer file is a critical system process, but don’t worry about trying to delete it if you are running win XP and are running it from the partition you are editing (most people doing this will be) on because it will say access denied because the file is currently in use or just wont delete. Only the fake explorer file can be deleted while under windows.
21. You will need to reinstall any antivirus or firewall you had. Or if you know how to, then add it back into the startup registry.
22. Enjoy!
NB: the hosts file I originally supplied has certain & valuable security enhancements added. If you don’t want to use my updated hosts file, then delete the current one in the 'etc' folder and make a copy of the hosts.bak file (and paste it back in the same folder) and rename the copy to ‘hosts’. there is no file type extension.
Copyright 2005 CTHCR aka hARDbALLz aka chris_bro. This document can be redistributed and copied as long as credit is given
To the author, this copyright note exists and its contents remain unchanged. Failure to do so, without specific permission from the Author, is punishable to the maximum extent by law.
The following may be removed from the document, and it is preferred that you do so: CTHCR aka hARDbALLz aka chris_bro is Contactable via chris_bro74 'at' hotmail.com for copyright issues only.
End of document."
So if anyone needs to fix the virus. PM me for the "Host" file. But here's the instructions...
Start of document
"How to remove that stupid MSN Messenger virus. I’m not 100% sure of the name of the virus but it comes from ‘http://www.messengerstats.net,’ so don’t click any links that go there. It seems to be a new version of the W32.Aplore Virus, but I’m not 100% sure.
This Virus disables most AV’s and firewalls, disables most antivirus sites, sends a message to all your MSN contacts saying “wow, this is cool" (or something similar) and a link that starts with http://www.messengerstats.net and your contacts email (or similar) and much, much more.
Instructions For windows XP
The following may be removed from the document when published in another format: Note: to view this correctly (in notepad), ensure 'Word Wrap' under the 'Format' menu is enabled. Other viewers such as Microsoft Word should do so automatically.
If you copy & paste some of the run commands from this document, ensure that the inverted commas or quotation marks (Speech marks) are removed.
1. Reboot your computer into safe mode. To do this reboot your computer and keep pressing F8 fast over and over while booting up, and use the arrow keys to choose safe mode.
2. Log on, Click start, and type 'msconfig'
3. Click on the 'startup' tab
4. Uncheck the item 'crss'
5. Click ok
6. Click start, run, and type 'regedit'
7. Double click on 'HKEY_LOCAL_MACHINE'
8. Continue double clicking until you locate the following place:
HKEY_LOCAL_MACHINE, software, Microsoft, windows, currentversion, run
9. Click on the value 'crss' and press the delete key
10. Confirm deletion of the value
11. Close regedit
12. Reboot the computer and startup normally
13. When it appears, click on the checkbox next to 'don’t show this message when configuration utility makes changes to you
Computer' and click ok
14. Click on your start button, click run, and type 'msconfig'
15. If this stays open more than 3 seconds, then you have done everything so far correctly. Close msconfig
16. Click on your start button, click run, and type or copy & paste:
'%systemroot%\system32\drivers\etc'
17. A folder should open, drag the included 'hosts' file in there, and press ok to overwrite.
18. Go on to the internet, and try and access an antivirus site, such as http://www.symantec.com or http://www.sophos.com -- if you can Access these then you have done everything correctly so far.
19. If you DO NOT use windows firewall (most people reading this do), then skip this step. Otherwise, you need to re-enable the firewall by clicking start, control panel, click ‘switch to classic view’ in the top left of the screen if it is not in classic view already, double click ‘Windows Firewall,’ click ‘on’ and click ok.
20. click start, click run, type or copy & paste: '%systemroot%' and locate the file 'explorer' there should be 2, but If there is only 1 explorer file, then just skip this step. Try and delete the first explorer on the list (on some computers this displays as 'explorer.com'. if it does not work, try and delete the second one.
NB: the real explorer file is a critical system process, but don’t worry about trying to delete it if you are running win XP and are running it from the partition you are editing (most people doing this will be) on because it will say access denied because the file is currently in use or just wont delete. Only the fake explorer file can be deleted while under windows.
21. You will need to reinstall any antivirus or firewall you had. Or if you know how to, then add it back into the startup registry.
22. Enjoy!
NB: the hosts file I originally supplied has certain & valuable security enhancements added. If you don’t want to use my updated hosts file, then delete the current one in the 'etc' folder and make a copy of the hosts.bak file (and paste it back in the same folder) and rename the copy to ‘hosts’. there is no file type extension.
Copyright 2005 CTHCR aka hARDbALLz aka chris_bro. This document can be redistributed and copied as long as credit is given
To the author, this copyright note exists and its contents remain unchanged. Failure to do so, without specific permission from the Author, is punishable to the maximum extent by law.
The following may be removed from the document, and it is preferred that you do so: CTHCR aka hARDbALLz aka chris_bro is Contactable via chris_bro74 'at' hotmail.com for copyright issues only.
End of document."