Link to home
Start Free TrialLog in
Avatar of YellowbusTeam
YellowbusTeam

asked on

Possible sysvxd.exe virus

Hi,

We have client that is getting an error when clicking through a link in Google, the web launches a seperate page
'16 Bit MS DOS Subsystem'
'C:\WINDOWS\Sysvxd.exe'

Anyone seen this error before? I am gussing that it is some form of virus?

sysvxd.exe-error.doc
ASKER CERTIFIED SOLUTION
Avatar of Vishnu Kiran
Vishnu Kiran
Flag of India image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of YellowbusTeam
YellowbusTeam

ASKER

Hi Surfer24,

Attached is the report our client obtained from the trend micro program you sent us the link to. It has found quite alot of entries, is this now something we need to go through and clear up.

Ta
hijackthis.doc
Hi thebrandednetwork,

The client is currently running NOD32 antivirus business addition, but has no spywear software at present.
What the next step to take if these pieses of software didint find anythig, would it be case of searching through the system to find irregular files.
I would run spybot search and destroy ( www.spybot.com ) and/or tendmicro housecall. If you are in a business environment I would strongly recommend looking into openDNS. Its a free service and easy to setup and any type of junk you may be getting it will keep it off. I will serve as an anti spyware server in a sense.
Hi folks,
Does anyone no anything about the following files and whether these could be the culprits?

O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/CursorManiaInit
ialSetup1.0.1.1.cab -?????

She installed this but could get rid now:
O16 - DPF: {96816368-C1E3-414D-A193-63C3CC921990} (MJPEGRender Control) - http://gretnaweddings-anvilhall.remotemanager.co.uk/common/activex/MJPEGRend
er.ocx

As these are two we pulled out of the Trendmicro hijackthis tool.

Ta