I have recently been attacted by this "MSN Virus" which doesn't allow you to search for help, load anti-virus, use the taskmanager, system restore or even MSConfig. I have also noticed that people have told you to use these things such as disabling system processes in MSConfig or something like that but most of us have noticed that it just isn't possible. I have found a possible cure to this bug but it require speed and a keen eye:
Firstly, I tried to load MSConfig, with no luck and then turned my attention to the taskmanager. If you haven't already realised when you load the taskmanager you get around 5 secs before it closes itself, in this time you must click "Processes" and then search for something fishy, I am not entirely sure if it is the same for everyone but I found 3 dodgy processes:
1) csrss.new (csrss is an inportant process and this bug is pretending to be an "update" of it)
2) dark
3) winsp3 (trying to be Windows Service Pack 3 [winsp3], which simply doesn't exist)
After killing csrss.new and winsp3, I found it possible to open everything again, the only problem is that it will only startup again after a system restart. This is where MSConfig comes in, simply click Start -> Run and then type "msconfig" and press enter. Click on the "Startup" tab and then find the dodgy processes, in this case csrss.new, dark and winsp3, deselect them and click "Apply".
Next you need to find these files and delete them before they reattack. So next to the process's name in msconfig there should be a path such as "C:\WINDOWS\vjqinn\csrss.new.exe" go there and immediatly delete these files including those that didn't occur in the taskmanager or in msconfig because they are still important. PLEASE NOTE THAT THESE FILES HAVE BEEN VERY WELL HIDDEN AND WILL NOT APPEAR EVEN WHEN YOU SHOW ALL FILES, you will need to type in the path.
Then you can close MSConfig and RESTART the computer.
----------------------------------
When you have successfully restarted the computer I suggest you run an anti-virus and Ad-aware by lavasoft (avaliable from www.download.com)
Then you must make sure the harmful files have successfully gone by going into the MSConfig and ensuring the files you found earlier are unchecked, thus not harmful.
Now all you have to do is ensure you never click any IM links without knowing if your buddy had actually sent it and only accept file transfers from people you know that don't have extensions such as .exe and .bat.