Showing posts with label antivirus. Show all posts
Showing posts with label antivirus. Show all posts

Wednesday, April 01, 2009

How to Diagnose, Prevent and Treat the Conficker worm


The Conficker worm has infected millions of Windows computers—and is set to be unleashed on April 1st, 2009. Here's what you need to know to keep yourself safe.

Symantec's got a pretty simple (and free) tool specifically for Conficker: Download this file on an uninfected computer, follow the steps, and you should be okay. (If you can't get to Symantec or other security sites, that's a good sign you've got Conficker.) Also, via PC Mag, here's the Conficker Working Group's page of repair of tools

Here is what LifeHacker says about it.

How Does It Spread?

The worm originally started spreading using a network attack against the file sharing services in Windows, but since it can automatically update itself, it adapted to spread through the autoplay feature on removable media like USB thumb drives, by adding a new option to open where you see "publisher not specified". This allows the worm to spread to systems already patched against the original vulnerability, so using anti-virus software is even more important, because once it's on your computer it can spread further.

Is My Computer Affected?

Most anti-virus software has already been able to detect and remove the Conficker worm for a while now, so you are probably not at risk as long as you keep up with your updates and have real-time scanning enabled.

To actually detect and remove the worm, you can use the freely available Microsoft Windows Malicious Software Removal Tool that can remove a large number of viruses—for a full guide, I've also written an article on how to scan and remove malicious viruses.

How Do I Stay Safe?

Staying safe from this, and many other viruses and worms, requires a combination of keeping your computer updated and using anti-virus software. Here's a couple of quick tips to follow:


Keeping your system and your data safe is extremely important, so make sure to take some time out of your day to keep your system patched, updated, and virus-free. Hit the link for Microsoft's explanation of the situation, or check out my article on scanning and removing malicious viruses for the walk-through approach.

Tuesday, February 12, 2008

Legitimate websites spreading viruses after being secretly hacked

(CNN) -- Internet researchers were scratching their heads over an attack that targeted some of the most popular sites on the Web with a trojan virus that exploits flaws in Microsoft's Internet Explorer Web browser.
The malware or virus doesn't affect Firefox, though it's probably because only Internet Explorer has all those security problems.

Several websites on the internet ( Web security company ScanSafe has reported a new mass infection of websites, which it claims accounts for 15% of the web traffic the company blocks.) are being targeted by unknown hackers.

They secretly hide a javascript code in the main pages of the website which detects which browser you are using and if it is Internet Explorer, it sends you a virus.

The script looks for various vulnerabilities specific to the visiting OS, and when it finds one pulls a .Mov file from the domain dedicated.abac.net. That in turn invokes a file from bds.invitations.fr, which installs a backdoor on end users' machines. Victims are unlikely to know they've been infected because the installation is clear and seamless, and the malware uses few PC resources. At last check, only three of 33 antivirus programs detected the malware, which appears to be a derivitive of the Rbot Trojan.

The outbreak coincides with another mass infection in progress that's infected tens of thousands of pages, including those of Boston University, security provider Computer Associates, and agencies from the state of Virginia and the city of Cleveland. It infects websites running Microsoft's Internet Information Server web program and the company's SQL database with links the redirect users to servers in China. The malicious sites then try to install keylogging software and other nasties.

Thanks to Mary Landesman of ScanSafe for the initial report on the topic

Wednesday, January 23, 2008

Hardware : USB antivirus

Do you get some virus anywhere you take your USB drive ?

Did my critical data in flash drive get erased by a virus ?

How do you prevent viruses and trojans from a computer and from USB drives ?

Here is the USB solution - USB antivirus.

It is not very useful for me - I don't need hardware to remove viruses. I use software - I'll tell you how in a future article on www.fundazone.com or johndasfundas.blogspot.com

But for those who can afford it and need to keep their data safe from viruses, trojans and spyware, this may be useful.

If you use your pen drive in many different computers it is safe to have the latest antivirus updated definitions. Still some new viruses may escape.

This USB pen drive antivirus removes viruses from your computer

Thursday, January 03, 2008

Another virus in orkut !

Orkut.com, the social networking community owned by orkut is being used by hackers to spread another virus which posts a "p0rn" video on your scrapbook and the following message.

Fizeram uma festinha na casa da Priscila, só que ela bebeu demais
perdeu a vergonha e tirou a roupa, ai a galera nao dispensou
tiraram muitas fotos dela e colocaram na internet.
até que ela é bonita, olha ai o novo album dela rsrs..
depois me fale o que achou..

clique na imagem para ver o slide completo



If you get a scrap like this, immediately alert the friend who scrapped you to tell all his/her friends not to click on it and that IT WAS FROM A VIRUS, not from them.

To remove the virus
Download and install this software called BankerFix

Run it and remove the virus.


Warn all your friends who might be infected.
To easily scrap all your friends use this

Orkut-Scrap many or all friends at once


remove the virus using one of the virus removal tools from the next post or the sidebar

Friday, September 07, 2007

Did any of you get a virus that said :
http://www.fundazone.com/2007/06/how-to-remove-use-internet-explorer-you-dope-i-dnt-hate-mozilla-but-use-ier-or-else-svchostexe-heap41a-virus/


"ORKUT IS BANNED,Orkut is banned you fool`,The administrators didnt write this program guess who did??`r`r MUHAHAHA!!"

"USE INTERNET EXPLORER YOU DOPE,I DNT HATE MOZILLA BUT USE IE `r OR ELSE…”

It is a virus that blocks orkut, youtube and firefox. Don't worry

Here is the cure to remove that virus

http://www.fundazone.com/2007/06/how-to-remove-use-internet-explorer-you-dope-i-dnt-hate-mozilla-but-use-ier-or-else-svchostexe-heap41a-virus/


USE INTERNET EXPLORER YOU DOPE,I DNT HATE MOZILLA BUT USE IE `r OR ELSE…

Another virus which wants to waste my time. I didn’t think hackers would write a virus to attack firefox. Anyway, I used Internet Explorer (IE means Internet Explorer) and typed in www.orkut.com

Yet another message “ORKUT IS BANNED,Orkut is banned you fool`,The administrators didnt write this program guess who did??`r`r MUHAHAHA!!

What about www.youtube.com ? That is banned too !!!

It’s just a worm, a virus or a trojan or whatever malicious hacker or craker program or script it is. Wrtitten is VBScript programming labguage by a crazy rascal who deserves to rot in his/her grave for disabling Firefox of all softwares !

How to remove the Orkut and Firefox and Youtube banning virus ?

Simple.

  • First press Control-Alt-Delete (Ctrl-Alt-Del is called the three finger exercise in Windows)
  • There Click Processes , then click User Name to arrange according to users.
  • Now, look for svchost.exe run by User name “user” or “admin” or “your computer name” There will be two of them. Right click and end both the svchost.exe processes where the User Name is NOT “SYSTEM” or “NETWORK SERVICE” or “LOCAL SERVICE” Only where the user name is “USER” or “ADMIN” or “ADMINISTRATOR” or “your name”
  • Next Click Start > Run > Type cmd in the box and press enter (Just get the Command Prompt of DOS - C:\windows\system32\cmd.exe)
  • There in the black Command Line, type “ cd \ ” and press Enter
  • It has to change to C:\>
  • Next, type attrib -s -r -h heap41a /s /d and press Enter
  • Then Open C: on My computer and delete the folder heap41a ie C:\heap41a
  • Then remove C:\heap41a\svchost.exe shortcut from C:\Documents and Settings\USER\Start Menu\Programs\Startup (Or Start > All Programs >Startup)
  • That’s all
  • Then clean the pen drive

Wednesday, April 25, 2007

Are you infected or Not ? Most likely you are !!! (If you are a computer)

Are u infected ? No, not you. I'm talking to your computer.

Is your computer infected by viruses and trojans and worms and bacteria (oops, not bacteria)

COMPUTER VIRUS Are you as infected as the rest of us?

Ever wondered why your PC is getting so slow? Or how did those annoying popups get in your internet browser? Well… You probably have some kind of malware in your computer.

Do you want to know if your computer is infected? The extent of the infection and what type of infection it is(Adware, Trojans, Hacking Tools, Worms, Spyware)?

Luckily, there is this new website www.infectedornot.com which allows you to scan your computer for virus.

They offer two free security tools: one they call Panda Nano Scan and another one called Panda Total Scan. The Nano Scan tool is designed to quickly diagnose your PC in about a minute. The Total Scan takes between 5 and 10 minutes. The main difference between these two tools is that the Total Scan (the one that takes a little bit more time) also checks for latent malware and not only active malware. This is useful information, since most of the computers are infected with latent malware.

InfectedOrNot.com also displays statistic information about the level of infection in all the tested computers. And, of course, more than half the users had some kind of infection. It is really much more common than you think.

In short: you should really go to InfectedOrNot.com and check your computer with either the Nano Scan or the Total Scan tool. Chances are you are already infected. It can't hurt to know.


Check out this website and find out what it has to offer. And if you are infected, know that you are just one among the 70% of computers that are infected.

Go heal ! Heal yourself from viruses, worms and trojans and malware and spyware and bots and rootkits and ....(whew, the list is long huh ?)

Sunday, April 15, 2007

PFW.exe in flash drive pfw.pif and autorun.inf - virus

PFW.pif was a hidden file I first saw in a pen drive (also variously called flash drive to thumb drive to thumbnail drive)

Anyway the hidden file is labelled as an MSDOS shortcut but it is a trojan or worm or virus or whatever.

How does PFW .pif spread ?
It has an autorun.inf file also in the root folder of the pen drive.

How do you remove it ...

If you have AVG free edition 7.5 installed and have the latest virus definitions, it is more than enough.

I'm not sure about Norton but if it is not updated, I guarantee that it will NOT catch this virus.

Manually remove the virus if you can !
Follow these steps
  1. Press Ctrl-Alt-Del . Task Manager opens. Choose Processes. Select PFW.exe . And click End Task
  2. Right click and Open Pen Drive (Autoplay will run the virus - Don't double click)
  3. Delete Pfw.pif and autorun.inf from the pen drive
  4. In My Computer, click Tools> Folder options> View - Show hidden and system files
  5. Delete C:\windows\system32\pfw.exe (it's a hidden file)
  6. Registry (Type regedit in Start >Run) Go to > HKCU>Sofrware>Microsoft>Windows>Current version>Explorer>Mountpoints2>(crazy names)
    1. Make backup of registry (right click Mount Points 2 and export file)
    2. Delete the names in mountpionts2 which are just a string of letters and numbers (not all of them are harmful, but this is easier) Don't delete C, D,E etc
    3. All finished. pfw.pif / pfw.exe is gone from your computer. Delete the virus from all the pen drives.
    4. Or to be careful , delete only the subkeys Shell which have Autoplay as default value (I'll explain this in detail later)
    5. http://www.johndasfundas.blogspot.com

Friday, April 13, 2007

Friday 13th virus South African VirusB

Virus
File Infector
Discovery Date 11/01/1987
Length 512 Bytes

Aliases

  • SouthAfrican
  • VirusB

Friday 13th is a file infecting virus. It does not become memory resident. This virus only infects .COM files. Although it does not infect COMMAND.COM.

Each time an infected file is executed, the virus looks for two other .COM files on the C: drive and one on the A: drive, if found they are infected.


The original Friday 13th COM virus first appeared in South Africa in 1987. Unlike the Jerusalem (Friday the 13th) viruses, it is not memory resident, nor does it hook any interrupts. This virus only infects .COM files, but not COMMAND.COM. On each execution of an infected file, the virus looks for two other .COM files on the C: drive and one on the A: drive, if found they are infected. This virus is extremely fast, and the only indication of propagation occurring is the access light being on for the A: drive, if the current default drive is C:. The virus will only infect a .COM file once. The files, after infection, must be less than 64K in length. On every Friday the 13th, if the host program is executed, it is deleted.


Symptoms

The only indication of propagation occurring is the access light being on for the A: drive, if the current default drive is C:. The files, after infection, must be less than 64K in length. Infected files increase in length by 512 bytes.

On every Friday the 13th, if the host file is executed, it is deleted.

Spread

The only way to infect a computer with a file infecting virus is to execute an infected file on the computer. The infected file may come from a multitude of sources including: floppy diskettes, downloads through an online service, network, etc. Once the infected file is executed, the virus may activate.

WordMacro/Friday Friday the 13th virus in Microsoft Word with password

NAME : Friday
ORIGIN: Germany

WordMacro/Friday consists of several macros, all of which start with the text 'NOP'. However, the virus is not related to the WordMacro/NOP virus.

On every Friday the 13th the virus renames IO.SYS to I_O.SYS, making the machine unbootable if the operating system is Windows 3.x or Windows 95. On Friday the 13th the virus also encrypts all saved files with the password "Friday13".

In addition, the virus exits Windows between 11:00 and 11:59 on Saturdays, encrypts documents with a password equal to the last three letters of the document name on Saturdays, protect the document with a password equal to the first 4 characters of the document name on Thursdays before 11 or on Wednesdays, exits Windows on Wednesdays after 23:00, etc.

WordMacro/Friday was reported to be in the wild in Germany in January 1997.

Friday, April 06, 2007

stimon.exe - Virus or hoax

> From: President George W. Bush

> Email: president@whitehouse.gov
> File: STIMON.EXE
> Located in Windows\System folder

> Status: Dangerous

> STIMON.EXE: This program is a tool of terrorism that is installed to turn
> Americans into members of AlQuada using subliminal messaging. These
> messages are delivered to the computer user via screen pixel manipulation
> and also adds audio overlay tracks into all commonly used system
> audification sounds. The object is to brainwash Americans into supporting
> world terrorism and backing the Iraq government to destroy the United
> States of America. God Bless America

> If this file is commonly found in all versions of Microsoft Windows from
> Win95 to XP. If you find STIMON.EXE on your hard drive, remove it
> immediately.

This is a hoax. If you delete stimon.exe you may disable your
scanner.

Stimon.exe enables a USB still-image device (such as a scanner) to
initiate data transfer to a program. For example, if your scanning device
has a scan button, it may start a program and begin scanning when you
press it. Create a shortcut and start it manually when needed if your
scanner otherwise fails to scan. May be required for your USB scanner to
work - including all HP scanners and some of their SCSI scanners

Saturday, March 31, 2007

Virus links in Orkut Scrapbook and testimonials



These are some of the links used by the viruses which spread though Orkut.

If you see such a link on your scrapbook or testimonial , don't click on it. Tell everyone who sent that scrap or testimonial that their computer is infected and they need to remove the virus.

Get a free Norton Security Scan, Spyware Doctor Starter Edition from the Google Pack on my blog sidebar !

http://my-own.net/asdf2007


urlcut.com/rndx
This is the screensaver version


Uses urlcut.com links
To remove it
Disable screensaver first.
Search and delete a file called imagens_site.scr

This is how to remove the virus :
http://johndasfundas.blogspot.com/2006/07/how-to-remove-orcu-virus.html
http://johndasfundas.blogspot.com/2007/03/contagion-worms-spreading-via-orkutcom.html

Friday, March 30, 2007

Testimonial and scrapbook orkut viruses

Testimonials and Scrapbooks affected by virus spreading via Orkut

Opa , como está? Olha, vazou na internet imagens amadoras do garoto João Hélio que foi cruelmente morto por assaltantes do RJ ao ficar preso ao cinto de segurança do carro de sua família que fora roubado. O Brasil todo está comovido com o ocorrido, rezemos por ele!
Para ver as imagens, copie o link e cole no navegador: tinyurl.com/yompks
Tenha uma ótima semana!!!Chdd\ arZro`^ cn`rghm\tinshm^`m`+sm_rq).mjboY44.kgi


Got this message in a scrap ? It's from a virus. Tell the person who sent it to you that their computer is infected.

Use an antivirus ! Update it freequently - Use the Google Pack to install Norton Security Scan & Spyware Doctor Starter Edition - Available as free download from my blog sidebar - Look on the right !

Remove Orcu virus from your computer as given here :
http://johndasfundas.blogspot.com/2006/07/how-to-remove-orcu-virus.html

This is what you get translated from Portuguese !
The gibberish from the automatic web traslater at google or Babel fish looks like :
Opa, how are you? It looks at, leaked in the Internet amateur images of the boy João Helium that was cruel died for assailant of the RIO DE JANEIRO when imprisoned being to the belt of security of the car of its family that it are stolen. Brazil all is comovido with the occurrence, prays for it! To see the images, it copies link and it glue in the navigator: tinyurl.com/yompks Has an excellent week! Chdd \  arZro `^  cn `r  ghm  \ tins  hm  ^ `m `+sm_rq) .mjboY44.kgi
It's a bad translation- I'll get the proper one later ...
Can anyone translate for me ?

Another one :
(Using of "Você" suggests Brazilian )

Você é uma pessoa especial.
Deixo este depoimento aqui para expressar minha amizade, com uma mensagem linda que serve como lição de vida para qualquer pessoa.
http://tinyurl.com/yompks
Viva a vida enquanto pode!
"You are a special person. I am leaving this comment here to express my friendship, with a nice message which serves as a life lesson to anyobe.
(website address given)
Live life while you can!! (i.e. Live life to the full!)
More :
Oi , como vai? Olha só, encontrei umas fotos do seu perfil num site de encontros, mas com o nome de outra pessoa, é bom vc dar uma olhadinha nisso, pois é realmente muito estranho. Tirei uma foto da página, para caso ela seja removida antes que veja.
O link da página é urlcut.com/muyt1
Copie-o e cole no navegador para visualizar.
Assim que tiver visto, me confirme se não é um equívoco.
Abraços!



"Hi, how's it going? Look, I found some photos from your profile on a meeting site, but with someone else's name, anyway, just take a look at it, it's really weird. I took one photo from the page just in case it got deleted before you see it. The link for the page is
linkezy.com/1nc


http://johndasfundas.blogspot.com/2007/03/testimonial-and-scrapbook-orkut-viruses.html

urlcut.com/rndx
urlcut.com/muyt1

Tries to install imagens_site.scr WHICH IS A VIRUS !!!!

This virus virus is more dangerous than the earlier ones as it has not only entered not only our scrapbooks but testimonials as well......

How does it spread?
It spreads through infected contacts. An orkut account gets infected once you click on the link. The Trojan posts a message in your friend's scrapbook area or a testimonial of the Orkut system. The message text is chosen by the attacker and can be a random sentence written in Brazilian Portuguese

Name of the Trojan: Infostealer.Orcu

Norton’s Description: Infostealer.Orcu is a Trojan horse that attempts to steal confidential information, such as bank and Paypal accounts. It may arrive as a message spammed across the Orkut network.

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP

Hackers are trying to steal Orkut users' bank account information by inserting an automated information theft worm, according to security researchers. The worm, known as MW.Orc, is propagating through Orkut when users launch an executable file disguised as a JPEG.

Only one thing we can do is prevention, ie not to open such files and delete it from ur scrapbook, inbox or testimonial ...... If somehow this virus gets into someones PC then i suggest u run an antivirus as fast as u can......

Plus u can always spread awareness about these viruses and spamming....

By the way tinyurlcomyompks is now blocked by tinyurl.com when they found out it is a virus.

Remove Orcu virus from your computer as given here :
http://johndasfundas.blogspot.com/2006/07/how-to-remove-orcu-virus.html

There are so many viruses out there - look at the Yahoo messenger virus which may even affect the photo album.

http://comunity01.com/comunity.html - Orkut testimonial (virus or not - dunno )

Another orkut testimonial with a link ...

I could not access the link - there was a 403 error -

"Você conhece as pessoas que o esquecem. Você esquece das pessoas que você encontrou.Mas às

vezes você conhece pessoas que você não pode esquecer. Esses são seus amigos.
Não há maior prazer que o de encontrar um velho amigo, exceto o de fazer um novo
A vida é em parte o que nós fazemos dela, e em parte o que é feito pelos amigos que nós escolhemos"
Da uma passadinha ai na minha comunidade e faça um novo amigo,desde ja um forte abraço!
http://comunity01.com/comunity.html


Forbidden

You don't have permission to access /comunity.html on this server.

Additionally, a 403 Forbidden error was encountered while trying to use an ErrorDocument to handle the request.


Apache/2.2.2 (Fedora) Server at comunity01.com Port 80

Looks suspicious, but not sure it's a virus ....

If anyone has information on this do let me know ....

Check out the info about the other orkut viruses and worms which spread through scraps and testimonials ...

Thursday, March 29, 2007

Contagion - Worms spreading via Orkut.com

Firstly, let me tell you it's not Orkut's Fault.

By blocking the virus, Orkut will have to make it tougher to use the features it offers.

But I still can't understand, how the worm bypasses the CAPTCHA (or something like that) that is the Image Verification feature required for posting links !!!

Just browsing through orkut wont spread virus. But once you click the link - U're done for ....

These are some of the links the virus used (now blocked by tinyurl.com)

tinyurl.com/yompks
tinyurl.com/3x23ma

Oi , como vai? Olha só, encontrei umas fotos do seu perfil num site de encontros, mas com o nome de outra pessoa, é bom vc dar uma olhadinha nisso, pois é realmente muito estranho. Tirei uma foto da página, para caso ela seja removida antes que veja.
O link da página é urlcut.com/img12
Copie-o e cole no navegador para visualizar.
Assim que tiver visto, me confirme se não é um equívoco.
Abraços!


Click here to learn How to remove the Orcu virus (Orkut virus or worm )...


1.Check your machine for "minhasfotos.exe," "winlogon_.jpg" and "wzip32.exe," . and if it is there scan your system with ewido,spybot,adaware and antivirus

To reduce virus or worm infections

1. Use antivirus

2. Use of browser other than IE will be better ( Firefox - Download Firefox from my sidebar )

3. also use followinf scanners

Contagion - Worms spreading via Orkut.com


1. Ewido - http://www.ewido.net/en/download/ or http://free.grisoft.com/doc/5390/lng/us/tpl/v5#ewido-free

2. Adaware - http://www.download.com/3405-8022-5153545.html?part=dl-ad-aware&subj=dl&tag=top5

3. Spybot - http://fileforum.betanews.com/detail/Spybot_Search_and_Destroy/1043809773/1

try the removal tools

http://www.symantec.com/enterprise/security_response/removaltools.jsp

http://www.avast.com/eng/avast_cleaner.html


if you dont have an antivirus in your system try any of the following they are free

1. http://free.grisoft.com/doc/1 or http://free.grisoft.com/freeweb.php/doc/2/

2. avast - http://www.avast.com/eng/avast_4_home.html


use crap cleaner (To remove unwanted files like temporary folder contents and etc, also it have some registry issue fixes also)

download it from http://www.filehippo.com/download_ccleaner/


Wednesday, March 28, 2007

Orkut testimonial virus worm

Again ! Another testimonial virus in orkut !


Você é uma pessoa especial.
Deixo este depoimento aqui para expressar minha amizade, com uma mensagem linda que serve como lição de vida para qualquer pessoa.
http://my-own.net/asd1
Viva a vida enquanto pode!

I guess this also will go to both testimonials and scrapbooks ...

Got this message in a scrap ? It's from a virus. Tell the person who sent it to you that their computer is infected.

Remove Orcu virus from your computer as given here :

http://johndasfundas.blogspot.com/2006/07/how-to-remove-orcu-virus.html


Monday, October 23, 2006

Yahoo Messenger nsl-school virus - De vile Messenger




If your computer is infected , this is what you do


  1. Download the file http://www.fundazone.com/antivirus/registry/registry-enable-regedit.reg
  2. Copy these instructions to notepad or word or note it down. Close Internet Explorer ( and Yahoo messenger) . Double click the .reg file and click yes when it asks whether you want to merge the file to the registry. This will enable the regedit and task manager tools and restore your home page and other settings.
  3. Then restart the computer
  4. After restarting Press Ctrl + Alt + Del . Click Processes.
    End the process svhost32.exe . ( may be more than one process is running )
  5. Start> Search > Files and folders. Search for svhost32.exe , svhost.exe and enet.exe
  6. Delete the files found.
  7. Restart for good luck.
Use firefox http://www.fundazone.com/software/firefox/
Firefox is a fast and nice browser with tabs and RSS feeds and cool stuff.


So, the story behind this post ? Once again, another virus spread in all the computers here.
This time, it was a virus using Yahoo Messenger (tm) or MSN messenger to spread itself. (The previous one I wrote about was using a popular social networking site - www.orkut.com . Now this one uses a chatting software (chatting, file sharing, photo album sharing, video conferencing(I even used it for webcasting !), much more) Yahoo Messenger.

Now, How do you know that your computer (or yur friends') has this virus ??

It sends out messages like

(Don't try any of these links !!!)

  • damn, she is so cute http://nsl-school.org?id=miss_world
  • oh my god , i've won a 20000 usd lottery http://nsl-school.org/?id=winning_list . Come to my house tonight for a party !!
  • Just check out my new personal website : http://mytermex.com c0ol !!!
  • check this link for me : http://nsl-school.org?id=forum . Why I cannot surf this site ???

And when you click on these links, it installs the virus in your computer too.



Here's what Suresh Kumar says. ( forums.sureshkumar.net/showthread.php?t=7790 )

I've copied it here for you.

If you are infected with it what is going to happen ?

1: It sets your default IE page to nsl-school.org, you can’t even change it back to other page. If you open IE from your comp some malicious code will automatically executed into your computer.

2: It will disables the Task manager / reg edit. So you can’t kill the Trojan process anymore.

3: Files that are gonaa installed by this virus are svhost.exe , svhost32.exe , internat.exe.

you can find these files in windows/ & temp/ directories.

4: It will sends the secured & protected information to attacker

How to remove this manually from your computer ?

1: Close the IE browser.

(IE - Internet Explorer. First copy this article into MS Word or Notepad or something )

Log out messenger / Remove Internet Cable.

2: To enable Regedit

Click Start, Run and type this command exactly as given below: (better - Copy and paste)

REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableRegistryTools /t REG_DWORD /d 0 /f

3: To enable task manager : (To kill the process we need to enable task manager)

Click Start, Run and type this command exactly as given below: (better - Copy and paste)

REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 0 /f

4: Now we need to change the default page of IE though regedit. ( regedit is very dangerous if you randomly change stuff in it or delete important setting, so be careful - or make a backup before editing (file -> Export) )

Start>Run>Regedit

From the below locations in Regedit chage your default home page to google.com or other.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main

HKEY_ LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main

HKEY_USERS\Default\Software\Microsoft\Internet Explorer\Main

Just replace the attacker site with google.com or set it to blank page.

5: Now we need to kill the process from back end. Press Ctrl + Alt + Del

Kill the process svhost32.exe . ( may be more than one process is running.. check properly)

6: Delete svhost32.exe , svhost.exe files from Windows/ & temp/ directories. Or just search for svhost in your comp.. delete those files.

( Svchost.exe is a generic host process name for services that run from dynamic-link libraries (DLLs).( meaning there is an original svchost.exe that is part of Windows - http://support.microsoft.com/kb/314056 )

7: Go to regedit search for svhost and delete all the results you get. ( Be careful )

Start menu > Run > Regedit >

8: Restart the computer. That’s it now you are virus free.


I don’t know whether any removal patch that works for this Trojan/virus. But we can easily delete it manually.


And - use Firefox or something ! Most viruses are written for Internet Explorer ...

Don't open these URLs !!!
Possible Domains Owned by the Developer of this Trojan
http://www.nsl-school.org
http://www.giftshop.vn
http://www.myglobal-news.com
http://www.italiandirectory.com

You can block these URLs in your browser's Security settings.
A good idea for places where many users will use the same computer and inadvertently click the link.

In Internet Explorer , Tools -> Internet Options -> Security -> Restricted Sites -> Sites

Add the above sites in the list !!!

Ah, the tragedy called viruses ...


Use firefox http://www.fundazone.com/software/firefox/
Firefox is a fast and nice browser with tabs and RSS feeds and cool stuff.

How to get N95 Masks in India - कैसे पाएं मास्क? Yellow, White, Blue or Black ?

कैसे पाएं मास्क? पीला, सफेद, नीला या काला? There are many colors of masks available in India of different colors. What is the difference ? W...