Cyberanswers is now on youtube

Register a free account
ne nw
Crawlability Inc. Files for SEO Technology Patent
se sw

Go Back   Forum Index > Internet > Spyware / Virus Removal
The Software Store

Spyware / Virus Removal Spyware, virus, browser hijack and other malware removal.

Reply
 
Thread Tools Display Modes
  #41  
Old 01-22-2008, 07:36 AM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,612
Send a message via MSN to Mobo
1) Download th3 attached file:
(Right click and select "Save Target as").
2)Unzip it with winzip or winrar
3) Double click on that downloaded registry file, you will be asked weather you're sure to add this to registry, click yes.
4) Restart your system.
5) Search for the file svhost32.exe and delete it if its found.
6) Search for the file svhost.exe and delete it if its found.
Attached Files
File Type: zip RepairRegistry.zip (445 Bytes, 85 views)
__________________
[Only Registered and Activated Users Can See Links. Click Here To Register...] [Only Registered and Activated Users Can See Links. Click Here To Register...]

Reply With Quote
Sponsored Links

  #42  
Old 02-21-2008, 07:05 AM
skam21 skam21 is offline
Junior Member
 
Join Date: Feb 2008
Posts: 1
Hagaklan virus

--------------------------------------------------------------------------------
Type
Virus
SubType
Worm
Discovery Date
05/15/2007
Length
varies
Minimum DAT
5031 (05/15/2007)
Updated DAT
5031 (05/15/2007)
Minimum Engine
5.1.00
Description Added
05/15/2007
Description Modified
05/16/2007


Overview -


W32/Hakaglan.worm is a worm written in AutoIT that spreads via Yahoo Messenger, removable drives and network shares
Aliases
IM-Worm.Win32.Sohanad.t (Kaspersky)
W32.Yautoit (Symantec)
W32/Sohana-R (Sophos)
Win32/YahLover.AO (CA)
Worm/Sohanad.NAK (Antivir)
Characteristics -


W32/Hakaglan.worm is a worm written in AutoIT that spreads via Yahoo Messenger, removable drives and network shares


Upon execution the worm drops the following files:
%WINDIR%\SSVICHOSST.exe -> Worm Component
%SYSDIR%\SKCVHOSThk.dll -> Keylogger Component
%SYSDIR%\SKCVHOST.exe -> Keylogger Component
%SYSDIR%\SKCVHOSTr.exe -> Keylogger Component

Creates the following registry keys to hook at system startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\
“Shell” =” Explorer.exe SSVICHOSST.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run\
“Yahoo Messengger” = “%SYSDIR%\ SSVICHOSST.exe”

The worm creates a job file (At1.job) which schedules to execute itself everyday at 09:00 hrs.

Modifes the following registry keys to hide folder options and disable the taskmanager, registry editing etc.
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Policies\Explorer\
"NofolderOptions"= “1”
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Policies\System\
"DisableTaskMgr"=”1”
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Policies\System\
"DisableRegistryTools"=”1”
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\Schedule\
"AtTaskMaxHours" =”0”
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\WorkgroupCrawler\Shares\
"shared"="\\[SHARES]\New Folder.exe"
Symptoms -


Ends the following processes and closes applications if the window title has:
[FireLion]
Bkav2006
System Configuration
Registry
Windows Task
cmd.exe

Attempts to delete following registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run="BkavFw"
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run=”IEProtection"

Downloader Component:

The worm connects to the following domains to download updated variants of itself and additional malware.

[Only Registered and Activated Users Can See Links. Click Here To Register...][BLOCKED].t35.com/
[Only Registered and Activated Users Can See Links. Click Here To Register...][BLOCKED].t35.com/
[Only Registered and Activated Users Can See Links. Click Here To Register...][BLOCKED].t35.com/
[Only Registered and Activated Users Can See Links. Click Here To Register...][BLOCKED].t35.com/


At the time of writing this description, variants of KeyLog-Perfect.dll, Keylog-Perfect and Generic ProcKill.c were observed to be downloaded.

Note: As the website being communicated is normally controlled by the malware author, any files being downloaded can be remotely modified and the behavior of these new binaries altered - possibly with every user infection.
Method of Infection -

The worm spreads through passing any of the above links pointing to a hosted copy of the worm to all users listed in infected person’s yahoo buddy list.

Victims typically get infected when they download and execute the spammed copy of the worm.

It also spreads via network shares and removable drives.
Removal -

A combination of the latest DATs and the Engine will be able to detect and remove this threat. AVERT recommends users not to trust seemingly familiar or safe file icons, particularly when received via P2P clients, IRC, email or other media where users can share files.
Reply With Quote
  #43  
Old 02-23-2008, 11:47 AM
tickyboy tickyboy is offline
Junior Member
 
Join Date: Feb 2008
Posts: 1
i've got the same problem..
Reply With Quote
  #44  
Old 03-02-2008, 04:24 AM
louallen louallen is offline
Junior Member
 
Join Date: Mar 2008
Posts: 1
i have to post to download the script?
Reply With Quote
  #45  
Old 03-11-2008, 02:11 AM
Keshav Keshav is offline
Junior Member
 
Join Date: Mar 2008
Posts: 1
NOD32 deletes virus but everyday it became active.
Reply With Quote
  #46  
Old 03-13-2008, 06:04 AM
anito9999 anito9999 is offline
Junior Member
 
Join Date: Mar 2008
Posts: 1
have the same problem ?

Plz help me anybody
Reply With Quote
  #47  
Old 03-13-2008, 07:15 AM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,612
Send a message via MSN to Mobo
Use my post at the top as a guide please.
__________________
[Only Registered and Activated Users Can See Links. Click Here To Register...] [Only Registered and Activated Users Can See Links. Click Here To Register...]

Reply With Quote
  #48  
Old 04-20-2008, 03:51 AM
chakkajkumar chakkajkumar is offline
Junior Member
 
Join Date: Apr 2008
Posts: 1
hi mobo,
i have downloaded the zip file and install the reg file. on restart of the system it again disabling the settings. any help?
Reply With Quote
  #49  
Old 05-16-2008, 08:56 PM
Rhyce Rhyce is offline
Junior Member
 
Join Date: May 2008
Posts: 1
Can i have a copy of the script too?
Reply With Quote
  #50  
Old 05-22-2008, 07:38 AM
hirengs hirengs is offline
Junior Member
 
Join Date: May 2008
Posts: 1
I have W32/Autorun.worm.gen!job and it automatically schedules Alt1.job automatically everytime. Virusscan Enterprise 7.0.0 , scan engine version 5.2.00 and virus definition 5299 detects it and says it is deleted but everytime I boot it reappears. Any solution?
Reply With Quote
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 04:02 AM.


234x60
Bulletin Board Custom Version by Mobo
Copyright © 2004-2007 Cyberanswers.org All rights reserved