| Home Forum Radio Memberlist Help Search Quick Links |
| Forum Index » Internet » Spyware / Virus Removal » Virus W32/Hakaglan.worm.gen |
| Spyware / Virus Removal Spyware, virus, browser hijack and other malware removal. |
![]() |
![]() |
|
Thread Tools | Display Modes | ![]() |
|
#1
|
|||
|
|||
|
Hi All,
My pc has affected by virus W32/Hakaglan.worm.gen. It has disabled the Task Manager and Registries. Upon execution the worm drops the following files: %WINDIR%\SSVICHOSST.exe -> Worm Component %SYSDIR%\SKCVHOSThk.dll -> Keylogger Component %SYSDIR%\SKCVHOST.exe -> Keylogger Component %SYSDIR%\SKCVHOSTr.exe -> Keylogger Component Creates the following registry keys to hook at system startup: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\ Shell = Explorer.exe SSVICHOSST.exe HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run\ Yahoo Messengger = %SYSDIR%\ SSVICHOSST.exe The worm creates a job file (At1.job) which schedules to execute itself everyday at 09:00 hrs. It is not allowing me to install updated antivirus. Anybody has the solution of this virus. Thanks, Meghana |
|
|
|
#2
|
||||
|
||||
|
First thing to do would be start / run / regedit
Navigate to HKCU\Software\Microsoft\Windows\CurrentVersion\Run \Yahoo Messengger\ Delete SCVHSOT.exe Step 2 Then Navigate to HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell Delete SCVHSOT.exe Step 3 HKCU\Software\Microsoft\Windows\CurrentVersion\Pol icies\System DisableTaskMgr Double click and set to 0 HKCU\Software\Microsoft\Windows\CurrentVersion\Pol icies\System DisableRegistryTools Double click and set to 0 The following registry entry is set: HKCU\Software\Microsoft\Windows\CurrentVersion\Pol icies\Explorer NofolderOptions Double click and set to 0 Step 4 Navigate to here and run a full system scan. Then remove all infections when the scan is complete. |
|
#3
|
||||
|
||||
|
Great news.
For anyone wanting the script i'll attach it here. Visitors please note that free registration and one post are nessecary to see the download link.
Last edited by Mobo; 10-08-2007 at 08:07 AM. |
|
#4
|
|||
|
|||
|
even i got same error.............. please give me the scripts .....n tell me what to do,....
|
|
#5
|
|||
|
|||
|
Thanks for this information. Saved my network!
|
|
#6
|
|||
|
|||
|
thanks a lot! i needed this!
|
|
#7
|
|||
|
|||
|
thanks
|
|
#8
|
|||
|
|||
|
thanks babeh!
|
|
#9
|
|||
|
|||
|
W32/hakaglan virus
Quote:
|
|
#10
|
|||
|
|||
|
Mobbo i don't seem to be able to download the script please help
|
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
| Display Modes | |
|
|
|
|
||