Forum Index

It appears you have not yet registered with our community which limits what you can do & see. It's Free To register, please click here.





Spyware / Virus Removal Spyware, virus, browser hijack and other malware removal.

Reply
 
Thread Tools Display Modes
  #1  
Old 09-25-2007, 01:26 AM
meghana meghana is offline
Junior Member
 
Join Date: Sep 2007
Posts: 1
alert Virus W32/Hakaglan.worm.gen

Hi All,

My pc has affected by virus W32/Hakaglan.worm.gen.
It has disabled the Task Manager and Registries.

Upon execution the worm drops the following files:
%WINDIR%\SSVICHOSST.exe -> Worm Component
%SYSDIR%\SKCVHOSThk.dll -> Keylogger Component
%SYSDIR%\SKCVHOST.exe -> Keylogger Component
%SYSDIR%\SKCVHOSTr.exe -> Keylogger Component

Creates the following registry keys to hook at system startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\
“Shell” =” Explorer.exe SSVICHOSST.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run\
“Yahoo Messengger” = “%SYSDIR%\ SSVICHOSST.exe”

The worm creates a job file (At1.job) which schedules to execute itself everyday at 09:00 hrs.

It is not allowing me to install updated antivirus.
Anybody has the solution of this virus.

Thanks,
Meghana
Reply With Quote
Posted


  #2  
Old 09-25-2007, 01:27 PM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,574
Send a message via ICQ to Mobo Send a message via AIM to Mobo Send a message via MSN to Mobo Send a message via Yahoo to Mobo Send a message via Skype™ to Mobo
First thing to do would be start / run / regedit
Navigate to
HKCU\Software\Microsoft\Windows\CurrentVersion\Run \Yahoo Messengger\
Delete
SCVHSOT.exe

Step 2
Then Navigate to
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell

Delete
SCVHSOT.exe

Step 3
HKCU\Software\Microsoft\Windows\CurrentVersion\Pol icies\System
DisableTaskMgr
Double click and set to 0


HKCU\Software\Microsoft\Windows\CurrentVersion\Pol icies\System
DisableRegistryTools
Double click and set to 0

The following registry entry is set:

HKCU\Software\Microsoft\Windows\CurrentVersion\Pol icies\Explorer
NofolderOptions
Double click and set to 0

Step 4
Navigate to here and run a full system scan. Then remove all infections when the scan is complete.
Reply With Quote
  #3  
Old 09-26-2007, 09:45 AM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,574
Send a message via ICQ to Mobo Send a message via AIM to Mobo Send a message via MSN to Mobo Send a message via Yahoo to Mobo Send a message via Skype™ to Mobo
Great news.

For anyone wanting the script i'll attach it here. Visitors please note that free registration and one post are nessecary to see the download link.

Hidden Block (you must be registered and have 1 posts):
You do not have sufficient rights to see the hidden data contained here.

Last edited by Mobo; 10-08-2007 at 08:07 AM.
Reply With Quote
  #4  
Old 09-26-2007, 03:48 PM
virsee virsee is offline
Junior Member
 
Join Date: Sep 2007
Posts: 3
even i got same error.............. please give me the scripts .....n tell me what to do,....
Reply With Quote
  #5  
Old 10-04-2007, 01:44 AM
samsarkissa samsarkissa is offline
Junior Member
 
Join Date: Oct 2007
Posts: 1
Thanks for this information. Saved my network!
Reply With Quote
  #6  
Old 10-06-2007, 01:08 AM
jaydz jaydz is offline
Junior Member
 
Join Date: Oct 2007
Posts: 1
thanks a lot! i needed this!
Reply With Quote
  #7  
Old 10-06-2007, 04:32 PM
botching botching is offline
Junior Member
 
Join Date: Oct 2007
Posts: 2
thanks
Reply With Quote
  #8  
Old 10-08-2007, 12:00 AM
learning learning is offline
Junior Member
 
Join Date: Oct 2007
Posts: 1
thanks babeh!
Reply With Quote
  #9  
Old 10-08-2007, 05:02 AM
sued sued is offline
Junior Member
 
Join Date: Oct 2007
Posts: 3
W32/hakaglan virus

Quote:
Originally Posted by Mobo
Great news.

For anyone wanting the script i'll attach it below.

*** hidden content ***
hi i have this w32/hakaglan virus. it has disabled my task manager, command prompt and registry editor. where can i get this script, and how do ni run it? thx a batch!!!
Reply With Quote
  #10  
Old 10-08-2007, 05:06 AM
sued sued is offline
Junior Member
 
Join Date: Oct 2007
Posts: 3
Mobbo i don't seem to be able to download the script please help
Reply With Quote
Reply

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump



All times are GMT -5. The time now is 06:23 AM.


Firefox 2