Sunday, August 31, 2008

Beware of Vietnamese Viruses on Your Messenger

First of all, i would like to apologize about some unknown message that was sent from my messenger to all of yours messenger. Those message was sent by some kind of Trojan which is breaching my PC and it's look like a Philippine or Vietnamese viruses. Because its language similar with Tagalog.

Trang Web nay coi cung hay, vao coi thu di http://........
this worm name is worm W32.Imaut.N ini.

These Viruses is quite dangerous, so beware of them. They could attack ypur Yahoo Messenger and your others messenger actually, because i have found it on my Network PC too. My Client PC which was infected by the viruses, always send those message to other PC on the network. And the result, i can't open regedit (registry editor) and also taskmgr (task manager) on infected PCs. So i think these viruses is quite dangerous.

On this post, i would like to share some information about fighting these viruses, here they are:

* Enable the regedit to clear the registry entry of the virus by typing on command prompt:

reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableRegistryTools

* Enable the task manager by opening the registry (which has been recovered by the first step) and aim to the:

HKEY_CURRENT_USER\Software\Microsoft\Windows\
CurrentVersion\Policies\System
you will find entry named "DisableTaskMg" and Clear out that entry to enable your task manager

* Furthermore find the others registry entry which is make your PC send a message automatically, those entries are:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\"Shell" = "Explorer.exe " SVCSHOST.exe"

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion
\Run\"Yahoo Messengger" = "%System%\SVCSHOST.exe"

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion
\Explorer\WorkgroupCrawler\Shares\"shared" = "[SHARED DRIVE]\ scvhosts.exe"

* Also clear all of the entry which is contained scvhosts.exe ; New Folder.exe and Explorer.exe (with letter E capital).

* And Then, we should terminate the process which was triggered by these viruses by opening the task manager and end the suspected processes which user is yours (not the System). Usually these processes named svchosts.exe , scvhosts.exe ,etc.

* The last one, go to the system folder, such as C:\Windows. Finds executable file who's name same with the previous processes such as: svchosts.exe and clean it immediately

* Scan your computer (Recommended) and Restart your PC to complete the step.

OK, i think that's all folks for the tips in fighting this Vietnam-viruses and thanks for all the source

5 comments:

Anonymous said...

[url=http://firgonbares.net/][img]http://firgonbares.net/img-add/euro2.jpg[/img][/url]
[b]oem software sales, [url=http://firgonbares.net/]buy pda software[/url]
[url=http://firgonbares.net/][/url] how to remove oval image adobe photoshop cs3 discount for software
discount software san [url=http://firgonbares.net/]windows software downloads[/url] buy dreamweaver in
[url=http://firgonbares.net/]cheap autocad software[/url] 8 Mac Retail
[url=http://firgonbares.net/]where can i sell my software[/url] discount software office
Acrobat 9 Pro Extended [url=http://firgonbares.net/]acdsee pro[/b]

Anonymous said...

[url=http://sunkomutors.net/][img]http://sunkomutors.net/img-add/euro2.jpg[/img][/url]
[b]adobe photoshop cs4 keeps locking up, [url=http://sunkomutors.net/]windows xp help[/url]
[url=http://sunkomutors.net/][/url] educator software discounts english educational software
where can i buy macromedia flash [url=http://sunkomutors.net/]best software to sell[/url] office enterprise 2007 keys
[url=http://sunkomutors.net/]buy dreamweaver templates[/url] shop creator software
[url=http://sunkomutors.net/]coreldraw extend free trial registry[/url] nero coupon
windows xp oem software [url=http://sunkomutors.net/]to buy oem software[/b]

Anonymous said...

[url=http://murudobaros.net/][img]http://murudobaros.net/img-add/euro2.jpg[/img][/url]
[b]where can i buy adobe creative suite 3 premium for mac, [url=http://murudobaros.net/]educator discount software[/url]
[url=http://murudobaros.net/]software reseller discount[/url] photoshop elements 6 for mac discount software photoshop
discount software for education [url=http://murudobaros.net/]difference between oem software[/url] sales quote software
[url=http://murudobaros.net/]office email software[/url] Creative Suite 4 Design
[url=http://murudobaros.net/]microsoft office 2003 professional training video[/url] were to buy software
software discounts for non [url=http://murudobaros.net/]discount language software[/b]

Anonymous said...

[url=http://vonmertoes.net/][img]http://vonmertoes.net/img-add/euro2.jpg[/img][/url]
[b]windows vista tutorial, [url=http://bariossetos.net/]windows vista ultimate upgrade[/url]
[url=http://vonmertoes.net/][/url] adobe acrobat reader 9 software free download format hard drive for windows xp
www macromedia com software [url=http://vonmertoes.net/]student discount software uk[/url] full software downloads
[url=http://bariossetos.net/]microsoft budget software[/url] software to purchase in
[url=http://vonmertoes.net/]university student software discount[/url] student discount software
music software downloads [url=http://hopresovees.net/]where to buy microsoft software[/b]

Anonymous said...

[url=http://bariossetos.net/][img]http://bariossetos.net/img-add/euro2.jpg[/img][/url]
[b]buy microsoft excel software, [url=http://hopresovees.net/]order free software[/url]
[url=http://hopresovees.net/][/url] discount software online adobe software educational discount
buy dreamweaver for [url=http://hopresovees.net/]adobe photoshop cs3 for mac full version[/url] star trek themes for windows xp
[url=http://bariossetos.net/]software package prices[/url] jewellery store software
[url=http://vonmertoes.net/]carlo gabriel nero[/url] nero burning rom
buy macromedia studio 8 [url=http://bariossetos.net/]buy photoshop at[/b]

 
Design by Wordpress Theme | Blogger Templates | JCPenney