<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-4901131500968738625</id><updated>2011-10-20T00:17:38.116-07:00</updated><title type='text'>Virus - Manual Deleting Solution</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://dangerous-virus.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4901131500968738625/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://dangerous-virus.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>selva</name><uri>http://www.blogger.com/profile/02725135057301336628</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>7</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-4901131500968738625.post-1304871408871511299</id><published>2009-01-03T14:50:00.000-08:00</published><updated>2010-02-03T11:42:35.604-08:00</updated><title type='text'>W32.Fujacks.D (spoclsv.exe/GameSetup.exe)- Virus</title><content type='html'>&lt;center&gt;&lt;!-- Begin: AdBrite, Generated: 2010-02-03 14:41:29  --&gt;
&lt;script type="text/javascript"&gt;
var AdBrite_Title_Color = 'CAF99B';
var AdBrite_Text_Color = 'FFFFFF';
var AdBrite_Background_Color = '000000';
var AdBrite_Border_Color = '000000';
var AdBrite_URL_Color = 'FFFFFF';
try{var AdBrite_Iframe=window.top!=window.self?2:1;var AdBrite_Referrer=document.referrer==''?document.location:document.referrer;AdBrite_Referrer=encodeURIComponent(AdBrite_Referrer);}catch(e){var AdBrite_Iframe='';var AdBrite_Referrer='';}
&lt;/script&gt;
&lt;script type="text/javascript"&gt;document.write(String.fromCharCode(60,83,67,82,73,80,84));document.write(' src="http://ads.adbrite.com/mb/text_group.php?sid=1515837&amp;zs=3330305f323530&amp;ifr='+AdBrite_Iframe+'&amp;ref='+AdBrite_Referrer+'" type="text/javascript"&gt;');document.write(String.fromCharCode(60,47,83,67,82,73,80,84,62));&lt;/script&gt;
&lt;div&gt;&lt;a target="_top" href="http://www.adbrite.com/mb/commerce/purchase_form.php?opid=1515837&amp;afsid=1" style="font-weight:bold;font-family:Arial;font-size:13px;"&gt;Your Ad Here&lt;/a&gt;&lt;/div&gt;
&lt;!-- End: AdBrite --&gt;&lt;/center&gt;

&lt;strong&gt;Systems Affected: &lt;/strong&gt;Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
&lt;p&gt;
When the worm executes, it performs the following actions:&lt;br /&gt;
&lt;/p&gt;
&lt;ol&gt;
 &lt;li&gt;Copies itself as the following files:&lt;br /&gt;
 &lt;br /&gt;
 &lt;ul&gt;
  &lt;li&gt;[DRIVE LETTER]\setup.exe
  &lt;/li&gt;
  &lt;li&gt;[NETWORK DRIVE LETTER]\GameSetup.exe
  &lt;/li&gt;
  &lt;li&gt;%System%\Drivers\spoclsv.exe&lt;br /&gt;
  &lt;br /&gt;
  &lt;strong&gt;Note:&lt;/strong&gt; %System% is a variable that refers to the System folder.
  By default this is C:\Windows\System (Windows 95/98/Me),
  C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows
  XP).&lt;br /&gt;
  &lt;/li&gt;
 &lt;/ul&gt;
 &lt;/li&gt;
 &lt;li&gt;Creates the following file to execute [DRIVE LETTER]\setup.exe:&lt;br /&gt;
 &lt;br /&gt;
 [DRIVE LETTER]\autorun.inf&lt;br /&gt;
 &lt;br /&gt;
 &lt;/li&gt;
 &lt;li&gt;Adds the value:&lt;br /&gt;
 &lt;br /&gt;
 &amp;quot;svcshare&amp;quot;=&amp;quot;spoclsv.exe&amp;quot;&lt;br /&gt;
 &lt;br /&gt;
 to the following registry subkeys:&lt;br /&gt;
 &lt;br /&gt;
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;
 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;
 &lt;br /&gt;
 so that it executes whenever Windows starts.&lt;br /&gt;
 &lt;br /&gt;
 &lt;/li&gt;
 &lt;li&gt;May delete entries that contain the following strings: &lt;br /&gt;
 &lt;br /&gt;
 &amp;quot;kav&amp;quot;&lt;br /&gt;
 &amp;quot;KAVPersonal50&amp;quot;&lt;br /&gt;
 &amp;quot;KvMonXP&amp;quot;&lt;br /&gt;
 &amp;quot;McAfeeUpdaterUI&amp;quot;&lt;br /&gt;
 &amp;quot;Network Associates Error Reporting Service&amp;quot;&lt;br /&gt;
 &amp;quot;RavTask&amp;quot;&lt;br /&gt;
 &amp;quot;ShStatEXE&amp;quot;&lt;br /&gt;
 &amp;quot;yassistse&amp;quot;&lt;br /&gt;
 &amp;quot;YLive.exe&amp;quot;&lt;br /&gt;
 &lt;br /&gt;
 from the registry subkey:&lt;br /&gt;
 &lt;br /&gt;
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;
 &lt;br /&gt;
 &lt;/li&gt;
 &lt;li&gt;Uses a series of &amp;quot;net share&amp;quot; commands to close any local shared folders found.&lt;br /&gt;
 &lt;br /&gt;
 &lt;/li&gt;
 &lt;li&gt;May delete files with the following extensions from the root folder of local partitions, except the C drive:&lt;br /&gt;
 &lt;br /&gt;
 &lt;ul&gt;
  &lt;li&gt;.gho
  &lt;/li&gt;
  &lt;li&gt;.exe
  &lt;/li&gt;
  &lt;li&gt;.scr
  &lt;/li&gt;
  &lt;li&gt;.pif
  &lt;/li&gt;
  &lt;li&gt;.com&lt;br /&gt;
  &lt;br /&gt;
  &lt;/li&gt;
 &lt;/ul&gt;
 &lt;/li&gt;
 &lt;li&gt;Uses the following password list in attempt to copy itself to available network shares:&lt;br /&gt;
 &lt;br /&gt;
 &lt;ul&gt;
  &lt;li&gt;admin$
  &lt;/li&gt;
  &lt;li&gt;admin$
  &lt;/li&gt;
  &lt;li&gt;1234
  &lt;/li&gt;
  &lt;li&gt;password
  &lt;/li&gt;
  &lt;li&gt;6969
  &lt;/li&gt;
  &lt;li&gt;harley
  &lt;/li&gt;
  &lt;li&gt;123456
  &lt;/li&gt;
  &lt;li&gt;golf
  &lt;/li&gt;
  &lt;li&gt;pussy
  &lt;/li&gt;
  &lt;li&gt;mustang
  &lt;/li&gt;
  &lt;li&gt;1111
  &lt;/li&gt;
  &lt;li&gt;shadow
  &lt;/li&gt;
  &lt;li&gt;1313
  &lt;/li&gt;
  &lt;li&gt;fish
  &lt;/li&gt;
  &lt;li&gt;5150
  &lt;/li&gt;
  &lt;li&gt;7777
  &lt;/li&gt;
  &lt;li&gt;qwerty
  &lt;/li&gt;
  &lt;li&gt;baseball
  &lt;/li&gt;
  &lt;li&gt;2112
  &lt;/li&gt;
  &lt;li&gt;letmein
  &lt;/li&gt;
  &lt;li&gt;12345678
  &lt;/li&gt;
  &lt;li&gt;12345
  &lt;/li&gt;
  &lt;li&gt;ccc
  &lt;/li&gt;
  &lt;li&gt;admin
  &lt;/li&gt;
  &lt;li&gt;5201314
  &lt;/li&gt;
  &lt;li&gt;qq520
  &lt;/li&gt;
  &lt;li&gt;123
  &lt;/li&gt;
  &lt;li&gt;1234567
  &lt;/li&gt;
  &lt;li&gt;123456789
  &lt;/li&gt;
  &lt;li&gt;654321
  &lt;/li&gt;
  &lt;li&gt;54321
  &lt;/li&gt;
  &lt;li&gt;111
  &lt;/li&gt;
  &lt;li&gt;000000
  &lt;/li&gt;
  &lt;li&gt;abc
  &lt;/li&gt;
  &lt;li&gt;11111111
  &lt;/li&gt;
  &lt;li&gt;88888888
  &lt;/li&gt;
  &lt;li&gt;pass
  &lt;/li&gt;
  &lt;li&gt;passwd
  &lt;/li&gt;
  &lt;li&gt;database
  &lt;/li&gt;
  &lt;li&gt;abcd
  &lt;/li&gt;
  &lt;li&gt;abc123
  &lt;/li&gt;
  &lt;li&gt;sybase
  &lt;/li&gt;
  &lt;li&gt;123qwe
  &lt;/li&gt;
  &lt;li&gt;server
  &lt;/li&gt;
  &lt;li&gt;computer
  &lt;/li&gt;
  &lt;li&gt;520
  &lt;/li&gt;
  &lt;li&gt;super
  &lt;/li&gt;
  &lt;li&gt;123asd
  &lt;/li&gt;
  &lt;li&gt;ihavenopass
  &lt;/li&gt;
  &lt;li&gt;godblessyou
  &lt;/li&gt;
  &lt;li&gt;enable
  &lt;/li&gt;
  &lt;li&gt;2002
  &lt;/li&gt;
  &lt;li&gt;2003
  &lt;/li&gt;
  &lt;li&gt;2600
  &lt;/li&gt;
  &lt;li&gt;alpha
  &lt;/li&gt;
  &lt;li&gt;110
  &lt;/li&gt;
  &lt;li&gt;111111
  &lt;/li&gt;
  &lt;li&gt;121212
  &lt;/li&gt;
  &lt;li&gt;123123
  &lt;/li&gt;
  &lt;li&gt;1234qwer
  &lt;/li&gt;
  &lt;li&gt;123abc
  &lt;/li&gt;
  &lt;li&gt;007
  &lt;/li&gt;
  &lt;li&gt;aaa
  &lt;/li&gt;
  &lt;li&gt;patrick
  &lt;/li&gt;
  &lt;li&gt;pat
  &lt;/li&gt;
  &lt;li&gt;administrator
  &lt;/li&gt;
  &lt;li&gt;root
  &lt;/li&gt;
  &lt;li&gt;sex
  &lt;/li&gt;
  &lt;li&gt;god
  &lt;/li&gt;
  &lt;li&gt;foobar
  &lt;/li&gt;
  &lt;li&gt;secret
  &lt;/li&gt;
  &lt;li&gt;test
  &lt;/li&gt;
  &lt;li&gt;test123
  &lt;/li&gt;
  &lt;li&gt;temp
  &lt;/li&gt;
  &lt;li&gt;temp123
  &lt;/li&gt;
  &lt;li&gt;win
  &lt;/li&gt;
  &lt;li&gt;asdf
  &lt;/li&gt;
  &lt;li&gt;pwd
  &lt;/li&gt;
  &lt;li&gt;qwer
  &lt;/li&gt;
  &lt;li&gt;yxcv
  &lt;/li&gt;
  &lt;li&gt;zxcv
  &lt;/li&gt;
  &lt;li&gt;home
  &lt;/li&gt;
  &lt;li&gt;xxx
  &lt;/li&gt;
  &lt;li&gt;owner
  &lt;/li&gt;
  &lt;li&gt;login
  &lt;/li&gt;
  &lt;li&gt;Login
  &lt;/li&gt;
  &lt;li&gt;pw123
  &lt;/li&gt;
  &lt;li&gt;love
  &lt;/li&gt;
  &lt;li&gt;mypc
  &lt;/li&gt;
  &lt;li&gt;mypc123
  &lt;/li&gt;
  &lt;li&gt;admin123
  &lt;/li&gt;
  &lt;li&gt;mypass
  &lt;/li&gt;
  &lt;li&gt;mypass123
  &lt;/li&gt;
  &lt;li&gt;901100
  &lt;/li&gt;
  &lt;li&gt;Administrator
  &lt;/li&gt;
  &lt;li&gt;Guest
  &lt;/li&gt;
  &lt;li&gt;admin
  &lt;/li&gt;
  &lt;li&gt;Root&lt;br /&gt;
  &lt;br /&gt;
  &lt;/li&gt;
 &lt;/ul&gt;
 &lt;/li&gt;
 &lt;li&gt;Ends all processes in windows that contain the following strings in the title:&lt;br /&gt;
 &lt;br /&gt;
 &lt;ul&gt;
  &lt;li&gt;QQKav
  &lt;/li&gt;
  &lt;li&gt;QQAV
  &lt;/li&gt;
  &lt;li&gt;VirusScan
  &lt;/li&gt;
  &lt;li&gt;Symantec AntiVirus
  &lt;/li&gt;
  &lt;li&gt;iDuba
  &lt;/li&gt;
  &lt;li&gt;esteem procs
  &lt;/li&gt;
  &lt;li&gt;Wrapped gift Killer
  &lt;/li&gt;
  &lt;li&gt;Winsock Expert
  &lt;/li&gt;
  &lt;li&gt;msctls_statusbar32
  &lt;/li&gt;
  &lt;li&gt;pjf(ustc)
  &lt;/li&gt;
  &lt;li&gt;IceSword&lt;br /&gt;
  &lt;br /&gt;
  &lt;/li&gt;
 &lt;/ul&gt;
 &lt;/li&gt;
 &lt;li&gt;Ends the following processes:&lt;br /&gt;
 &lt;br /&gt;
 &lt;ul&gt;
  &lt;li&gt;Mcshield.exe
  &lt;/li&gt;
  &lt;li&gt;VsTskMgr.exe
  &lt;/li&gt;
  &lt;li&gt;naPrdMgr.exe
  &lt;/li&gt;
  &lt;li&gt;UpdaterUI.exe
  &lt;/li&gt;
  &lt;li&gt;TBMon.exe
  &lt;/li&gt;
  &lt;li&gt;scan32.exe
  &lt;/li&gt;
  &lt;li&gt;Ravmond.exe
  &lt;/li&gt;
  &lt;li&gt;CCenter.exe
  &lt;/li&gt;
  &lt;li&gt;RavTask.exe
  &lt;/li&gt;
  &lt;li&gt;Rav.exe
  &lt;/li&gt;
  &lt;li&gt;Ravmon.exe
  &lt;/li&gt;
  &lt;li&gt;RavmonD.exe
  &lt;/li&gt;
  &lt;li&gt;RavStub.exe
  &lt;/li&gt;
  &lt;li&gt;KVXP.kxp
  &lt;/li&gt;
  &lt;li&gt;KvMonXP.kxp
  &lt;/li&gt;
  &lt;li&gt;KVCenter.kxp
  &lt;/li&gt;
  &lt;li&gt;KVSrvXP.exe
  &lt;/li&gt;
  &lt;li&gt;KRegEx.exe
  &lt;/li&gt;
  &lt;li&gt;UIHost.exe
  &lt;/li&gt;
  &lt;li&gt;TrojDie.kxp
  &lt;/li&gt;
  &lt;li&gt;FrogAgent.exe
  &lt;/li&gt;
  &lt;li&gt;Logo1_.exe
  &lt;/li&gt;
  &lt;li&gt;Logo_1.exe
  &lt;/li&gt;
  &lt;li&gt;Rundl123.exe&lt;br /&gt;
  &lt;br /&gt;
  &lt;/li&gt;
 &lt;/ul&gt;
 &lt;/li&gt;
 &lt;li&gt;May end the following services, some of which may be security-related:&lt;br /&gt;
 &lt;br /&gt;
 &lt;ul&gt;
  &lt;li&gt;Schedule
  &lt;/li&gt;
  &lt;li&gt;sharedaccess
  &lt;/li&gt;
  &lt;li&gt;RsCCenter
  &lt;/li&gt;
  &lt;li&gt;RsRavMon
  &lt;/li&gt;
  &lt;li&gt;RsCCenter
  &lt;/li&gt;
  &lt;li&gt;RsRavMon
  &lt;/li&gt;
  &lt;li&gt;KVWSC
  &lt;/li&gt;
  &lt;li&gt;KVSrvXP
  &lt;/li&gt;
  &lt;li&gt;KVWSC
  &lt;/li&gt;
  &lt;li&gt;KVSrvXP
  &lt;/li&gt;
  &lt;li&gt;kavsvc
  &lt;/li&gt;
  &lt;li&gt;AVP
  &lt;/li&gt;
  &lt;li&gt;AVP
  &lt;/li&gt;
  &lt;li&gt;kavsvc
  &lt;/li&gt;
  &lt;li&gt;McAfeeFramework
  &lt;/li&gt;
  &lt;li&gt;McShield
  &lt;/li&gt;
  &lt;li&gt;McTaskManager
  &lt;/li&gt;
  &lt;li&gt;McAfeeFramework
  &lt;/li&gt;
  &lt;li&gt;McShield
  &lt;/li&gt;
  &lt;li&gt;McTaskManager
  &lt;/li&gt;
  &lt;li&gt;navapsvc
  &lt;/li&gt;
  &lt;li&gt;wscsvc
  &lt;/li&gt;
  &lt;li&gt;KPfwSvc
  &lt;/li&gt;
  &lt;li&gt;SNDSrvc
  &lt;/li&gt;
  &lt;li&gt;ccProxy
  &lt;/li&gt;
  &lt;li&gt;ccEvtMgr
  &lt;/li&gt;
  &lt;li&gt;ccSetMgr
  &lt;/li&gt;
  &lt;li&gt;SPBBCSvc
  &lt;/li&gt;
  &lt;li&gt;Symantec Core LC
  &lt;/li&gt;
  &lt;li&gt;NPFMntor
  &lt;/li&gt;
  &lt;li&gt;MskService
  &lt;/li&gt;
  &lt;li&gt;FireSvc&lt;br /&gt;
  &lt;br /&gt;
  &lt;/li&gt;
 &lt;/ul&gt;
 &lt;/li&gt;
 &lt;li&gt;Scans the compromised computer and infects any .exe files it finds.&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;&lt;u&gt;&lt;font color="#00CC00"&gt;&lt;b&gt;Manual Deleting Solution:&lt;/b&gt;&lt;/font&gt;&lt;/u&gt;&lt;/h3&gt;
&lt;ol&gt;
  &lt;li&gt;Restart your PC. Then go to safe mode (press F8).&lt;/li&gt;
  &lt;li&gt;Open &lt;b&gt;Start&lt;/b&gt;&amp;gt;&amp;gt;&lt;b&gt;Run&lt;/b&gt; and type &lt;strong&gt;cmd&lt;/strong&gt; and press 
  enter. This will open windows command prompt window. On this window, type as 
  directed in steps further and press enter at the end of each step.&lt;/li&gt;
  &lt;li&gt;type &lt;strong&gt;cd\&lt;/strong&gt;&lt;/li&gt;
  &lt;li&gt;type &lt;strong&gt;cd windows\system32&lt;/strong&gt;&lt;/li&gt;
  &lt;li&gt;type &lt;strong&gt;attrib -r -h -s spoclsv.exe&lt;/strong&gt;&lt;/li&gt;
  &lt;li&gt;type &lt;strong&gt;del&lt;/strong&gt; &lt;strong&gt;spoclsv.exe&lt;/strong&gt;&lt;/li&gt;
  &lt;li&gt;type &lt;strong&gt;del&lt;/strong&gt; &lt;strong&gt;spoclsv.exe&lt;/strong&gt;&lt;/li&gt;
  &lt;li&gt;now type &lt;strong&gt;d:&lt;/strong&gt; and press enter for d: drive partition.&lt;/li&gt;
  &lt;li&gt;type &lt;strong&gt;attrib -r -h -s gamesetup.exe&lt;/strong&gt;&lt;/li&gt;
  &lt;li&gt;type &lt;strong&gt;gamesetup.exe&lt;/strong&gt;&lt;/li&gt;
  &lt;li&gt;type &lt;b&gt;exit&lt;/b&gt;&lt;/li&gt;
  &lt;li&gt;Open &lt;b&gt;Start&lt;/b&gt; ---&amp;gt;&amp;gt; &lt;b&gt;Run&lt;/b&gt; and type &lt;strong&gt;msconfig&lt;/strong&gt; and 
  press enter. This will open windows msconfig window then uncheck &lt;b&gt;
  spoclsv.exe&lt;/b&gt; and &lt;b&gt;gamesetup.exe&lt;/b&gt;&lt;/li&gt;
  &lt;li&gt;Open &lt;b&gt;Start&lt;/b&gt; ---&amp;gt;&amp;gt; &lt;b&gt;Run&lt;/b&gt; and type &lt;strong&gt;regedit&lt;/strong&gt; and 
  press enter. This will open windows Registry Editor window then find and 
  remove&lt;b&gt;. (spoclsv.exe&lt;/b&gt; and &lt;b&gt;gamesetup.exe)&lt;/b&gt;&lt;/li&gt;
  &lt;li&gt;Then update your antivirus software (your all software (.exe) attacked 
  virus). So reinstall your software.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;b&gt;Note:&lt;/b&gt; Similarly repeat from steps 8 to 10 for all your hard disk 
partitions to remove the files created by the virus.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4901131500968738625-1304871408871511299?l=dangerous-virus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dangerous-virus.blogspot.com/feeds/1304871408871511299/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4901131500968738625&amp;postID=1304871408871511299' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4901131500968738625/posts/default/1304871408871511299'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4901131500968738625/posts/default/1304871408871511299'/><link rel='alternate' type='text/html' href='http://dangerous-virus.blogspot.com/2007/04/w32fujacksd-virus_28.html' title='W32.Fujacks.D (spoclsv.exe/GameSetup.exe)- Virus'/><author><name>selva</name><uri>http://www.blogger.com/profile/02725135057301336628</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4901131500968738625.post-2802135397820463266</id><published>2009-01-03T14:40:00.000-08:00</published><updated>2010-02-03T11:43:57.727-08:00</updated><title type='text'>Win32/NSAnti (amvo.exe/autorun.inf ) - Virus</title><content type='html'>&lt;center&gt;&lt;!-- Begin: AdBrite, Generated: 2010-02-03 14:41:29  --&gt;
&lt;script type="text/javascript"&gt;
var AdBrite_Title_Color = 'CAF99B';
var AdBrite_Text_Color = 'FFFFFF';
var AdBrite_Background_Color = '000000';
var AdBrite_Border_Color = '000000';
var AdBrite_URL_Color = 'FFFFFF';
try{var AdBrite_Iframe=window.top!=window.self?2:1;var AdBrite_Referrer=document.referrer==''?document.location:document.referrer;AdBrite_Referrer=encodeURIComponent(AdBrite_Referrer);}catch(e){var AdBrite_Iframe='';var AdBrite_Referrer='';}
&lt;/script&gt;
&lt;script type="text/javascript"&gt;document.write(String.fromCharCode(60,83,67,82,73,80,84));document.write(' src="http://ads.adbrite.com/mb/text_group.php?sid=1515837&amp;zs=3330305f323530&amp;ifr='+AdBrite_Iframe+'&amp;ref='+AdBrite_Referrer+'" type="text/javascript"&gt;');document.write(String.fromCharCode(60,47,83,67,82,73,80,84,62));&lt;/script&gt;
&lt;div&gt;&lt;a target="_top" href="http://www.adbrite.com/mb/commerce/purchase_form.php?opid=1515837&amp;afsid=1" style="font-weight:bold;font-family:Arial;font-size:13px;"&gt;Your Ad Here&lt;/a&gt;&lt;/div&gt;
&lt;!-- End: AdBrite --&gt;&lt;/center&gt;
&lt;p&gt;&lt;strong&gt;Trouble:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Recently we received a mail from one of our readers whose computer was 
infected by &lt;strong&gt;Win32/NSAnti&lt;/strong&gt; virus, this virus mainly causes drive 
opening problem by double click in windows XP.&lt;/p&gt;
&lt;p&gt;If your system is infected by this virus you can’t see hidden files and 
folders , even after &lt;strong&gt;applying&lt;/strong&gt; the settings&lt;strong&gt; to show 
hidden folders. &lt;/strong&gt;This setting is reverted back to &lt;strong&gt;Don’t show 
hidden files and folders &lt;/strong&gt;by the virus&lt;strong&gt;.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;This happens because virus protects the two hidden, system files called
&lt;strong&gt;d.com and autorun,inf &lt;/strong&gt;which are created by amvo.exe and &lt;strong&gt;
amvo0.dll&lt;/strong&gt; , &lt;strong&gt;amvo1.dll&lt;/strong&gt; which resides in system32 folder 
on the OS drive (hard disk partition on which windows operating system is 
installed).&lt;strong&gt; &lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Fix:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;In order to fix the problems caused by this virus ,you will need to delete 
all these files created by the virus.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Follow the set of commands to delete these files&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
  &lt;li&gt;Open Start&amp;gt;&amp;gt;Run and type &lt;strong&gt;cmd&lt;/strong&gt; and press enter. This will 
  open windows command prompt window. On this window, type as directed in steps 
  further and press enter at the end of each step.&lt;/li&gt;
  &lt;li&gt;type &lt;strong&gt;cd\&lt;/strong&gt;&lt;/li&gt;
  &lt;li&gt;type &lt;strong&gt;cd windows\system32&lt;/strong&gt;&lt;/li&gt;
  &lt;li&gt;type &lt;strong&gt;attrib -r -h -s amvo.exe&lt;/strong&gt;&lt;/li&gt;
  &lt;li&gt;type &lt;strong&gt;del&lt;/strong&gt; &lt;strong&gt;amvo.exe&lt;/strong&gt;&lt;/li&gt;
  &lt;li&gt;type &lt;strong&gt;attrib -r -h -s&lt;/strong&gt; &lt;strong&gt;avmo0.dll&lt;/strong&gt; ,repeat 
  the steps 5 and 6 again to delete &lt;strong&gt;avmo1.dll&lt;/strong&gt;&lt;/li&gt;
  &lt;li&gt;now type &lt;strong&gt;d:&lt;/strong&gt; and press enter for d: drive partition.&lt;/li&gt;
  &lt;li&gt;type &lt;strong&gt;attrib -r -h -s autorun.inf&lt;/strong&gt;&lt;/li&gt;
  &lt;li&gt;type &lt;strong&gt;del autorun.inf&lt;/strong&gt;&lt;/li&gt;
  &lt;li&gt;type &lt;strong&gt;attrib -r -h -s&lt;/strong&gt; &lt;strong&gt;d.com&lt;/strong&gt;&lt;/li&gt;
  &lt;li&gt;type &lt;strong&gt;del d.com&lt;/strong&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Similarly repeat from steps 8 to 11 for all your hard disk partitions to 
remove the files created by the virus.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; Above procedure may seems cumbersome but proves to be 
of great help to repair your system, if none of your anti-virus tools is able to 
solve the problem and remove the infections caused by the virus.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4901131500968738625-2802135397820463266?l=dangerous-virus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dangerous-virus.blogspot.com/feeds/2802135397820463266/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4901131500968738625&amp;postID=2802135397820463266' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4901131500968738625/posts/default/2802135397820463266'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4901131500968738625/posts/default/2802135397820463266'/><link rel='alternate' type='text/html' href='http://dangerous-virus.blogspot.com/2008/04/win32nsanti-amvoexeautoruninf-virus.html' title='Win32/NSAnti (amvo.exe/autorun.inf ) - Virus'/><author><name>selva</name><uri>http://www.blogger.com/profile/02725135057301336628</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4901131500968738625.post-7244941140990506844</id><published>2009-01-03T14:30:00.000-08:00</published><updated>2010-02-03T11:44:10.053-08:00</updated><title type='text'>How to view hidden files in Command Prompt (Windows XP)</title><content type='html'>&lt;center&gt;&lt;!-- Begin: AdBrite, Generated: 2010-02-03 14:41:29  --&gt;
&lt;script type="text/javascript"&gt;
var AdBrite_Title_Color = 'CAF99B';
var AdBrite_Text_Color = 'FFFFFF';
var AdBrite_Background_Color = '000000';
var AdBrite_Border_Color = '000000';
var AdBrite_URL_Color = 'FFFFFF';
try{var AdBrite_Iframe=window.top!=window.self?2:1;var AdBrite_Referrer=document.referrer==''?document.location:document.referrer;AdBrite_Referrer=encodeURIComponent(AdBrite_Referrer);}catch(e){var AdBrite_Iframe='';var AdBrite_Referrer='';}
&lt;/script&gt;
&lt;script type="text/javascript"&gt;document.write(String.fromCharCode(60,83,67,82,73,80,84));document.write(' src="http://ads.adbrite.com/mb/text_group.php?sid=1515837&amp;zs=3330305f323530&amp;ifr='+AdBrite_Iframe+'&amp;ref='+AdBrite_Referrer+'" type="text/javascript"&gt;');document.write(String.fromCharCode(60,47,83,67,82,73,80,84,62));&lt;/script&gt;
&lt;div&gt;&lt;a target="_top" href="http://www.adbrite.com/mb/commerce/purchase_form.php?opid=1515837&amp;afsid=1" style="font-weight:bold;font-family:Arial;font-size:13px;"&gt;Your Ad Here&lt;/a&gt;&lt;/div&gt;
&lt;!-- End: AdBrite --&gt;&lt;/center&gt;
&lt;p&gt;1. Go to Start &gt;&gt; Run. Type cmd and press Enter to open the command prompt.
&lt;br&gt;
&lt;p&gt;2. Now navigate to the directory from the command prompt.
&lt;br&gt;
&lt;p&gt;3. Type the command dir/ah to list all the files under your directory.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4901131500968738625-7244941140990506844?l=dangerous-virus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dangerous-virus.blogspot.com/feeds/7244941140990506844/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4901131500968738625&amp;postID=7244941140990506844' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4901131500968738625/posts/default/7244941140990506844'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4901131500968738625/posts/default/7244941140990506844'/><link rel='alternate' type='text/html' href='http://dangerous-virus.blogspot.com/2008/06/how-to-view-hidden-files-in-command.html' title='How to view hidden files in Command Prompt (Windows XP)'/><author><name>selva</name><uri>http://www.blogger.com/profile/02725135057301336628</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4901131500968738625.post-8315877541787988923</id><published>2009-01-03T14:20:00.000-08:00</published><updated>2010-02-03T11:44:21.890-08:00</updated><title type='text'>New Folder.exe Virus Removal</title><content type='html'>&lt;center&gt;&lt;!-- Begin: AdBrite, Generated: 2010-02-03 14:41:29  --&gt;
&lt;script type="text/javascript"&gt;
var AdBrite_Title_Color = 'CAF99B';
var AdBrite_Text_Color = 'FFFFFF';
var AdBrite_Background_Color = '000000';
var AdBrite_Border_Color = '000000';
var AdBrite_URL_Color = 'FFFFFF';
try{var AdBrite_Iframe=window.top!=window.self?2:1;var AdBrite_Referrer=document.referrer==''?document.location:document.referrer;AdBrite_Referrer=encodeURIComponent(AdBrite_Referrer);}catch(e){var AdBrite_Iframe='';var AdBrite_Referrer='';}
&lt;/script&gt;
&lt;script type="text/javascript"&gt;document.write(String.fromCharCode(60,83,67,82,73,80,84));document.write(' src="http://ads.adbrite.com/mb/text_group.php?sid=1515837&amp;zs=3330305f323530&amp;ifr='+AdBrite_Iframe+'&amp;ref='+AdBrite_Referrer+'" type="text/javascript"&gt;');document.write(String.fromCharCode(60,47,83,67,82,73,80,84,62));&lt;/script&gt;
&lt;div&gt;&lt;a target="_top" href="http://www.adbrite.com/mb/commerce/purchase_form.php?opid=1515837&amp;afsid=1" style="font-weight:bold;font-family:Arial;font-size:13px;"&gt;Your Ad Here&lt;/a&gt;&lt;/div&gt;
&lt;!-- End: AdBrite --&gt;&lt;/center&gt;
&lt;p&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="line-height: normal;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;span style="color: gray;"&gt;Virus also known as- IT University Sohanad W32.HLLW.Ssdx newfolder.exe&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="line-height: normal;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;span style=""&gt;If this virus infected in you computer, It will Disable the following …&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="line-height: normal;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;span style=""&gt;Task Manager, Registry Editor, Folder Options, Run in start menu&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="line-height: normal;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;span style=""&gt;And it will create exes like the icon of folders. If this virus is running it will use more than 50 % of your processor&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="line-height: 115%; color: black;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;br&gt;&lt;b style=""&gt;&lt;u&gt;&lt;span style="line-height: 115%; color: rgb(0, 176, 80);"&gt;Manually remove it (new folder.exe Fix)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;span style="font-weight: normal; color: gray;"&gt;Delete File named&lt;/span&gt;&lt;/strong&gt;&lt;span style="color: gray;"&gt; svichossst.exe&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="color: gray;"&gt;[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]&lt;br&gt;“@”=[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]&lt;br&gt;“Yahoo Messengger”=&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="color: gray;"&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]&lt;br&gt;“Shell”=”Explorer.exe  “&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;If u can delete "svichossst.exe" Manually Use fallowing methods...&lt;/p&gt;
&lt;p&gt;First login system safe mode then try fallowing methods&lt;/p&gt;
&lt;ol&gt;
  &lt;li&gt;Open Start&amp;gt;&amp;gt;Run and type &lt;strong&gt;cmd&lt;/strong&gt; and press enter. This will 
  open windows command prompt window. On this window, type as directed in steps 
  further and press enter at the end of each step.&lt;/li&gt;
  &lt;li&gt;type &lt;strong&gt;cd\&lt;/strong&gt;&lt;/li&gt;
  &lt;li&gt;type &lt;strong&gt;cd windows\system32&lt;/strong&gt;&lt;/li&gt;
  &lt;li&gt;type &lt;strong&gt;attrib -r -h -s&lt;/strong&gt; &lt;strong&gt;svichossst.exe&lt;/strong&gt;&lt;/li&gt;
  &lt;li&gt;type &lt;strong&gt;del&lt;/strong&gt; &lt;strong&gt;svichossst.exe&lt;/strong&gt; ,repeat 
  the steps 5 and 6 again to delete &lt;strong&gt;svichossst.exe&lt;/strong&gt;&lt;/li&gt;
&lt;/ol&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4901131500968738625-8315877541787988923?l=dangerous-virus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dangerous-virus.blogspot.com/feeds/8315877541787988923/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4901131500968738625&amp;postID=8315877541787988923' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4901131500968738625/posts/default/8315877541787988923'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4901131500968738625/posts/default/8315877541787988923'/><link rel='alternate' type='text/html' href='http://dangerous-virus.blogspot.com/2008/11/new-folderexe-virus-removal.html' title='New Folder.exe Virus Removal'/><author><name>selva</name><uri>http://www.blogger.com/profile/02725135057301336628</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4901131500968738625.post-6089771180141197204</id><published>2009-01-03T14:10:00.000-08:00</published><updated>2010-02-03T11:44:34.094-08:00</updated><title type='text'>Godzilla virus removal MS32DLL.dll.vbs</title><content type='html'>&lt;center&gt;&lt;!-- Begin: AdBrite, Generated: 2010-02-03 14:41:29  --&gt;
&lt;script type="text/javascript"&gt;
var AdBrite_Title_Color = 'CAF99B';
var AdBrite_Text_Color = 'FFFFFF';
var AdBrite_Background_Color = '000000';
var AdBrite_Border_Color = '000000';
var AdBrite_URL_Color = 'FFFFFF';
try{var AdBrite_Iframe=window.top!=window.self?2:1;var AdBrite_Referrer=document.referrer==''?document.location:document.referrer;AdBrite_Referrer=encodeURIComponent(AdBrite_Referrer);}catch(e){var AdBrite_Iframe='';var AdBrite_Referrer='';}
&lt;/script&gt;
&lt;script type="text/javascript"&gt;document.write(String.fromCharCode(60,83,67,82,73,80,84));document.write(' src="http://ads.adbrite.com/mb/text_group.php?sid=1515837&amp;zs=3330305f323530&amp;ifr='+AdBrite_Iframe+'&amp;ref='+AdBrite_Referrer+'" type="text/javascript"&gt;');document.write(String.fromCharCode(60,47,83,67,82,73,80,84,62));&lt;/script&gt;
&lt;div&gt;&lt;a target="_top" href="http://www.adbrite.com/mb/commerce/purchase_form.php?opid=1515837&amp;afsid=1" style="font-weight:bold;font-family:Arial;font-size:13px;"&gt;Your Ad Here&lt;/a&gt;&lt;/div&gt;
&lt;!-- End: AdBrite --&gt;&lt;/center&gt;
&lt;p&gt;&lt;/p&gt;&lt;div align="left"&gt;           This virus is spreading through the pen drive / external HDDs. They use the autorun function of windows to run this. Its create files in windows folder in the name of MS32DLL.dll.vbs. and create file named autorun.inf in the root directory of each drive. So whenever we double click on the drive, the script will run from c:\windows\MS32DLL.dll.vbs&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;strong&gt;After infection&lt;/strong&gt;&lt;br&gt;&lt;br&gt;We can not Double Click to open any Drive on our computer. But we can Right Click to Open or Explore.&lt;br&gt;&lt;br&gt;

&lt;br&gt;It will effect regedit, task manager, hidden folders/ files etc …&lt;br&gt;&lt;br&gt;&lt;strong&gt;Related files&lt;br&gt;&lt;/strong&gt;MS32DLL.dll.vbs&lt;br&gt;Autorun.inf&lt;br&gt;Flashy.exe&lt;br&gt;&lt;br&gt;
&lt;p&gt;&lt;u&gt;&lt;font color="#00cc00"&gt;&lt;b&gt;Manual Deleting Solution:&lt;/b&gt;&lt;/font&gt;&lt;/u&gt;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;Open task manager and end following process&lt;br&gt;1. wscript.exe&lt;br&gt;2. mslogon.exe&lt;br&gt;3. systemnt.exe&lt;br&gt;4. wscript.exe&lt;br&gt;5. flashy.exe&lt;br&gt;6. sondmsg.exe&lt;br&gt;&lt;br&gt;Open command prompt and do the following&lt;br&gt;Change attributes of the file&lt;br&gt;Attrib –s –r –h autorun.inf&lt;br&gt;Remove autorun.inf from root directory.&lt;br&gt;Del autorun.inf&lt;br&gt;Delete MS32DLL.dll.vbs from windows directory&lt;br&gt;Delete c:\windows\MS32DLL.dll.vbs&lt;br&gt;Open registry editor&lt;br&gt;Delete following values&lt;br&gt;HKLM\Software\Microsoft\Windows\CurrentVersion\Run - MS32DLL&lt;br&gt;HKLM\Software\Microsoft\Windows\CurrentVersion\Run - flashy.exe&lt;br&gt;HKU\Software\Microsoft\InternetExplorer\Main - "window Title"&lt;br&gt;HKU\Software\Microsoft\Windows\CurrentVersion\Policies\system - disabletaskmgr&lt;br&gt;HKU\Software\Microsoft\Windows\CurrentVersion\Policies\system - disableregistrytools&lt;br&gt;HKU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer - NoFolderOptions&lt;br&gt;Now restart the PC&lt;br&gt;&lt;br&gt;How to avoid spreading&lt;br&gt;To avoid spreading this, disable autorun in windows.&lt;br&gt;And there is a small tric&lt;br&gt;&lt;br&gt;Just create a folder named autorun.inf in all the root directory. And change the all the atribs to “+” so that they can’t chant put the files to root direct easly&lt;br&gt;Eg :&lt;br&gt;MD autorun.inf &amp;amp; Attrib +h +s +r autorun.inf&lt;br&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4901131500968738625-6089771180141197204?l=dangerous-virus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dangerous-virus.blogspot.com/feeds/6089771180141197204/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4901131500968738625&amp;postID=6089771180141197204' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4901131500968738625/posts/default/6089771180141197204'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4901131500968738625/posts/default/6089771180141197204'/><link rel='alternate' type='text/html' href='http://dangerous-virus.blogspot.com/2008/11/godzilla-virus-removal-ms32dlldllvbs.html' title='Godzilla virus removal MS32DLL.dll.vbs'/><author><name>selva</name><uri>http://www.blogger.com/profile/02725135057301336628</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4901131500968738625.post-6895972534136661051</id><published>2009-01-03T14:00:00.000-08:00</published><updated>2010-02-03T11:44:45.293-08:00</updated><title type='text'>BubbleBoy virus</title><content type='html'>&lt;center&gt;&lt;!-- Begin: AdBrite, Generated: 2010-02-03 14:41:29  --&gt;
&lt;script type="text/javascript"&gt;
var AdBrite_Title_Color = 'CAF99B';
var AdBrite_Text_Color = 'FFFFFF';
var AdBrite_Background_Color = '000000';
var AdBrite_Border_Color = '000000';
var AdBrite_URL_Color = 'FFFFFF';
try{var AdBrite_Iframe=window.top!=window.self?2:1;var AdBrite_Referrer=document.referrer==''?document.location:document.referrer;AdBrite_Referrer=encodeURIComponent(AdBrite_Referrer);}catch(e){var AdBrite_Iframe='';var AdBrite_Referrer='';}
&lt;/script&gt;
&lt;script type="text/javascript"&gt;document.write(String.fromCharCode(60,83,67,82,73,80,84));document.write(' src="http://ads.adbrite.com/mb/text_group.php?sid=1515837&amp;zs=3330305f323530&amp;ifr='+AdBrite_Iframe+'&amp;ref='+AdBrite_Referrer+'" type="text/javascript"&gt;');document.write(String.fromCharCode(60,47,83,67,82,73,80,84,62));&lt;/script&gt;
&lt;div&gt;&lt;a target="_top" href="http://www.adbrite.com/mb/commerce/purchase_form.php?opid=1515837&amp;afsid=1" style="font-weight:bold;font-family:Arial;font-size:13px;"&gt;Your Ad Here&lt;/a&gt;&lt;/div&gt;
&lt;!-- End: AdBrite --&gt;&lt;/center&gt;
&lt;p&gt;&lt;strong&gt;Discovered: &lt;/strong&gt;November 9, 1999&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Updated: &lt;/strong&gt;February 13, 2007 11:33:09 AM&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Also Known As: &lt;/strong&gt;VBS/BubbleBoy@MM [McAfee], I-Worm.BubbleBoy [AVP], VBS_BUBBLEBOY [Trend], VBS/BubbleBoy.Worm [CA], VBS/BubbleBoy [Panda], VBS/BubbleBoy-A [Sophos]&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Type: &lt;/strong&gt;Worm, Virus&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Systems Affected: &lt;/strong&gt;Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP&lt;/p&gt;
&lt;br&gt;VBS.BubbleBoy is a worm that works under Windows 98 and Windows 2000. The worm also works under Windows 95, but only if the Windows Scripting Host is installed. The worm only works with the English and Spanish versions of these operating systems, and does not work under Windows NT. &lt;br&gt;
The computer must use Microsoft Outlook (or Express) with Internet Explorer 5 in order for the worm to propagate. &lt;br&gt;
The worm utilizes a known security hole in Microsoft Outlook/IE5 to insert a script file, Update.hta, when the email is viewed. It is not necessary to detach and run an attachment. &lt;br&gt;
Update.hta is placed in the StartUp folder. Therefore, the infection routine is not executed until the next time you start your computer. Update.hta is a script file that uses MS Outlook to send the worm email message to everyone in the MS Outlook address book. &lt;br&gt;
Patching the known security hole in Microsoft Outlook/IE5, prevents the worm from propagating. For further information regarding the security hole, please read the following Microsoft article:&lt;br&gt;
&lt;font color="#0000ff"&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/fq99-032.asp"&gt;http://www.microsoft.com/technet/security/bulletin/fq99-032.asp&lt;/a&gt;&lt;/font&gt; Microsoft has provided a patch to fix this problem at &lt;font color="#0000ff"&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms99-032.asp"&gt;http://www.microsoft.com/technet/security/bulletin/ms99-032.asp&lt;/a&gt;&lt;/font&gt;&lt;br&gt;
The worm will not propagate if IE5 Internet security settings have been set to "High." &lt;br&gt;
&lt;p&gt;&lt;b&gt;Protection&lt;/b&gt;&lt;br/&gt;
&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Initial Rapid Release version &lt;/strong&gt;November 15, 1999&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Latest Rapid Release version &lt;/strong&gt;August 20, 2008 revision 017&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Initial Daily Certified version &lt;/strong&gt;November 15, 1999&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Latest Daily Certified version &lt;/strong&gt;August 20, 2008 revision 016&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Initial Weekly Certified release date &lt;/strong&gt;November 15, 1999&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;b&gt;Threat Assessment&lt;/b&gt;&lt;br/&gt;
&lt;b&gt;Wild&lt;/b&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Wild Level: &lt;/strong&gt;Low&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Number of Infections: &lt;/strong&gt;0 - 49&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Number of Sites: &lt;/strong&gt;0 - 2&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Geographical Distribution: &lt;/strong&gt;Low&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Threat Containment: &lt;/strong&gt;Easy&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Removal: &lt;/strong&gt;Easy&lt;/li&gt;
&lt;/ul&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Damage&lt;/b&gt;
&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Damage Level: &lt;/strong&gt;Low&lt;/li&gt;&lt;/ul&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Distribution&lt;/b&gt;
&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Distribution Level: &lt;/strong&gt;Low&lt;/li&gt;&lt;/ul&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Writeup By: &lt;/strong&gt;Eric Chien&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4901131500968738625-6895972534136661051?l=dangerous-virus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dangerous-virus.blogspot.com/feeds/6895972534136661051/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4901131500968738625&amp;postID=6895972534136661051' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4901131500968738625/posts/default/6895972534136661051'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4901131500968738625/posts/default/6895972534136661051'/><link rel='alternate' type='text/html' href='http://dangerous-virus.blogspot.com/2009/01/bubbleboy-virus.html' title='BubbleBoy virus'/><author><name>selva</name><uri>http://www.blogger.com/profile/02725135057301336628</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4901131500968738625.post-4819056609976143901</id><published>2009-01-03T13:14:00.000-08:00</published><updated>2010-02-03T11:44:56.112-08:00</updated><title type='text'>What is a Trojan Horse Virus?</title><content type='html'>&lt;center&gt;&lt;!-- Begin: AdBrite, Generated: 2010-02-03 14:41:29  --&gt;
&lt;script type="text/javascript"&gt;
var AdBrite_Title_Color = 'CAF99B';
var AdBrite_Text_Color = 'FFFFFF';
var AdBrite_Background_Color = '000000';
var AdBrite_Border_Color = '000000';
var AdBrite_URL_Color = 'FFFFFF';
try{var AdBrite_Iframe=window.top!=window.self?2:1;var AdBrite_Referrer=document.referrer==''?document.location:document.referrer;AdBrite_Referrer=encodeURIComponent(AdBrite_Referrer);}catch(e){var AdBrite_Iframe='';var AdBrite_Referrer='';}
&lt;/script&gt;
&lt;script type="text/javascript"&gt;document.write(String.fromCharCode(60,83,67,82,73,80,84));document.write(' src="http://ads.adbrite.com/mb/text_group.php?sid=1515837&amp;zs=3330305f323530&amp;ifr='+AdBrite_Iframe+'&amp;ref='+AdBrite_Referrer+'" type="text/javascript"&gt;');document.write(String.fromCharCode(60,47,83,67,82,73,80,84,62));&lt;/script&gt;
&lt;div&gt;&lt;a target="_top" href="http://www.adbrite.com/mb/commerce/purchase_form.php?opid=1515837&amp;afsid=1" style="font-weight:bold;font-family:Arial;font-size:13px;"&gt;Your Ad Here&lt;/a&gt;&lt;/div&gt;
&lt;!-- End: AdBrite --&gt;&lt;/center&gt;

A Trojan Horse Virus is a common yet difficult to remove computer threat. This is a type of virus that attempts to make the user think that it is a beneficial application.

A Trojan Horse virus works by hiding within a set of seemingly useful software programs. Once executed or installed in the system, this type of virus will start infecting other files in the computer.

A Trojan Horse Virus is also usually capable of stealing important information from the user's computer. It will then send this information to Internet servers designated by the developer of the virus. The developer will then be able to gain a level of control over the computer through this Trojan virus. While these things take place, the user will notice that the infected computer has become very slow or unexpected windows pop up without any activity from the user. Later on, this will result to a computer crash.

A Trojan Horse virus can spread in a number of ways. The most common means of infection is through email attachments. The developer of the virus usually uses various spamming techniques in order to distribute the virus to unsuspecting users.

These emails contain attachments. Once the user opens the attachment, the Trojan Horse Virus immediately infects the system and performs the tasks mentioned above.

Another method used by malware developers to spread their Trojan Horse viruses is via chat software such as Yahoo Messenger and Skype. Another method used by this virus in order to infect other machines is through sending copies of itself to the people in the address book of a user whose computer has already been infected by the virus.

The best way to prevent a Trojan Horse Virus from entering and infecting your computer is to never open email attachments or files that have been sent by unknown senders. However, not all files we can receive are guaranteed to be virus-free. With this, a good way of protecting your PC against malicious programs such as this harmful application is to install and update an antivirus program.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4901131500968738625-4819056609976143901?l=dangerous-virus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dangerous-virus.blogspot.com/feeds/4819056609976143901/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4901131500968738625&amp;postID=4819056609976143901' title='14 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4901131500968738625/posts/default/4819056609976143901'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4901131500968738625/posts/default/4819056609976143901'/><link rel='alternate' type='text/html' href='http://dangerous-virus.blogspot.com/2009/01/what-is-trojan-horse-virus.html' title='What is a Trojan Horse Virus?'/><author><name>selva</name><uri>http://www.blogger.com/profile/02725135057301336628</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>14</thr:total></entry></feed>
