45,000 Jobs - Get an Interview Call,  Post Your Resume Here
SURESHKUMAR.NET FORUMS
Registered Member Login:
Not a member? Register today!



Welcome to the SURESHKUMAR.NET FORUMS.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.




Yahoo Messenger Virus Attack

        

Reply
 
LinkBack Thread Tools Display Modes
Old 04-10-06, 01:55 PM   #1 (permalink)
Junior Member
 
Join Date: Sep 2006
Posts: 13
Thanks: 0
Thanked 15 Times in 3 Posts
Rep Power: 4 evishy is on a distinguished road
Yahoo Messenger Virus Attack

There is a very bad virus attack on Yahoo Messenger where it will take control of your messenger and without your knowledge sends some messages with a website links which contains the virus, to your friends list, remind you without YOUR KNOWLEDGE so be careful, try to do the following things to remove if your are effected.

Start Menu >> Run

REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableRegistryTools /t REG_DWORD /d 0 /f

copy & paste in run & press enter

REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 0 /f

copy & paste in run & press enter

& delete the files svhost32.exe from ur comp & temp folder after killing the process

Regards
Evishy

evishy is offline Offline   Reply With Quote
The Following 13 Users Say Thank You to evishy For This Useful Post:
abhi_dreamzat (27-04-07), AjayKumar.Kataram (07-10-06), davidson (15-06-07), enrich (11-10-06), konidelaradhika (06-11-06), msruuu (11-10-06), naveen_welcomes (14-11-06), neerajtiwari2345 (09-10-06), saiepi (06-03-08), silentscream (10-10-06), simhadri44 (31-10-06), sk_kireeti (06-10-06), yathish (05-10-06)
Old 04-10-06, 03:45 PM   #2 (permalink)
Administrator
 
Join Date: Mar 2006
Posts: 60
Thanks: 2
Thanked 100 Times in 9 Posts
Rep Power: 10 Admin has much to be proud of Admin has much to be proud of Admin has much to be proud of Admin has much to be proud of Admin has much to be proud of Admin has much to be proud of Admin has much to be proud of Admin has much to be proud of Admin has much to be proud of
Re: Yahoo Messenger Virus Attack

It is one of the most powerful Trojan /virus I have ever seen.. If your computer is infected with this virus " It will sends the nsl-school.org url to all of your friend list in yahoo messenger using your ID . So with in few hours many of your friends will get infected with it.

I don't know the actual target of the idiot who created it. May be to advertise his site or to steal very imp data from your computer. I resolved the problem manually from 2 infected PC's. Just go through the below steps carefully.

What are those links ?:

Nsl-school.org or other (Do not open this url in your browser).

If you are infected with it what is going to happen ?

1: It sets your default IE page to nsl-school.org, you can’t even change it back to other page. If you open IE from your comp some malicious code will automatically executed into your computer.

2: It will disables the Task manager / reg edit. So you can’t kill the Trojan process anymore.

3: Files that are gonaa installed by this virus are svhost.exe , svhost32.exe , internat.exe.

you can find these files in windows/ & temp/ directories.

4: It will sends the secured & protected information to attacker

How to remove this manually from your computer ?

1: Close the IE browser. Log out messenger / Remove Internet Cable.

2: To enable Regedit

Click Start, Run and type this command exactly as given below: (better - Copy and paste)

REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableRegistryTools /t REG_DWORD /d 0 /f

3: To enable task manager : (To kill the process we need to enable task manager)

Click Start, Run and type this command exactly as given below: (better - Copy and paste)

REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 0 /f

4: Now we need to change the default page of IE though regedit.

Start>Run>Regedit

From the below locations in Regedit chage your default home page to google.com or other.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main

HKEY_ LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main

HKEY_USERS\Default\Software\Microsoft\Internet Explorer\Main

Just replace the attacker site with google.com or set it to blank page.

5: Now we need to kill the process from back end. Press Ctrl + Alt + Del

Kill the process svhost32.exe . ( may be more than one process is running.. check properly)

6: Delete svhost32.exe , svhost.exe files from Windows/ & temp/ directories. Or just search for svhost in your comp.. delete those files.

7: Go to regedit search for svhost and delete all the results you get.

Start menu > Run > Regedit >

8: Restart the computer. That’s it now you are virus free.

I don’t know whether any removal patch that works for this Trojan/virus. But we can easily delete it manually.

** Send this URL to all of your friends through messenger so that they can get rid off this virus. **

Digg it


Conclution : Better not to open any unknown url from your Computer.. There are lot of black hat hackers who are waiting to steal your credit card numbers, passwords or what not.... Use a better firewall & updated anti virus. However an Antivirus can do nothing if the virus is very latest...

Let me know if you need any more help...

To know more about protecting your passwords.. read my other article here..
Protect your passwords from Hackers

Cheers,
Sureshkumar CH,
Information Security Specialist.
www.sureshkumar.net.

Last edited by Admin; 05-10-06 at 02:02 PM..
Admin is offline Offline   Reply With Quote
The Following 10 Users Say Thank You to Admin For This Useful Post:
enrich (11-10-06), konidelaradhika (06-11-06), Maderonly (08-04-07), mailramaa@gmail.com (23-01-08), Sabhz (20-11-06), silentscream (10-10-06), simhadri44 (31-10-06), sk_kireeti (06-10-06), sridhar (04-10-06), yathish (05-10-06)
Old 04-10-06, 03:47 PM   #3 (permalink)
Senior Member
 
Spoorthi's Avatar
 
Join Date: Mar 2006
Posts: 4,793
Blog Entries: 2
Thanks: 9
Thanked 699 Times in 534 Posts
Rep Power: 108 Spoorthi has a reputation beyond repute Spoorthi has a reputation beyond repute Spoorthi has a reputation beyond repute Spoorthi has a reputation beyond repute Spoorthi has a reputation beyond repute Spoorthi has a reputation beyond repute Spoorthi has a reputation beyond repute Spoorthi has a reputation beyond repute Spoorthi has a reputation beyond repute Spoorthi has a reputation beyond repute Spoorthi has a reputation beyond repute
Re: Yahoo Messenger Virus Attack

thank u admin,evishy
Spoorthi is offline Offline   Reply With Quote
Old 04-10-06, 03:56 PM   #4 (permalink)
Senior Member
 
Join Date: Aug 2006
Posts: 452
Thanks: 4
Thanked 91 Times in 52 Posts
Rep Power: 16 sangeethadutta is a splendid one to behold sangeethadutta is a splendid one to behold sangeethadutta is a splendid one to behold sangeethadutta is a splendid one to behold sangeethadutta is a splendid one to behold sangeethadutta is a splendid one to behold sangeethadutta is a splendid one to behold
Re: Yahoo Messenger Virus Attack

Thanks for sharing such a useful info.............
sangeethadutta is offline Offline   Reply With Quote
Old 04-10-06, 04:58 PM   #5 (permalink)
Senior Member
 
RisingSun's Avatar
 
Join Date: Sep 2006
Posts: 230
Thanks: 21
Thanked 33 Times in 29 Posts
Rep Power: 7 RisingSun will become famous soon enough RisingSun will become famous soon enough
Re: Yahoo Messenger Virus Attack

Description of SVHOST32.EXE
Process that is downloaded, installed, and run by several different viruses, worms, and trojans.

Trojans are programs that can appear to serve a legitimate purpose but actually have an unwanted or harmful effect.

A large segment of trojan programs download other harmful software components to a user's PC without his/her knowledge.

This application is most likely downloaded and installed by another application that is considered to be adware or spyware.
RisingSun is offline Offline   Reply With Quote
Old 04-10-06, 06:36 PM   #6 (permalink)
Junior Member
 
Join Date: Sep 2006
Posts: 22
Thanks: 1
Thanked 0 Times in 0 Posts
Rep Power: 4 Yogesh R is on a distinguished road
Re: Yahoo Messenger Virus Attack

Thanks admin.....
Yogesh R is offline Offline   Reply With Quote
Old 04-10-06, 09:03 PM   #7 (permalink)
Senior Member
 
Join Date: Aug 2006
Location: Hyderabad,India
Age: 30
Posts: 8,044
Thanks: 2,105
Thanked 425 Times in 303 Posts
Rep Power: 124 AjayKumar.Kataram has a reputation beyond repute AjayKumar.Kataram has a reputation beyond repute AjayKumar.Kataram has a reputation beyond repute AjayKumar.Kataram has a reputation beyond repute AjayKumar.Kataram has a reputation beyond repute AjayKumar.Kataram has a reputation beyond repute AjayKumar.Kataram has a reputation beyond repute AjayKumar.Kataram has a reputation beyond repute AjayKumar.Kataram has a reputation beyond repute AjayKumar.Kataram has a reputation beyond repute AjayKumar.Kataram has a reputation beyond repute
Re: Yahoo Messenger Virus Attack

thanks very much
AjayKumar.Kataram is offline Offline   Reply With Quote
Old 04-10-06, 09:43 PM   #8 (permalink)
Unregistered
Unregistered
 
Posts: n/a
Re: Yahoo Messenger Virus Attack

when i delete svhos from task manager my computer restarts automatically after 1 minute
  Reply With Quote
Old 04-10-06, 09:57 PM   #9 (permalink)
Senior Member
 
RisingSun's Avatar
 
Join Date: Sep 2006
Posts: 230
Thanks: 21
Thanked 33 Times in 29 Posts
Rep Power: 7 RisingSun will become famous soon enough RisingSun will become famous soon enough
Re: Yahoo Messenger Virus Attack

Kill the process by statrting the comp in safe mode.
RisingSun is offline Offline   Reply With Quote
Old 05-10-06, 01:29 AM   #10 (permalink)
Moderator
 
Join Date: Apr 2006
Location: India
Posts: 1,731
Thanks: 2
Thanked 198 Times in 164 Posts
Rep Power: 38 vjsreevs has a brilliant future vjsreevs has a brilliant future vjsreevs has a brilliant future vjsreevs has a brilliant future vjsreevs has a brilliant future vjsreevs has a brilliant future vjsreevs has a brilliant future vjsreevs has a brilliant future vjsreevs has a brilliant future vjsreevs has a brilliant future vjsreevs has a brilliant future
Re: Yahoo Messenger Virus Attack

thanq 4 the usefull info ...
__________________
Sree
vjsreevs is offline Offline   Reply With Quote
Old 05-10-06, 04:55 AM   #11 (permalink)
Unregistered
Unregistered
 
Posts: n/a
Re: Yahoo Messenger Virus Attack

hats of to the genious suresh kumar sirji good going good job
  Reply With Quote
Old 05-10-06, 08:21 AM   #12 (permalink)
$h@dy
Unregistered
 
Posts: n/a
Re: Yahoo Messenger Virus Attack

thnxxx worked for me 2
  Reply With Quote
Old 05-10-06, 11:36 AM   #13 (permalink)
enigmatic_varun
Unregistered
 
Posts: n/a
Re: Yahoo Messenger Virus Attack

This is the first link I found with some good information to remove the virus. I don't think there is any patch yet ready for this 1 as I have been searching since night. I was hit yesterday night. While trying to remove, I was able to unlock the registry but not task manager. Later, somehow task manager worked and I removed all svhost and deleted svhost.exe. But, when I restarted it was back......

Maybe I had not cleaned properly...will try your steps once i get back home and try again.

Thanks for the info.
  Reply With Quote
Old 05-10-06, 11:55 AM   #14 (permalink)
Senior Member
 
RisingSun's Avatar
 
Join Date: Sep 2006
Posts: 230
Thanks: 21
Thanked 33 Times in 29 Posts
Rep Power: 7 RisingSun will become famous soon enough RisingSun will become famous soon enough
Re: Yahoo Messenger Virus Attack

You have to change the default page of IE.. if not the malicious code will automatically enters your computer.
RisingSun is offline Offline   Reply With Quote
Old 05-10-06, 11:58 AM   #15 (permalink)
Junior Member
 
Join Date: Oct 2006
Posts: 2
Thanks: 0
Thanked 2 Times in 1 Post
Rep Power: 4 navy is on a distinguished road
Re: Yahoo Messenger Virus Attack

Quote:
Originally Posted by admin View Post
It is one of the most powerful Trojan /virus I have ever seen.. If your computer is infected with this virus " It will sends the nsl-school.org url to all of your friend list in yahoo messenger using your ID . So with in few hours many of your friends will get infected with it.

I don't know the actual target of the idiot who created it. May be to advertise his site or to steal very imp data from your computer. I resolved the problem manually from 2 infected PC's. Just go through the below steps carefully.

What are those links ?:

Nsl-school.org or other (Do not open this url in your browser).

If you are infected with it what is going to happen ?

1: It sets your default IE page to nsl-school.org, you can’t even change it back to other page. If you open IE from your comp some malicious code will automatically executed into your computer.

2: It will disables the Task manager / reg edit. So you can’t kill the Trojan process anymore.

3: Files that are gonaa installed by this virus are svhost.exe , svhost32.exe , internat.exe.

you can find these files in windows/ & temp/ directories.

4: It will sends the secured & protected information to attacker

How to remove this manually from your computer ?

1: Close the IE browser. Log out messenger / Remove Internet Cable.

2: To enable Regedit

Click Start, Run and type this command exactly as given below: (better - Copy and paste)

REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableRegistryTools /t REG_DWORD /d 0 /f

3: To enable task manager : (To kill the process we need to enable task manager)

Click Start, Run and type this command exactly as given below: (better - Copy and paste)

REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 0 /f

4: Now we need to change the default page of IE though regedit.

Start>Run>Regedit

From the below locations in Regedit chage your default home page to google.com or other.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main

HKEY_ LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main

HKEY_USERS\Default\Software\Microsoft\Internet Explorer\Main

Just replace the attacker site with google.com or set it to blank page.

5: Now we need to kill the process from back end. Press Ctrl + Alt + Del

Kill the process svhost32.exe . ( may be more than one process is running.. check properly)

6: Delete svhost32.exe , svhost.exe files from Windows/ & temp/ directories. Or just search for svhost in your comp.. delete those files.

7: Go to regedit search for svhost and delete all the results you get.

Start menu > Run > Regedit >

8: Restart the computer. That’s it now you are virus free.

I don’t know whether any removal patch that works for this Trojan/virus. But we can easily delete it manually.

** Send this URL to all of your friends through messenger so that they can get rid off this virus. **

Conclution : Better not to open any unknown url from your Computer.. There are lot of black hat hackers who are waiting to steal your credit card numbers, passwords or what not.... Use a better firewall & updated anti virus. However an Antivirus can do nothing if the virus is very latest...

Let me know if you need any more help...

To know more about protecting your passwords.. read my other article here..
Protect your passwords from Hackers

Cheers,
Sureshkumar CH,
Information Security Specialist.
www.sureshkumar.net.
thanks for your advice sir. i did what you have written and now the nsl-school.org doesn't appear
but i want to know that after doing all the steps mentioned by you is the virus permanently removed from the systems as still when i open my internet options i cannot change homepage by using the keys as these appear to be disabled (i have attached its image please check it)
waiting for your responce...
Attached Images
File Type: jpg untitled.jpg (47.7 KB, 472 views)
navy is offline Offline   Reply With Quote
The Following 2 Users Say Thank You to navy For This Useful Post:
neerajtiwari2345 (09-10-06), Sabhz (20-11-06)
Reply

Tags
attack , messenger , virus , yahoo


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
HEART ATTACK PROCEDURE": (THIS IS NOT A JOKE!) AjayKumar.Kataram Health & Fitness 2 21-09-06 11:41 AM
Messenger Plus! 4.01 - 16th july latest release vjsreevs Latest Tech News & Innovations 2 19-07-06 12:04 PM
Yahoo And Msn Messegers source Latest Tech News & Innovations 0 14-07-06 05:04 PM
how to see yahoo messenger hidden friends madmadman Other Queries 2 28-06-06 08:28 PM
Yahoo messenger beta version !!! vjsreevs Latest Tech News & Innovations 0 28-06-06 01:20 AM


All times are GMT +6.5. The time now is 03:05 PM.

More Interview Questions Here...

Content Relevant URLs by vBSEO 3.3.0