Win32 AutoRun Worm-Funny UST scandal worm create a hidden background service (xmss.exe). It copied itself on Local disk and Windows Directory (%Windir%). Terminated “Windows Task Manager”, Windows Command Prompt (DOS-Prompt) & crashed System Internal Process Explorer (procxp.exe).
Files created by this worm
* x:autorun.inf
* x:xmss.exe
* x:Funny UST Scandal.avi.exe
* %Windir%\autorun.inf
* %Windir%\xmss.exe
* %Windir%\Funny UST Scandal.avi.exe
How to remove
1. Disabled System Restore for Temporary - KB 264887
2. Boot Windows in Safe Mode - KB 315222
3. In Windows Safe Mode, Open Windows Registry Editor
Windows Start > Run > Regedit
Browse to the following registry settings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Shell
Replace the value 'explorer.exe, xmss.exe' with 'exporer.exe'
4. Delete all the following files
* C\autorun.inf
* C\xmss.exe
* C\Funny UST Scandal.avi.exe
* X:\autorun.inf
* X:\xmss.exe
* X:\Funny UST Scandal.avi.exe
* %Windir%\autorun.inf
* %Windir%\xmss.exe
* %Windir%\Funny UST Scandal.avi.exe
5. Clean All Windows Temporary Files
6. Restart the Windows
** edit registry values with false data can damage your OS **
Showing posts with label trojen. Show all posts
Showing posts with label trojen. Show all posts
Thursday, March 20, 2008
Wednesday, October 31, 2007
Tips for protecting your system from virus
Tips for protecting your system from virus
* disable AutoRun In CD Drive
* do not download any executable file from your mail. like .com, .bat, .exe etc
* avoid clicking on executable file having default icon(icon of cmd.exe)
* disable system restore
* keep an eye on temp folders and system restore point because these are the favorite place of trojens and small virus
* do not open mail from unknown sender
* check you startup list at every logon
* do not give write permission in sharing ( in Network)
* keep an eye on process list, if any specious process found check it.
* disconnect internet when not in use, because intruder attacks are high when you are in idle state
these tips will only protect your system from small virus and trojens, use an antivirus for protecting from high risk virus and a firewall, update your virus definition Frequently
Virus Type
* disable AutoRun In CD Drive
* do not download any executable file from your mail. like .com, .bat, .exe etc
* avoid clicking on executable file having default icon(icon of cmd.exe)
* disable system restore
* keep an eye on temp folders and system restore point because these are the favorite place of trojens and small virus
* do not open mail from unknown sender
* check you startup list at every logon
* do not give write permission in sharing ( in Network)
* keep an eye on process list, if any specious process found check it.
* disconnect internet when not in use, because intruder attacks are high when you are in idle state
these tips will only protect your system from small virus and trojens, use an antivirus for protecting from high risk virus and a firewall, update your virus definition Frequently
Virus Type
- Boot viruses
- Program viruses
- Multipartite viruses
- Stealth viruses
- Polymorphic viruses
- Macro Viruses
- Active X
- Downloader
- Remote Access.
- Email Sending
- Data Destruction
- Proxy Trojan
- FTP Trojan
- security software disabler
- denial-of-service attack (DoS)
- URL trojan
Subscribe to:
Posts (Atom)