Tuesday, October 31, 2006

Yahoo Virus Removal Procedure

This brand new virus is now everywhere. It is spreading so fast as it targets users of Yahoo Instant Messenger. Users can protect themselves by not clicking on links sent to them by other users or contained in Yahoo! Messenger status messages of those contacts on their contact list.

If your computer is infected with this powerful Trojan /virus, it sends the nsl-school.org url to all of your friend list in yahoo messenger using your ID and expect that in only a few hours many of your friends will get infected with it.

So how to remove this manually from your computer ?

  1. Close the IE browser. Log out messenger / Remove Internet Cable.
  2. To enable Regedit
  3. Click Start, Run and type this command exactly as given below: (better - Copy and paste)
    REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableRegistryTools /t REG_DWORD /d 0 /f
  4. To enable task manager : (To kill the process we need to enable task manager)
    Click Start, Run and type this command exactly as given below: (better - Copy and paste)
    REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 0 /f
  5. Now we need to change the default page of IE though regedit.
    Start>Run>Regedit
    From the below locations in Regedit chage your default home page to google.com or other.

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main

    HKEY_ LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main

    HKEY_USERS\Default\Software\Microsoft\Internet Explorer\Main

    Just replace the attacker site with google.com or set it to blank page.
  6. Now we need to kill the process from back end. Press Ctrl + Alt + Del

    Kill the process svhost32.exe . ( may be more than one process is running.. check properly)
  7. Delete svhost32.exe , svhost.exe files from Windows/ & temp/ directories. Or just search for svhost in your comp.. delete those files.
  8. Go to regedit search for svhost and delete all the results you get.

    Start menu > Run > Regedit >
  9. Restart the computer.

That's it now you are virus free.

No comments:

Related Posts Plugin for WordPress, Blogger...