14
March , 2010
Sunday

Computer Tips Made Simple! – Thinker

Sometimes broken softwares, viruses, adwares and spywares sometimes tend to make things worse for you ...
This is the first post of the thinker, here on T.hink.in. This will be my ...
Metro Manorama with Asian School Of business is organising WizQuiz a General Quiz competition for ...
It is the best. Take my word for it! I have been searching for a ...
Virus Name: Free Internet Optimizer Damage Rating for Internet Optimizer: 4/10 Internet Optimizer is a software which ...
When the infected file with the virus Brontok is launched for the first time, you ...
Your computer is infected! Windows has detected spyware infection! It is recommended to use special antispyware tools ...
I have been ignoring this blog for sometime mainly cuz whatever I wanted to say ...
BlogCamp Kerala is here and how? What a wonderful way to kickstart blogging promo in Kerala. ...
Permalink Sturctures in wordpress are very important when it comes to SEO for your blog. ...

W32 Sohanad Worm – Virus Removal

Posted by Thinker On October - 22 - 2008 1 COMMENT

Sohanad is a worm that spreads by sending links to their contacts as messengers such as Yahoo, AOL and Windows Live Messenger. The changes in Internet Explorer (IE) and the page does not allow the address of the homepage. Also, disable the Registry Editor, Task Manager and select Run from the Start menu. Flaw in Internet Explorer is the origin of these virus attacks. Firefox users are from a growing attack against the virus, so if you want to stay away from such sohanad worm and virus removal prevention and attacks, you have the Firefox browser.

worm brontok

Posted by Thinker On October - 22 - 2008 1 COMMENT
When the infected file with the virus Brontok is launched for the first time, you will see a Windows Explorer window, with a folder named “My Pictures”.

By installing the brontok worm changes the following registry key, the inaccessibility of tools registry, the command line, and viewing of files and folders in Windows Explorer.

Then Brontok copies itself under the following names

%UserProfile%\Local Settings\Application Data\br<random number>on.exe
%UserProfile%\Local Settings\Application Data\csrss.exe
%UserProfile%\Local Settings\Application Data\inetinfo.exe
%UserProfile%\Local Settings\Application Data\lsass.exe
%UserProfile%\Local Settings\Application Data\services.exe
%UserProfile%\Local Settings\Application Data\smss.exe
%UserProfile%\Local Settings\Application Data\svchost.exe
%UserProfile%\Local Settings\Application Data\winlogon.exe

The Emails sent may contain the following attachments with the Brontok Worm:

  • ccapps.exe
  • jangan dibuka.exe
  • kangen.exe
  • my heart.exe
  • myheart.exe
  • syslove.exe
  • untukmu.exe
  • winword.exe

DriveCleaner 2006 Virus Removal

Posted by Thinker On September - 22 - 2008 1 COMMENT

Disguised as a anti-virus, this software calls itself Drive Cleaner 2006 and claims to remove all the viruses in your system. How ironic since this itself is a adware trojan and specifically a virus! Here is how the installation click looks like.

2006 DriveCleaner Virus Removal

If your computer has files like

C:\Program Files\DriveCleaner 2006 Free\UDC2006.exe

C:\Program Files\Common Files\DriveCleaner 2006 Free\udcsdr.exe

C:\Program Files\Common Files\DriveCleaner 2006 Free\udcpas.exe

C:\Program Files\DriveCleaner 2006 Free\UDC6cw.exe

To remove Drive Cleaner 2006, it is fairly simple process and to remove this virus, just uninstall it from the control panel (There will be a entry called DriveCleaner) and use Hijack This and remove the above named entries for DriveCleane. Hopefully you are clean now!!!

Recent Comments

There is something about me..

Recent Comments

WizQuiz Prizes worth 3.5 lakhs waiting for you

On Jul-20-2009
Reported by Thinker

10 Tips On How to Earn That Promotion?

On Jun-4-2008
Reported by Thinker

Thinkin of Kerala? Just Jet2Kerala!

On Jun-22-2009
Reported by Thinker

BlogCamp Kerala

On Jul-5-2008
Reported by Thinker

Recent Posts