RVHOST.EXE VIRUS DETAILS
Discovered: December 12, 2006
Updated: December 13, 2006 3:26:10 AM
Also Known As: IM-Worm.Win32.Sohanad.t [Kaspersky], W32/Sohana-R [Sophos]
Type: Worm
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
W32.Yautoit.N is a worm that spreads through Yahoo! Instant Messenger.
Once executed, the worm downloads a file from the following location:
[http://]www.freewebs.com/nhattru[REMOVED]
The worm then saves the downloaded file as the following file:
%System%\RVHOST.exe
The worm creates the following file on shared drives:
%System%\new folder.exe
The worm then creates the following Windows job file with settings to execute RVHOST.exe at 9:00am every day:
%Windir%\Tasks\At1.job
The worm creates the following registry entries so that it runs every time Windows starts:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\"Shell" = "Explorer.exe " RVHOST.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Yahoo Messengger" = "%System%\RVHOST.exe"
The worm also creates the following registry entry:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\WorkgroupCrawler\Shares\"shared" = "[SHARED DRIVE]\New Folder.exe"
The worm then modifies the following registry entries to disable the Task Manager and the Registry Editor:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\"DisableTaskMgr" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\"DisableRegistryTools" = "1"
The worm also modifies the following registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\"NofolderOptions" = "1"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Schedule\"AtTaskMaxHours" = "0"
The worm then deletes the following registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\"Run" = "BkavFw"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\"Run" = "IEProtection"
The worm ends the following processes and closes applications if they are running:
Registry Editor
Task Manager
Bkav2006
game_y.exe
"System Configuration"
Next, the worm sends the following messages through Yahoo! Instant Messenger:
"E may, vao day coi co con nho nay ngon lam [http://]nhattruongquang.0catch.com
"Vao day nghe bai nay di ban [http://]nhattruongquang.0catch.com"
"Vao day nghe bai nay di ban [http://]nhattruongquang.0catch.com"
"Biet tin gi chua, vao day coi di [http://]nhattruongquang.0catch.com"
"Trang Web nay coi cung hay, vao coi thu di [http://]nhattruongquang.0catch.com"
"Toi di lang thang lan trong bong toi buot gia, ve dau khi da mat em roi? Ve dau khi bao nhieu mo mong gio da vo tan... Ve dau toi biet di ve dau? [http://]nhattruongquang.0catch.com"
"Khoc cho nho thuong voi trong long, khoc cho noi sau nhe nhu khong. Bao nhieu yeu thuong nhung ngay qua da tan theo khoi may bay that xa... [http://]nhattruongquang.0catch.com"
"Tha nguoi dung noi se yeu minh toi mai thoi thi gio day toi se vui hon. Gio nguoi lac loi buoc chan ve noi xa xoi, cay dang chi rieng minh toi... [http://]nhattruongquang.0catch.com"
"Loi em noi cho tinh chung ta, nhu doan cuoi trong cuon phim buon. Nguoi da den nhu la giac mo roi ra di cho anh bat ngo... [http://]nhattruongquang.0catch.com"
"Tra lai em niem vui khi duoc gan ben em, tra lai em loi yeu thuong em dem, tra lai em niem tin thang nam qua ta dap xay. Gio day chi la nhung ky niem buon...[http://]nhattruongquang.0catch.com"
Info: Thanks to symantec.
Rvhost.exe Removal Tool
To remove this virus/worm automatically
just download the tool here :
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Double click it after downloading, and have it running on it's own. Wait for it to finish scanning and removing the malwares and viruses on your pc. You will know when it's done when the text file appear containing the scan results. And your finish.
Make sure to disable any antivirus you have before executing the tool.
Enjoy!
Showing posts with label usb virus. Show all posts
Showing posts with label usb virus. Show all posts
Saturday, February 28, 2009
Sunday, March 23, 2008
USB DRIVE / FLASH DRIVE VIRUS REMOVAL TOOLS
WHAT IS A USB FLASH DRIVE?
A USB flash drive is a NAND-type flash memory data storage device integrated with a USB (universal serial bus) connector. USB flash drives are typically removable and rewritable, much shorter than a floppy disk (1-4 inches or 25-102 mm), and weigh less than 2 ounces (56g). Storage capacities range from 64MB to 16GB or more. Some allow 1 million write or erase cycles[1] and have 10-year data retention, connected by USB 1.1 or USB 2.0 or both. USB Memory card readers are also available, whereby rather than being built-in, the memory is a removable flash memory card housed in what is otherwise a regular USB flash drive, as described below.
USB flash drives offer potential advantages over other portable storage devices, particularly the floppy disk. They are more compact, faster, hold more data, are more reliable for lack of moving parts, and have a more durable design. Additionally, it has become increasingly common for computers to ship without floppy disk drives. USB ports, on the other hand, appear on almost every current mainstream PC and laptop. These types of drives use the USB mass storage standard, supported natively by modern operating systems such as Windows, Mac OS X, Linux, and other Unix-like systems.
With nothing being mechanically driven in a flash drive, the name is something of a misnomer. It is called a "drive" because it appears to the computer operating system (and the user) in a manner identical to a mechanical disk drive, and is accessed in the same way.
A flash drive consists of a small printed circuit board typically in a plastic or metal casing and more recently in rubber casings to increase their robustness. This makes the drive sturdy enough to be carried about in a pocket, for example as a key fob, or on a lanyard. Only the USB connector protrudes, and it is typically protected either by a removable cap or by retracting into the body of the drive. Most flash drives use a standard type-A USB connection allowing them to be connected directly to a port on a personal computer.
To access the data stored in a flash drive, the drive must be connected to a USB port, either a host controller built into a computer, a USB hub, or some other device designed to access the data, such as an mp3 player with a USB-in port. Flash drives are active only when plugged into a USB connection and draw all necessary power from the supply provided by that connection. Some flash drives, however, especially high-speed drives, may require more power than the limited amount provided by a bus-powered USB hub, such as those built into some computer keyboards or monitors. These drives will not work unless plugged directly into a host controller (i.e., the ports found on the computer itself) or a self-powered hub.
Source : http://www.wikipedia.org/
USB DRIVE VIRUS REMOVAL TOOLS
Since the development of USB Drive disk and memory cards,
new type of viruses emerges affecting mobile phones, mp4 players, mp3 players,
ipod devices and other similar gadgets. And when inserted on a PC, just by double clicking the USB drive, the virus is easily installed. Some of the leading
Antivirus detect it, but mostly are not, because this type of viruses are new and can easily be updated with a new variant. These viruses are programmed using Visual Basic Script, and AutoIt Program they install automatically and spreads automatically, until you realized that your PC is running slow, always restarting, and when a typical program is opened it's just automatically shuts down, registry are disabled as well as the taskbar manager, so you have no way of stopping the processes. The virus may steal some information about you, and even passwords.
Before you even bother to go to your nearest PC Repair shop. Here are some
tools you may use to be able to delete the virus and the infection they made.
Flash Disinfector
http://tinyurl.com/2uw7go
NoobKiller
http://tinyurl.com/2o6juu
ComboFix
http://tinyurl.com/27gkbc
SDFix
http://tinyurl.com/37tb9k
L2MFix
http://tinyurl.com/2qfcae
One file download for Broadband users.
http://tinyurl.com/3dmr68
Problem downloading with easy-share?
View tutorial here:
http://tinyurl.com/3bmke9
Using this tools You have a 90% chance that your problem will be fixed.
Hope I helped a bit!
c",) Shadowprince
A USB flash drive is a NAND-type flash memory data storage device integrated with a USB (universal serial bus) connector. USB flash drives are typically removable and rewritable, much shorter than a floppy disk (1-4 inches or 25-102 mm), and weigh less than 2 ounces (56g). Storage capacities range from 64MB to 16GB or more. Some allow 1 million write or erase cycles[1] and have 10-year data retention, connected by USB 1.1 or USB 2.0 or both. USB Memory card readers are also available, whereby rather than being built-in, the memory is a removable flash memory card housed in what is otherwise a regular USB flash drive, as described below.
USB flash drives offer potential advantages over other portable storage devices, particularly the floppy disk. They are more compact, faster, hold more data, are more reliable for lack of moving parts, and have a more durable design. Additionally, it has become increasingly common for computers to ship without floppy disk drives. USB ports, on the other hand, appear on almost every current mainstream PC and laptop. These types of drives use the USB mass storage standard, supported natively by modern operating systems such as Windows, Mac OS X, Linux, and other Unix-like systems.
With nothing being mechanically driven in a flash drive, the name is something of a misnomer. It is called a "drive" because it appears to the computer operating system (and the user) in a manner identical to a mechanical disk drive, and is accessed in the same way.
A flash drive consists of a small printed circuit board typically in a plastic or metal casing and more recently in rubber casings to increase their robustness. This makes the drive sturdy enough to be carried about in a pocket, for example as a key fob, or on a lanyard. Only the USB connector protrudes, and it is typically protected either by a removable cap or by retracting into the body of the drive. Most flash drives use a standard type-A USB connection allowing them to be connected directly to a port on a personal computer.
To access the data stored in a flash drive, the drive must be connected to a USB port, either a host controller built into a computer, a USB hub, or some other device designed to access the data, such as an mp3 player with a USB-in port. Flash drives are active only when plugged into a USB connection and draw all necessary power from the supply provided by that connection. Some flash drives, however, especially high-speed drives, may require more power than the limited amount provided by a bus-powered USB hub, such as those built into some computer keyboards or monitors. These drives will not work unless plugged directly into a host controller (i.e., the ports found on the computer itself) or a self-powered hub.
Source : http://www.wikipedia.org/
USB DRIVE VIRUS REMOVAL TOOLS
Since the development of USB Drive disk and memory cards,
new type of viruses emerges affecting mobile phones, mp4 players, mp3 players,
ipod devices and other similar gadgets. And when inserted on a PC, just by double clicking the USB drive, the virus is easily installed. Some of the leading
Antivirus detect it, but mostly are not, because this type of viruses are new and can easily be updated with a new variant. These viruses are programmed using Visual Basic Script, and AutoIt Program they install automatically and spreads automatically, until you realized that your PC is running slow, always restarting, and when a typical program is opened it's just automatically shuts down, registry are disabled as well as the taskbar manager, so you have no way of stopping the processes. The virus may steal some information about you, and even passwords.
Before you even bother to go to your nearest PC Repair shop. Here are some
tools you may use to be able to delete the virus and the infection they made.
Flash Disinfector
http://tinyurl.com/2uw7go
NoobKiller
http://tinyurl.com/2o6juu
ComboFix
http://tinyurl.com/27gkbc
SDFix
http://tinyurl.com/37tb9k
L2MFix
http://tinyurl.com/2qfcae
One file download for Broadband users.
http://tinyurl.com/3dmr68
Problem downloading with easy-share?
View tutorial here:
http://tinyurl.com/3bmke9
Using this tools You have a 90% chance that your problem will be fixed.
Hope I helped a bit!
c",) Shadowprince
Tuesday, March 18, 2008
REMOVING SSCVIIHOST.EXE
USB Virus Name : SSCVIIHOST.exe
Virus Type : WORM_SOHANAD.BO
Virus Type : WORM_SOHANAD.BO
REMOVAL INSTRUCTIONS
1. Download RRT.exe run the program, click check all, then click remove,
to remove the restrictions made by the virus.
2. Press Ctrl-Alt-Del to open task manager.
On the processes tab find the following running processes:
SSCVIIHOST.exe/blastclnnn.exe
Right Click on each process and choose End Process Tree.
Close the Task Manager.
3. Click Start>Run and Type Regedit.
Press Ctrl-F and find the following registry keys.
a) SSCVIIHOST.exe
b) blastclnnn.exe
c) New Folder.exe
d) pc-off.bat
Right Click on the value and click delete.
After finding one entry, Press F3 to continue the search.
4. After you delete those registry entries,
Goto Start>Search>Click All files and folders,
on the more advanced options put a check
on search system folders, hidden, and subfolders.
Enter these as keywords, and delete those files if found.
a) SSCVIIHOST.exe
b) blastclnnn.exe
c) New Folder.exe
d) pc-off.bat
Common Locations are
C:/Windows
C:/Windows/System
C:/Windows/System32
C:/Windows/Prefetch
5. After deleting those files, do a search again and this time
type these keyword, *.exe.
On the results panel, sort it by clicking the size field.
Any file that has a folder icon, a detail that tells it is an application
and with a filesize of only 245kb, right click and delete all of them.
6. Restart your PC. Test if your PC is running normal again and no
SSCVIIHOST.exe is running by running the task manager. Ctrl-Alt-Del.
If the virus is still in your PC, it means you missed a registry entry.
Do the steps again to clear it. Make sure you do it one by one.
PREVENTION
When opening your USB Disk do not double click on it, instead use the
folder options to navigate it. If your antivirus does not detect this type
of virus, I recommend Avira Free Personal Edition Antivirus,
it detects most of the USB viruses today.
Hope my guide helped you.
ShadowPrince c",)
Labels:
autoit,
avira,
usb antivirus,
usb virus,
virus removal,
worm sohanad
Subscribe to:
Posts (Atom)