Showing posts with label usb virus. Show all posts
Showing posts with label usb virus. Show all posts

Saturday, February 28, 2009

How to Remove RVHOST.exe Virus/Worm

RVHOST.EXE VIRUS DETAILS

Discovered: December 12, 2006
Updated: December 13, 2006 3:26:10 AM
Also Known As: IM-Worm.Win32.Sohanad.t [Kaspersky], W32/Sohana-R [Sophos]
Type: Worm
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP

W32.Yautoit.N is a worm that spreads through Yahoo! Instant Messenger.

Once executed, the worm downloads a file from the following location:
[http://]www.freewebs.com/nhattru[REMOVED]

The worm then saves the downloaded file as the following file:
%System%\RVHOST.exe

The worm creates the following file on shared drives:
%System%\new folder.exe

The worm then creates the following Windows job file with settings to execute RVHOST.exe at 9:00am every day:
%Windir%\Tasks\At1.job

The worm creates the following registry entries so that it runs every time Windows starts:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\"Shell" = "Explorer.exe " RVHOST.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Yahoo Messengger" = "%System%\RVHOST.exe"

The worm also creates the following registry entry:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\WorkgroupCrawler\Shares\"shared" = "[SHARED DRIVE]\New Folder.exe"

The worm then modifies the following registry entries to disable the Task Manager and the Registry Editor:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\"DisableTaskMgr" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\"DisableRegistryTools" = "1"

The worm also modifies the following registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\"NofolderOptions" = "1"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Schedule\"AtTaskMaxHours" = "0"

The worm then deletes the following registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\"Run" = "BkavFw"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\"Run" = "IEProtection"

The worm ends the following processes and closes applications if they are running:
Registry Editor
Task Manager
Bkav2006
game_y.exe
"System Configuration"

Next, the worm sends the following messages through Yahoo! Instant Messenger:
"E may, vao day coi co con nho nay ngon lam [http://]nhattruongquang.0catch.com

"Vao day nghe bai nay di ban [http://]nhattruongquang.0catch.com"

"Vao day nghe bai nay di ban [http://]nhattruongquang.0catch.com"

"Biet tin gi chua, vao day coi di [http://]nhattruongquang.0catch.com"

"Trang Web nay coi cung hay, vao coi thu di [http://]nhattruongquang.0catch.com"

"Toi di lang thang lan trong bong toi buot gia, ve dau khi da mat em roi? Ve dau khi bao nhieu mo mong gio da vo tan... Ve dau toi biet di ve dau? [http://]nhattruongquang.0catch.com"

"Khoc cho nho thuong voi trong long, khoc cho noi sau nhe nhu khong. Bao nhieu yeu thuong nhung ngay qua da tan theo khoi may bay that xa... [http://]nhattruongquang.0catch.com"

"Tha nguoi dung noi se yeu minh toi mai thoi thi gio day toi se vui hon. Gio nguoi lac loi buoc chan ve noi xa xoi, cay dang chi rieng minh toi... [http://]nhattruongquang.0catch.com"

"Loi em noi cho tinh chung ta, nhu doan cuoi trong cuon phim buon. Nguoi da den nhu la giac mo roi ra di cho anh bat ngo... [http://]nhattruongquang.0catch.com"

"Tra lai em niem vui khi duoc gan ben em, tra lai em loi yeu thuong em dem, tra lai em niem tin thang nam qua ta dap xay. Gio day chi la nhung ky niem buon...[http://]nhattruongquang.0catch.com"

Info: Thanks to symantec.

Rvhost.exe Removal Tool

To remove this virus/worm automatically
just download the tool here :
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Double click it after downloading, and have it running on it's own. Wait for it to finish scanning and removing the malwares and viruses on your pc. You will know when it's done when the text file appear containing the scan results. And your finish.
Make sure to disable any antivirus you have before executing the tool.

Enjoy!

Sunday, March 23, 2008

USB DRIVE / FLASH DRIVE VIRUS REMOVAL TOOLS

WHAT IS A USB FLASH DRIVE?

A USB flash drive is a NAND-type flash memory data storage device integrated with a USB (universal serial bus) connector. USB flash drives are typically removable and rewritable, much shorter than a floppy disk (1-4 inches or 25-102 mm), and weigh less than 2 ounces (56g). Storage capacities range from 64MB to 16GB or more. Some allow 1 million write or erase cycles[1] and have 10-year data retention, connected by USB 1.1 or USB 2.0 or both. USB Memory card readers are also available, whereby rather than being built-in, the memory is a removable flash memory card housed in what is otherwise a regular USB flash drive, as described below.

USB flash drives offer potential advantages over other portable storage devices, particularly the floppy disk. They are more compact, faster, hold more data, are more reliable for lack of moving parts, and have a more durable design. Additionally, it has become increasingly common for computers to ship without floppy disk drives. USB ports, on the other hand, appear on almost every current mainstream PC and laptop. These types of drives use the USB mass storage standard, supported natively by modern operating systems such as Windows, Mac OS X, Linux, and other Unix-like systems.

With nothing being mechanically driven in a flash drive, the name is something of a misnomer. It is called a "drive" because it appears to the computer operating system (and the user) in a manner identical to a mechanical disk drive, and is accessed in the same way.

A flash drive consists of a small printed circuit board typically in a plastic or metal casing and more recently in rubber casings to increase their robustness. This makes the drive sturdy enough to be carried about in a pocket, for example as a key fob, or on a lanyard. Only the USB connector protrudes, and it is typically protected either by a removable cap or by retracting into the body of the drive. Most flash drives use a standard type-A USB connection allowing them to be connected directly to a port on a personal computer.

To access the data stored in a flash drive, the drive must be connected to a USB port, either a host controller built into a computer, a USB hub, or some other device designed to access the data, such as an mp3 player with a USB-in port. Flash drives are active only when plugged into a USB connection and draw all necessary power from the supply provided by that connection. Some flash drives, however, especially high-speed drives, may require more power than the limited amount provided by a bus-powered USB hub, such as those built into some computer keyboards or monitors. These drives will not work unless plugged directly into a host controller (i.e., the ports found on the computer itself) or a self-powered hub.

Source : http://www.wikipedia.org/

USB DRIVE VIRUS REMOVAL TOOLS

Since the development of USB Drive disk and memory cards,
new type of viruses emerges affecting mobile phones, mp4 players, mp3 players,
ipod devices and other similar gadgets. And when inserted on a PC, just by double clicking the USB drive, the virus is easily installed. Some of the leading
Antivirus detect it, but mostly are not, because this type of viruses are new and can easily be updated with a new variant. These viruses are programmed using Visual Basic Script, and AutoIt Program they install automatically and spreads automatically, until you realized that your PC is running slow, always restarting, and when a typical program is opened it's just automatically shuts down, registry are disabled as well as the taskbar manager, so you have no way of stopping the processes. The virus may steal some information about you, and even passwords.

Before you even bother to go to your nearest PC Repair shop. Here are some
tools you may use to be able to delete the virus and the infection they made.

Flash Disinfector
http://tinyurl.com/2uw7go

NoobKiller
http://tinyurl.com/2o6juu

ComboFix
http://tinyurl.com/27gkbc

SDFix
http://tinyurl.com/37tb9k

L2MFix
http://tinyurl.com/2qfcae

One file download for Broadband users.
http://tinyurl.com/3dmr68

Problem downloading with easy-share?
View tutorial here:
http://tinyurl.com/3bmke9

Using this tools You have a 90% chance that your problem will be fixed.

Hope I helped a bit!

c",) Shadowprince

Tuesday, March 18, 2008

REMOVING SSCVIIHOST.EXE

USB Virus Name : SSCVIIHOST.exe

Virus Type : WORM_SOHANAD.BO

REMOVAL INSTRUCTIONS

1. Download
RRT.exe run the program, click check all, then click remove,
to remove the restrictions made by the virus.

2. Press Ctrl-Alt-Del to open task manager.
On the processes tab find the following running processes:
SSCVIIHOST.exe/blastclnnn.exe
Right Click on each process and choose End Process Tree.
Close the Task Manager.

3. Click Start>Run and Type Regedit.
Press Ctrl-F and find the following registry keys.
a) SSCVIIHOST.exe
b) blastclnnn.exe
c) New Folder.exe
d) pc-off.bat
Right Click on the value and click delete.
After finding one entry, Press F3 to continue the search.

4. After you delete those registry entries,
Goto Start>Search>Click All files and folders,
on the more advanced options put a check
on search system folders, hidden, and subfolders.
Enter these as keywords, and delete those files if found.
a) SSCVIIHOST.exe
b) blastclnnn.exe
c) New Folder.exe
d) pc-off.bat
Common Locations are
C:/Windows
C:/Windows/System
C:/Windows/System32
C:/Windows/Prefetch

5. After deleting those files, do a search again and this time
type these keyword, *.exe.
On the results panel, sort it by clicking the size field.
Any file that has a folder icon, a detail that tells it is an application
and with a filesize of only 245kb, right click and delete all of them.

6. Restart your PC. Test if your PC is running normal again and no
SSCVIIHOST.exe is running by running the task manager. Ctrl-Alt-Del.
If the virus is still in your PC, it means you missed a registry entry.
Do the steps again to clear it. Make sure you do it one by one.

PREVENTION

When opening your USB Disk do not double click on it, instead use the
folder options to navigate it. If your antivirus does not detect this type
of virus, I recommend Avira Free Personal Edition Antivirus,
it detects most of the USB viruses today.

Hope my guide helped you.

ShadowPrince c",)







Sign up for PayPal and start accepting credit card payments instantly.