vdub12
New Member
- Reaction score
- 2
OK this virus isn't so bad.
Just like many of the rouges it looks worse then it is.
Here are my notes for removal.
First off fire up process explorer and kill the random named processes.
Run regedit and first make a backup of the registry then delete these keys.
Now change the following keys to what I have listed here.
Next enable hidden files as well as protected system files and go to the allusers folder under appdata and remove the randomly named files.
Run the unhide.exe utility available here
Finally restart the system. If after restart you still don't have desktop icons then you have a variant that includes a rootkit. For this run combo fix. Combo fix will repair the volsnap.sys file for you as well as kill some additional registry entries.
Reboot the system and re-enable the internet and email shortcuts in the start menu, they should still be disabled.
The final part of this removal in my opinion was the worse. The virus does delete files. It basically clears the all users / start menu folder. Attached to this thread is a copy of the icons that I took from a clean XP Pro system. However this will not help in win 7, vista, XP home or other version OS's.
I think it might help if others will post icons from all users from other OS's but I think the biggest problem is going to be getting customers program icons back. I have not figured that part out yet. Dose anyone know if these icons are in the restore data?
Anyway, this is what I have so far. The test system is running great and other then the program icons its flawless.
Just like many of the rouges it looks worse then it is.
Here are my notes for removal.
First off fire up process explorer and kill the random named processes.
Run regedit and first make a backup of the registry then delete these keys.
Code:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “CertificateRevocation” = ’0′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “WarnonBadCertRecving” = ’0′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop “NoChangingWallPaper” = ’1′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations “LowRiskFileTypes” = ‘/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments “SaveZoneInformation” = ’1′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = ’1′
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system “DisableTaskMgr” = ’1′
Now change the following keys to what I have listed here.
Code:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “CheckExeSignatures” = ‘yes’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced “Hidden” = ’1′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced “ShowSuperHidden” = 1′
Next enable hidden files as well as protected system files and go to the allusers folder under appdata and remove the randomly named files.
Run the unhide.exe utility available here
Finally restart the system. If after restart you still don't have desktop icons then you have a variant that includes a rootkit. For this run combo fix. Combo fix will repair the volsnap.sys file for you as well as kill some additional registry entries.
Reboot the system and re-enable the internet and email shortcuts in the start menu, they should still be disabled.
The final part of this removal in my opinion was the worse. The virus does delete files. It basically clears the all users / start menu folder. Attached to this thread is a copy of the icons that I took from a clean XP Pro system. However this will not help in win 7, vista, XP home or other version OS's.
I think it might help if others will post icons from all users from other OS's but I think the biggest problem is going to be getting customers program icons back. I have not figured that part out yet. Dose anyone know if these icons are in the restore data?
Anyway, this is what I have so far. The test system is running great and other then the program icons its flawless.