Name: VBS / Autorun-QO (or) LOVERAHULSAS.vbs
Style: virus / spyware
Type: Worm
Propagation method:
(1) move the storage media
(2) Network sharing
Affected operating systems: Windows
VBS/Autorun-QO displays the text "THIS IS AN ANTI-VIRUS AND WILL HELP YOUR SYSTEM TO WORK PROPERLY" and "RAHUL THE H@CkEr".
VBS/Autorun-QO copies itself to accessible drives and the Windows system folder as LOVERAHULSAS.vbs.
VBS/Autorun-QO spreads together with a file autorun.inf. The autorun.inf file is also detected as VBS/Autorun-QO.
The following registry will be created/affected.
HKCU \ Software \ Microsoft \ Internet Explorer \ Main
Window Title
"RAHUL THE H @ CkeR"
HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer
NoFolderOptions
0
HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ System
DisableTaskmgr 0
HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ System
DisableRegistryTools 0
HKLM \ Software \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon
Shell explorer.exe
HKLM \ Software \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon
Userinit
Internet Explorer start page is adverse to get change and its corresponding registry is modified as selected by the malicious code author.
HKCU \ Software \ Microsoft \ Internet Explorer \ Main Start Page
My tip/advise:
First of all you have to remove all the autorun.inf files from all the drives of your system.Also after doing so,open the registry and change the values that were affected by the virus to its default values.Some of the default values can be checked here.Then restart your system.
Success/Failure put your valuable comments here....
Tuesday, March 3, 2009
Koobface Worm/Virus attacks Facebook W32.KOOBFACE.B VIRUS
Recently we had ViddyHo Phishing attack on Google talk and Twitter. And now it is Facebook
this this time in new threat.
This virus emerged as a hot topic last year December 2008.This virus mainly spreads easily by just spoofing Youtube Video links.
How will you be affected?
First of all you will receive some sort of Youtube Video links.If you click on them,you will be redirected to some sites that will ask you to update some software versions.The update files will be mainly of the kind "setup.exe" which when installs,causes the damage by taking your personal information that is present in cookies of your browser.
So Facebook users be careful !!
More details on how this virus affects you can be known here
Tags:
W32.KOOBFACE.B VIRUS,facebook worm threat, koobface, facebook worm, facebook worm virus, facebook virus,
Tuesday, February 24, 2009
ViddyHo Phishing attack on Google talk and Twitter
A new phishing attack came into light late this morning."ViddyHo" by name is letting all the trouble through the instant messaging services.
What to do in order to escape from this attack?
What to do in order to escape from this attack?
Well,in order not to get into this phishing attack,you should be careful while you are suing IM.You are strongly requested not to click on any of the suspicious links [they may be any thing telling you videos,photos,sexual or adult rated links].
Also donot use your IM login information anywhere else other than the intended website.This also has sever effects on you!!
So be careful !
Also donot use your IM login information anywhere else other than the intended website.This also has sever effects on you!!
So be careful !
Subscribe to:
Posts (Atom)