Dynadot

Yahoo Messenger Virus Attack

Spaceship Spaceship
Watch

blackwizard

Account Closed
Impact
12
There is a very bad virus attack on Yahoo Messenger where it will take control of your messenger and without your knowledge sends some messages with a website links which contains the virus, to your friends list, remind you without YOUR KNOWLEDGE so be careful, try to do the following things to remove if your are effected.

It is one of the most powerful Trojan/virus I have ever seen.. If your computer is infected with this virus " It will sends the nsl-school.org url or some more and also it sends abuses, Says "Check out my Website and links to the virus Page" and more stuffs like this to all of your friend list in yahoo messenger using your ID. So with in few hours many of your friends will get infected with it.

I don't know the actual target of the idiot who created it. May be to advertise his site or to steal very important data from your computer. I resolved the problem manually from my PC.

Just go through the below steps carefully ::


What are those links ?:

Nsl-school.org or other (Do not open this url in your browser).

If you are infected with it what is going to happen ?

1: It sets your default IE page to nsl-school.org, you can’t even change it back to other page. If you open IE from your comp some malicious code will automatically executed into your computer.

2: It will disables the Task manager / reg edit. So you can’t kill the Trojan process anymore.

3: Files that are gonaa installed by this virus are svhost.exe , svhost32.exe , internat.exe.

you can find these files in windows/ & temp/ directories.

4: It will sends the secured & protected information to attacker

How to remove this manually from your computer ?

1: Close the IE browser. Log out messenger / Remove Internet Cable.

2: To enable Regedit

Click Start, Run and type this command exactly as given below: (better - Copy and paste)

REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableRegistryTools /t REG_DWORD /d 0 /f

3: To enable task manager : (To kill the process we need to enable task manager)

Click Start, Run and type this command exactly as given below: (better - Copy and paste)

REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 0 /f

4: Now we need to change the default page of IE though regedit.

Start>Run>Regedit

From the below locations in Regedit chage your default home page to google.com or other.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main

HKEY_ LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main

HKEY_USERS\Default\Software\Microsoft\Internet Explorer\Main

Just replace the attacker site with google.com or set it to blank page.

5: Now we need to kill the process from back end. Press Ctrl + Alt + Del

Kill the process svhost32.exe . ( may be more than one process is running.. check properly)

6: Delete svhost32.exe , svhost.exe files from Windows/ & temp/ directories. Or just search for svhost in your comp.. delete those files.

7: Go to regedit search for svhost and delete all the results you get.

Start menu > Run > Regedit >

8: Restart the computer. That’s it now you are virus free.

I don’t know whether any removal patch that works for this Trojan/virus. But we can easily delete it manually.

Send this URL to all of your friends through messenger so that they can get rid off this virus.

Conclution : Better not to open any unknown url from your Computer.. There are lot of black hat hackers who are waiting to steal your credit card numbers, passwords or what not.... Use a better firewall & updated anti virus. However an Antivirus can do nothing if the virus is very latest...

Adios!

PM me If you need any Help!

Thanks!

-blackwizard!
 
1
•••
The views expressed on this page by users and staff are their own, not those of NamePros.
As much as I enjoy articles trying to help others I cannot say I approve of posting articles on how to edit your Registry to fix a YIM Virus. Edit one wrong thing in your registry can make Windows unusable, impossible to even start up.

Please do not post anymore of these.

- Steve
 
0
•••
Steve, People have tried it out and they say it works and also It has done nothing to their system. Also, Ive done it myself and My comp. is fine.

thanks
 
0
•••
haha that virus already removed my run command box

:(
 
0
•••
Thanks for the heads up.

I was busy all day and no time to turn on any messenger, but now I'm aware of the problem before doing it.
 
0
•••
No Problem BAsed!
vinod_41 said:
haha that virus already removed my run command box

:(

What do you mean, "removed my run command box"?


Ill try helpin you out, i Ill know the problem!

Thanks!
 
0
•••
Thats why I use Aim..and Msn :)
 
0
•••
blackwizard said:
No Problem BAsed!


What do you mean, "removed my run command box"?


Ill try helpin you out, i Ill know the problem!

Thanks!

that virus actually disabled

Windows task manager
disabled run command
disabled default home page

:p

i'm going to format that drive today :hi:
 
0
•••
Try use windows defender to kill the process if not able to enable task manager.
 
0
•••
blackwizard said:
Steve, People have tried it out and they say it works and also It has done nothing to their system. Also, Ive done it myself and My comp. is fine.

thanks

BW,

If you have cleaned you system using this method, great post and the members should thank you.

If however, you read this somewhere and have not applied the reg edits yourself I will be very disappointed.

I know about this virus (no, I wasnt infected), but this is the first fix I have heard on it.

Like I say, if BW has run this fix on his own system we owe him a debt of thanks.

Peace,
Cyberian
 
0
•••
~ Cyberian ~ said:
BW,

If you have cleaned you system using this method, great post and the members should thank you.

If however, you read this somewhere and have not applied the reg edits yourself I will be very disappointed.

I know about this virus (no, I wasnt infected), but this is the first fix I have heard on it.

Like I say, if BW has run this fix on his own system we owe him a debt of thanks.

Peace,
Cyberian

Yes, I followed these steps when my comp was infected with this Virus. And my comp. is working great! Havin no problem. :)

I can assure you, this works well.

Adios!
 
0
•••
  • The sidebar remains visible by scrolling at a speed relative to the page’s height.
Back