Pintasan ke kandungan utama

Blog / Arkib / Virus Sohanad.AE - Mengancam pengguna YM

Virus Sohanad.AE - Mengancam pengguna YM

Virus yang diklasifikasikan sebagai Wurm ini merebak melalui Yahoo! Messenger. Mungkin dah ada di kalangan anda yg dah terkena penangan wurm ni(macam abang aku semalam). Bahayanya wurm ni, mesej yang mengandungi virus/wurm tu akan datang dari buddy/members list kita sendiri..padahal mesej tu dihantar sendiri secara automatik oleh wurm berkenaan..Ini contoh mesej yang dihantar :

Do you realize who is in this image:
http://{BLOCKED}coolpics.net/who.jpg .
Just think for a moment and tell me soon
;)) :D who is beside you in this pic
http://thecoolpics.net/friendpic1.jpg so good-looking
:( the page cannot be displayed
http://{BLOCKED}coolpics.net/error.jpg
Something was wrong !!! Check it again and tell me later.
THanks Images shot in Iraq _ The war will never end
http://{BLOCKED}coolpics.net/Iraqwar.jpg
< < :( Miss World 2006: http:// {BLOCKED}coolpics.net/ MissWorld.jpg

Jadi kalau dapat mesej camtu, jangan p klik pulak! Antara payload atau kesan wurm ni ialah dia akan ‘disable’kan task manager dan registry editor..selain tu, dia akan hantar mesej yg sama kepada members/buddy anda..huhu..

Di bawah ialah penerangan untuk buang wurm + ‘enable’kan balik task manager dan registry editor..(minta maaf, dalam bahasa inggeris, tak sempat nak translate)

—————————————————————————————————-

Sohanad.AE is a worm that enters as a downloaded file through Yahoo Messenger, infects windows. Upon execution it disables the Windows Task Manager and Registry Editor and copies itself as SVCHOST32.EXE and SVHOST.EXE in the Windows folder which is different than the windows system file SVCHOST.EXE

The worm modifies registry and loads itself during each startup.

HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows\ CurrentVersion\ Run

It also creates the following registry keys to modify the settings of Yahoo Messenger

HKEY_CURRENT_USER\ Software\ Yahoo\ pager\ View\ YMSGR_buzz HKEY_CURRENT_USER\ Software\ Yahoo\ pager\ View\ YMSGR_Launchcast

It changes the Internet Explorer (IE) home page to coolpics.net

This worm spreads through Yahoo Messenger by sending an instant message to all the contacts of an active user. This message contains a link to a remote copy of itself. When the recipient clicks the link, a copy of this worm is downloaded and executed on the recipients’ system.

(Below are removal instructions. You may print this page for easy reference)

Enable Task Manager and Registry Editor

Open Notepad and copy and paste the following:

On Error Resume Next
Set shl = CreateObject(”WScript.Shell”)
Set fso = CreateObject(”scripting.FileSystemObject”)
shl.RegDelete “HKCU\Software\Microsoft\Windows\CurrentVersion\
Policies\System\DisableRegistryTools”
shl.RegDelete “HKCU\Software\Microsoft\Windows\CurrentVersion\
Policies\System\DisableTaskMgr”

Save this file with .VBS extension.
While saving enter the name in double quotes and select all files from the save as type in notepad.
For the ease of use, save the file on desktop.
for example “filename.vbs”
When the file is saved as a vbs file then the file icon changes as a VBScript script file.
Execute the file. Double click on the file name to execute.

Click Yes at the prompt of the message box.
Click Ok.

Disable system restore

disable System Restore in Windows ME and xp.

Click on start > all programs > Accessories > System Tools > System Restore
Click on System Restore settings.
Check the box to Turn off system restore on all drives.
press apply. press ok.

Delete svhost.exe and svchost32.exe

search and delete files named svhost.exe and svchost32.exe
Your windows system file is svchost.exe, do not delete it.
Observe the difference and the missing c.
The worm creates svhost.exe and svchost32.exe
whereas windows system file is svchost.exe

Remove Autostart Entries from Registry

(If the worm has not executed yet then the entries below will be absent.)

Open Registry Editor. start > run. Type regedit. Press ok.

In the left panel double click on the following entries

HKEY_LOCAL_MACHINE>SOFTWARE>Microsoft>
Windows>CurrentVersion>Run

In the right panel, locate and delete the following entries

Task Manager = “%Windows%\system\svchost32.exe”
Svchost = “%Windows%\system\svhost.exe”

(%Windows% is the Windows folder, C:\Windows or C:\WINNT

Be careful not to remove svchost.exe which is a windows system file)

Remove Keys and Entries

In the left panel double click on the following entries
HKEY_CURRENT_USER>Software>Yahoo>pager>View

in the left panel locate and delete the following keys:
YMSGR_buzz
YMSGR_Launchcast

In the left panel double click on the following entry

HKEY_CURRENT_USER>Software>Policies>Microsoft>
Internet Explorer>Control Panel

In the right panel locate and delete the entry
Homepage = “1″

In the left panel double click on the following entries
HKEY_CURRENT_USER>Software>Microsoft>
Windows>CurrentVersion>Policies>Explorer

In the right panel locate and delete the entry
NoRun = “1″

Close Registry Editor.

Reset IE Home Page and Search Page

Close all browser (IE) windows.
Click Start>Settings>Control Panel.
Double click on Internet Options.
In the Internet Properties window click the Programs tab.
Click the Reset Web Settings button.
Select “Also reset my home page”.
Click Yes.
Click OK.



22 respon untuk entri “Virus Sohanad.AE - Mengancam pengguna YM”

  1. ikram_zidane (#)

    THANKS, IT HELPED A LOT !!


  2. novatech (#)

    erm, skarang ni virus makin ganas sbb penulis virus makin bijak bergeliga, skarang ni ada dgr dah ada yg attack hardware, pastu hiding sbg protected file system, hampagas! kesimpulannya, selalu la update windows anda
    dan, takyah la ada suara2 menyarakan penggunaan linux, sama jek haha!


  3. pali (#)

    yaa… tapi sebelum update pastikan anda menggunakan windows original. kalau tak, nak update patch baru memang sia2. :)


  4. CypherHackz (#)

    aku perasan yang ikram_zidane penah kene sebab aku ada dapat ym dari die. hu3. sebab aku dah tahu, so aku tak klik. bahaya seh…


  5. al-Marbawi (#)

    huhu.. alamak.. ni yang den maleh nie.. dah la eden pengguno YM yang setia (ceh!)


  6. ikram_zidane (#)

    hohoho.. cypher.. sorry la.
    aku pakai meebo je sekarang..


  7. Reezo (#)

    Kalau dia dh disablekan reg.editor tu, camna nk buka reg.editor? Konpius aku…???


  8. Bat (#)

    Okeh..good question..try download benda nih(bukan virus ok!)

    http://www.infomalaya.com/vault/tools/sohanad_regtools.rar

    Lepas extract, run file “regtools.vbs”, lepas tu akan keluar satu msg yang cakap registry kita dan di’enable’kan, lepas tu run file “run.bat”

    Siap.. :-)


  9. novatech (#)

    kekeke..aku guna gaim jek utk konet seme jenis messenger.. agak2 boleh kena gak ke?


  10. BlackSun (#)

    aku kalau ym pakai tunel ajer .. kes kes kes kes mudah dah selamat .. dan senang nak menyamar ..


  11. din (#)

    Ni kene taruk kat blog sy plak ni… sebarkan…


  12. Bat (#)

    taruk la din :-) jangan lupa kasik kredit..huhu


  13. skyER's (#)

    salam.. bab YM nie, xder tips2 ker nk kick org dlm chatroom.. or tips2 lain. aku dh brp kali komputer jem sbb ader org boom aku n kick dr room pn sama juga.. okies..harap ader pakar YM disini..


  14. Bat (#)

    salam sKyEr’s..Aiseh, kalau nak kick orang dalam chatroom, kena jadi moderator la..

    Aku bukan pakar, tapi aku dah tak guna YM untuk berYM, aku sekarang guna Meebo.. :)


  15. skyER's (#)

    huhu..xkn kt chat room biase ader moderator.. org lain xder, jgn kdekut ilmu se, bkn niat jahat pun, wa janji akan bls org yg kick n boom aku jer..hehe. lagi satu ader x cara msuk chat room yg xder dlm list, aku pernah msuk dgn invated dr org lain mcm putrajaya room, kopitiam room..


  16. arjang (#)

    even with the .vbs file i cant get regedit and taskmanager to work..plz help


  17. LHee-ya (#)

    hm.. thak’s
    udah bagi2 solusi buat virus ni..
    hm.. sebetulnya aku blom kena sih.. tp buat jaga2 yah gpp lah..
    hehehe…


  18. untouchkable (#)

    huhu….udakena virus spam nich….masih bingung cara mendelete nya…..buat yg lain hati -hati ya
    thanks


  19. nita (#)

    cilakak je…terklik pulak…camner ha..


  20. k_ri (#)

    saya da copy dan paste dalam ym gak..adakah ia tetap run walaupun hanya copy coding dia je?tolong terangkan…


  21. k_ri (#)

    abg2 yang pakar..tlgla bagi tunjuk ajar..


  22. Bat (#)

    @k_ri: Cara senang, cuba reinstall balik ym, huhu..


Panduan untuk memberi komen

  • Sekiranya ingin bertanya soalan, sila spesifikkan soalan anda.
  • Jangan terasa hati sekiranya komen anda tidak terjawab. Ada kalanya penulis entri ini terpaksa mengutamakan komitmen masing-masing.
  • Perdebatan secara sihat dialu-alukan. Tapi sila gunakan bahasa yang sopan dan sedap dibaca.
  • Komen yang berbentuk spam akan dipadam serta merta tanpa notis 24 jam(hehe).
  • Dan, terima kasih kerana sudi memberikan komen. ^_^

Tinggalkan komen