Remove Yahoo Messenger virus

hello… sorry for the long vacation actually i been busy with my work and some other part time job, thats why i haven’t got time to add new post. ok now back to our topic on how to remove YM virus. if any of you been receiving link from your friend but when you ask him/her they say that they did’t send it thats mean your friend pc/notebook been infected with ym trojan or maybe alot of friend in your list complain that you been sending them link or spaming link to them then its mean your pc/laptop been infected with this virus.. i maybe have the solution to remove it..but it is not as simple as you thought it is..

What are those links ?:
www.myspacee-img.com/image.php or other (Do not open this url in your browser).

the virus symptom

1. It sets your default IE page to nsl-school.org, you can’t even change it back to other page. If you open IE from your comp some malicious code will automatically executed into your computer.

2. It will disables the Task manager / reg edit. So you can’t kill the Trojan process anymore.

3. Files that are gonaa installed by this virus are svhost.exe , svhost32.exe , internat.exe.
You can find these files in windows/ & temp/ directories.

4. It will sends the secured & protected information to attacker

Remove It Manually (Just follow the step below and you’ll be back to your normal activity and save from virus)

1. Close the IE browser. Log out messenger / Remove Internet Cable.

2. To enable Regedit

Click Start, Run and type this command exactly as given below: (better – Copy and paste)

Code: REG add HKCUSoftwareMic*ftWindowsCurrentVersionPoliciesSystem /v DisableRegistryTools /t REG_DWORD /d 0 /f

3. To enable task manager : (To kill the process we need to enable task manager)

Click Start, Run and type this command exactly as given below: (better – Copy and paste)

Code: REG add HKCUSoftwareMic*ftWindowsCurrentVersionPoliciesSystem /v DisableTaskMgr /t REG_DWORD /d 0 /f

4. Now we need to change the default page of IE though regedit.

Start>Run>Regedit

From the below locations in Regedit chage your default home page to hackgyan.com or other

Code: HKEY_CURRENT_USERSOFTWAREMic*ftInternet ExplorerMain
HKEY_ LOCAL_MACHINESOFTWAREMic*ftInternet ExplorerMain
HKEY_USERSDefaultSoftwareMic*ftInternet ExplorerMain

Just replace the attacker site with hackgyan.com or set it to blank page.

5. Now we need to kill the process from back end. For this, Press “Ctrl + Alt + Del”
Kill the process svhost32.exe . ( may be more than one process is running.. check properly)

6. Delete svhost32.exe , svhost.exe files from Windows/ & temp/ directories. Or just search for svhost in your comp.. delete those files.

7. Go to regedit search for svhost and delete all the results you get
Code: Start>Run>Regedit

8. Restart the computer. Done… hehe

Good luck ..

be save and dont make the infection spread.. :p

( Source : Comptalks )

Share and Enjoy:
  • Digg
  • del.icio.us
  • Facebook
  • Google Bookmarks
  • Technorati
  • Twitter

23 Responses to “Remove Yahoo Messenger virus”

Leave a Reply

Spam Protection by WP-SpamFree