Showing posts with label Virus. Show all posts
Showing posts with label Virus. Show all posts

Monday, October 6, 2008

Alert on Dangerous Computer Virus

                           virus-alert

A dangerous computer virus is afloat and users are warned to be alert during the next few das.

Do not open any message with an attachment entitled 'POSCARD FROM HALLMARK' regardless of who sent it to you. It is a virus which opens A POSCARD MESSAGE, which 'burns' the whole hard disc C of your computer.

This virus will be received from someone who has your email address in his/her contact list. This is the reason why you need to send this important message to your friends asap.

If you receive a mail called POSTCARD even from your friend..please do not open it...

This worst virus announced by CNN. It has been classified by Microsoft as the most destructive virus ever. This Virus was discovered by McAfee yesterday, and there is no repair yet for this virus.

It destroys the Zero Sector of the Hard Disk, where the vital information is kept.

Monday, September 15, 2008

Hot to know whether your computer is safe with wuauclt.exe

This post helps you to recognize whether the wuauclt.exe file is a virus, trojan, spyware, adware which you can remove, or a file belonging to a Windows system or an application you can trust.

wuauclt.exe is located in the folder C:\Windows\System32. Known file sizes on Windows XP are 124184 bytes (66% of all occurrence)


Here are the possibilities to be a dangerous file :

  • wuauclt.exe is located in the folder C:\Windows then the security rating is 73% dangerous. File sizes can be one of the followings (230518 bytes (40% of all occurrence), 230520 bytes, 196608 bytes, 17039 bytes, 60519 bytes, 58656 bytes)
  • wuauclt.exe is located in a subfolder of C:\Windows\System32 then the security rating is 88% dangerous. File sizes can be one of the followings (File size is 26967 bytes (50% of all occurrence), 19553 bytes)
  • wuauclt.exe is located in a subfolder of "C:\Documents and Settings" then the security rating is 64% dangerous. File size is 33068 bytes
  • wuauclt.exe is located in a subfolder of C:\Windows then the security rating is 100% dangerous. File size is 21873 bytes
  • wuauclt.exe is located in the folder C:\Windows\System32\drivers then the security rating is 56% dangerous. File size is 81794 bytes
wuauclt.exe is not a Windows system file. The process is loaded during the Windows boot process.
See the following Registry Keys

Registry key: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices).

Thursday, September 11, 2008

Your computer drives get invisible by a virus attack!

Since this has became a huge issue, I tried the following solution.

This can be used in any version of windows. Actually Windows XP Pro has a Gpedit.msc which is nothing but the Group Policy Editor. If you are using Windows XP Home edition the program is not included. But don't worry you can download the program with the following link

Download Group Policy Editor !

This program is used to hide or unhide drives.

  • First set them to hidden
  • Then immediately reset them to unhide
  • Reboot to reflect the newly updated changes

If you need to download and install the program (Gpedit.msc).

  1. Unzip the zipped file that you downloaded
  2. Open the Read This .txt file under GPEdit_Files folder and follow the guide

To start Group Policy Editor click Start, Run and type Gpedit.msc and click the OK button.

I hope this will help you!!!

Monday, September 8, 2008

How to Remove lsass Error (lsass.exe)


This post helps you to recognize whether the lsass.exe file is a
virus, trojan, spyware, adware which you can remove, or a file belonging to a Windows system or an application you can trust.

lsass.exe is located in the folder C:\Windows\System32 Known file sizes on Windows XP are 13312 bytes (84% of all occurrence), 11776 bytes, 7680 bytes, 14848 bytes, 16384 bytes.

It is a Windows core system file. The program is not visible. File lsass.exe is a trustworthy file from Microsoft. Program listens for or sends data on open ports to LAN or Internet. Therefore the technical security rating is 8% dangerous.

Here are the possibilities to be a dangerous file :

  • lsass.exe is located in a subfolder of C:\Windows then the security rating is 83% dangerous. File size can be any of the followings. (253952 bytes (21% of all occurrence), 225280 bytes, 258048 bytes, 229376 bytes, 296462 bytes, 25600 bytes, 373774 bytes, 234512 bytes, 264192 bytes, 213842 bytes, 1223670 bytes, 262144 bytes, 64858 bytes, 213854 bytes, 884726 bytes, 22061 bytes, 678117 bytes, 107520 bytes, 766464 bytes, 1078463 bytes, 578510 bytes, 163781 bytes, 122368 bytes, 1930240 bytes, 205547 bytes, 965587 bytes, 996200 bytes, 622592 bytes, 830991 bytes, 94208 bytes, 106496 bytes, 389751 bytes, 1173471 bytes, 943295 bytes, 840936 bytes, 182732 bytes, 1220801 bytes, 227519 bytes, 1046915 bytes, 1145807 bytes, 432655 bytes, 20057 bytes, 812558 bytes, 1198096 bytes, 891976 bytes, 215265 bytes, 109056 bytes, 61952 bytes, 1163513 bytes, 285154 bytes, 109568 bytes, 478440 bytes, 532470 bytes, 1290240 bytes, 365797 bytes, 665590 bytes, 107008 bytes, 223464 bytes, 1107135 bytes)
  • lsass.exe is located in the folder C:\Windows then the security rating is 80% dangerous. File Size can be any of the followings. (34992 bytes (30% of all occurrence), 385536 bytes, 46592 bytes, 51254 bytes, 979968 bytes, 6049 bytes, 107520 bytes, 45568 bytes, 11264 bytes, 982528 bytes, 3732 bytes, 3908 bytes, 53675 bytes, 45861 bytes, 108032 bytes, 977920 bytes, 69632 bytes, 146944 bytes, 46123 bytes, 29853 bytes, 27136 bytes, 960512 bytes, 3724 bytes, 46170 bytes, 981190 bytes, 92785 bytes, 47206 bytes, 13312 bytes, 51310 bytes, 51339 bytes, 198144 bytes, 32858 bytes, 42301 bytes, 84992 bytes, 49152 bytes, 52177 bytes, 999110 bytes, 89895 bytes, 114321 bytes, 124542 bytes, 70059 bytes, 109568 bytes, 29941 bytes, 146432 bytes, 39424 bytes, 107008 bytes, 26624 bytes, 974848 bytes)
  • lsass.exe is located in a subfolder of C:\Windows\System32 then the security rating is 84% dangerous. File size can be any of the followings. (102400 bytes (11% of all occurrence), 731136 bytes, 241664 bytes, 76800 bytes, 736256 bytes, 94208 bytes, 4672 bytes, 1016832 bytes, 339456 bytes, 2072064 bytes, 731648 bytes, 718848 bytes, 83976 bytes, 735744 bytes, 1789952 bytes, 80896 bytes, 84484 bytes, 240640 bytes, 18472 bytes, 74752 bytes, 170537 bytes, 732160 bytes, 40960 bytes, 282185 bytes)
  • If lsass.exe is located in a subfolder of C:\Windows\System32\drivers then the security rating is 43% dangerous. File size can be any of the followings. (29696 bytes (44% of all occurrence), 24724 bytes, 17408 bytes, 138752 bytes)
  • If lsass.exe is located in a subfolder of "C:\Documents and Settings" then the security rating is 49% dangerous. File size can be any of the followings. (229621 bytes (23% of all occurrence), 229888 bytes, 42065 bytes, 81920 bytes, 45373 bytes, 42639 bytes, 589312 bytes, 44401 bytes, 40928 bytes, 42692 bytes)
  • If lsass.exe is located in a subfolder of "C:\Program Files\Common Files" then the security rating is 34% dangerous. File size can be any of the followings. (39109 bytes (22% of all occurrence), 41210 bytes, 38130 bytes, 38139 bytes, 41472 bytes, 33792 bytes, 34304 bytes)
  • If lsass.exe is located in a subfolder of "C:\Program Files" then the security rating is 59% dangerous. File size can be any of the followings. (94208 bytes (33% of all occurrence), 76800 bytes, 245624 bytes, 13069 bytes)
  • If lsass.exe is located in a subfolder of C:\ then the security rating is 46% dangerous. File size can be any of the followings. (279552 bytes (50% of all occurrence), 50151 bytes)
  • If lsass.exe is located in C:\ then the security rating is 73% dangerous. File size can be any of the followings. (69900 bytes (50% of all occurrence), 8726 bytes)
  • File size can be any of the followings. (238173 bytes (50% of all occurrence), 731136 bytes)
  • If lsass.exe is located in the folder "C:\Program Files" then the security rating is 42% dangerous. File size can be any of the followings. (76965 bytes)


Friday, July 4, 2008

How to remove VirusBurst (Removal Instructions)

Are you infected with VirusBurst?

Here is the solution,

What this program does:
VirusBurst is a anti-spyware program that is known to issue fake warnings on your computer in order to manipulate you into buying its full commercial version. The program is generally installed by a Trojan that automatically downloads and installs the program.

If you are infected with this program you will receive warnings in your task bar stating that you are infected with spyware and to run its special anti-spyware tool. This tool turns out to be the commercial version of VirusBurst. These warnings are fake and are a goad to have you buy the commercial version of this software. The current text for these alerts is "System detected virus activities. They may cause critical system failure. Please, use antimalware software to clean and protect your system from parasite programs. Click this baloon to get all available software."

Tools Needed for this fix:

There are two ways you can remove this.

Automated Removal Instructions:

  1. Print out these instructions as we will need to close every window that is open later in the fix.
  2. Download roguescanfix_setup.exe from here:
    roguescanfix_setup.exe
    Confirm that the file roguescanfix_setup.exe now resides on your desktop.
  3. Double-click on the roguescanfix_setup.exe file found on your desktop.
  4. Select your language from the drop down menu and then press the OK button.
  5. Now press the Next button.
  6. Select the option that says I accept the agreement and press the Next button
  7. Press the Next button again.
  8. Now click on the Install button.
  9. The installation program will start installing RogueScanFix into C:\Program Files\Roguescanfix and then display a new screen. At the next screen, leave the checkmark in the Launch RogueScanFix and press the Finish button.
  10. RogueScanFix will automatically be started and you will be presented with the Credits screen. At this screen press the spacebar and you will be presented with a menu. Press the number 1 on your keyboard and press enter. At the next screen simply press the spacebar on your computer to start the removal process.
    Note: Please note that when the program starts it will download a program from the Internet that it needs to use during the cleanup. If your firewall gives an alert about this, please allow the download.exe or run.bat program to access the Internet.

    When the program starts, your desktop will disappear, which is normal, so please do not be concerned. It will then start the VirusBurst uninstallation program. When that program starts, click on the Uninstall button. When it has finished uninstalling, you can then press the OK button to finish the uninstalling of VirusBurst.
    When this program is finished, and it was able to delete all the files, you will see a small prompt that says Completed script execution. Simply press the OK button. It will then open the Brute Force Uninstaller program. Close this by press ing the Exit button. If there a notepad open called task.txt, you can close that as well. Now continue to Step 11.
    If there were more files that needed to be deleted, the program will prompt you to reboot your computer. Press the Yes button and allow the computer to reboot. When you are back at the desktop, close the task.txt notepad if it is open, and proceed to Step 11.
  11. Go to this page and click on the smitRem Download Link link to download smitRem.exe. When downloading smitRem.exe save it to your desktop. You will now see an icon on your desktop that looks like the one below.

  12. Double-click on the smitRem.exe file. You will now see a screen similar to the one below.

    Click on the Start button and the program will start extracting the files into a folder on your desktop called smitRem. When it is finished, click on the OK button. If you look on your desktop you will now see a folder called smitRem.

  13. Next, please reboot your computer into Safe Mode by doing the following:
    1. Restart your computer
    2. After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
    3. Instead of Windows loading as normal, a menu should appear
    4. Select the first option, to run Windows in Safe Mode.
    5. When you are at the logon prompt, log in as an Administrator
  14. When your computer has started in safe mode and you see the desktop.

  15. Close all open Windows.
  16. Open the smitRem folder on your desktop and the contents of the folder will be similar to the image below.

    Double-click on the RunThis.bat file, as shown by the arrow in the image above, to start the tool.

  17. When the tool starts you will see a series of screens with information on them. Read each screen, and when you are finished reading it, simply press any key on your keyboard. After reading the various screens that appear, the program will start the removal process.
    If there is an uninstaller present for an infection that smitRem removes it will start this uninstaller.
    Simply click on the Uninstall button and allow the uninstaller to finish. When it is completed, it will close automatically and smitRem will prompt you to continue. Now you should press any key to continue.
    When no more uninstallers can be found, the tool will continue. Your desktop will disappear and you will start seeing text scroll across the screen. This is normal and nothing to be concerned about. When smitRem has finished running it will automatically start the Disk Cleanup program as shown by the image below.

    This program will remove all Temp, Temporary Internet Files, and empty your Recycle Bin in order to remove any leftover files installed by this infection. This process can take up to a few hours depending on your computer, so please be patient. When it is complete, it will close automatically and you will be back at your desktop.

  18. When the tool is finished, it will will create a log named smitfiles.txt in the root of your drive, eg; Local Disk C: or the partition where your operating system is installed. Examining that log should show that the infection was cleaned.
  19. Reboot your computer back to normal mode.
  20. Perform an onlinescan with Panda: Panda Online
    1. Once you are on the Panda site click the Scan your PC button
    2. A new window will open...click the Check Now button
    3. Enter your Country
    4. Enter your State/Province
    5. Enter your e-mail address and click send
    6. Select either Home User or Company
    7. Click the big Scan Now button
    8. If it wants to install an ActiveX component allow it
    9. It will start downloading the files it requires for the scan (Note: It may take a few minutes)
    10. When download is complete, click on Local Disks to start the scan


Your computer should now be free of the VirusBurst infection. If you are still receiving taskbar security warnings stating that you are infected open C:\Program Files\RoguesScanFix\task.txt and paste the contents of that log into a new topic in the HijackThis Logs Analysis or the Am i Infected forums and someone will advise you as to your next step. When posting the topic please also mention that you have already done the steps in this guide.

Manual Removal Instructions:

  1. Print out these instructions as we will need to close every window that is open later in the fix.
  2. Download FixVB.reg to your desktop by right clicking on the following link and then selecting Save Link As or Save File as, depending on your browser.
    FixVB.reg Download Link

    Confirm that the file FixVB.reg now resides on your desktop as we will need it later.
  3. Go to this page and click on the smitRem Download Link link to download smitRem.exe. When downloading smitRem.exe save it to your desktop. You will now see an icon on your desktop that looks like the one below.

  4. Double-click on the smitRem.exe file. You will now see a screen similar to the one below.

    Click on the Start button and the program will start extracting the files into a folder on your desktop called smitRem. When it is finished, click on the OK button. If you look on your desktop you will now see a folder called smitRem.

  5. Go to your desktop and double click on the FixVB.reg file that you downloaded earlier. When it asks if you would like to merge the information, press the Yes button and then the OK button.
  6. Click on the Start button and then select the Run option.
  7. In the Open: field type c:\windows\system32 and then press the OK button.
  8. When the folder appears, if it says These files are hidden, click on the Show the contents of this folder option.
  9. We now need to make it so you can see hidden files.
    1. Click on the Tools menu and select Folder Options.
    2. Click on the View tab.
    3. Under the Hidden files and folders category select Show hidden files and folders.
    4. Uncheck Hide protected operating system files.
    5. Press Apply and then OK.
    6. If you still can not see the file, then undo these changes and skip to step 11.
  10. Scroll through the list of files in this folder and look for eowygj.dll. Right-click on eowygj.dll and select rename. Rename the file to eowygj.dll.bad.
    Look for the file duxzj.dll and rename the file to duxzj.dll.bad.
    Look for the file gtpbx.dll and rename the file to gtpbx.dll.bad.
    Look for the file xtgwjrm.dll and rename the file to xtgwjrm.dll.bad.
    Look for the file wuwbxp.dll and rename the file to wuwbxp.dll.bad.
    Look for the file oqabf.dll and rename the file to oqabf.dll.bad.
    Look for the file qxfgcg.dll and rename the file to qxfgcg.dll.bad.
    Look for the file syycum.dll and rename the file to syycum.dll.bad.
    Look for the file titiau.dll and rename the file to titiau.dll.bad.
    Look for the file zphnok.dll and rename the file to zphnok.dll.bad.
    Look for the file gqagksr.dll and rename the file to gqagksr.dll.bad.
    Look for the file httge.dll and rename the file to httge.dll.bad.
    Look for the file tazth.dll and rename the file to tazth.dll.bad.
    Look for the file dpfwu.dll and rename the file to dpfwu.dll.bad.
    Look for the file ficqv.dll and rename the file to ficqv.dll.bad.
    Look for the file qnusjji.dll and rename the file to qnusjji.dll.bad.
    Note: Please rename any of the above files that you may find. If you do not find any of these files, then you should post a note about it in the Am I Infected? forum.
  11. After you rename the file, you can close the System32 folder window.
  12. Next, please reboot your computer into Safe Mode by doing the following:
    1. Restart your computer
    2. After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
    3. Instead of Windows loading as normal, a menu should appear
    4. Select the first option, to run Windows in Safe Mode.
    5. When you are at the logon prompt, log in as a user with administrator privileges or one that has permission to delete files in the C:\Windows folder.
  13. When your computer has started in safe mode and you see the desktop.
  14. Click on the Start Menu
  15. Click on the Control Panel option.
  16. Double-click on the Add or Remove Programs icon.
  17. Find the entries for VirusBurst 6.1 and double-click on it to uninstall the program. Follow the prompts to uninstall the program, but do not allow it to reboot the computer if it asks.
  18. When it has completed uninstalling you can close Add or Remove Programs and your Control Panel.
  19. Delete the following files and folders (Do not be concerned if this folder does not exist):
    C:\Windows\System32\eowygj.dll.bad
    C:\Windows\System32\xtgwjrm.dll.bad
    C:\Windows\System32\gtpbx.dll.bad
    C:\Windows\System32\wuwbxp.dll.bad
    C:\Windows\System32\oqabf.dll.bad
    C:\Windows\System32\duxzj.dll.bad
    C:\Windows\System32\qxfgcg.dll.bad
    C:\Windows\System32\syycum.dll.bad
    C:\Windows\System32\titiau.dll.bad
    C:\Windows\System32\\zphnok.dll
    C:\Windows\System32\httge.dll
    C:\Windows\System32\gqagksr.dll
    C:\WINDOWS\System32\tazth.dll
    C:\WINDOWS\system32\dpfwu.dll
    C:\WINDOWS\System32\ficqv.dll
    C:\Windows\System32\qnusjji.dll
    C:\Program Files\VirusBurst\
  20. Close all open Windows.
  21. Open the smitRem folder on your desktop and the contents of the folder will be similar to the image below.

    Double-click on the RunThis.bat file, as shown by the arrow in the image above, to start the tool.

  22. When the tool starts you will see a series of screens with information on them. Read each screen, and when you are finished reading it, simply press any key on your keyboard. After reading the various screens that appear, the program will start the removal process.
    If there is an uninstaller present for an infection that smitRem removes it will start this uninstaller.
    Simply click on the Uninstall button and allow the uninstaller to finish. When it is completed, it will close automatically and smitRem will prompt you to continue. Now you should press any key to continue.
    When no more uninstallers can be found, the tool will continue. Your desktop will disappear and you will start seeing text scroll across the screen. This is normal and nothing to be concerned about. When smitRem has finished running it will automatically start the Disk Cleanup program as shown by the image below.

    This program will remove all Temp, Temporary Internet Files, and empty your Recycle Bin in order to remove any leftover files installed by this infection. This process can take up to a few hours depending on your computer, so please be patient. When it is complete, it will close automatically and you will be back at your desktop.

  23. When the tool is finished, it will will create a log named smitfiles.txt in the root of your drive, eg; Local Disk C: or the partition where your operating system is installed. Examining that log should show that the infection was cleaned.
  24. Reboot your computer back to normal mode.
  25. Perform an onlinescan with Panda: Panda Online
    1. Once you are on the Panda site click the Scan your PC button
    2. A new window will open...click the Check Now button
    3. Enter your Country
    4. Enter your State/Province
    5. Enter your e-mail address and click send
    6. Select either Home User or Company
    7. Click the big Scan Now button
    8. If it wants to install an ActiveX component allow it
    9. It will start downloading the files it requires for the scan (Note: It may take a few minutes)
    10. When download is complete, click on Local Disks to start the scan

Your computer should now be free of the VirusBurst infection.