Showing posts with label virus info. Show all posts
Showing posts with label virus info. Show all posts

Saturday, April 14, 2007

BrO_AcT Facts That You Need To Know

BrO_AcT Facts That You Need To Know

Lately, a lot of my friend's computer have been infected by BrO_AcT worm/virus. And it cause them a lot of trouble to get rid of this new virus. Moreover, the information on the Net is still very limited since it is a new virus. Recently, I've found the facts about this virus on the Net and want to share with you so that you will know if you've been a victim or not.

1)What is BrO_AcT ?

Symantec AV -> identify it as W32.sillyDC.
DrWeb CureIT -> identify it as Win32.HLLW.Broact
TrenMicro -> identify it as WORM_VB.BHE

Panda AV -> identify it as W32/SexyGirl.A.worm
Avira -> identify it as Worm/VB.DH.1

2)How it Spreads ?

Normally it spread via removable storage devices(USB drive) . Infected thumb drive will show these files: "MySexy.exe", "User.exe" and "Sexy.Dat".

3)Symptomps

-Popup box appears after login into the Windows, with the title "BrO_AcT.exe". It contains a message but I don't remember what it is written.
-Look at your title bar. An infected hardisk will show the folder name + [:Restricted by BrO_Act:]
- When you try to open C:\Windows\System32 folder, explorer close itself.
- Right click My Computer, select Properties, select Computer, click Change button, you find that your computer name has been changed to "ReAct_User"
-Your antivirus has been deactivated.
-You can't access Task Manager, Regedit, Msconfig, Folder option, and Command prompt.

4)How Do I Confirm that I'm Infected ?

Run Hijackthis. These are the entries added:
C:\WINDOWS\system32\BrO_AcT.exe
F2 - REG:system.ini: Shell=Explorer.exe "C:\WINDOWS\default__.pif"
O4 - HKLM\..\Run: [System] C:\WINDOWS\SYSTEM32\BrO_AcT.exe
O4 - HKCU\..\Run: [svchost] C:\WINDOWS\SYSTEM32\ReAct_User\svchost.exe


5)What Will This Virus Do or Create in Your Computer ?

It will create and add the following files :-

-C:\Windows\system32\BrO_AcT.exe
-C:\WINDOWS\default__.pif
-C:\WINDOWS\SYSTEM32\ReAct_User\svchost.exe
-C:\WINDOWS\SYSTEM32\ReAct_User\winlogon.exe
-C:\ReActLog (Something with this name)
-NTDETCH.com (on all your drive, root folder)
-Autorun.inf (on all your drive, root folder)
-Hundreds of files in C:\System Volume -Information\_restore{7C0D0734-E9F5-4A30-ABD4-977206CFACB2}\RP411 (With name like -A0062080.com, A0062083.pif, A0062092.exe and etc)
-C:\WINDOWS\system32\MySexy.exe
-C:\WINDOWS\system32\regedit.com
-C:\WINDOWS\system32\msconfig.com

It also will copy itself to any portable USB drive connected to the infected system and creating:-
->Autorun.innf
->BrO_AcT.exe
->My_SeXy.exe

and the USB drive will autorun anytime you connect it to the system. "THIS IS THE WAY HOW THE VIRUS SPREAD".


6) How Do I Get Rid of BrO_Act.exe ?


Update your anti-virus with latest virus definition. As far as I know :-

Nod32 AV - not detect, system infected
BitDefender 10 - not detect, system infected
McAfee - not detect, system infected

Avira - detected as
Worm/VB.DH.1
AVG 7.5 Pro - detected as W32/VB
Kapersky - detected as Win32.VB.DH


I hope this little info will help you to eliminate this annoying virus.


AddThis Social Bookmark Button AddThis Feed Button

Wednesday, March 21, 2007

What VIRUSES may do?


WHAT VIRUSES MAY DO TO YOUR COMPUTER

What can virus do to your computer once it has been infected? Below are possibilities you may experience when you are infected with a virus. Remember that you also may be experiencing any of the below issues and not have a virus.

  • Deleted files.

  • Various messages in files or on programs.

  • Changes volume label.

  • Marks clusters as bad in the FAT.

  • Randomly overwrites sectors on the hard disk.

  • Replaces the MBR with own code.

  • Create more than one partition.

  • Attempts to access the hard disk drive, which can result in error messages such as: Invalid drive specification.

  • Causes cross-linked files.

  • Causes a "sector not found" error.

  • Cause the system to run slow.

  • Logical partitions created, partitions decrease in size.

  • A directory may be displayed as garbage.

  • Directory order may be modified so files, such as COM files, will start at the beginning of the directory.

  • Cause Hardware problems such as keyboard keys not working, printer issues, modem issues etc.

  • Disable ports such as LPT or COM ports.

  • Caused keyboard keys to be remapped.

  • Alter the system time / date.

  • Cause system to hang or freeze randomly.

  • Cause activity on HDD or FDD randomly.

  • Increase file size.

  • Increase or decrease memory size.

  • Randomly change file or memory size.

  • Extended boot times.

  • Increase disk access times.

  • Cause computer to make strange noises, make music, clicking noises or beeps.

  • Display pictures.

  • Different types of error messages.

source : http://www.computerhope.com

Add to : Social Bookmarking

Monday, March 5, 2007

Step by Step Removing "Hacked by Pokemon" virus


Did your Internet Explorer title bar shown this "Hacked by Pokemon"?Don't worry this is not a high risk virus.Just some visual basic program.The file that run this visual basic is BHA.VBS.DLL. I will show you how to remove this bug manually.

What will This Virus Do ?


-Infected every of your partition including removable drive.This is because the script was written to generate bha.vbs.dll and autorun.inf.

-Spread via removable drive such as pendrive or other storage device because of its capability to generate dll file using vbs script.

-Will generate new registry value in your windows registry that is:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\MS32DLL - winpath&"\Bha.dll.vbs

HKCR\vbsfile\DefaultIcon - shell32.dll

And also modify this registry value:

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Window Title","Hacked by pokemon"

-All your partition cannot open normally if your PC infected because the authority was given to the 'autoplay' option not 'open' option if normal condition.To ensure this,just right click one of your drives and see the first bolt option,is it open or autoplay.

How to Show Autorun.inf & bha.vbs.dll in Your Computer?

-Go to Tools>Folder Option

-Uncheck Hide protected operating system files (Recommended) and Use simple file sharing(Recommended)

-Click Apply and Close the window.

WARNING: When you open your drive partition, MAKE SURE you open by right clicking it and choose Open, IF NOT,the thread will RUNNING again.

How to Delete/Remove *vbs File ?

1) CTRL + ALT + DEL and find wscript.exe if exist to make sure its running or not. If exist, click End Process.

2)You may delete 2 files that i mention above manually in every partition.

3) or, Start -> Search. Search for *vbs files . Delete the file if it is found.

How To Clean The Registry ?

-After clean and delete the file, now you must clean the windows registry because this thread generate new registry value after they were activated.

-Run registry editor:START--->Run (type regedit)

-Open this location:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\MS32DLL

Delete registry named MS32DLL

-And open this location:

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main

-Choose Window title and edit the string.

-You may put any names or delete the string value (Window title)

-Then reboot your PC

I hope this GUIDE will help you to eliminate this annoying virus . Good Luck !!!

Add to : Social Bookmarking

Design by Free blogger template