Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,150,652 members, 7,809,460 topics. Date: Friday, 26 April 2024 at 10:01 AM

Virus Has Killed Me - Computers - Nairaland

Nairaland Forum / Science/Technology / Computers / Virus Has Killed Me (1356 Views)

Shortcut Virus Removal From Windows 7 PC / "My Removable Device" Shortcut Virus - Help / How To Retrieve Your Files From FOLDERS Turned Into SHORTCUTS By VIRUS (2) (3) (4)

(1) (Reply) (Go Down)

Virus Has Killed Me by Nobody: 6:59pm On Apr 29, 2009
Kindly help, a virus with foot as made my compuer to be malfunctioned and useless. i can not even format it can somebody help?
Re: Virus Has Killed Me by veightar: 7:31pm On Apr 29, 2009
You need to add extra information.
What type of virus is that and how did it do that.
I think I might be able to help.
By the way, the fact that you are not able to format it means its not your computer
that is not having the problem but the hard disk. It will be normal if you replace the disk.
But to repair, I know this kind of virus that was coded in dos format so that it can even work
when you're not in GUI mode. If that is the case and the drive is now write protected as it always
does to pen drives, then you need to visit the manufacturers web site. They often have tools for
formating such write protect drive or try to unlock it if it has that function. Search for a switch on it
and change the direction.
Or maybe try to use windows set up to format your drive
Re: Virus Has Killed Me by Infoseye(m): 8:22pm On Apr 29, 2009
@post from what u said the virus name is Funnyust scandal or so it shows an icon of a feet just like a video double clicking it makes the virus active. It spreads infect any usb storage device and render ur pc useless even if u try to scan or install anti virus it blocks it, also if u open anything problem e.g Word even note it closes it.
Guess what? It enters ur pc through yahoo messenger while sharing files, and d sweetest thing about it is that no anti virus can remove it. After my research on net looking for a solution I met an indian he gave me his website with procedures,softwares to get rid of this virus. Cant remember the website but open google type funnyust scandal remover download and use it, it will scan and remove the virus immediately and lastly scan ur flash also if not it will infect ur pc again let me know how it goes if u cant get the software JUST FORMAT UR PC AND USB STORAGE DEVICE AND FINALY BACK UP UR FILES TO A CD B4 FORMATING!
Re: Virus Has Killed Me by curtez: 1:12pm On May 01, 2009
Guys i am really digging the information you guys are sharing please keep it up wink. please i have a problem my self. how do i treat this notorious virus called Raila Odinga. shocked i need as much infomation i can get. the virus is now a global issue.  angry
Re: Virus Has Killed Me by sameolg616(m): 1:35pm On May 01, 2009
call me on 08061679732 or add me on ur messenger:for_u2_nv2001@yahoo.com
Re: Virus Has Killed Me by Infoseye(m): 1:36pm On May 01, 2009
Format your PC no antivirus can remove it cuz its a written program not a virus.
Re: Virus Has Killed Me by netotse(m): 1:48pm On May 01, 2009
na wa for this raila odinga o. . .i sed i had it and it didnt take me 5 mins to remove it sef!
Re: Virus Has Killed Me by swing4real(m): 8:48pm On May 01, 2009
@Infoseye

You have any idea how to remove Trojan Horse Agent2.DRC?.If you know please kindly help, I have used spybot and AVG and it keeps coming back,
Re: Virus Has Killed Me by curtez: 12:08am On May 02, 2009
whowh his guy is making me get scared. all the same i do not believe thier is no cure to the virus. pls @ netotse how did you remove it. share the knowledge. cool
Re: Virus Has Killed Me by Smartsboy(m): 7:13am On May 02, 2009
smiley
Re: Virus Has Killed Me by veightar: 9:08pm On May 02, 2009
Ok. You guys are doing great. But the problem is, the real name of the virus is not always the same for everyone unless you use an antivirus to detect it. I can even change the name of a virus before infecting your pc with it so that you might get more confuse than you're already are. Use usb disk security when the virus stops you from installing an antivirus. Then scan your pc from the net using any antivirus. That will be good if you don't want to format your disk.
But when the virus destroys your system to the extend of modifying the system files, then the best option is to format
Re: Virus Has Killed Me by swing4real(m): 7:24am On May 04, 2009
Plz any of u guys know any software, i will use to scan my pc aside AVG and Spyboy? Please help
Re: Virus Has Killed Me by Infoseye(m): 11:11am On May 04, 2009
Get nod 32
Re: Virus Has Killed Me by Nwaaba1(m): 1:00pm On May 04, 2009
hello my brothers go and get usb security it will remove them all thanks.
Re: Virus Has Killed Me by onasharon(m): 6:58pm On May 04, 2009
pls can some one help me to remove a virus named ahsan's i was unable to remove it thru my antivirus and is taking all my computer desktop is renaming them one by one.pls help i know long enjoy my laptop and my usb drive
Re: Virus Has Killed Me by itismd(m): 3:42pm On May 08, 2009
I derive joy removing virus from a system manually. It's kind of  part of what i do in the office.
i have studied its activities, they all have some things in common -- disabling registry editing tool, removing 'Run' from start menu, disabling Task Manager, hiding folder options' etc.   

I learnt how to disable viruses manually using regedit (registry), msconfig, gpedit.msc . Its a long process and risky process( careful, u can mess up the system through registry) to remove virus manually. But its the best way to fix back u system. Anti viruses will not fix back some registry tweaks like "hide folder option''  You can search the internet for the virus name or the xtics, you will be surprised how the detailed solution (manual removal ) will be displayed to u in one of the websites or forums.
This is how i tackle new viruses that i have not heard of. JUST BE CAREFUL OF WINDOWS REGISTRY. Don't go there if u are not sure of what to do . I have mistakenly messed up systems that lead to re installation from doing so.

For people that are not in IT
The best thing is to get a good anti virus (like Kaspersky, Nod, Mcafee. i can help u get one) and keep updating and you will be free.
PLEASE NEVER PUT MORE THAN ONE anti virus on same system esp norton with another. If ur system is under attack, the result will be worse than the original virus attack.

@curtez, don't be too alarmed Raila Odinga is just a virus developed to campaign a politician. it does not cause much harm to the system.
Just download maybe kaspersky 1mnth trial , install update and scan.

or got through this if u are an IT person

Technical details

This Trojan has a malicious payload. It is a Windows PE EXE file. The Trojan components may vary in size from 17KB to 286KB.

Installation

Once launched, the Trojan extracts a file with the following name from its body to the current user's desktop:

Raila Odinga.gif

and launches it. The user will see the following image:



The Trojan also copies its executable file to the following directory:
%System%\drivers\RailaOdinga.exe

It also extracts the following file from its body:
%Temp%\nswC.tmp\System.dll

In order to ensure that the Trojan is launched automatically each time the system is booted, the Trojan adds a link to its executable file in the system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] @ = "%System%\drivers\RailaOdinga"

The Trojan also creates the following shortcut:
%Documents and Settings%\Start Menu \Programs\Autorun\RailaOdinga.lnk

When this shortcut is run, the Trojan executable file will be launched.


Payload

The Trojan copies its executable file to all removable media under the following name:

:\smss.exe

It also copies the extracted image:

:\Raila Odinga.gif

stands for the letter of the removable disk.

The Trojan creates an autorun.inf file in the root of the removable disk. This file will automatically launch the Trojan executable file when the user attempts to open the infected disk using Explorer.

The Trojan also recursively copies its executable file to all folders on the removable disk. These copies use the names of files which are located in these folders together with an .exe extension.

Removal instructions

If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:

* Use Task Manager to terminate the Trojan process.
* Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine).
* Delete the following system registry key parameter:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] @ = "%System%\drivers\RailaOdinga"

* Delete the following files:

%Temp%\nswC.tmp\System.dll
%System%\drivers\RailaOdinga.exe
%Documents and Settings%\ Start Menu \Programs\Autorun\RailaOdinga.lnk

* Delete the following file from the desktop:

Raila Odinga.gif

* Delete all copies of the Trojan from removable disks.
* Delete the autorun.inf file from the root directory of all removable disks.


@onasharon  the virus that renames My computer and Recycle bin to Ahsan's is bit more tricky because it looks like windows processes
system.exe
csrss.exe
Home video.avi.exe

i dont have time to go tru this anymore, i have to get back to work. Just get a good antivirus  and u will be free. u can get from sales@edgebasetech.com

Bye peeps
Re: Virus Has Killed Me by netotse(m): 4:43pm On May 08, 2009
itismd:

I derive joy removing virus from a system manually. It's kind of  part of what i do in the office.
i have studied its activities, they all have some things in common -- disabling registry editing tool, removing 'Run' from start menu, disabling Task Manager, hiding folder options' etc.   

I learnt how to disable viruses manually using regedit (registry), msconfig, gpedit.msc . Its a long process and risky process( careful, u can mess up the system through registry) to remove virus manually. But its the best way to fix back u system. Anti viruses will not fix back some registry tweaks like "hide folder option''  You can search the internet for the virus name or the xtics, you will be surprised how the detailed solution (manual removal ) will be displayed to u in one of the websites or forums.
This is how i tackle new viruses that i have not heard of. JUST BE CAREFUL OF WINDOWS REGISTRY. Don't go there if u are not sure of what to do . I have mistakenly messed up systems that lead to re installation from doing so.

For people that are not in IT
The best thing is to get a good anti virus (like Kaspersky, Nod, Mcafee. i can help u get one) and keep updating and you will be free.
PLEASE NEVER PUT MORE THAN ONE anti virus on same system esp norton with another. If ur system is under attack, the result will be worse than the original virus attack.

@curtez, don't be too alarmed Raila Odinga is just a virus developed to campaign a politician. it does not cause much harm to the system.
Just download maybe kaspersky 1mnth trial , install update and scan.

or got through this if u are an IT person

Technical details

This Trojan has a malicious payload. It is a Windows PE EXE file. The Trojan components may vary in size from 17KB to 286KB.

Installation

Once launched, the Trojan extracts a file with the following name from its body to the current user's desktop:

Raila Odinga.gif

and launches it. The user will see the following image:



The Trojan also copies its executable file to the following directory:
%System%\drivers\RailaOdinga.exe

It also extracts the following file from its body:
%Temp%\nswC.tmp\System.dll

In order to ensure that the Trojan is launched automatically each time the system is booted, the Trojan adds a link to its executable file in the system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] @ = "%System%\drivers\RailaOdinga"

The Trojan also creates the following shortcut:
%Documents and Settings%\Start Menu \Programs\Autorun\RailaOdinga.lnk

When this shortcut is run, the Trojan executable file will be launched.


Payload

The Trojan copies its executable file to all removable media under the following name:

:\smss.exe

It also copies the extracted image:

:\Raila Odinga.gif

stands for the letter of the removable disk.

The Trojan creates an autorun.inf file in the root of the removable disk. This file will automatically launch the Trojan executable file when the user attempts to open the infected disk using Explorer.

The Trojan also recursively copies its executable file to all folders on the removable disk. These copies use the names of files which are located in these folders together with an .exe extension.

Removal instructions

If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:

* Use Task Manager to terminate the Trojan process.
* Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine).
* Delete the following system registry key parameter:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] @ = "%System%\drivers\RailaOdinga"

* Delete the following files:

%Temp%\nswC.tmp\System.dll
%System%\drivers\RailaOdinga.exe
%Documents and Settings%\ Start Menu \Programs\Autorun\RailaOdinga.lnk

* Delete the following file from the desktop:

Raila Odinga.gif

* Delete all copies of the Trojan from removable disks.
* Delete the autorun.inf file from the root directory of all removable disks.


@onasharon  the virus that renames My computer and Recycle bin to Ahsan's is bit more tricky because it looks like windows processes
system.exe
csrss.exe
Home video.avi.exe

i dont have time to go tru this anymore, i have to get back to work. Just get a good antivirus  and u will be free. u can get from sales@edgebasetech.com

Bye peeps


lol, if not for the fact that u were talking sense as per the registry thing i woulda got on your case for dropping u're email addy here(BTW by doing that u're inviting scam mails o, where do u think all thos scammers get email addy's from sef)

i like u're style sha. . .it seems like me u've found your way abt the registry the hard way lol!
Re: Virus Has Killed Me by itismd(m): 5:22pm On May 08, 2009
@netotse am just offering information to people that might need it. After all I get my way through, through goggling. I forgot to put spaces in the email ady, to stop spam robots from picking it.


Infoseye:

Format your PC no antivirus can remove it cuz its a written program not a virus.

, but all viruses are written programs. Formatting should be the last option.
Re: Virus Has Killed Me by Nobody: 12:00pm On May 11, 2009
process explorer - it can be set as your default task manager, in whichcase task manager cannot be disabled
autoruns - you will see any programs configured to run at logon and you can trace their paths
Re: Virus Has Killed Me by netotse(m): 1:44pm On May 11, 2009
@oyb
process explorer?the sysinternals one right? they've discontinued it in favour of process monitor and trying to use that thing gives me a headache!do u hv the setup for procexp?
Re: Virus Has Killed Me by Nobody: 2:05pm On May 11, 2009
nooo process explorer has NOT been discontinued

sysinternals was bought over by MS.

you can go to their website or uyou can simply download the entire suite from here -

http://majorgeeks.com/Sysinternals_Suite_d5473.html

hope niger state internet will not frustrate you, its like 8mb.

if you decide you only want process explorer, enter it into the search bar, you will find a link to it. majorgeeks is completely safe. been using it since 2005

me too i never master process monitor , its supposed to be great for finding out just what a process is doing. . .

(1) (Reply)

Sbs 2008 Help / Mtn Usb Modem For Sale @4k / Post Screenshots And Compare Internet Speeds Across Africa

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 52
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.