Visit >> My New BLOG!!!!

Showing posts with label Worms and Viruses. Show all posts
Showing posts with label Worms and Viruses. Show all posts

Friday, October 26, 2007

How to Remove IMGKULOT.vbs (.vbs/Capiz-A) From Your System

This is script worm that affects only Windows operating systems. It spreads itself on removable storage devices such as diskettes, CDs, USB Flash Drives and the like and installs itself on the Registry, thus affecting the system and it will continually display this error:

Windows - No Disk Exception Processing Message c0000013 Parameters 75b6bf9c 4 75b6bf9c 75b6bf9c

As it turns out, his computer had a virus, quite a new one, which is called IMGKULOT, or VBS/Capiz-A.

Here are the following steps to remove it manually.
1. Open Windows Task Manager by presssing Ctrl-Alt-Del and clicking on the Task Manager button on the dialog box that appears.

2. In the Processes tab, locate wscript.exe. If you can’t see it, try clicking on the “Show processes from all users” checkbox.

3. Highlight wscript.exe, and click on the “End Process” button.

4. Highlight explorer.exe and click on the “End process” button as well.

5. In the Task Manager menu, select File->New Task (Run…), type “cmd” on the Create New Task dialog box, and click on the OK button. This will open a command prompt window.

6. Go to C:\WINDOWS\System32 by typing “cd C:\WINDOWS\System32″ in the command prompt.

7. Delete all “imgkulot” files that appear on that directory by typing “del imgkulot.* /f /s /q /a”

8. Delete all “autorun” files in your root directory by typing “del c:\autorun.* /f /s /q /a”

9. If your hard disk have several partitions, apply #8 to the other drives as well.

10. The files of the virus has already been removed at this point. However, there is still a registry entry (modified by the virus) that needs to be restored. To open the Registry Editor, in the Task Manager menu, select File->New Task (Run…), type “regedit” on the Create New Task dialog box, and click on the OK button.
Go to the the registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon.

11. The following key and value pair should appear. If not, please modify as is: “Userinit”=”C:\WINDOWS\system32\userinit.exe,”

12. Restart your computer.

The worm should be completely removed by now, however, some of your removable drives may be affected as well, so be careful with what you plug in to your computer. Alwasy disable autorun feature and do a scan on your removable drives, and also, format it often.

imagina_boy@linuxmail.org is behind this worm.

Hope you can make it.

How to Remove Pooh.vbs and Nhatquanglan Worms


I had recently encountered this on my PC at work so I decided that I will share to you the steps on how to eliminate this worm on your PC, especially to those who are using USB Flash Drives and Floppy Diskettes.

The Nhatquanglan worm (usually together with the Pooh.vbs worm), slows down your PC and disables Windows Task Manager, Folder Options, Registry, Group Policy Editor, and the like. If you have this symptoms, there is a possibility that you are also infected by the Pooh.vbs worm.

Symptoms taht you're PC is infected by the Nhatquanglan worm:

1. This worm spreads by USB drives though it is possible that other portable media may be involved too.

2. Inability to use Windows Task Manager, the Folder Options, Registry, etc.

3. There is a crappy looking folder icon that is seen (with same name as the original folder), the file size of which is 282 kb.

4. It makes the computer slow down, and no anti-virus as of now seems to catch hold of it.

5. Inability to stop the USB drive from remove hardware safely option.

7. Inability to format the USB drive.

8. The worm is an autorun .exe file and executes and infects every time a USB drive is plugged in.


Steps on how to remove the Nhatquanglan worm:

1. Download HijackThis (free), and the Task Manager fix of the Interra Group (also free), and a program called Spybot Killer.

2. Run the Hijack this (rename it first or it wont start), and fix all files with scvhost.exe (not svchost.exe), run spybot, and then task manager fix. This should cure it. As u learn more about viruses, hijack this is probably the most useful program to have.

3. Reboot, and should run ok.


Pooh.vbs or the W32/DKR worm, is a VisualBasic script that can be detected by some AntiVirus like Norton and McAfee. Pooh.vbs comes with an HTML file (the aikelyu.html) that opens on WIndows Log-on. It exploits the autorun feature in memorycards and copies itself to computers and connected memory cards thereafter. Because it does not spread itself to the internet, it hasn't gained enough notoreity to be included in virus defenses of various programs. Also clean your infected memory cards.

The aikelyu.html file:









Symptoms that you're PC is infected with Pooh.vbs
1. You cannot open your Local Disk (C:) by clicking it your My Computer and there is a message alert box. If you also try to right-click it, you will notice that the first right-click option is Autoplay.

2. When you're encoding something, let's say, on Microsoft Excel/Word, you will encounter some sort of URL (http://www.freewebtowns...) in the middle of your work... and it also disables some features on your Microsoft Excel or Word and the like.

3. When you log - on to Windows, you will see the aikelyu.html file, located on C:\WINDOWS\system32\aikelyu.html.


If you had created a restore point prior to the detection of your Pooh.vbs, you can have a system restore, and everything will be back to normal.

Download Nod32 and use it to scan for files.

So here are the steps that I had done to remove the Pooh.vbs worm:
1. Reboot your PC and run your PC on SAFE MODE (press F9 during boot-up) and log-in as an Administrator.

2. Also download StartUp ControlPanel. You will use this later. For more informations regarding StartUp Control Panel, go here

3. Open Windows Task Manager ([Ctrl] + [Alt] - [Delete] or [Crtl] + [LShift] - [Esc] ) and go to the Processes tab.

4. Terminate Wscipt.exe and Explorer.exe process.

5. Open Command Prompt (open Run and type cmd)

6. On the Command Prompt, type the following:
del c:\pooh.vbs /f/s/q/a
del d:\pooh.vbs /f/s/q/a (include your other drives and USB drives that have been infected)

del c:\autorun.inf
del d:\autorun.inf (include your other drives and USB drives that have been infected)

del c:\windows\system32\kernell.dll.vbs

del c:\aikelyu.html /f/s/q/a

7. Now use the StartUp Control Panel you had just downloaded earlier to remove the aikelyu.html during Windows startup. Also, to check if that the aikelyu.html file has been deleted, open Microsoft Configuartion (open Run and type msconfig) and select the Startup tab and see if there is still the aikelyu.html with a check on it. If it is still there, uncheck it.

8. Open the Run Dialog Box again and type regedit.

9.
Navigate through: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon on the left pane. After which, on the right pane, check the Shell string has a value of explorer.exe. The corrupted string value has a userinit=userinit.exe combined with explorer.exe, so delete it.

10. To finally check that you had deleted pooh.vbs from your system, go to Control Panel - Folder Options. On the View tab, choose "Show hidden files", uncheck "Hide protected operating system files (Recommended)" and "Hide extensions for known file types". and press OK.

11. Open Windows Explorer ( [Windows] - [E] ), and go to C:\ and find if the pooh.vbs file is still there. Go to C:\WINDOWS\system32 and check if the aikelyu.html file and kernell.dll.vbs file is still there. If they are still present, manually delete them and empty your Recycle Bin.

12. Reboot your PC!

That's all... Hope you can make it.