Saturday, September 15, 2007

Hacked By Godzilla in Explorer( Called as MS32dll.dll.vbs)

How to remove “Hacked by Godzilla - MS32DLL.dll.vbs” (VBS.Zodgila) worm?

* Open Task Manager ( Right click on your taskbar and click “Task Manager” )
* Click on Processes tab and select “wscript.exe” and click “End Process” button. (Remember to remove all wscript.exe)
* Go to My Computer, Click on Tools -> Folder Options, click on View tab
* Under Advance settings,
check “Show Hidden files and folders“,
uncheck “Hide extensions for known file types“,
uncheck “Hide protected operating system files (Recommended)”
and click “OK” button
* Go to C:\WINDOWS or C:\WINNT and delete file MS32DLL.dll.vbs
* Now go to all your drive in your computer, and delete autorun.inf and MS32DLL.dll.vbs including your USB Drive and Floppy disk. All the autorun.inf and MS32DLL.dll.vbs file is located at the root directory of your drive, ex: c:\MS32DLL.dll.vbs, d:\MS32DLL.dll.vbs …

To access your drive, Go to My Computer, right click on the drive and select “Explore”

* Next we are going to clean your registry record. Click Start -> Run, type regedit
* Go to HKEY_LOCAL_MACHINE \Software \Microsoft \Windows \Current Version \Run and delete MS32DLL (right click on it and select delete)
* Now we are going to disable CD Autorun, Go to HKEY_LOCAL_MACHINE \SYSTEM \CurrentControlSet \Services \Cdrom look for Autorun and double click on it and enter 0 as it’s DWORD value

You can skip this steps if you do not wish to disable CD Autorun feature. But Hacked By Godzilla worm spread when CD Autorun is ON.

* Go to HKEY_CURRENT_USER \Software \Microsoft \Internet Explorer \Main and delete “Window Title” which has it’s value of “Hacked by Godzilla“
* Now go back to My Computer, Click on Tools -> Folder Options, click on View tab
* Under Advance settings,
uncheck “Show Hidden files and folders“,
check “Hide extensions for known file types“,
check “Hide protected operating system files (Recommended)”
and click “OK” button
* Empty your Recycle Bin.
* Restart your PC and your PC should be clean from Hacked by Godzilla now

Monday, September 3, 2007

About killvbs.dll.vbs

For killvbs.vbs trojan virus please use right click always
For permanent
goto regedit
then HK_LM in that go to software then Microsoft then WINDOWSNT then Currentversion after that winlogon then in shell delete the wcscript.exe and killvbs.vbs
it will help or use software ms32dll.dll.vbs (i recommend it download it)

Saturday, August 25, 2007

About RavMon virus

Hi!RavMon.exe, which is (even) provided by Microsoft.com...but a new virus named RavMon.exe has arrived...
Parts:
1 : > RavMon.exe
2 : > Autorun.inf
3 : > Unknown Resident Program/dll/etc...

RavMon.exe is the action agent... Autorun.inf directs it... and The Unknown Application(s) MasterMind it...When it attacks the first two files are found in every root-directory of Hard disks... like in C:, D:, E:, etc... and if you right click on drive, you will notice that Open, Explore like commands are changed from English to some other language... and after all if you click on any like (Open, Explore...), then you are no more able to See Hidden and System Files....

My Solution:
I just written a Dos-Batch file to remove this virus.. it looks like thisc:cd\attrib ravmon.exe -s -h -rdel ravmon.exeattrib autorun.inf -s -h -rdel autorun.inf[for all partitions]WARNING: TO USE THIS FILE YOU MUST RE-INSTALL OS... IF YOU JUST USE THIS FILE WITHOUT RE-INSTALLING OS, THEN ITS USELESS...

STEP BY STEP PROCEDURE:

1 : > BOOT YOUR COMPUTER FROM BOOTABLE DEVICE...
2 : > EXECUTE BATCH FILE FROM DOS-PROMPT
3 : > JUST AFTER THAT RESTART AND WITHOUT USING YOUR OLD OS, RE-INSTALL YOUR OS....CONGRATULATIONS YOU ARE SUCCESSFULL

HELP IN VIRUS

WANNA BE HELPED BY EXPERTS IN VIRUS SOLUTION!!!!!!!!!!!!!!!!!
TOUGH TO DECIDE WHICH ANTI VIRUS WORKS!!!!!!!!!!!!!!!!!!!
CLICK IN THIS SITE