Expert Virus Removal Services and Technical advice.

We are Providing Computer users with Expert Virus Removal Services and Technical Advice.

Threats and their Removal.

Do you need a quick solution to a technical problem? With our live remote-assistance tool, a member of our support team can view your desktop and share control of your mouse and keyboard to get you on your way to a solution.

Spywares and their Removal.

Are you worried that your computer might be nfected with Spywares? Then this is were you can find Support.

Advices for Protecting the Computer.

Expert Advices for Protecting your computer from attacks from all threats

Different Anti Virus Software and Tools.

Familiarizing different Anti Virus Software and removal Tools.

Showing posts with label Multiple Malware. Show all posts
Showing posts with label Multiple Malware. Show all posts

February 15, 2011

Remove the WGA Virus



The WGA virus poses as Microsoft's anti-piracy software. It enters your computer when you click on a link sent by an unknown user on AOL Messenger. The WGA virus registers itself as a new system driver service called "wgavn." This virus has numerous aliases or names. This makes it really tough for you, if not impossible, to remove it manually. The easiest and best way to remove the WGA virus is by using your built-in anti-malware program.

January 24, 2011

TROJ_GAMETHI.FMS

This is a Trojan Horse that will come in disguise of the users. Trojans are usually downloaded from the Internet and installed by unsuspecting users with or without their consent.Trojans typically carry payloads or other malicious actions that can range from the mildly annoying to the irreparably destructive. They may also modify system settings to automatically start. Restoring affected systems may require procedures other than scanning with an anti-virus program.

This comes in a combination of malware when there is an exploit HTML_SHELLCOD.SM. It brings 8 infections out of which Troj_GAMETHI.FMS is one of them. 


Effects:
This trojan drops copies of itself in system32 folder with a name
  • fqtkz.exe
It creates the following registry keys 
  • HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\Internet Explorer\Main
    TabProcGrowth = "0"
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\Windows\CURRENTVERSION\URL
    SystemMgr = "Del"
Removal:

1) Disable system restore.
2) Use Process explorer tool to find the processes that are related to the Trojan.
3) If the detected file is displayed in either Windows Task Manager or Process Explorer but you cannot delete it, restart your computer in safe mode.
Search and delete the registry keys

  • In HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\
    Internet Explorer\Main
    • TabProcGrowth = "0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\
    Windows\CURRENTVERSION\URL
    • SystemMgr = "Del"
     
Delete the files that are dropped by the trojan in the system 32 folder. Uncheck Hide protected operating system files in Folders Option>View tab, and then check the Search Hidden Files and Folders checkbox in the "More advanced options" option to include all hidden files and folders in the search result as the trojan may apply the hidden attributes to the files it dropped.

January 22, 2011

Multiple Malware

There are instances where more than one malware infecting at a same time because of many vulnerabilities and many ways that different malware can attack on a PC. It leads to severe situations and that will crash the PC entirely. There is one particular exploit that brings all the malware and trojans at a time HTML_SHELLCOD.SM that exploits CVE- 2010 3962 and because of which following trojans and malware attack the PC:

  • TROJ_LAMECHI.D,
  • JS_EXPLOIT.ADA,
  • JS_EXPLOIT.SM1, 
  • HTML_SHELLCOD.SM, 
  • TROJ_DLOADER.DAM, 
  • TROJ_GAMETHI.FMS, 
  • PE_PARITE.A, 
  • TSPY_ARDAMAX.HR
HTML_SHELLCOD.SM, a recently discovered malware that took advantage of a certain vulnerability in Internet Explorer (IE) and after all these infections infect the system and it many eagle-eyed cybercriminals look to further to inject their malicious money-making machinations that exploits all of the vulnerabilities present in the most efficient way possible.


Once HTML_SHELLCOD.SM has successfully taken advantage of the Uninitialized Memory Corruption Vulnerability (CVE-2010-3962) in IE, it connects to various URLs to download other malicious files detected as TROJ_LAMECHI.D, JS_EXPLOIT.ADA, JS_EXPLOIT.SM1, HTML_SHELLCOD.SM, TROJ_DLOADER.DAM, TROJ_GAMETHI.FMS, PE_PARITE.A, and TSPY_ARDAMAX.HR onto the affected systems.

This malware can render an infected system unusable.and puts the user’s confidential information at risk if another malware with backdoor capabilities affect the system. For instance, TROJ_GAMETHI.FMS, one of the malware HTML_SHELLCOD.SM downloads, steals user names and passwords related to popular online games such as Maple Story, Dungeon Fighter, Ragnarok Online, and World of Warcraft and can compromise the user accounts.

TSPY_ARDAMAX.HR will drop a file named TROJ_GAMETHI.FMS which drops more files on the infected system.  It also logs keystrokes and accesses certain sites and hacks chat logs which compromises user's privacy by stealing usernames and passwords. TROJ_GAMETHI.FMS terminates processes and downloads component files.

 PE_PARITE.A is a malware that infects .exe and .scr fils and spreads the entire network drives by choosing a port.

Prevention: 
Users can prevent this threat by updating their operating system with all the available patches and updating their anti-virus with latest updates. Scan the PC with the updated Malware by disabling system restore, it will remove the threat.

Related Posts Plugin for WordPress, Blogger...

Search This Blog

Followers

Categories

Twitter Delicious Facebook Digg Stumbleupon Favorites More