RE: annoynmous virus found in Win2K3 and also spread to memory flash d

RE: annoynmous virus found in Win2K3 and also spread to memory flash d

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
RE: annoynmous virus found in Win2K3 and also spread to memory flash d Milo ( MSPSS) 05-01-2007
Posted by =?Utf-8?B?eWFubmllbXg=?= on May 8, 2007, 11:32 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I found this information. I live in Vietnam and have an infected PC too:

the answer is in Vietnamese but if you know PCs and servers well enough you
can figure out what they are saying because the technical stuff is still in
English

and Symantec does not detect this virus. I submitted it to them over 2
weeks ago, have a tracking number and everything but it still does not detect
it. I submitted another virus to them and they fixed it within 5 days but
not this one. Very disappointing. And since I am in Vietnam and they have no
local number I have not called them to follow up on it. Symantec Support
Tracking #:8795726


anyway I have not tested this yet because the PC is at another site: but
good luck


1. bạn thử copy đoạn code này tạo thành file auto.bat rồi chạy
nó trong chế
độ Safe Mode

@echo off
cls
del C:\windows\system\fun.exe
del C:\windows\system32\dc.exe
del C:\windows\system32\sviq.exe
del C:\windows\repair.ini
del C:\windows\DataV.ini
del C:\windows\config\Win.exe
del C:\windows\system32\winsit.exe

lưu thành tên nào cũng được . rồi run nó

2. start --> Run gõ regedit -> ok
3. vào HKEY_CURRENT_USER\Software\Microsoft\windows\current\version\run
4. xóa Winstart ( phần khởi động cùng window)
5. HKEY_LOCAL_MACHINE\software\microsoft\windows NT\currentVersion\winlogon
6. chọn Useinit --> set Useinit to Blank
7. set Shell to Explorer.exe

lần sau khi port bài nhớ nhìn rõ tên file CVIQ.EXE hay là SVIQ.EXE nhé

thân chào ! chúc bạn thành công và clear .... clear ...... nó ra khỏi
cái máy


Posted by =?Utf-8?B?eWFubmllbXg=?= on May 9, 2007, 11:06 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
so I removed the virus from the infected machine using the steps below and
some additional steps, here is what I did:

1.) you have to be quick on this step: in Task Manager end task on DC, FUN
and SVIQ...I used the End Process Tree

2.) look for the following files
(extension is usually EXE but not always)
fun
dc
sviq
repair
DataV
Other
win
winsit
cviq
They can be located in one or more of the following directories:
C:\windows\system
C:\windows\system32
C:\windows
C:\windows\inf
C:\windows\config
C:\windows\system32\config
C:\windows\system\config

3.) In regedit clean these keys:
HKEY_CURRENT_USER\Software\Microsoft\windows\current\version\run
HKEY_LOCAL_MACHINE\Software\Microsoft\windows\current\version\run
HKEY_LOCAL_MACHINE\software\microsoft\windows NT\currentVersion\winlogon
subkeys: Useinit --> set Useinit to Blank
Shell to Explorer.exe

HKEY_CURRENT_USER\software\microsoft\windowsNT\currentVersion\windows
delete subkeys: load=other.exe
run=win.exe

4.) run MSCONFIG and look to see if anything else is starting or loading
that looks weird and remove it...of course be careful because you can destroy
your system if you remove the wrong things
5.) reboot and make sure the virus is gone (it should be)


Posted by =?Utf-8?B?bGF5bWFu?= on May 10, 2007, 1:47 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
installing AVG as antivirus software solved my problem. If you have low RAM
(128 MB) then you may have to run a small .bat file to delete the dc.exe,
fun.exe and sviq.exe while you end them in the task manager. The AVG
freeware can also clean off your flash drive if it is infected too. Much
easier than deleting manually.

The registry list below worked too, but DO NOT set the userinit value to
blank. leave it alone. Otherwise you will not be allowed to log in to
windows and will have to use the recovery CD to get in again.

"yanniemx" wrote:

> so I removed the virus from the infected machine using the steps below and
> some additional steps, here is what I did:
>
> 1.) you have to be quick on this step: in Task Manager end task on DC, FUN
> and SVIQ...I used the End Process Tree
>
> 2.) look for the following files
> (extension is usually EXE but not always)
> fun
> dc
> sviq
> repair
> DataV
> Other
> win
> winsit
> cviq
> They can be located in one or more of the following directories:
> C:\windows\system
> C:\windows\system32
> C:\windows
> C:\windows\inf
> C:\windows\config
> C:\windows\system32\config
> C:\windows\system\config
>
> 3.) In regedit clean these keys:
> HKEY_CURRENT_USER\Software\Microsoft\windows\current\version\run
> HKEY_LOCAL_MACHINE\Software\Microsoft\windows\current\version\run
> HKEY_LOCAL_MACHINE\software\microsoft\windows NT\currentVersion\winlogon
> subkeys: Useinit --> set Useinit to Blank
> Shell to Explorer.exe
>
> HKEY_CURRENT_USER\software\microsoft\windowsNT\currentVersion\windows
> delete subkeys: load=other.exe
> run=win.exe
>
> 4.) run MSCONFIG and look to see if anything else is starting or loading
> that looks weird and remove it...of course be careful because you can destroy
> your system if you remove the wrong things
> 5.) reboot and make sure the virus is gone (it should be)
>

Similar ThreadsPosted
simulation virus spread, thesis information needed September 20, 2006, 1:16 am
antivirus for usb flash disk March 23, 2006, 2:05 pm
Virus in DOS Upper Memory? Win PE ? August 23, 2005, 2:34 am
I think I've found a virus.... September 7, 2007, 3:35 pm
virus found April 6, 2008, 5:34 pm
Flash Player security update is available; Security Bulletins released by Adobe July 10, 2007, 7:29 pm
Virus found: IRC/Backdoor.flood February 5, 2007, 7:10 pm
Found a virus undetected - any thoughts ? June 28, 2007, 8:08 am
avg found a virus called downloader.tibs October 4, 2006, 5:06 pm
The memory could not be read September 8, 2005, 2:02 am

The site map in XML format XML site map

Contact Us | Privacy Policy