Havent been feeling v.well lately.Think someone spread me the flu bug.Its not so jia lat of course,but i doubt i can do any streneous activity.Its a off on kind of situation,i could be feeling ok in the afternoon,but when i wake up or b4 i go to sleep in the night,i feel terrible...Oh well,deserve it for sharing ice cream with a sick person.Kay Kiang ar Ton just send me a virus on this week and i of all people was dumb enough to open it.Too trusty la,me..ARGH!at least have a courtesy to pass down a message or something.Well,i could be an asshole and keep this antidote to myself,and let everyone reformat their com.Yet again,God will punish me for my bad deedsSo here goes,.This virus/trojan is a MSN malware virus and it’s taken me two days to clear the bloody thing off my system.If you accept it, it writes to your registry (registering a COM object) and places files in your /system/folder. It’s a pig to remove.You’ll know you have it because it launches MSN and sends the virus to all your online contacts - great way to make yourself popular.Stupid virus writters!,dun you have better things to do?! This is how i solve it..
Firstly it’s worth noting that Mcafee won’t find it, and from what I can tell neither will AVG. In fact the only AV vendor (at time of rant) that knows about it is Sophos and they have reported on their side.So viruscan and any sort of virus removing tool is out of the picture. The easiest way that I can find to remove the virus is to do it yourself: 1. Get Hijackthis from: http://www.trendsecure.com/portal/en-US/threat_analytics/hijackthis.php. 2. Run it and check the results, you’ll see: O21 - *blah blah blah blah class stuff* followed by “sysprinters.dll/subject to the filename. (file missing) This is the registry entry with pointing to the offending file.When you accept or click the following file,myphoto2007.zip,it creates random files,so it might not be the file stated,but its close..Check this in Hijackthis and click “Fix Checked” - accept the message. 3. Reboot and remove the following files: c:\documents and settings\*your id*\new.txt c:\windows\myalbum2007.zip c:\windows\sysprinters.dll c:\install - with a couple of files in there including credits.bat 4. Done! Now go and apologise to all your friends… Obviously finish with another check on Hijackthis and run a full AV scan. Will be meeting Rachelle for the last time before she goes for shanghai.Haha,eat again?! |