Hello everyone sorry for late update this blog, I have been really very busy analyze forex market and grown my another business, busy IRL also… :D

Now my story…….

Last week my cousins tell me in his office he got strange virus. He said there is lot shortcut in desktop an computers running slow. How actually some newbie out there know exactly which one real programs/folders and which one shortcut? Don’t say you’re not noob! almost many people not take to much attention on this simple different, that’s why with simple social technique virus maker can win beating yourself! :P

LOOOOOOOOOOOOKKKKKKKK!!!!!!

shortcut

To know when your computer infected by this virus there is 4 important point:

  1. In your “My Documents” folder there is file named “database.mdb“.
  2. There is clone folder with extension .lnk maximum 5 first folder arranged by name, rules until second sub folders.
  3. There is files Autorun.inf, Thumb.db, Microsoft.lnk in each root drive and folders, rules until second sub folders. (You might not see them because it’s set hidden)
  4. Your Registry Editor is disabled.

This virus master actually in “My Document” folder named “database.mdb” Wait… you will know why this is called as virus master. Actually virus will created clone for folder using “wscript.exe” execution. wscript.exe is microsoft windows based script host programs.

Virus will change your registry:

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
“Explorer”=”Wscript.exe //e:VBScript \”C:\Documents and Settings\Administrator\My Documents\database.mdb\””

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
“WinUpdate”=”Wscript.exe /e:VBScript \”C:\WINDOWS\:Microsoft Office Update for Windows XP.sys\””

I think you all know how this registry changed will affect on your computer each time it reboot no need to explain this right? Really simple social technique.

Now time for how to clean this virus manually:

1. Disabled “System Restore” in cleaning process.

2. Kill wscript.exe process from your computer background programs.

3. In cleaning process you have to rename file wscript.exe to any name  ex:blabla (temporary only in cleaning process) and don’t forget to rename it back again to wscript.exe once your computer clean.

4. Deleted file “database.mdb” from “My Documents” folder.

5. Disabled any startup process which has link with “database.mdb” you can use msconfig or hijackthis.

6. Delete file autorun.inf, microsoft.inf and thumb.db use command prompt and type “del Microsoft.inf /s” (should in root drive to deleted in all in drive) for autorun.inf  and thumb.db since this file set with attrib RSHA type “del autorun.inf /s /ah /f” (should in root drive to deleted in all in drive, change autorun.inf with thumb.db to deleted all thumb.db)

7. deleted all .lnk files with size 1kb, you can use advanced search function. Carefully when you want to deleted look on this sample:

lnk

Deleted only shortcut with size 1kb and using folder icon, this is social  virus spreading technique that mostly tricky newbie out there.

7. Repair your registry using repair.inf

[Version]
Signature=”$Chicago$”
Provider=Nobody

[DefaultInstall]
AddReg=UnhookRegKey
DelReg=del

[UnhookRegKey]
HKLM, Software\CLASSES\batfile\shell\open\command,,,”””%1″” %*”
HKLM, Software\CLASSES\comfile\shell\open\command,,,”””%1″” %*”
HKLM, Software\CLASSES\exefile\shell\open\command,,,”””%1″” %*”
HKLM, Software\CLASSES\piffile\shell\open\command,,,”””%1″” %*”
HKLM, Software\CLASSES\regfile\shell\open\command,,,”regedit.exe “%1″”
HKLM, Software\CLASSES\scrfile\shell\open\command,,,”””%1″” %*”
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0, “Explorer.exe”
HKLM, SYSTEM\ControlSet001\Control\SafeBoot, AlternateShell,0, “cmd.exe”
HKLM, SYSTEM\ControlSet002\Control\SafeBoot, AlternateShell,0, “cmd.exe”

[del]
HKLM,SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Winupdate
HKCU,SOFTWARE\Microsoft\Windows\CurrentVersion\Run, explorer

8. Scan with your best antivirus program to make sure your system clean and restarted your computer. Now see if this virus coming back or not :)

Good luck :)

Similar Posts:

    Digg Del.icio.us StumbleUpon Reddit Twitter RSS

how to remove lnk virus, lnk virus, kill4shortcutvirus exe, BackDoor-EZC!lnk, lnk virus removal, SHORTCUT VIRUS, worm:win32/dorkbot!lnk, LNK file (ink) virus, dorkbot!ink, dorkbot lnk, e518892 exe, remove lnk virus, lnk virus remover, virus lnk remover, shortcut to skype lnk, fix shortcut virus, 894133bf exe, backdoor-ezc!ink, copy of shortcut to (1), lnk a, deal runner virus, how to delete lnk virus, ink virus, virus that creates shortcuts, win32/dorkbot!ink, backdoor-ezc lnk, ink virus removal, lnk virus fix, ink virus remover, loading script c:\windows\:microsoft office update for windows xp sys failed, folder ink removal, recycler\e518892 exe, virus lnk removal, virus ink remover, virus lnk, thumbs lnk, virus create shortcut, dcim ink, Dorkbot!lnk, download kill4shortcutvirus exe, bcd8f464 exe, worm:win32/dorkbot!ink, remove ink virus, cara menghilangkan virus vbscript encoded script file, cara hilang kan virus amburadul, cmd restore ink folders, 8585485\dcim exe, adt45 lnk, backdoor ezc lnk, maslah lnk file, inkfix_xp, dorkbot ink, shortcut cleaner virus, win32/dorkbot d worm, virus that creates shortcut, How to Clean Shortcut Virus, how to fix lnk virus, how to clean lnk virus, hapus virus shortcut, how to cure shortcut lnk, how to remove virus lnk, lnk virüsü, lnk runner removal, membasmi virus shortcut, cara membersihkan memori yang terkena virus, cara hapus virus shortcut, virus copy shortcut link remover, systemfix ink, virus shortcut, virus ink removal, all short cuts turn into internet explorer lnk, File extension LNK LNK, desktop shortcut virus, download software untuk menghapus virus wscript exe-corrupt file, error loading setup50039 fon, e5188982 exe, msdtadmin, remover virus systemfix ink, repair shorcuts created by virus, remove 8585485, my document turns to shortcut on flash scr virus, shortcut virus cleaner, microsoft office update for windows xp sys failed, multiple shortcuts virus, shorcut link virus, shortcut virus remover, virus shortcut cleaner, virus dorkbot!ink, virus create lnk, virus 894133bf exe, virus shortcut remover, virus ms word shotcut, vdbuf exe, virus creates shortcuts, loading script c:\windows\:microsoft office update, lnk virus fix microsoft, mengembalikan shortcut, mengatasi virus lnk, folders turn shortcut virus, how to remove dorkbot b, format doc berubah jadi microsoft word document ( vbe), how to remove the ink virus, how to clean lnk/dorkbot off of thumbdrive, how to clean ink virus, huoodx exe, folders changed to lnk, how to fix file word change vbscript encoded, how to fix shortcut virus, how to remove ink virus, cara mengatasi the directory or file cannot be created, cara membuang virus shortcut, cara mengembalikan file word yang berubah menjadi vbscript encoded script file, cannot find script file database mdb, cara menghapus VBscript Encoded Script file, cara membuka file vbscript, cara hapus dorkbot b, file doc jadi vbs, DCIM lnk, dorkbot b removal, virus that changes exe files to type ah, what is shortcut virus, windows 7 inf hidden worms, zuoopix virus, آنتی ویروس dorkbot d, atasi word berubah vbscrift, anti adt45 ink, backdoor-ezc lnk removal tool, "mengembalikan file"+"win32/Dorkbot D"+"worm", BackDoor-EZC!lnk removal tool, a variant of win32/dorkbot b worm, ویروس lnk, basmi virus shortcut e5188982 exe, a virus change word document to short 1 kb, adakah virus vbscript encode script file, วิธีแก้ worm win32/dorkbot!ink, ظهور WINDOWS CANNOT FIND RECYCLER \E5188982 exe, فيروس shortcut lnk\, فيروس اختصار المجلدات, BackDoor-EZC!nk, backdoor-ezc lnk removal, bagaimana cara membuka file yang terkena virus g:recycler\e5188982 exe, buka file kena shortcut, backdoor-ezc!lnk remove, antivirus untuk menghilangkan virus Ms-Dos program, فيروس ink, วิธีแก้ไวรัสwin32 dorkbot b, Bagaimana cara mengatasi notebook yang problem windows program 32 nya, แก้ the file or folderjeune scrthat this shortcut to cant be found, 8585485 virus on windows 7, 8585485 virus removal, antivirus untuk win32/dorkbot d worm, backdoor ezc!lnk, 8585485virus, aplikasi pembunag pif virus, bcd8f464 exe آنتی ویروس, antivirus menghapus vbscript encoded script file, ฆ่าไวรัส backdoor-ezc!lnk, backdoor ezc!ink, * ink remover, 8585485 virus how to remove in windows 7, how to repair file from dorkbot, how to repair shortcut virus, how to kill lnk viruses, how can i get rid of variant win32/dorkbotb, how to treat shortcut virus, how stop discovering shortcut ( lnk) virus in network, hapus virus ink, hapus virus adt45, hapus manual virus folder exe, how to kill lnk, how unhide file attribute after win32/dorkbot remove xp, how to copy recycler\e5188982 exe, how to delete virus lnk, how to remove shortcut virus, how to delete virus lnk:runner, how to disable virus shorcut folder, how to recover folders win32/dorkbot d worm, how to clean virus folder shortcut, how to get rid of dorkbot ink, how to kill ink virus, how manual remove virus backdoor ezc lnk, folder to lnk virus, Ink files in memory card, ink virüsü, iiiiii Ink, folder to shortcut virus, folder shortcut virus remover, folders became shortcuts virus prevent, inf hidden worms, virus make shortcut, virus disabling shortcuts, type file lnk file, virus change doc file to Vbscript encode file, virus microsoft shortcuts replaced by word, virus lnk runner, virus folder to lnk, virus recycler folder e5188982, usb bi loi recycler\e5188982 exe, virus makes hidden folders ink, virus shortcut ie

If you're new here, you may want to subscribe to my RSS feed. You may copy or publish this article to your blog or other site as long you give credit link back to this site article. Thanks for visiting my blog!