This is a new stupid virus/trojan that will redirected all your traffic to google.com (209.85.225.99) infected my client on 01-01-2010, This virus was made using visual basic with size around 212-233KB. If active it has another supported files with random size.
How to know if you’re infected?
It’s very easy, if you browsing on internet or opening antivirus website then your page always redirected to google website that mean you’re infected by this virus.
Master Files
When this virus active it will created some master files and downloading some another supported files from internet. It will spreading files in different location to make it hard to cleaned. This virus also hiding as windows service and windows drivers.
This is a list of virus master files:
- %systemroot%\windows\system32
- wmispqd.exe
- Wmisrwt.exe
- qxzv85.exe
- qxzv47.exe
- secupdat.dat
- %systemroot%\Documents and Settings\%user%\%xx%.exe, Where xx is random character with size 6KB (example: rclxuio.exe).
- %systemroot%\windows\system32\drivers
- Kernelx86.sys
- xx%.sys, where xx is random character with size 40KB (example: cvxqkopsd.sys)
- Ndisvvan.sys
- krndrv32.sys
- %systemroot%\Documents and Settings\%user%\secupdat.dat
- %systemroot%\Windows\inf
- Netsf.inf
- Netsf_m.inf
Spreading Technique and Virus Affect
This virus will spreading in your network or using any removable disk using a autorun technique. If we look in the back mostly all virus using this same technique to spreading, Maybe a good option to modify your windows to disable autorun.
Virus will blocking some windows function like: System Restore, Windows Firewall, RPC DCOM, etc. Virus will also redirected mostly antivirus or security website into google.com using hosts file.
How to Remove W32/SmallTroj.VPCG
1. Deactivated “System Restore” when in cleaning progress.
2. Disconnected your computer from Network/LAN.
3. Rename msvbvm60.dll (%systemroot%\Windows\system32\msvbvm60.dll) to backup.dll This step to prevent virus active because this virus was made using visual basic, virus will need msvbvm60.dll to run, when you rename it virus can’t active. After you cleaned this virus I recommended you to rename backup.dll back to msvbvm60.dll.
4. Deleted virus master files using Mini PE2XT, Because some rootkit hidden as windows service and driver you need to boot your computers using Mini PE2XT then follow the step:
Menu -> Programs -> File Management -> Windows Explorer
Then deleted files “Virus Master Files” (check in this article).
5. Deleted registry made by virus using Mini PE2XT
Menu -> Programs -> Registry Tools -> Avast! Registry Tools
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\\ctfmon.exe
HKEY_LOCAL_MACHINE\system\ControlSet001\services\kernelx86
HKEY_LOCAL_MACHINE\system\CurrentControlSet\services\kernelx86
HKEY_LOCAL_MACHINE\system\CurrentControlSet\services\passthru
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ctfmon.exe
HKEY_LOCAL_MACHINE\system\ControlSet001\services\%xx%
HKEY_LOCAL_MACHINE\system\CurrentControlSet\services\%xx%
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List
* %windir%\system32\ wmispqd.exe = %system%\ wmispqd.exe:*:enabled:UpnP Firewall
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List
* %windir%\system32\ wmispqd.exe = %system%\ wmispqd.exe:*:enabled:UpnP Firewall
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
* %windir%\system32\ wmispqd.exe = %system%\ wmispqd.exe:*:enabled:UpnP Firewall
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon
* Change string value Userinit to = userinit.exe
ATTENTION: %xx% is random character, this key created to run .SYS with size 40KB.
6. Restart your computer then use this repair-inf (rename it to repair.inf) right click on it then choose install.
[Version]
Signature=”$Chicago$”
Provider=Nobody
[DefaultInstall]
AddReg=UnhookRegKey
DelReg=del
[UnhookRegKey]
HKLM, Software\CLASSES\batfile\shell\open\command,,,”"”%1″” %*”
HKLM, Software\CLASSES\comfile\shell\open\command,,,”"”%1″” %*”
HKLM, Software\CLASSES\exefile\shell\open\command,,,”"”%1″” %*”
HKLM, Software\CLASSES\piffile\shell\open\command,,,”"”%1″” %*”
HKLM, Software\CLASSES\regfile\shell\open\command,,,”regedit.exe “%1″”
HKLM, Software\CLASSES\scrfile\shell\open\command,,,”"”%1″” %*”
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0, “Explorer.exe”
HKLM, software\microsoft\ole, EnableDCOM,0, “Y”
HKLM, SOFTWARE\Microsoft\Security Center,AntiVirusDisableNotify,0×00010001,0
HKLM, SOFTWARE\Microsoft\Security Center,FirewallDisableNotify,0×00010001,0
HKLM, SOFTWARE\Microsoft\Security Center,AntiVirusOverride,0×00010001,0
HKLM, SOFTWARE\Microsoft\Security Center,FirewallOverride,0×00010001,0
HKLM, SYSTEM\ControlSet001\Control\Lsa, restrictanonymous, 0×00010001,0
HKLM, SYSTEM\ControlSet002\Control\Lsa, restrictanonymous, 0×00010001,0
HKLM, SYSTEM\CurrentControlSet\Control\Lsa, restrictanonymous, 0×00010001,0
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden, CheckedValue,0×00010001,0
[del]
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System,DisableRegistryTools
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System,DisableCMD
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,NoFolderOptions
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run,ctfmon.exe
HKLM, SYSTEM\ControlSet001\Services\kernelx86
HKLM, SYSTEM\ControlSet002\Services\kernelx86
HKLM, SYSTEM\CurrentControlSet\Services\kernelx86
HKLM, SYSTEM\CurrentControlSet\Services\mojbtjlt
HKLM, SYSTEM\ControlSet001\Services\mojbtjlt
HKLM, SYSTEM\ControlSet002\Services\mojbtjlt
HKLM, SYSTEM\ControlSet001\Services\Passthru
HKLM, SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore
HKLM, SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate, DoNotAllowXPSP2
HKLM, SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ctfmon.exe
7. Deleted all temporary internet files using ATF Cleaner.
8. Restore your hosts files using HostsXpert.
9. To make sure your system totally clean and to prevent virus from coming back please scan full your system using Norman Malware Cleaner, If you don’t like Norman I would recommended you to use AVIRA.
Good luck!
SIMILAR POST :
- 6 Step to: Remove Jengkol Virus
- Repair:Antivirus XP 2008, CNN fake message, get_flash_update.exe, Spam & Fake blue screen of death(BSOD)
- Stop Virus Stargate
- 8 Tools Kido/Conficker/Downadup Remover
- Remove GoldenGhost Virus W32/Agent.GYMR
- Bugil
- how to delete qxzv85 exe@
- www sandra dewi
- qxzv85 exe@ removal
- secupdat dat trojan
- qxzv85 exe@
- remove W32/SmallTroj VPCG
- W32/Smalltroj VPCG
- how to remove qxzv85 exe
- restrictanonymous banking website
- remove smalltroj
- w32 Smalltroj
- sitemap generator google 8181 cant how
- cryf file
- Photo bugil
- W32/ SmallTroj VPCG
- Foto bugil
- how to register msvbvm60 DLL in centos
- remove secupdat dat
- client for microsoft sharing passthru netsf inf
- smalltroj
- How to remove secupdat dat
- W32/Smalltroj
- W32/SmallTroj VPCG
- w32 smalltroj
- Spam/Misconf Mailer Internet Kiosk
- Take me out bugil
- bugil
- ndisvvan sys
- qxzv47 exe@ removal
- BUGIL
- kernelx86 sys virus
- w32 smalltroj removal
- W32/smalltroj VPCG
- photo bugil
- FOTO BUGIL
- remove qxzv85 exe@
- Sandra dewi bugil
- ndisvvan sys passthru
- how to remove kernelx86 sys
- virus netsf inf
- passthru service virus
- removal smalltroj
- how to remove client for microsoft sharing virus
- www sandra dewi com
- client for microsoft sharing microsoft uninstall
- antivirus SmallTroj VPCG
- kernelx86 remover
- client for microsoft sharing removal tool
- qxzv47 exe@
- trojan ndisvvan sys
- client for microsoft sharing removal
- Client for Microsoft Sharing
- how to remove qxzv47 exe
- kernelx86 sys removal
- remove kernelx86 sys
- client for microsoft sharing
- malware kernelx86 sys remover
- secupdat dat remove
- qxzv85 exe@ quitar
- w32/smalltroj
- secupdat dat virus how to remove
- client for microsoft sharing virus
- secupdat dat
- remove client for microsoft sharing virus
- delete restrictanonymous
- removing wmisrwt
- client for microsoft sharing cant remove help
- uninstall client for microsoft sharing
- malware Smalltroj VPCG
- virus foto bugil
- ms passthru virus remove
- how to remove client for microsoft sharing
- Virus W32/Smalltroj VPCG
- client for microsoft sharing desinstalar
- client for microsoft sharing quitar
- eleiminar qxzv85
- ndisvvan removal
- quitar client for microsoft sharing
- eliminar client for microsoft sharing
- vsjpcgyh sys
- antivirus W32/Smalltroj VPCG
- Qxzv85 exe@
- how to delete ndisvvan sys
- how to remove qxzv85 exe@
- how to remove qxzv85 exe@ manually
- client for microsoft sharing is virus
- spam/misconf mailer
- computer blogs
- eliminar qxzv85 exe@
- what is qxzv47 exe
- Foto Bugil
- uninstall client for microsoft sharing virus
- dewi porno
- desinstalar client for microsoft sharing
- how to remove secupdat dat
- get rid off client for microsoft sharing
- remover W32/SmallTroj VPCG
- secupdat dat removal tool
- ndisvvan sys netsf inf
- remove QXZV47
- internet security 2010 virus msvbvm60 dll
- virus client for microsoft sharing
- client for microsoft sharing вирус
- ndisvvan sys disabled lan
- client for microsoft sharing msn
- client for microsoft sharing remove
- get rid of Client For Microsoft Sharing
- borrar client for microsoft sharing
- вирус wmisrwt exe
- ndisvvan sys client for microsoft sharing
- foto bugil
- client for microsoft sharing virus remove
- secupdat dat eliminar
- netsf inf virus
- remove client for microsoft sharing
- eliminar secupdat dat
- windows 2000 system files qxzv85 exe
- client for microsoft sharing service
- wmisrwt
- secupdat exe
- qxzv85@ exe
- trojan client for microsoft sharing
- what is qxzv85 exe
- eliminar Client for Microsoft Sharing
- client for microsfot sharing
- Spam/Misconf Mailer
- فيروس qxzv47 exe
- how to remove foto bugil virus
- HKEY_LOCAL_MACHINESystemCurrentControlSetServicesPassthru ndisvvan sys
- client for microsoft sharing remove tools
- cannot uninstall client for microsoft sharing
- qxzv85 exe removable tools
- netsf inf remover
- remove W32/Smalltroj VPCG
- fake client for microsoft sharing
- eliminar dcom
- Anti W32/SmallTroj VPCG
- qxzv47 exe removal
- qxzv47 exe
- could not uninstall client for Microsoft Sharing
- remove ndisvvan sys
- how to uninstall client for microsoft sharing
- qxzv85 exe
- eliminar DCOM
- client for microsoft sharing uninstall
- secupdat dat removal fix
- kernelx86 sys file size
- remove SECUPDAT dat
- could not unistall the client for microsoft sharing component
- remove VBS/Cryf A
- how to remove virus W32/SmallTroj VPCG
- qxzv85 exe removal
- ndisvvan
- remover virus W32/SmallTroj VPCG
- small troj vpcg
- virus client for microsofts sharing
- Client For Microsoft Sharing
- repair Client For Microsoft Sharing
- ndisvvan sys blue screen
- secupdat dat trojan removal free
- virus Client for Microsoft sharing
- Smalltroj VPCG
- client for microsoft sharing malware
- como Eliminar Client for Microsoft Sharing
- windows blue screen ndisvvan sys
- secupdat dat tool
- could not uninstall the client for microsoft sharing
- blue screen ndisvvan sys
- qxzv85 exe remover
- how to remove W32/SmallTroj
- файл qxzv85 exe@
- client for microsoft sharing virus removal
- virus removal tool for client for microsoft sharing
- secupdat dat virus removal tools
- msvbvm60 dll was not found virus blocking taskmanager
- secupdat dat virus
- 209 85 225 99 virus ie
- kernelx86 sys infected
- virus qxzv85 exe@
- secupdat dat virus removal tool
- no se puede eliminar secupdat dat
- removetools for client for microsoft sharing
- ndisvvan sys bsod
- quitar virus secupdat searchqu
- cara hapus ndisvvan sys remover
- como eliminar secupdat dat
- NDISVVAN SYS virus
- how to uninstall client for microsoft sharing virus
- ndisvvan sys restarting computer
- fix secupdat
- remove w32/smalltroj vpcg
- remove ndisvvan sys manually
- ndisvvan sys netsf_m inf
- virus msvbvm60 taskmanager
- QXZV85 EXE@
- borrar secupdat dat
- secupdat
- how to remove searchqu com
- kernelx86 sys
- netsf inf
- restrictanonymous conficker
- ndisvvan free removal tool
- kernelx86 sys remove tool
- netsf_m inf fix
- wirus client for microsoft sharing
- remove searchqu com
- 1h
- w32 smalltroj vpcg
- W32/Smalltroj IIUH
- client for microsoft sharing new client in my local area connection properties
- qxzv85 exe remove
- how to remove virus secupdat dat
- W32/SmallTroj
- open antivirus website always redirect to search engine
- ndisvvan trojan
- remover client for microsoft sharing
- virus infection client for microsoft sharing installed
- kernelx86 sys reinstalar
- remove searchqu
- searchqu malware
- searchqu removal tool
- is searchqu a virus
- ndisvvan sys remove
- client for microsoft sharing como desinstalar
- delete client for microsoft sharing
- Mini PE2XT
- how to remove the client for microsoft sharing virus
- como eliminar searchqu com
- how to remove ndisvvan
- como dat virus
- Could not uninstall Client for Microsoft Sharing
- como eliminar client for microsoft sharing
- searchqu com virus ?
- client for microsoft sharing fix
- client for microsoft sharing cannot uninstall
- Client for microsoft sharing вирус
- gambar bugil sandra dewi
- remove W32/ SmallTroj VPCG tools
- searchqu com spyware
- como eliminar client services
- pe2-xt
- searchqu
- smalltroj vpcg
- remover searchqu
- ndisvvan sys avast
- client for microsoft sharing kernelx86 sys
- qxzv85 exe seen at system32
- como remover searchqu
- como eliminar searchqu
- How to uninstall Searchqu
- searchqu remove
- computing and internet category
- quitar searchqu
- how to uninstal client for microsoft sharing
- http://www istanto net/remove-w32smalltroj-vpcg html
- manual removal secupdat dat
- virus w32/smalltroj remover
- qxzv85 exe antivirüsü
- how to remove w32/smalltroj
- como dat virus removal
- ServicesPassthru
- fix ndisvvan sys
- client for microsoft sharing eliminar
- how can I get rid of searchqu
- client for microsoft sharing grayed
- redirected to searchqu
- how to remove secupdat
- cannot delete file secupdat dat
- searchqu removal
- uninstall Searchqu com
- searchqu virus
- delete searchqu
- howto remove searchqu
- 0h
- desinstalar searchqu
- uninstall searchqu
- searchqu com malware?
- How to Remove Secupdat dat
- network card cannot be uninstalled needed to boot virus ndisvvan sys
- kernelx86 sys | E31A5EC3B52A3EBC9E86E9C8D58F8F78
- fix qxzv85 exe error
- netsf_m inf
- searchqu quitar
- eliminar searchqu
- virus w32 smalltroj
- searchqu remover
- removal searchqu
- remove www searchqu com
- remove secupdat
- searchqu internet explorer
- how do I remove searchqu?
- ndisvvan sys virus
- how to remove ndisvvan sys
- cannot access http://<this-server-address>:8181/ google site map ubuntu
- repair kernelx86 sys
- virus size
- Client for microsoft sharing trojan
- how remove client for microsoft sharing
- client for microsoft sharing windows xp
- virus win32 bule screen
- ndisvvan sys disable network
- netsf inf netsf_m inf ndisvvan sys
- ndisvvan virus
- Client for microsoft sharing remove
- ndisvvan sys removal
- cara menghapus trojan W32/Smalltroj
- how to delete secupdat dat
- ndisvvan sys bluescreen
- virus secupdat dat
- ndisvvan sys no internet
- Uninstall Client for microsoft sharing
- ndisvvan sys fix
- removal ndisvvan
- secupdat dat ndisvvan sys
- TRICK menghapus trojan
- ndisvvan repair
- désinstaller searchqu
- searchqu com remove
- client for microsoft sharing win xp uninstal
- bsod ndisvvan sys
- how to remove searchqu
- worm qxzv85 exe@
- removing ndisvvan sys
- why is my home page searchqu
- remove ndisvvan
- VIRUS FAKE client for microsoft sharing
- searchqu delete
- how do i remove searchqu
- removing searchqu
- what is searchqu
- eliminar virus en system32 qxzv85 exe
- blue screen error ndisvvan sys
- ndisvvan sys blue screen xp
- cara delete file secupdat dat
- limpiar virus qxzv85
- client for microsoft sharing avira
- ndisvvan sys removal tool
- cara delete secupdat dat
- secupdat eliminar
- netsf inf ndisvvan sys
- nadia bugil
- 0
- como faço para desinstalar a home page searchqu com?
- remove ndisvvan sys network cannot
- kernelx86 sys virus removal
- searchqu uninstall
- Could not unistall the Client for Microsoft shering component is it virus?
- searchqu remoçao
- como quitar client for microsoft sharing
- what is www searchqu com
- como eliminar windows firewall
- como quitar el client for microsoft sharing
- secupdat dat remover
- could not uninstall client for microsoft sharing
- searchqu com remover
- searchqu com uninstall
- como retirar searchqu
- what is searchqu com?
- rootkit ndisvvan sys removal
- remove searchqu ?
- i dont wantto use searchqu as server
- uninstall Client for Microsoft Sharing
- client for Microsoft sharing virus
- whats made secupdat dat
- searchqu com how to delete
- desintalar searchqu
- desintalar cliente for microsoft sharing
- how to remove a mailer virus
- desinstaller searchqu
- www searchqu com vius
- How to Remove searchqu
- tool fix secupdat
- searchqu com removal
- eliminar searchqu com
- clean virus W32/SmallTroj VPCG
- como desinstalar searchqu com
- CLIENT FOR MICROSOFT SHARING
- how to get rid of searchqu
- searchqu com
- how to get rid of searchqu com
- remove client for microsoft sharing kernelx86 sys
- secupdat dat manual removal
- delete secupdat dat
- whats searchqu
- removing secupdat dat file
- manually remove secupdat dat
- how do I permanently remove searchqu com
- searchqu desinstalar
- smalltroj keeps coming back
- www searchqu com remove
- ndisvvan sys client for microsoft
- how to blue screen client on network
- removing secupedat
- How do i remove searchqu
- w32smalltroj
If you're new here, you may want to subscribe to my RSS feed. You may copy or publish this article to your blog or other site as long you give credit link back to this site article. Thanks for visiting my blog!







Did you know?


January 12th, 2010 at 12:12 AM
[...] Remove W32/SmallTroj.VPCG » Istanto Blogs [...]
January 22nd, 2010 at 1:37 PM
[...] Remove W32/SmallTroj.VPCG » Istanto Blogs [...]