The Malware was send by email. A message from DHL (package courier) says that you get a package and asks you to click a link, that’s how the malware being installed.
This is the symptoms:
- XP Internet Security 2011 window, ask you to click for scanning and remove the viruses detected.
- You can’t open any file, each time you click, that malware window comes. It disabled your Antivirus. If you click and click, sometimes the file/program run after the malware’s window. You can’t close the malware’s window by clicking the cross sign in the top-right corner. So, let it be and do the work in multi windows.
- You can’t go to internet. If you click the browser, it shows a warning if your computer is infected etc.
Solution:
- Try to run Hijackthis, and locate the virus. You might not able to ask for analyzing to www.hijackthis.de since you might not able to go to internet. You have to be careful here. I found the virus : %user profile%\Local Settings\Application Data\sbp.exe
- Use Unlocker to delete it. It deletes only with re-boot. I couldn’t find the process in Task Manager.
- After delete that virus, you might be frustrated since you can’t run any program. Seems the virus have changed the registry for running .exe; Everytime you click an .exe, a dialog box comes asking what application to open. So, we have to repair the registry:
- Use Regedit through DOS command. You can’t use directly Start -> Run -> Regedit as ussual.
- • Click Start, Run and type Command
• Type the following commands :
cd\windows (click “Enter”)
regedit (click “Enter”)
• If Registry Editor opens successfully, then navigate to the following key:
HKEY_CLASSES_ROOT \ exefile \ shell \ open \ command
• Double-click the (Default) value in the right pane
• Delete the current value data, and then type:
“%1″ %*
(quote-percent-one-quote-space-percent-asterisk.)
• Navigate to:
HKEY_CLASSES_ROOT\.exe
• In the right-pane, set (default) to exefile
• Exit the Registry Editor. - After step 5, you will be able to run Malwarebyte. Let it clean up the rest.
- Finally, use CCleaner to clean the temporary files and registries.
Posted by augustassps