<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>bugs of a debugger &#187; Security</title>
	<atom:link href="http://arunmvishnu.com/category/security/feed" rel="self" type="application/rss+xml" />
	<link>http://arunmvishnu.com</link>
	<description>itz all about me, my works, my views, my feelings …. all my bla bla blas</description>
	<lastBuildDate>Sat, 26 Nov 2011 17:15:38 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Is the Official Web site of the Department of General Education , Kerala Hacked?</title>
		<link>http://arunmvishnu.com/security/is-the-official-web-site-of-the-department-of-general-education-kerala-hacked.html</link>
		<comments>http://arunmvishnu.com/security/is-the-official-web-site-of-the-department-of-general-education-kerala-hacked.html#comments</comments>
		<pubDate>Sat, 06 Dec 2008 13:41:00 +0000</pubDate>
		<dc:creator>Arun Vishnu</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://arunvishnuflip.wordpress.com/2008/12/06/is-the-official-web-site-of-the-department-of-general-education-kerala-hacked/</guid>
		<description><![CDATA[It seems like the official web site of the Department of General Education , Government of Kerala is hacked. Today i was checking the website and noticed a news &#8220;Hacked by the. Mo3tafa , Sha2ow&#8221; in the hot news box. The news content is just &#8220;tHe.Mo3tafA Was Here !!! Your Box 0wn3d By Deface Team We Love Iran Ashiyane Digital Security Team Special Thanks to Ashiyane Defacers &#38; Programmers Team www.ashiyane.org/forums I Don&#8217;t Know Any [...]]]></description>
			<content:encoded><![CDATA[<p><a class="highslide img_3" href="http://2.bp.blogspot.com/_Bh7NdB3FYMA/STqDIhF3acI/AAAAAAAAD8E/8vWxZAtXvdA/s1600-h/2.jpg" onclick="return hs.expand(this)"><img style="display:block;text-align:center;cursor:hand;width:320px;height:206px;margin:0 auto 10px;" src="http://2.bp.blogspot.com/_Bh7NdB3FYMA/STqDIhF3acI/AAAAAAAAD8E/8vWxZAtXvdA/s320/2.jpg" border="0" alt="" /></a><br />
<a class="highslide img_4" href="http://1.bp.blogspot.com/_Bh7NdB3FYMA/STqC7pG-EgI/AAAAAAAAD78/ZajqWs5le6I/s1600-h/Capture.JPG" onclick="return hs.expand(this)"><img style="display:block;text-align:center;cursor:hand;width:320px;height:198px;margin:0 auto 10px;" src="http://1.bp.blogspot.com/_Bh7NdB3FYMA/STqC7pG-EgI/AAAAAAAAD78/ZajqWs5le6I/s320/Capture.JPG" border="0" alt="" /></a></p>
<p>It seems like the official web site of the Department of General Education , Government of Kerala is hacked. Today i was checking the website and noticed a news &#8220;Hacked by the. Mo3tafa , Sha2ow&#8221; in the hot news box. The news content is just <span class="Apple-style-span" style="color:rgb(255,0,0);">&#8220;</span><span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:78%;"><span class="Apple-style-span" style="color:rgb(255,0,0);">tHe.Mo3tafA Was Here !!!  Your Box 0wn3d By  Deface Team We Love Iran Ashiyane Digital Security Team Special Thanks to Ashiyane Defacers &amp; Programmers Team www.ashiyane.org/forums I Don&#8217;t Know Any Rival For Muslims&#8221;.</span></span></p>
<p>Home page of the Department of General Education: http://www.education.kerala.gov.in/</p>
<p>Posted news: http://www.education.kerala.gov.in/admin/news_details.php?id=39</p>
]]></content:encoded>
			<wfw:commentRss>http://arunmvishnu.com/security/is-the-official-web-site-of-the-department-of-general-education-kerala-hacked.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Removing Funny ust scandal virus</title>
		<link>http://arunmvishnu.com/security/removing-funny-ust-scandal-virus.html</link>
		<comments>http://arunmvishnu.com/security/removing-funny-ust-scandal-virus.html#comments</comments>
		<pubDate>Tue, 06 May 2008 03:25:00 +0000</pubDate>
		<dc:creator>Arun Vishnu</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[worm]]></category>
		<category><![CDATA[yahoo]]></category>

		<guid isPermaLink="false">http://arunvishnuflip.wordpress.com/2008/05/06/removing-funny-ust-scandal-virus/</guid>
		<description><![CDATA[This virus is affected to your yahoo messenger and it will change your status to something like Funny ust scandal .. It also send the virus file through your yahoo messenger. Try the following steps to remove that virus. Boot the system in safe mode Open command promt(Type &#8220;cmd&#8221; in Start-&#62;Run without quotes) Type the following 3 commands taskkill /f /im smss.exe taskkill /f /im killer.exe taskkill /f /im smss.exe Now we want to delete [...]]]></description>
			<content:encoded><![CDATA[<p>This virus is affected to your yahoo messenger and it will change your status to something like Funny ust scandal .. It also send the virus file through your yahoo messenger. Try the following steps to remove that virus.
</p>
<ol>
<li>Boot the system in safe mode</li>
<li>Open command promt(Type &#8220;cmd&#8221; in Start-&gt;Run without quotes)</li>
<li>Type the following 3 commands
<ol>
<li>taskkill /f /im smss.exe</li>
<li>taskkill /f /im killer.exe</li>
<li>taskkill /f /im smss.exe</li>
</ol>
</li>
<li>Now we want to delete the virus files. For that execute the following commands
<ol>
<li>del /a:h /f  c:\autorun.inf</li>
<li>del /a:h /f  c:\smss.exe</li>
<li>del /a:h /f  c:\funny ust scandal.avi.exe</li>
</ol>
</li>
<blockquote>
<p>Repeate the above 3 commands for all the drive(&#8216;d&#8217;,'e&#8217;,'f&#8217;) except CD/DVD drive. Do the same by connecting your flash drive. The virus may b there..</p>
<p>Eg:- if u have D drive then replace &#8216;c&#8217; of &#8220;c:\autorun.inf&#8221; as &#8220;d:\autorun.inf&#8221;</p>
</blockquote>
<ol>
<li>del /a:h /f  c:\windows\killer.exe</li>
<li>del /a:h /f  c:\windows\autorun.inf</li>
<li>del /a:h /f  c:\windows\smss.exe</li>
<li>del /a:h /f  c:\windows\funny ust scandal.exe</li>
<li>del /a:h /f  &#8220;%userprofile%\Start Menu\Programs\Startup\lsass.exe&#8221;</li>
</ol>
<li>Goto Start -&gt; Run and<br />
type &#8220;regedit&#8221; without quotes then search and delete the registry entries</p>
<ol>
<li>smss.exe</li>
<li>lsass.exe</li>
<li>killer.exe</li>
<li>Scandal.avi.exe</li>
</ol>
</li>
<li>Restart your system in normal mode</li>
</ol>
<p>The above steps are bit difficult. I will create a tool for removing the virus when i get time. Now bit bussy @ office. Hope this will help you <img src='http://arunmvishnu.com/home/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://arunmvishnu.com/security/removing-funny-ust-scandal-virus.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Show Hidden Files and Folders</title>
		<link>http://arunmvishnu.com/tips-tricks/show-hidden-files-and-folders.html</link>
		<comments>http://arunmvishnu.com/tips-tricks/show-hidden-files-and-folders.html#comments</comments>
		<pubDate>Sat, 18 Aug 2007 22:29:00 +0000</pubDate>
		<dc:creator>Arun Vishnu</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://arunvishnuflip.wordpress.com/2007/08/18/show-hidden-files-and-folders/</guid>
		<description><![CDATA[Some windows users, who are infected by some worms may have problem in viewing the hidden files and folders. If you have any problem to enabling &#8220;Show hidden files and folders&#8221; in windows explorer then download and run this file . PS: Press &#8220;yes &#8221; if you get any warning.]]></description>
			<content:encoded><![CDATA[<p>Some windows users, who are infected by some worms may have problem in viewing the hidden files and folders. If you have any problem to enabling &#8220;Show hidden files and folders&#8221; in windows explorer then <a href="http://arunmvishnuf.googlepages.com/ShowHdnFlsFldrs.reg">download and run this file</a> .</p>
<p>PS: Press &#8220;yes &#8221; if you get any warning.</p>
]]></content:encoded>
			<wfw:commentRss>http://arunmvishnu.com/tips-tricks/show-hidden-files-and-folders.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Removing the SpyLocked Spyware</title>
		<link>http://arunmvishnu.com/tips-tricks/removing-the-spylocked-spyware.html</link>
		<comments>http://arunmvishnu.com/tips-tricks/removing-the-spylocked-spyware.html#comments</comments>
		<pubDate>Mon, 06 Aug 2007 12:08:00 +0000</pubDate>
		<dc:creator>Arun Vishnu</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://arunvishnuflip.wordpress.com/2007/08/06/removing-the-spylocked-spyware/</guid>
		<description><![CDATA[SpyLocked 4.3 is a fake but dangerous anti-spyware application, that is installed on your computer without your permission using Trojan and other malwares. When infected with the SpyLocked 4.3 software you will also see fake taskbar alerts stating that you have running spyware applications on your computer. SpyLocked 4.3 also displays a fake warning alert with flashing icon on your system tray. A Pop up balloon warning messages claiming that your PC is infected. For [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-family:verdana;font-size:100%;"><br />
<a class="highslide img_7" href="http://bp0.blogger.com/_Bh7NdB3FYMA/RrdiDgtZdKI/AAAAAAAABSg/mY_U2P_6o84/s1600-h/spyloc.jpg" onclick="return hs.expand(this)"><img style="float:left;cursor:pointer;margin:0 10px 10px 0;" src="http://bp0.blogger.com/_Bh7NdB3FYMA/RrdiDgtZdKI/AAAAAAAABSg/mY_U2P_6o84/s320/spyloc.jpg" alt="" border="0" /></a><br />
</span><span style="font-family:Verdana;font-size:100%;">SpyLocked 4.3 is a fake but dangerous anti-spyware application, that is installed on your computer without your permission using Trojan and other malwares. </span><span style="font-family:Verdana;font-size:100%;"><br />
When infected with the SpyLocked 4.3 software you will also see fake taskbar alerts stating that you have running spyware applications on your computer. SpyLocked 4.3 also displays a fa</span><span style="font-family:Verdana;font-size:100%;">ke warning alert with flashing icon on your system tray. A Pop up balloon warning messages claiming that your PC is infected. For example : &#8220;Critical System Error&#8221;, &#8220;Your computer is infected&#8221;, &#8220;System Alert&#8221;, &#8220;Security Alert&#8221;, Trojan-Spy.win32@mx&#8221;, &#8220;Virus Alert&#8221;, &#8220;Security Alert&#8221; or &#8220;Spyware.Cyberlog-X&#8221;.</span><span style="font-family:verdana;font-size:100%;"></p>
<p></span></p>
<p><span style="font-family:Verdana;font-size:100%;">If your computer is infected by SpyLocked and hijacked by the unfamiliar        webpage or securityiepage.com , then your computer in trouble because it        does</span><span style="font-family:verdana;font-size:100%;"><a class="highslide img_8" href="http://bp1.blogger.com/_Bh7NdB3FYMA/RrdiLwtZdLI/AAAAAAAABSo/swpVQcQ89Uc/s1600-h/spylocked_alert.jpg" onclick="return hs.expand(this)"><img style="float:right;cursor:pointer;margin:0 0 10px 10px;" src="http://bp1.blogger.com/_Bh7NdB3FYMA/RrdiLwtZdLI/AAAAAAAABSo/swpVQcQ89Uc/s320/spylocked_alert.jpg" alt="" border="0" /></a></span><span style="font-family:Verdana;font-size:100%;"> transfer back and forth information from the infected computer which        makes it a potential for application/data theft.</p>
<p><span style="font-weight:bold;font-style:italic;"></p>
<p>Symptoms</p>
<p></span></span>
<ul style="font-family:verdana;">
<li><span style="font-size:100%;">Pop up balloon warning messages claiming that          your PC is infected. SpyLocked&#8217;s Examples are:</p>
<p>&#8220;<b>Critical System Error</b>&#8220;,<br />
&#8220;<b>Your computer is infected</b>&#8220;,<br />
<b>&#8220;Trojan-Spy.win32@mx&#8221;,<br />
&#8220;Virus Alert&#8221;,<br />
&#8220;Security Alert&#8221;<br />
&#8220;System Alert&#8221;<br />
&#8220;Warning! Spyware Threat!&#8221; or<br />
&#8220;Spyware.Cyberlog-X&#8221;</b>          infections..<br />
</span></li>
<li><span style="font-size:100%;">Hijacked homepage to unfamiliar webpage or <b>         Onlinestability.com</b>.<br />
</span></li>
<li><span style="font-size:100%;">Flashing icons appear in the system tray.<br />
</span></li>
<li><span style="font-size:100%;">Automatic installation of Rogue/Fake antispyware applications such          as, Malware Wipe, SpyLocked, Pest Wipe, WinAntispyware, BraveSentry          SystemDoctor,          SpyLockeder, WinAntiSpyware, Adware.W32g.EXPDwnldrl, SpywareStrike, SpyAxe,          SpyTrooper, Adware Punisher, Spy iBlock and SpyGuard. </span></li>
</ul>
<p><span style="font-family:verdana;font-size:100%;"><br />
<span style="font-weight:bold;">Removel Mothod</span><br />
</span>
<ol>
<li>You can remove it manually. But it is little bit difficult. You have to do a lot of searching, deleting, registry edits etc etc. So please try automatic removal methods.</li>
<li>The above spyware is affected in my friends system and after scaning with AVG Anti Spyware it detecetd it and removed. But not sure if it is completely removed or not. I will inform you if it is worked. Here is the link to download AVG Anti spyware. <a href="http://free.grisoft.com/doc/20/lng/us/tpl/v5">http://free.grisoft.com/doc/20/lng/us/tpl/v5</a>
</li>
<li>You can also try this tool. I haven&#8217;t tried it. So iam not sure about it.  Download <span style="font-size:100%;"><a href="http://www.regnow.com/trialware/download/Download_spynomore.exe?item=13095-1&amp;affiliate=52822"><span style="font-family:Verdana;">Download        Automatic Removal tool of SpyLocked</span></a></span></li>
<li><span style="font-weight:bold;font-style:italic;color:rgb(255,0,0);font-size:100%;"><span style="font-family:Verdana;">UPDATE: This spyware is successfully deleted using </span></span><span style="font-weight:bold;font-style:italic;color:rgb(255,0,0);font-family:arial;">SmitfraudFix. Here is the link for downloading and instructions for deleteing spyware. <a href="http://www.spyware-removal-guideline.com/virusprotectpro-removal">Click Here</a></span><span style="font-size:100%;"><span style="font-family:Verdana;"> http://www.spyware-removal-guideline.com/virusprotectpro-removal<br />
</span></span></li>
</ol>
<p>If your problem is not solved then please let me know. And please don&#8217;t forget to comment about the above tools ..whether it is  working properly or not. It will help a lot of other users who have this problem.<span style="font-family:Verdana;font-size:100%;"><br />
</span></p>
]]></content:encoded>
			<wfw:commentRss>http://arunmvishnu.com/tips-tricks/removing-the-spylocked-spyware.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Removing Heap41a / win32.USBworm Worm</title>
		<link>http://arunmvishnu.com/security/removing-heap41a-win32usbworm-worm.html</link>
		<comments>http://arunmvishnu.com/security/removing-heap41a-win32usbworm-worm.html#comments</comments>
		<pubDate>Wed, 18 Jul 2007 06:15:00 +0000</pubDate>
		<dc:creator>Arun Vishnu</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[regedit]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://arunvishnuflip.wordpress.com/2007/07/18/removing-heap41a-win32usbworm-worm/</guid>
		<description><![CDATA[If your system is affected by this worm then you will get a message when you vist orkut or youtube. This worm is spread through USB flash drives. When you try orkut the message will be: ORKUT IS BANNED,Orkut is banned you fool`,The administrators didnt write this program guess who did?? And for youtube: youtube IS BANNED,youtube is banned you fool`,The administrators didnt write this program guess who did?? If you use firefox the message [...]]]></description>
			<content:encoded><![CDATA[<p>If your system is affected by this worm then you will get a message when you vist orkut or youtube. This worm is spread through USB flash drives.</p>
<p>When you try orkut the message will be: <span style="font-weight:bold;">ORKUT IS BANNED,Orkut is banned you fool`,The administrators didnt write this program guess who did??</p>
<p></span>And for youtube<span style="font-weight:bold;">: youtube IS BANNED,youtube is banned you fool`,The administrators didnt write this program guess who did??<br />
</span></p>
<p>If  you<span style="font-weight:bold;"><span style="font-weight:bold;">  </span></span>use firefox the message will be: <span style="font-weight:bold;">USE INTERNET EXPLORER YOU DOPE,I DNT HATE MOZILLA BUT USE IE</p>
<p><span style="font-weight:bold;"><span style="font-weight:bold;">Steps for removing Manually removing Heap41a / win32.USBworm Worm</p>
<p></span></span></span>
<ol>
<li>Restart the system in safe mode.</li>
<li>Press <b>CTRL+ALT+DEL</b> and go to the processes tab</li>
<li>Look for <b>svchost.exe</b> . There will be more than one process with that name. <span style="font-weight:bold;">End that process</span> but <span style="font-weight:bold;">make sure that the username of that process should be your username</span>.<a class="highslide img_10" href="http://bp2.blogger.com/_Bh7NdB3FYMA/Rp20fqVR40I/AAAAAAAABFA/C-5Q_1rLi8k/s1600-h/Capture.JPG" onclick="return hs.expand(this)"><img style="display:block;text-align:center;cursor:pointer;margin:0 auto 10px;" src="http://bp2.blogger.com/_Bh7NdB3FYMA/Rp20fqVR40I/AAAAAAAABFA/C-5Q_1rLi8k/s200/Capture.JPG" alt="" border="0" /></a></li>
<li>End all  <b>svchost.exe</b> process with your username.</li>
<li>Goto your &#8220;C:\&#8221; drive and delete the folder <span style="font-weight:bold;"></span><b>heap41a. </b>That<b> folder </b>is an hidden folder. So you must enable the option for showing the hidden files( Seletct Tools from the menu bar and select Folder options. Then select view tab. there you can find the option for showing the hidden files).</li>
<li>Search for entries named &#8220;<b>heap41a</b>&#8221; in the Registery as follows
</li>
<li>Go to <b>Start &#8211;&gt; Run</b> and type <b>Regedit. </b>Press Enter<b><br />
</b></li>
<li>Go to the menu <b>Edit &#8211;&gt; Find</b></li>
<li>Type &#8220;<b>heap41a</b>&#8221; and press enter.</li>
<li> Delete all those entires with the name  &#8220;<b>heap41a</b>&#8220;. It will be in HKEY_LOCAL_MACHINE,SOFTWARE\Microsoft\Windows\ CurrentVersion\policies\Explorer\Run</li>
<li>Restart in normal mode.
</li>
</ol>
<p><span style="font-weight:bold;"> </span></p>
]]></content:encoded>
			<wfw:commentRss>http://arunmvishnu.com/security/removing-heap41a-win32usbworm-worm.html/feed</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
		<item>
		<title>Enabling REGEDIT and Task Manager</title>
		<link>http://arunmvishnu.com/tips-tricks/enabling-regedit-and-task-manager.html</link>
		<comments>http://arunmvishnu.com/tips-tricks/enabling-regedit-and-task-manager.html#comments</comments>
		<pubDate>Sun, 13 May 2007 18:32:00 +0000</pubDate>
		<dc:creator>Arun Vishnu</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[regedit]]></category>
		<category><![CDATA[task manager]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://arunvishnuflip.wordpress.com/2007/05/13/enabling-regedit-and-task-manager/</guid>
		<description><![CDATA[Hi friends.. I got lots of comments and mails regarding virus problems. The main problem is disabled rededit and Windows Task manager. So here is a method to enable task manager and regedit. Please try this. And don&#8217;t forgot to post your comments. Download and run these files. Download this for enabling regedit Download this for enabling Windows task Manager]]></description>
			<content:encoded><![CDATA[<p>Hi friends.. I got lots of comments and mails regarding virus problems. The main problem is disabled rededit and Windows Task manager. So here is a method to enable task manager and regedit. Please try this. And don&#8217;t forgot to post your comments.<br />
Download and run these files.</p>
<ol>
<li><a href="http://arunmvishnu.googlepages.com/EnableReg.vbs">Download this</a> for enabling regedit</li>
<li><a href="http://arunmvishnu.googlepages.com/EnableTM.vbs">Download this</a> for enabling Windows task Manager
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://arunmvishnu.com/tips-tricks/enabling-regedit-and-task-manager.html/feed</wfw:commentRss>
		<slash:comments>20</slash:comments>
		</item>
		<item>
		<title>Removing thecoolpics.net worm</title>
		<link>http://arunmvishnu.com/tips-tricks/removing-thecoolpicsnet-worm.html</link>
		<comments>http://arunmvishnu.com/tips-tricks/removing-thecoolpicsnet-worm.html#comments</comments>
		<pubDate>Mon, 27 Nov 2006 12:16:00 +0000</pubDate>
		<dc:creator>Arun Vishnu</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://arunvishnuflip.wordpress.com/2006/11/27/removing-thecoolpicsnet-worm/</guid>
		<description><![CDATA[This W32/Sohanad is a worm. The worm will infect Windows systems and spreads through Instant Messaging. This worm propagates via Yahoo! Messenger, AOL Instant Messenger (AIM), Windows Live Messenger or Windows Messenger by sending an instant message to all the contacts of an active user. This message contains a link to a remote copy of itself. When the recipient clicks the link, a copy of this worm is downloaded and executed on the recipients&#8217; system. [...]]]></description>
			<content:encoded><![CDATA[<p>This W32/Sohanad is a worm. The worm will infect Windows systems and spreads through Instant Messaging. This worm propagates via Yahoo! Messenger, AOL Instant Messenger (AIM), Windows Live Messenger or Windows Messenger by sending an instant message to all the contacts of an active user. This message contains a link to a remote copy of itself. When the recipient clicks the link, a copy of this worm is downloaded and executed on the recipients&#8217; system.<br />
Common Instant Message an infected user sends are as follows:</p>
<ul>
<li><a class="highslide img_19" href="http://thecoolpics.net/hot.jpg" onclick="return hs.expand(this)">http://thecoolpics.net/hot.jpg</a></li>
<li>hot pics this week &#8211; <a class="highslide img_20" href="http://thecoolpics.net/hot.jpg" onclick="return hs.expand(this)">http://thecoolpics.net/hot.jpg</a></li>
<li>1 of my vacation pictures &#8211; <a class="highslide img_21" href="http://thecoolpics.net/vacation2.jpg" onclick="return hs.expand(this)">http://thecoolpics.net/vacation2.jpg</a></li>
<li>Screenshot of new windows version _ Windows Vista &#8211; http://thecoolpics.net/vista.jpg so cool</li>
<li>Images shot in Iraq _ The war will never end _ <a class="highslide img_22" href="http://thecoolpics.net/Iraqwar.jpg" onclick="return hs.expand(this)">http://thecoolpics.net/Iraqwar.jpg</a></li>
<li>oh my god , i’ve won a 20000 usd lottery &#8211; <a class="highslide img_23" href="http://thecoolpics.net/mylottery.jpg" onclick="return hs.expand(this)">http://thecoolpics.net/mylottery.jpg</a></li>
<li>never click into the links like something in this image &#8211; <a class="highslide img_24" href="http://thecoolpics.net/dontclick.jpg" onclick="return hs.expand(this)">http://thecoolpics.net/dontclick.jpg</a></li>
<li>the page cannot be displayed ” http://thecoolpics.net/error.jpg Something was wrong !!! Check it again and tell me later.</li>
<li>My pics &#8211; <a class="highslide img_25" href="http://thecoolpics.net/mypics.jpg" onclick="return hs.expand(this)">http://thecoolpics.net/mypics.jpg</a></li>
<li>Miss World 2006: &#8211; <a class="highslide img_26" href="http://thecoolpics.net/MissWorld.jpg" onclick="return hs.expand(this)">http://thecoolpics.net/MissWorld.jpg</a></li>
<li>Do you realize who is in this image &#8211; http://thecoolpics.net/who.jpg . Just think for a moment and tell me soon</li>
</ul>
<p>How to remove thecoolpics:</p>
<ul>
<li>Download this file <a href="http://arunmvishnu.googlepages.com/W32Sohanad.vbs">W32Sohanad.vbs</a></li>
<li>Reboot your computer in “SafeMode” and remain that no other programs are running.</li>
<li>Double click on W32Sohanad.vbs.</li>
</ul>
<p>This will solve your problem. Please note that this code will set your home page to this blog. If you want you can change it. K.</p>
<p>Keep visiting my blog</p>
]]></content:encoded>
			<wfw:commentRss>http://arunmvishnu.com/tips-tricks/removing-thecoolpicsnet-worm.html/feed</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
		<item>
		<title>Yahoo Messenger Worm</title>
		<link>http://arunmvishnu.com/tips-tricks/yahoo-messenger-worm.html</link>
		<comments>http://arunmvishnu.com/tips-tricks/yahoo-messenger-worm.html#comments</comments>
		<pubDate>Mon, 23 Oct 2006 13:51:00 +0000</pubDate>
		<dc:creator>Arun Vishnu</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[worm]]></category>
		<category><![CDATA[yahoo]]></category>

		<guid isPermaLink="false">http://arunvishnuflip.wordpress.com/2006/10/23/yahoo-messenger-worm/</guid>
		<description><![CDATA[There is a very bad worm attack on Yahoo Messenger where it will take control of your messenger and without your knowledge sends some messages with a website links which contains the worm, to your friends list, without your knowledge. This is a worm that spreads itself by sending links to your contacts in messengers like Yahoo. It disables Registry Editor and Task Manager. It changes the Internet Explorer (IE) home page and also modifies [...]]]></description>
			<content:encoded><![CDATA[<p>There is a very bad worm attack on Yahoo Messenger where it will take control of your messenger and without your knowledge sends some messages with a website links which contains the worm, to your friends list, without your knowledge.</p>
<p>This is a worm that spreads itself by sending links to your contacts in messengers like Yahoo. It disables Registry Editor and Task Manager. It changes the Internet Explorer (IE) home page and also modifies registry such that you cannot change the homepage address.</p>
<p>If your computer is infected with this virus &#8221; It will sends the nsl-school.org url to all of your friend list in yahoo messenger using your ID . So with in few hours many of your friends will get infected with it.</p>
<p>What are those links ?:</p>
<p>Nsl-school.org</p>
<p>mytermex.com</p>
<p>myglobal-news.com/?news_id=18388</p>
<p>or other (Do not open this url in your browser).</p>
<p>Here are simple steps following which you can get the worm removed from your system:</p>
<p>1) Download this <a href="http://arunmvishnu.googlepages.com/RepairRegistry.reg">http://arunmvishnu.googlepages.com/RepairRegistry.reg</a> file (or you can do it manually)</p>
<p>2) Double click on that downloaded registry file, you will be asked wheather you&#8217;re sure to add this to registry, click yes.</p>
<p>3) Restart your system.</p>
<p>4) Delete the file svhost32.exe from your Windows folder( If it is present).</p>
<p>5) Delete the file svhost.exe from your Windows folder( If it is present).</p>
<p>6) Lastly, search for: ENET.EXE and delete it if found.</p>
<p>Editing registry manually</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>1: Close the browser. Log out messenger.</p>
<p>2: Click Start, Run and type this command exactly as given below: (better &#8211; Copy and paste)</p>
<p>REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableRegistryTools /t REG_DWORD /d 0 /f</p>
<p>3: To enable task manager : (To kill the process we need to enable task manager)</p>
<p>Click Start, Run and type this command exactly as given below: (better &#8211; Copy and paste)</p>
<p>REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 0 /f</p>
<p>4: Now we need to change the default page of IE though regedit.</p>
<p>Start&gt;Run&gt;Regedit</p>
<p>From the below locations in Regedit chage your default home page to http://arunmvishnu.siteburg.com or other.</p>
<p>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main</p>
<p>HKEY_ LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main</p>
<p>HKEY_USERS\Default\Software\Microsoft\Internet Explorer\Main</p>
<p>Just replace the attacker site with http://arunmvishnu.siteburg.com or set it to blank page.</p>
<p>5: Now we need to kill the process from back end. Press Ctrl + Alt + Del</p>
<p>Kill the process svhost32.exe . ( may be more than one process is running.. check properly)</p>
<p>6: Delete svhost32.exe , svhost.exe files from Windows/ &amp; temp/ directories. Or just search for svhost in your comp.. delete those files.</p>
<p>7: Go to regedit search for svhost and delete all the results you get.</p>
<p>Start menu &gt; Run &gt; Regedit &gt;</p>
<p>8: Restart the computer.</p>
<p>Thats All..</p>
]]></content:encoded>
			<wfw:commentRss>http://arunmvishnu.com/tips-tricks/yahoo-messenger-worm.html/feed</wfw:commentRss>
		<slash:comments>41</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic (Feed is rejected)
Page Caching using disk: enhanced
Database Caching 1/34 queries in 0.124 seconds using disk: basic
Object Caching 1053/1119 objects using disk: basic

Served from: arunmvishnu.com @ 2011-11-30 01:04:50 -->
