dont get infected!!
April 11th, 2008 
viruses .. “malware, spyware, adware , worms, trojan” its all a big one headache.. try your best to get away from getting infected with any of these .. get urself immune even if there is no-way to do so
, try your best . Working with ministry most of their pc’s are infected regularly specially that they use a bullshit anti-virus called officescan its one of trends micro antivirus, but it doesn’t remove trojans nor ad/spyware so whats the use of it dunno yet.
anyway .. most pc’s which are not connected to network , which means not updated regularly with new virus definitions are infected. I have to try my best to remove the viru, even though its not my job to do so. Technical people job but they just dont need to do it, here we are the out-source as they call us in ministry .. well i wont say its not good for me cause i actually like it, its like a challenge for me everytime with new “champion” virus ![]()
i had to remove some with tools , others with antivirus .. and most have to manually , i recommend using Kaspersky antivirus its good , specially if it lasts for years like mine expire 2010
.. or NOD32 , heard its good .. but never used it yet.
two viruses be aware from ( NooH , and Amvo ) actually trojans .
and here is a method on removing both :
first NooH :
Summary:
This virus enters you computer from an external device (Flash Disk, External HD, Memoery Card). It runs with explorer autoplay. It copies Sys.
exe to this folder “c:\Windows\Web\Sys.exe”.
Effects:
1- Disables Windows Task Manager.
2- Disables Windows Command Prompt.
3- Disables Windows Folder Options.
4- Copies itself to all removable media.
Resolution:
Restart your computer.
After restart a message will appear “Noooh.. please try to open task manager” and an OK Button.
Don’t click the OK button.
Open the task manager and this process “Sys.exe”
Click ‘Start‘.
Open ‘My Computer‘.
Select the ‘Tools‘ menu and click ‘Folder Options‘.
Select the ‘View’ tab.
Under the ‘Hidden files and folders‘ heading select ‘Show hidden files and folders‘.
Uncheck the ‘Hide file extensions for known types‘ option.
Uncheck the ‘Hide protected operating system files (recommended)‘ option.
Click Yes to confirm.
Click OK.
Download KillBox,unzip/extract it to your desktop.
Start up Killbox and place a check in ‘Delete on Reboot‘.
In the ‘Full path of file to delete‘ box,copy and paste:
C:\Windows\Web\Sys.exe
Then press the red button with the white cross.
It will then provide a window for you to confirm the delete.
Next it will ask if you now wish to reboot,select YES.
Allow it to reboot.
If it does’nt reboot automatically,reboot manually.
Have Hijack This fix the following by placing a check in the appropriate boxes and selecting ‘Fix checked’.
Make sure all browser and all Windows Explorer windows are closed before fixing:
O4 - HKLM\..\Run: [NoooH] C:\Windows\Web\Sys.exe
Exit Hijackthis,restart your pc
————-
AMVO Trojan : amvo.exe
Virus Manual Removal Steps
This is a nasty virus, dont know who dropped it on me. It spreads via USB Memory Sticks. It cannot be seen in the process list, hides itself and hides all files. And my antivirus doesn’t seem to find a problem! ![]()
Effects on ur PC :
* Cannot show hidden files
* Slows down USB devices
* Adds infections to plugged in USB devices
* Drives open in new windows from My Computer
How to get rid off?
Step 1
The usual way is to Format the system, but it is not a permanent solution. To get rid run regedit, find all keys related to amvo.exe or the name of the virus.
Run msconfig in the Start Up Tab you can find the amvo.exe or its variants.
Remove all occurrence of the name from regedit.
Reboot the System.
Step 2
If you know how to use dos prompt command , just go to start –> run–> write “cmd”
in dos window goto c:\windows\system32 and do this write ” attrib -h -s -r amvo0.dll”
and delete the file amvo0.dll by writing the command “del amvo0.dll”.
Step 3
Reboot and do the following changes to the Registry using regedit
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Explorer searchidden en 1
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Explorer searchsystemdirs en 1
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Explorer\Advanced hidden en 1
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Explorer\Advanced showsuperhiden en 1
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Explorer\Advanced superhiden en 1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN CheckedValue 1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN DefaultValue 1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL CheckedValue 1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL DefaultValue 1
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Policies\Explorer NoDriveTypeAutoRun 0×00000091 (145)
thats it hope it helps a little for any more info just comment i’ll try to reply soon![]()
Posted in 








