How to Remove Happy99.exe (ska)

6/22/2009 09:32:00 AM Posted In Edit This 0 Comments »

These are the steps you can follow to remove Happy99.exe

Steps marked optional are not absolutely necessary and are completely safe to skip. If you’re not comfortable with DOS, get someone knowledgeable to help you with this. I cannot make guarantees of perfect safety since its a manual removal, Perform these at your own risk. If you have Windows NT, you don’t have to follow the removal steps.

1. Click Start, then Shut Down, then “Restart Computer in MS-DOS mode”, then click Yes. It’s important to exit Windows in order to be able to replace the file WSOCK32.DLL which Windows normally has in use.

2.At the DOS prompt type this exactly and press enter at the end of each line:

CD \WINDOWS\SYSTEM

3. Delete SKA.EXE and SKA.DLL by typing

DEL SKA.EXE
DEL SKA.DLL

If you get “File not found” you’re either not infected or in the wrong directory. Make sure you’re in your Windows System directory; check to see if you followed step 2 exactly.

4.Copy WSOCK32.SKA to WSOCK32.DLL by typing

ATTRIB -R WSOCK32.DLL
COPY WSOCK32.SKA WSOCK32.DLL

Answer “Yes” if it asks if you want to overwrite WSOCK32.DLL.

WSOCK32.SKA is a backup of the original WSOCK32.DLL. You are replacing the modified DLL with the original. If you get a “Sharing violation” make sure you followed step 1.

5.Optional Delete WSOCK32.SKA by typing

DEL WSOCK32.SKA

You can leave WSOCK32.SKA on your system. It is a copy of your original WSOCK32.DLL Do not delete WSOCK32.SKA if you are unable to replace WSOCK32.DLL with WSOCK32.SKA.

6.Return to Windows by typing

EXIT

7.Optional Delete Windows Registry Key.
Click Start, then Run, then type regedit in the text box, then click OK. Click HKEY_LOCAL_MACHINE, then Software, then Microsoft, then Windows, then CurrentVersion. Under RunOnce check for SKA.EXE and select it if it is there. Press delete and then click Yes. Close Regedit. Don’t change anything else without making a backup of the registry first. If you don’t find SKA.EXE in the registry, it doesn’t mean you’re not infected. SKA.EXE is only added to the registry if HAPPY99.EXE is unable to modify WSOCK32.DLL when you run it. Also, you’ll only find it in the registry if you haven’t rebooted since you ran HAPPY99.EXE.

8.Optional Choose Start, Programs, Accessories, Notepad, choose File, then Open then type C:\WINDOWS\SYSTEM\LISTE.SKA in the File Name box. Warn the people on the list, then delete LISTE.SKA. Make it clear to the people you warn that they won’t be infected unless they ran happy99.exe, to avoid alarming them unnecessarily. If you haven’t sent out any infected e-mails, there won’t be a LISTE.SKA.

9. Optional Delete the HAPPY99.EXE file. The location of HAPPY99.EXE will vary depending on where you saved it. You can delete it simply by dragging it to the Recycle Bin from within Windows or whatever method you prefer. You may still have some messages with HAPPY99.EXE attached in your mailbox. These cannot do anything unless you run them. You can delete them if you want to or just ignore them. 10.Optional If you aren’t sure whether WSOCK32.DLL is infected, choose Start, then Find, then “Files or Folders”. Then type WSOCK32.DLL in the “Named” box. In the “Look in” box choose drive C: or whatever drive you have Windows on. In the “Containing Text” box type “ska.dll” without the quotes. Then click “Find Now”. If you don’t find any files, that means that wsock32.dll isn’t the modified version. If you don’t have the modified WSOCK32.DLL, the virus has no way to attach to e-mails, even if you have SKA.EXE, SKA.DLL, and WSOCK32.SKA in the Windows System folder. If you have SKA.EXE in the RunOnce registry section, and you haven’t deleted SKA.EXE, then the virus will try to modify WSOCK32.DLL the next time you restart the computer.

Very Cool Mozilla Firefox Tricks

6/22/2009 09:28:00 AM Posted In Edit This 0 Comments »

chrome://browser/content/browser.xul – Opens another Firefox inside a tab in the the existing Firefox window.

chrome://browser/content/preferences/preferences.xul - Opens the Options dialog box inside the Firefox tab.

chrome://browser/content/bookmarks/bookmarksPanel.xul - Opens the “Bookmarks Manager” inside a tab in the Firefox window.

chrome://browser/content/history/history-panel.xul – Opens the History Panel in the Firefox tab.

chrome://mozapps/content/extensions/extensions.xul?type=extensions - Opens the Extensions window in the current tab.

chrome://browser/content/preferences/cookies.xul – Opens the “cookies window” inside a tab in the Firefox window.

chrome://browser/content/preferences/sanitize.xul – Opens the “Clear Private Data” window inside the current tab.

chrome://browser/content/aboutDialog.xul – Opens the “About Firefox” Dialog box inside the tab.

chrome://browser/content/credits.xhtml – Opens a scrolling list of firefox contributors. The one’s who we must thank for creating Firefox

chrome://global/content/alerts/alert.xul - Dancing Firefox.

How to Remove JAY.EXE and MVEO.EXE Virus

6/22/2009 09:01:00 AM Posted In Edit This 0 Comments »

Follow this steps to locate all the mveo.exe and jay.exe files,
1. open windows explorer window
2. click tools then click folder options
3. select view tab
4. on the hidden files and folders menu tick on show hidden files and folders.
5. uncheck hide extensions for known file types
6. uncheck hide protected operating system files (recommended)
7. click apply then OK

Next we will have to remove the jay.exe and mveo.exe files
1. Press ctrl+alt+del to open taask manager
2. In the processes tab look for the mveo.exe and end process.

To delete all the jay.exe and mveo files, search for it using the search for files and folder option in the start menu.
1. type jay.exe in the searchbar
2. click more advanced option
3. put a check on search hidden files and folders
4. then click on start search
5. delete all jay.exe entries
6. repeat steps 1-5 to search for mveo.exe
7. also delete autorun.inf file

To delete registry entries
1. click on start
2. click on run
3. in the run text box type regedit
4. press ctrl+f and type in the textbox jay.exe
5. delete all entires having jay.exe entries
6. press F3 to search the next entry.

note: if an entry is in c:\windows… edit the value and go to the end of the string and
delete only the jay.exe text on the end of the string

To edit the IE windows back to its original name:
1. open regedit
2. press ctrl+f
3. type in the searchbar window title
4. If the value that appears has the jaymyka.wen9.com value, change it to Internet Explorer
note: this would be the title bar of your Internet Explorer.

After all of these steps are done:
try to look again for the jay.exe and mveo.exe files using the search for files and folders application of windows.

after deleting all those files restart your computer.

How to Remove Worm MyMP3.vbs

6/22/2009 08:57:00 AM Posted In Edit This 0 Comments »

To remove MyMP3.vbs just follow the below procedure:

1. First, temporarily disable your system restore

2. Restart your computer

3. boot in safe mode

4. Open your registry editor Start –> Run –> type regedit

5. Go to this key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

6. Delete value with data C:\WINDOWS\MyMP3.vbs

7 .We will now have to delete all the related files, doing this manually and a pain even for expert users so I will provide a batch code so you can remove all files easily.

How to remove SCVHOST.exe (W32/YahLover.Worm.gen or Win32/Autorun.R.worm)

6/22/2009 08:53:00 AM Posted In Edit This 0 Comments »

This virus/worm installs itself in autorun.inf and once double click it will spread itself unto your system. Furthermore, it copies itself through all the shared folders on your computers throughout the network and installs itself in the registry entries remotely.

Here are indication that your computer is infected with this virus.

  • This virus/worm blocks the task manager
The worm changes the registry to prevent running task manager and editing registry for harder detection.
  • It automatically restarts the computer when you try to go to the command prompt.
  • It duplicates itself to different locations of the shared folders. The duplicated virus/worm uses a FOLDER icon with an .exe file extension. WARNING! DO NOT double click these folders.
  • It autostart via registry keys Windows->Run and add itself to WinNT->WinLogon->Explorer.exe

How to remove the virus

You can use NOD32 or any strong antovirus programs to remove this virus but if you don’t have a anti-virus or your antivirus can’t remove this virus try following the steps below to remove it manually.

  • Boot your system in Safe Mode Command Prompt Only
  • After you log-in the command prompt will be opened (LOG-IN AS ADMINISTRATOR).
  • Type CD C:\WINDOWS\SYSTEM32 (I assume that your Windows System files are located at Drive C)
  • Type DIR /ah, this will display all hidden files on this directory folder. You will see the following files which is used by the virus to spread itself: AUTORUN.INI, BLASTCLNNN.EXE, and SCVHOST.EXE
  • Type ATTRIB -H -R -S SCVHOST.EXE
  • Type ATTRIB -H -R -S BLASTCLNNN.EXE
  • Type ATTRIB -H -R -S AUTORUN.INI
  • Type DEL SCVHOST.EXE
  • Type DEL BLASTCLNNNN.EXE
  • Type DEL AUTORUN.INI
  • Type CD\
  • Type ATTRIB -H -R -S AUTORUN.INF
  • Type DEL AUTORUN.INF

After following the steps on removing the virus/worm files, the virus should now be removed from the registry of your system.

  • At the command prompt type REGEDIT and press ENTER key. This will run the Registry Editor
  • From the registry, look for the keys: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, you will see an entry Yahoo! Messengger (it’s spelled like this) with a value c:\windows\system32\scvhost.exe, Delete this entry.
  • Look again for the key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, there’s an entry named: SHELL, it has a value = Explorer.exe SCVHOST.EXE , DON’T delete this entry!!! Just edit this entry and REMOVE the SCVHOST.EXE so that Explorer.exe will be the only value that remains from this registry entry.

After carefully following all the steps restart your computer on normal mode and the virus should now be gone.