” nsl-school.org ” - Yahoo Messenger virus/trojen Solution

If you're new here, you may want to subscribe to the RSS feed to receive future posts quickly.It's completely free!Thanks for visiting!


This brand new virus is now everywhere. It is spreading so fast as it targets users of Yahoo Instant Messenger. Users can protect themselves by not clicking on links sent to them by other users or contained in Yahoo! Messenger status messages of those contacts on their contact list.

If your computer is infected with this powerful Trojan /virus, it sends the nsl-school.org url to all of your friend list in yahoo messenger using your ID and expect that in only a few hours many of your friends will get infected with it.

Many of my friends’ PCs are now infected with this. I searched online and found a cure which I think worked for many who tried it. Here’s the solution from one of the security alert forum.

There is a very bad virus attack on Yahoo Messenger where it will take control of your messenger and without your knowledge sends some messages with a website links which contains the virus, to your friends list, remind you without YOUR KNOWLEDGE so be careful, try to do the following things to remove if your are effected.

One of our viewers compiles the below steps to a batch file so that it can be used by novice users… —>>>> DOWNLOAD

First download it and run it. Check whether the system is cleaned or not. If not try again with the below steps.


So how to remove this manually from your computer ?

1: Close the IE browser. Log out messenger / Remove Internet Cable.

2: To enable Regedit

Click Start, Run and type this command exactly as given below: (better - Copy and paste)

REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableRegistryTools /t REG_DWORD /d 0 /f

3: To enable task manager : (To kill the process we need to enable task manager)

Click Start, Run and type this command exactly as given below: (better - Copy and paste)

REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 0 /f

4: Now we need to change the default page of IE though regedit.

Start>Run>Regedit

From the below locations in Regedit chage your default home page to google.com or other.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main

HKEY_ LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main

HKEY_USERS\Default\Software\Microsoft\Internet Explorer\Main

Just replace the attacker site with google.com or set it to blank page.

5: Now we need to kill the process from back end. Press Ctrl + Alt + Del

Kill the process svhost32.exe . ( may be more than one process is running.. check properly)

6: Delete svhost32.exe , svhost.exe files from Windows/ & temp/ directories. Or just search for svhost in your comp.. delete those files.

7: Go to regedit search for svhost and delete all the results you get.

Start menu > Run > Regedit >

8: Restart the computer. That’s it now you are virus free.

One of our viewers compiles the above steps to a batch file so that it can be used by novice users… —>>>> DOWNLOAD

18 Responses to “” nsl-school.org ” - Yahoo Messenger virus/trojen Solution”

Pages: [2] 1 » Show All

  1. 18
    Anonymous Says:

    The link in my signature has one of the best tutorials i\’ve seen about the svchost.exe application error. You might check it out.

  2. 17
    krissy Says:

    Super thanks! im not good with pcs but like…damn! you rock! i think im virus free :) Thanks a lot!

  3. 16
    neo999 Says:

    If your run command is disabled, you can use the Batch file given above to do it automatically.

  4. 15
    Prashant Says:

    My Run command is there but even after typing the instructions of enabling task manager and regedit as mentioned above my Regedit and task manager don’t appear ..what am I supposed to do ?? also my computer makes a bugging sound and my computer becomes inactive for about 2 seconds besides being extremely slow…please help !!

  5. 14
    Sharath Says:

    If you have the RUN and Task-Manager disabled in your system, here are the steps you can follow to get it virus/worm removed:
    http://www.geocities.com/avsharath/Removing_W32Sohanad_Worm.htm

  6. 13
    EXILE Says:

    Easiest way to get run is Window’s Key and the Letter R, just press and hold the window key on your keyboard and hit R it will open the RUN option

  7. 12
    Ange Says:

    Help!!! My computer doesn’t have ‘Run’ anymore.. how can rid my computer this horrid trojan virus?????

  8. 11
    swapy Says:

    1st 2 processes can be done in command prompt. After tht task manager opens. But in regedit how to set the homepage?? :( i can c google.com in regedit window but how to set it??? Also RUN option is disabled.

    Anyways, by using Trojan Guarder, tht yahoo messenger problem is solved, but still 3 problems are there.
    1] Default site in IE cant be set.
    2] RUN option disabled.
    3] Task Bar doesnt opens.

Pages: [2] 1 » Show All

Leave a Reply