” nsl-school.org ” - Yahoo Messenger virus/trojen Solution
| If you're new here, you may want to subscribe to the RSS feed to receive future posts quickly.It's completely free!Thanks for visiting! | |
This brand new virus is now everywhere. It is spreading so fast as it targets users of Yahoo Instant Messenger. Users can protect themselves by not clicking on links sent to them by other users or contained in Yahoo! Messenger status messages of those contacts on their contact list.
If your computer is infected with this powerful Trojan /virus, it sends the nsl-school.org url to all of your friend list in yahoo messenger using your ID and expect that in only a few hours many of your friends will get infected with it.
Many of my friends’ PCs are now infected with this. I searched online and found a cure which I think worked for many who tried it. Here’s the solution from one of the security alert forum.
There is a very bad virus attack on Yahoo Messenger where it will take control of your messenger and without your knowledge sends some messages with a website links which contains the virus, to your friends list, remind you without YOUR KNOWLEDGE so be careful, try to do the following things to remove if your are effected.
One of our viewers compiles the below steps to a batch file so that it can be used by novice users… —>>>> DOWNLOAD
First download it and run it. Check whether the system is cleaned or not. If not try again with the below steps.
So how to remove this manually from your computer ?
1: Close the IE browser. Log out messenger / Remove Internet Cable.
2: To enable Regedit
Click Start, Run and type this command exactly as given below: (better - Copy and paste)
REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableRegistryTools /t REG_DWORD /d 0 /f
3: To enable task manager : (To kill the process we need to enable task manager)
Click Start, Run and type this command exactly as given below: (better - Copy and paste)
REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 0 /f
4: Now we need to change the default page of IE though regedit.
Start>Run>Regedit
From the below locations in Regedit chage your default home page to google.com or other.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main
HKEY_ LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main
HKEY_USERS\Default\Software\Microsoft\Internet Explorer\Main
Just replace the attacker site with google.com or set it to blank page.
5: Now we need to kill the process from back end. Press Ctrl + Alt + Del
Kill the process svhost32.exe . ( may be more than one process is running.. check properly)
6: Delete svhost32.exe , svhost.exe files from Windows/ & temp/ directories. Or just search for svhost in your comp.. delete those files.
7: Go to regedit search for svhost and delete all the results you get.
Start menu > Run > Regedit >
8: Restart the computer. That’s it now you are virus free.
One of our viewers compiles the above steps to a batch file so that it can be used by novice users… —>>>> DOWNLOAD



August 14th, 2008 at 8:02 pm
The link in my signature has one of the best tutorials i\’ve seen about the svchost.exe application error. You might check it out.
December 6th, 2007 at 10:31 pm
Super thanks! im not good with pcs but like…damn! you rock! i think im virus free
Thanks a lot!
November 11th, 2007 at 2:41 am
If your run command is disabled, you can use the Batch file given above to do it automatically.
November 10th, 2007 at 3:58 am
My Run command is there but even after typing the instructions of enabling task manager and regedit as mentioned above my Regedit and task manager don’t appear ..what am I supposed to do ?? also my computer makes a bugging sound and my computer becomes inactive for about 2 seconds besides being extremely slow…please help !!
December 1st, 2006 at 6:45 pm
If you have the RUN and Task-Manager disabled in your system, here are the steps you can follow to get it virus/worm removed:
http://www.geocities.com/avsharath/Removing_W32Sohanad_Worm.htm
November 7th, 2006 at 9:48 pm
Easiest way to get run is Window’s Key and the Letter R, just press and hold the window key on your keyboard and hit R it will open the RUN option
November 6th, 2006 at 11:00 am
Help!!! My computer doesn’t have ‘Run’ anymore.. how can rid my computer this horrid trojan virus?????
November 5th, 2006 at 12:02 pm
1st 2 processes can be done in command prompt. After tht task manager opens. But in regedit how to set the homepage??
i can c google.com in regedit window but how to set it??? Also RUN option is disabled.
Anyways, by using Trojan Guarder, tht yahoo messenger problem is solved, but still 3 problems are there.
1] Default site in IE cant be set.
2] RUN option disabled.
3] Task Bar doesnt opens.