12.05.2009

Exploit Rogue Scanner : How To

Category : , ,
It seems like a lot of people have been or are affected with a virus called Exploit Rogue Scanner (type 820). I posted a guide on another blog, but since a lot more people visit this site, Xeph and I decided to put a guide here as well.

To start things of Windows XP users should update to Service Pack 3 because we think it prevents the virus from injecting itself in your Registry. Exploit Rogue Scanner Type 820 is a downloader, expect it to hit your registry and nothing else. It rides the websites you visit, so please be CAREFUL. Exploit Rogue Scanner Type 820 sends an error through your registry, causing your Security Center to send an "alert message" that the applications you open are virus infected. THIS IS NOT TRUE. It's kind of like a fake system error. You won't be able to open system related programs like well, your firewall options and stuff. It also has key log, so while infected I suggest you don't log in to your online accounts.

Here's the thing, if you let it error a number of times, chances are your anti-virus will block it. When the virus is blocked read what the error message, it will probably show where the virus is EXACTLY LOCATED. Write it down.

The fix :
Start> Settings> Control Panel> Folder Options> View> in the hidden files and folders section uncheck everything and select show all hidden files and folders, click Ok/Apply/SAVE.

Download combofix.exe, but don't use it yet as you won't be able to turn off your anti-virus because the virus prevents you from opening it.

Restart/Reboot in safe mode, either the traditional "press F8" way or try as fast as you can before it errors : "click run then type in MSconfig > boot.ini > /safemode"

Run combofix while in safe mode, it won't fix the virus BUT, it will 'cause the virus to mellow down a bit, restart again, in normal mode. Since the virus won't error as much, it will give you enough time to turn your anti-virus off and run combofix.exe, when combofix is finished, check out the log, look for the folder where the virus is located.

DELETE IT!

Run combofix.exe once more just to be safe, restart,

Congratulations, you're PC is back to normal.

Please please, update to SP3.

0 comments :

Blog Widget by LinkWithin
 

Xephan and Reema Copyright © 2009

Tweaked by Oh! Maiii