FrEn

E-mail Print

Noooh Fix (Sys.exe, ComSys.dll)

Written by Administrator  |  Friday, 18 September 2009 05:10
AddThis Social Bookmark Button

Information

Amendment to the parameters of the system which could impact negatively on the functioning of the system.
Amendment parameters in the Registry preventing you:

  • Using standard tools for editing registry
  • To restore the system
  • Using the Task Manager
  • Using cmd.exe

The virus displays the following information : Please Try to open - TaskManager - now


Alias :

  • Trojan.VB.DRRX [PCTools]
  • Trojan.BAT.Killfiles.OZ [PCTools]
  • Virus.Win32.AutoRun.cb [Kaspersky Lab]
  • W32.SillyFDC [Symantec]
  • W32/Hooon.worm [McAfee]
  • TROJ_AGENT.SCD [Trend Micro]


File

  • <Windows>\Web\Sys.exe
  • <System>\ComSys.dll
  • <System>\KillAll.bat
  • <All Root Partition>:\autorun.inf
  • <All Root Partition>:\Sys.exe


Registry Keys created:

  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System


Values created:

  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    • NoooH = <Windows>\Web\Sys.exe
    • Ce qui entraine le lancement de ce programme à chaque démarrage de Windows
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
    • DisableSR = 0x00000001
    • Désactive la restauration système
  • [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    • DisableTaskMgr = 0x00000001
    • DisableRegistryTools = 0x00000002
    • Désactive le gestionnaire des tâches et les outils d'édition de la base de registre
  • [HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System]
    • DisableCMD = 0x00000001
    • Désactive cmd.exe


ATTENTION

This virus runs automatically each time you open or explore a partition, it is preferable to download the patch and unpack it on the desktop, reboot your machine in Safe Mode and run the patch, always in safe mode.

Download

 

Comments  

 
0 #4 sheeweexy 2012-02-03 22:51
A good site. I'm offtopic, where you can buy a good telescope?
{viagra oral jelly|viagra oral jelly uk|buy viagra oral jelly]
Quote
 
 
0 #3 sheeweexy 2012-02-03 09:56
A good site. I'm offtopic, where you can buy a good telescope?
cialis black 800mg
Quote
 
 
0 #2 sheeweexy 2012-02-02 08:26
Hi all football fans! What's going to Barcelona? Why the decline in the game?
viagra super active online
Quote
 
 
0 #1 Wewirorimet 2012-01-27 00:05
Do I need to delete Sergio Ramos was in Barcelona last match with the real?
levitra prix
Quote
 

Add comment


Security code
Refresh

Related articles
Latest posts
  • Free malware removal tool for Guard Online

    Written by %s admin 10/10/2011
    Guard Online is a another rogue Antispyware from the OpenCloud and AV Guard Online familly, it's a malware that pretends to be an Antivirus. Guard Online conducts a fake scan of your system; you are…
  • Free malware removal tool to remove AV Guard Online

    Written by %s admin 05/10/2011
    AV Guard Online is a another rogue Antispyware from the OpenCloud familly, it's a malware that pretends to be an Antivirus. AV Guard Online conducts a fake scan of your system; you are warned by a…
  • Free removal tool to remove Security Guard 2012

    Written by %s admin 05/10/2011
    Security Guard 2012 is a another rogue Antispyware from the OpenCloud familly, it's a malware that pretends to be an Antivirus. Security Guard 2012 conducts a fake scan of your system; you are warned…
  • Free removal tool for Advanced PC Shield 2012

    Written by %s admin 01/10/2011
    Advanced PC Shield 2012 is a another rogue Antispyware, it's a malware that pretends to be an Antivirus. Advanced PC Shield 2012 conducts a fake scan of your system; you are warned by a fake alarm…
  • Security Sphere 2012 Free Removal Tool

    Written by %s admin 01/10/2011
    Security Sphere 2012 is another spyware from the Security Tool family. Security Sphere 2012 is not a legit program; it's a fake, a counterfeit. Security Sphere 2012 claims to fix your system, but…
.
Information | Contact

© All Rights Reserved. net-studio.org 2009