Admin@mbox3.magellan-net.de
alina@yourmx.de
bm@schweinischer-bote.de
boris@cosmeta.de
boss@dan2n.de
btiggemann@mbox3.magellan-net.de
catcher009@blacknbeauty.de
Christopher_Zantopp@web.de
dok123@discardmail.com
dominik.keilbach@rocketmail.com
dominik2712@web.de
einkauf@dan2n.de
elke@kunesch.eu
erik_burgbacher_bi17l4lo@send.electronicmailfor.me.uk
feedme@die-bauer.de
feedme@dog-net.org
feedme@drakensang.de-web.cc
feedme@kraffner.de
feedme@schlaegel.it
feedme@sql-kunesch.de
feedme@wipeout6.de
fetcher@open-host.de
frank@spiracyworld.co.uk
getspam@schlaegel-online.de
harun-ali@web.de
iCollectGarbage@gmx.de
ifyoudone@r0ckt.de
ifyyou@r0ckt.de
info@die-bauer.de
info@mbox3.magellan-net.de
info@r0ckt.de
info@rbcms.de
john.deer@spamreducer.eu
john@cannedmeat.elementfx.com
k.tramm@xspin.de
Karl-Heinz.Becher@gmx.de
Kevin.Becaud@bio-muesli.info
kickers88@live.de
knuddels119k@yahoo.de
loremiosumsitdoloramet@yahoo.de
loremiosumsitdoloramet@yahoo.de
lotharwalter@ymail.com
luna@r0ckt.de
matz0302oyqp@domut.de
mgoessel@gmx.net
michael.k@drakensang.de-web.cc
michael.k@drakensang.de-web.cc
michael.k@sql-kunesch.de
michaknopf@googlemail.com
mk@r0ckt.de
msneijder@mbox3.magellan-net.de
nasti_mkorsa@sql-kunesch.de
newcyborg@gmx.net
schlucks@gmx.net
schwarz@die-bauer.de
service@mbox3.magellan-net.de
sp4mf4ng@j-schmitz.net
spam@teh1.de
spamcatcher@spamtrap.dtdns.net
spamela@spamschlucker.org
spamhog.ihatespam@gmail.com
spamlearn@schlarb-it.de
spamlearn@schlarb-it.de
spamtarget@junge-piraten.de
spamtrap@r0ckt.de
spamtrap@sprachdidaktik.org
spoof@dog-net.org
stephan@spamschlucker.org
support@mbox3.magellan-net.de
thanks@marvin-webservice.net
trap.mitschutz@sprachdidaktik.org
trap@sprachdidakt.de
trap@sprachdidaktik.org
trep@marvin-webservice.net
unwanted@shadowpage.de
vertrieb@dan2n.de
wb@munzinger.de
willmehr@drakensang.de-web.cc
willmehr@drakensang.de-web.cc
willmehr@wipeout6.de
wir@dragoncrew.de
xkbzy@grossermist.de
a Image

Today, while searching for some interesting topics, i found a guy, having a problem with a
৺vbscript, causing his Internet Explorer having the title attribute ৺hacked by [Computername]

I read through the source code, and was able to fix it. Here's a summary of all necessary steps, to get rid of this script.

The Script infects all removable disks such as harddisks, SD-Cards and flash drives,
only with the target to spread itself to other computers.

If you'd like to have a german explanation, read here, where i initially solved it: http://www.computerforum.de/thread.php?threadid=112802

Disabling ৺VBScript
The Script is build to reproduce itself - So the first step necessary is to disable vb script.
Open your start menu, hit on run type in regedit and locate the following key:

৺ Hkey_Local_Machine\Software\Microsoft\Windows Script Host\Settings


There, look for the entry enabled and put its value to 0 (zero)
Simple double click the Entry to modify its value.

Restart your computer to ensure running instances of the script are closed.

Delte Files
Now, you are able to delete the files, created by the script. (A script, that is actually
not running cant recopy itself to other locations)

locate the files

৺ autorun.inf


৺ {YourComputerName}.vbs


৺ {AnotherComputerName}.vbs


on every removable device you have attached at any time and delete them.

Removing Registry Entrys
The script is creating some registry entrys on your computer.
first, open regedit again, and locate the following key:

৺ HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\


there, have a look for a entry, that has the name of YOUR computer
its value should be pointing to

৺ C:\Windows\system32\{YourComputerName}.vbs


  • First remove this regentry
  • Then locate the file in your windows folder and delete it, too


The outcome
The Scripts outcome is - as mentioned above - the modification of IEs title.
To get rid of this string, stay in registry, and locate the following key:

৺ HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\


There, find the entry Window Title and delete it without replacement.

Nearly Done
After you have achieved all these actions, you can Set the enabled value back to 1 again.
The Script should be gone now.

Related Tags:

Related Links:

Stay tuned:

r a t y y

Top 25 Tag-Cloud (last 14 days):

Trackbacks on this post:

Comments on this post:

Spoon
2009-09-01 16:43:28
omg searching so long. THX :D
bender
2009-08-10 12:00:04
Thanks dude. Really thought i have to run the recovery now. But this really solved it.

Leave a Comment:

Captcha-Code:        reload
Name:
Captcha:
Comment:

Donate!

Like my stuff? Feel free to donate!
 
Modellbau Forum pspad Browser-Statistiken WhatPulse logo dog-net.org Valid XHTML 1.0 Transitional CSS ist valide!

NewsWorld | 2009-08-07 18:45:14

LeadImage

Computerforum.de Back Online.

Computerforum.de is back online since today (07.08.09 @ 10:11) The Forum is serving 3 new Skins and many new features...

The restart was remarkable: Within a few hours, many users found their way back, and made a total of about 300 posts - after more than a month of downtime. Thanks for your loyalty.

read more...

NewsWorld | 2009-07-26 21:05:14

LeadImage

Save the Knight

Knight Rider 2008 is a great remake of the original Knight Rider. For now, Season 2 and further Releases are "unsafe".

So we need every Subscriber, to sing the ৺petition.

read more...

NewsWorld | 2009-07-09 03:20:01

LeadImage

Michael Jackson Memorial live in HD

Microsoft will stream the ৺Michael Jackson Memorial in FullHD to the web...

read more...
Copyright © 2008 - 2010 | by dog.net Development | Imprint | Load in 1.056774