Yahoo Messenger Worm Evolving - My Experience

Discussion in 'malware problems & news' started by Cadillakin, May 22, 2007.

Thread Status:
Not open for further replies.
  1. Cadillakin

    Cadillakin Registered Member

    Joined:
    May 22, 2007
    Posts:
    18
    Just a note...

    My system restore was turned off. Not that significant to me because I use True Image to do basically the same thing.. Interesting that in gpedit.msc, some of the changes by the worm, made to my system, are not showing configured as you might surmise. Instead of the changed attribute or function showing "enabled" or "disabled", it shows "not configured" as if it has never been tampered with. As noted in my initial posting up top, an enabling, disabling, accompanied by "apply" after each change, then resetting to "not configured", then apply, restores the default setting...
     
  2. splokok

    splokok Registered Member

    Joined:
    Aug 2, 2007
    Posts:
    3
    Location:
    philippines
    Good Apps you got there Andy! SDfix restored my laptop at a good point.

    But i have one more question on the table: Please help I cant see my DVD Drive anymore.

    Here's the situation:

    1. Got infected by sonahad.AI worm
    2 NOD32 took care of removing the worm but i deleted the files lsass.exe -
    it even cleaned the syshost.exe also.
    3.Found this cool forums and read a lot of useful information and got hold of SDfix - Fixed and restored all the other changed information by the worm.
    4. Two things remain pending though - My DVD drive could not be found and Restore point does not restore coz it says there is no restore point even it shows in windows.
    5. I am not that good yet but i tried to find the dllcache andy mentioned because i want to try to restore the old msconfig and rstrui. following the advice above but i cant get hold of it.

    ?? how and where can i find it in my system??

    My LAPTOP Specs

    Toshiba A105-S4004
    OS- Windows XP Media Center
    MATSHITA DVD-RAM UJ-841S
    etc.

    I tried to uninstall in the control panel the DVD drive and reinstall but i get errors still - it is detected by windows xp but it says it has errors and may not work and when i reboot - my dvd drive is still not there.

    How can i restore my system back - Is my DVD drive broken?

    Thanks a lot guys and More power to all of you masters. :ninja:
     
  3. splokok

    splokok Registered Member

    Joined:
    Aug 2, 2007
    Posts:
    3
    Location:
    philippines
    Windows cannot load the device driver for this hardware. The driver may be corrupted or missing. (Code 39)

    -

    tried windows troubleshooting but still a problem

    tried to rollback - no rollback.
    ' im lost - - please help. :mad:

    thanks :cool:
     
  4. eniqmah

    eniqmah Registered Member

    Joined:
    Jul 7, 2006
    Posts:
    391
    Just along this line, I "lock" IE, amongst some other programs, with a pw using a program named "Program protector". After that, I hide the locked IE.exe completely using "Lock folder XP". So I was disappointed when I visited the link and got no response. After unlocking IE, the fun began.
     
  5. SKA

    SKA Registered Member

    Joined:
    Aug 2, 2002
    Posts:
    181
    Can anyone give me download link for SDFix
    I cant see it in any message here

    Thanks !
    SKA
     
  6. splokok

    splokok Registered Member

    Joined:
    Aug 2, 2007
    Posts:
    3
    Location:
    philippines

    http://www.forospyware.com/t77529.html

    you can see the
    Descarga la utilidad SDFix.zip.


    :eek: guess that means download Download the utility sdfix.zip - took some small spanish lessons from my school coz the philippines is a colonial country from spain before


    :thumb: resolved all my problems = was able to restore my drive and restore points by following these steps discussed here:

    http://support.microsoft.com/kb/314060

    deleting the corropted upperfilters and lowerfilters.

    everything went fine.

    :blink: now im so busy backing up to dvd rams.


    just sharing.:D
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.