Aug
14

Yahoo Messenger Sending Picture Links un-necessarily

Well, lately one of my friend got this worm in her pc and this issue is getting on her nerves and mine too. Cause i am added in her messenger list and after every 5 seconds her ID sends me a message which directs me to open a link and view her PICS 😀

EXAMPLE: 1 of my vacation pictures http:// /vacation1.jpg

But apparently, there is nothing like that, rather it is a worm which gets executed right after you click that link, it gets installed into your PC and then starts behaving the same.. So its a communicable worm 😀

Anyways when i searched online for the same i got the following Solution:-

The Worm name is WORM_SOHANAD.B

1) copy the following lines as it is and paste it in notepad

REGEDIT4

[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem]
“DisableTaskMgr”=dword:00000000

[HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesSystem]
“DisableTaskMgr”=dword:00000000

[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem]
“DisableRegistryTools”=dword:00000000

[HKEY_CURRENT_USERSoftwareYahoopagerViewYMSGR_buzz]
“content url”=-

[HKEY_CURRENT_USERSoftwareYahoopagerViewYMSGR_Launchcast]
“content url”=-

[HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerMain]
“Start Page” = “http://www.yahoo.com”

[-HKEY_CURRENT_USERSoftwarePoliciesMicrosoftInternet ExplorerControl PanelHomepage]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
“Task Manager”=-

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
“Svchost”=-

Save the notepad file as “repair.reg”

Or Alternatively Download this file and rename it to repair.reg Yahoo Registry Patch

2)When saved the registry patch, now double click the file and it will ask if you want to add the registry information, click yes.

3) Now Restart your system in safe mode, by pressing f8 key before you see windows billbord logo.

4) when the Computer boots up, goto run and type windows, There you can see a file svhost32.exe and Delete the file (if it exists)

5) Now Delete the file svhost.exe from the same folder(if exists)
6) Search for: ENET.EXE and delete it if found.
7) Now on successful deletion of these files, restart you system in normal mode and see if the files you deleted still exist or they are gone forever
. The second case is more favorable 😛

if you are not successful doing this attempt, then here is the official link for trend micro antivirus go ahead and read the advanced solution :p

and they may ask you to buy their product too .. hehehe.. pretty straight forward

if you can cure ur pc with this solution, then do leave a comment, its for free :p

Good Luck,

cheers !!