from symantec on that version you are talking about, note last paragraph. Icky poo. Unless you have lots of resources that just love terious work...
my .02 1. Restore the following registry entries to their previous values, if required: 2. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SecurityCenter\"AntiVirusDisableNotify" = "01000000" - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SecurityCenter\"FirewallDisableNotify" = "01000000" - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SecurityCenter\"UpdatesDisableNotify" = "01000000" - HKEY_CURRENT_USER\SOFTWARE\Microsoft\SecurityCenter\"AntiVirusDisableNotify" = "01000000" - HKEY_CURRENT_USER\SOFTWARE\Microsoft\SecurityCenter\"FirewallDisableNotify" = "01000000" - HKEY_CURRENT_USER\SOFTWARE\Microsoft\SecurityCenter\"UpdatesDisableNotify" = "01000000" - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\EnableFirewall" = "00000000" - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\InternetSettings\Zones\0\"1200" = "00000000" - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\InternetSettings\Zones\0\"1201" = "00000000" - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\InternetSettings\Zones\0\"1208" = "00000000" - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\InternetSettings\Zones\0\"1608" = "00000000" - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\InternetSettings\Zones\0\"1804" = "01000000" - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\InternetSettings\Zones\0\"2500" = "03000000" - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\InternetSettings\Zones\1\"1200" = "00000000" - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\InternetSettings\Zones\1\"1201" = "00000000" - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\InternetSettings\Zones\1\"1208" = "00000000" - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\InternetSettings\Zones\1\"1608" = "00000000" - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\InternetSettings\Zones\1\"1804" = "01000000" - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\InternetSettings\Zones\1\"2500" = "03000000" - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\InternetSettings\Zones\2\"1200" = "00000000" - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\InternetSettings\Zones\2\"1201" = "00000000" - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\InternetSettings\Zones\2\"1208" = "00000000" - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\InternetSettings\Zones\2\"1608" = "00000000" - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\InternetSettings\Zones\2\"1804" = "01000000" - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\InternetSettings\Zones\2\"2500" = "03000000" - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\InternetSettings\Zones\3\"1200" = "00000000" - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\InternetSettings\Zones\3\"1201" = "00000000" - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\InternetSettings\Zones\3\"1208" = "00000000" - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\InternetSettings\Zones\3\"1608" = "00000000" - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\InternetSettings\Zones\3\"1804" = "01000000" - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\InternetSettings\Zones\3\"2500" = "03000000" - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\InternetSettings\Zones\4\"1200" = "00000000" - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\InternetSettings\Zones\4\"1201" = "00000000" - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\InternetSettings\Zones\4\"1208" = "00000000" - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\InternetSettings\Zones\4\"1608" = "00000000" - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\InternetSettings\Zones\4\"1804" = "01000000" - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\InternetSettings\Zones\4\"2500" = "03000000" - HKEY_CURRENT_USER\Software\Microsoft\InternetExplorer\Main\"EnableBrowserExtensions" = "yes" - HKEY_CURRENT_USER\Software\Microsoft\InternetExplorer\Main\"SearchBar" = "http://www.google.ie" - HKEY_CURRENT_USER\Software\Microsoft\InternetExplorer\Main\"SearchPage" = "http://www.google.com" - HKEY_CURRENT_USER\Software\Microsoft\InternetExplorer\Main\"StartPage" = "http://www.google.com" - HKEY_LOCAL_MACHINE\Software\Microsoft\InternetExplorer\Main\"Default_Search_URL" = "http://www.google.ie" - HKEY_LOCAL_MACHINE\Software\Microsoft\InternetExplorer\Main\"SearchPage" = "http://www.google.com" - HKEY_LOCAL_MACHINE\Software\Microsoft\InternetExplorer\Main\"StartPage" = "http://www.google.com" - HKEY_LOCAL_MACHINE\Software\Microsoft\InternetExplorer\Search\"SearchAssistant" = "http://www.google.com" 1. Exit the Registry Editor. *Note: *If the risk creates or modifies registry subkeys or entries under HKEY_CURRENT_USER, it is possible that it created them for every user on the compromised computer. To ensure that all registry subkeys or entries are removed or restored, log on using each user account and check for any HKEY_CURRENT_USER items listed above. On Wed, Sep 2, 2009 at 10:22 AM, Dana <[email protected]> wrote: > I don't know how many machines you are talking about and you have a newer > version (presumably nastier tho) but > > the computers I worked on took a ridiculous amont of time to fix. There was > a manual fix and it involved really long lists of registry keys that might > or might now be affected. And the users thought they could not possibly have > done such a thing and instantly reinfected them One guy told me I did not > need to check his machine because he had just run virus software, Guess > which one he ran ;) > > I mean, a lot depends on who you are dealing with and how important any > data on those machines might be, But I would not do that again for anything > short of salvaging a cure for cancer, > > My suggestion is that you invest in a ghost server. For whatever that might > be worth, > > On Wed, Sep 2, 2009 at 10:08 AM, Scott Raley <[email protected]> wrote: > >> >> We are debating that now since the virus mutates on itself. >> >> >> -----Original Message----- >> From: Dana [mailto:[email protected]] >> Sent: Wednesday, September 02, 2009 11:59 AM >> To: cf-community >> Subject: Re: Fracking Hacking Spammers! >> >> >> awesome :) It would have been better to re-image the machines I am talking >> about, I was told not to, well, as a sympom of the madness there, is the >> best way I can explain it. But based on what you just said it's pretty >> much >> the only way to go any more? >> >> On Wed, Sep 2, 2009 at 9:49 AM, Scott Raley <[email protected]> wrote: >> >> > >> > It is now Antivirus 2010 and there is a new version call Braviax which >> is >> > programmed to embed itself in a lot of spyware tools, spybot, malware >> > bytes, >> > superantispyware, etc so you have to rename stuff to get it to work >> > correctly. It infects regedit and a lot of files in windows system so >> when >> > you think you fixed something you didn't. >> > >> > >> > >> >> >> >> ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~| Want to reach the ColdFusion community with something they want? Let them know on the House of Fusion mailing lists Archive: http://www.houseoffusion.com/groups/cf-community/message.cfm/messageid:303303 Subscription: http://www.houseoffusion.com/groups/cf-community/subscribe.cfm Unsubscribe: http://www.houseoffusion.com/cf_lists/unsubscribe.cfm?user=11502.10531.5
