Page 1 of 2 12 LastLast
Results 1 to 25 of 27

Thread: Virus in registry, pls help

  1. #1
    meetdilip
    Guest

    Default Virus in registry, pls help

    hi,

    mycomputer>hkey_current_user\software\microsoft\wi ndows\currentversion\internet setting\zonemap\domains\koolynoody.net

    it also exists in hkey_local_machine, hkey__users total 2 entries in current user, 2 in local machine and 6 in current user.

    It do something with the browser. when i clicked internet explorer to run yahoo antispy, my download manager(internet download accelerator), went active, ie it was about to download something.

    i ran yahoo antispy previously and removed this downloader "koolynoody". but when i restarted the system, i couldn't type yahoo in firefox or google chrome, then i clicked the C drive, but instead of opening, it showed properties. so was the case with desktop and other drive, and we couldn't type anything. i used address bar and accessed drives, checked for autorun files(after turning on hidden files). couldn't find any. i scanned regisrty for koolynoody and found one entry, the i used tune up utilities and found 10 entries. couldn't delete some of them.

    Under mycomputer>hkey_current_user\software\microsoft\wi ndows\currentversion\internet setting\ I found a lot of untrustworthy websites, having words prone, sex, download etc. too many of them.

    so is the case with current users>default, user>S-1-5.... and local machine.

    pls help me if you know something about this.

  2. #2
    kirankumargb
    Guest

    Default

    reboot your system in safe mode and the run the utility and scan for registry ..
    another thing you can do but its RISKY so back up your registry and do it...
    In safe mode go to registry and find the key and manually delete the whole key itself not just the entry ( if the entry is in its own key) else just delete the key..
    if your HDD partitions are in Fat32 reboot it with win98 start-up disk and go to command prompt and search your partition for the Autorun.inf file it compulsorily should be there if your drive when you try to open, opens anything else best way to check it is right click on drive and see what the first entry is if its OPEN then no problem, if its Autorun then there surely is a problem.
    use the start-up disk and delete all the related autoun.inf files manually(in windows they will not get deleted) to check the autorun.inf file just edit it and see what are the files it is running......!


    its browser hijacker you can follow these steps>if your using mozilla firefox then >Open Firefox
    Select TOOLS
    Select OPTIONS
    in the MAIN tab
    TICK "Always check to see if Firefox is the default browser at startup"
    OK
    Close Firefox
    Re-Open Firefox

    Answer YES to keep as default

    (Note it can be confusing if you are going to switch browsers a lot)

    --

    Kooly Noody
    You may need to reset IE settings:
    How to use Reset Internet Explorer Settings (RIES)

    To use RIES in Internet Explorer 7, follow these steps:

    1. Click the Tools menu, and then click Internet Options.
    2. On the Advanced tab, click Reset.
    3. In the Reset Internet Explorer Settings dialog box, click Reset.
    4. When Internet Explorer 7 finishes restoring the default settings, click Close, and then click OK two times.
    5. Close Internet Explorer 7. The changes take effect the next time that you open Internet Explorer 7. or u can remove it by dowloading spybot search and destroy from>www.download.com/Spybot-Search-Dest... and superantispyware from>www.superantispyware.com/superantis... scan it in safe mode by pressing F8 key then remove the infection
    Last edited by kirankumargb; 03-10-09 at 11:40 AM. Reason: addition

  3. #3
    meetdilip
    Guest

    Default i am manually deleting the entries

    thanks. i am already doing it manually. but the problem is that the internet setting(mycomputer>hkey_current_user\software\micr osoft\wi ndows\currentversion\internet setting) is showing a lot of scrap websites. about 50 i think. not sure which one is good.

    i have spybot. it should have told me when there was a modification in registry entry. please tell me how to make a registry back and registry scan.
    i did immunize ie and firefox.

    please tell me how to create a registry back up. Actaully spybot has one. i dont know how activate the stored backup.


    see, never set firefox as default, because these spyware plugins will be installed in default browser. i use ie 6 as default. i never use it. i used it to run antispy from yahoo toolbar.

    i use windows firewall. it is already blocking some features of firefox and internet download accelerator.these hijacker work with all of these. thats why i downloaded safari and google chrome.

  4. #4
    Guardian Angel just4kix's Avatar
    Join Date
    Dec 2007
    Liked
    4 times
    Posts
    10,904

    Default

    You can try "System Restore". Choose a day much before the day the problem happened.

  5. #5
    kirankumargb
    Guest

    Default

    creating the registry back up is very easy

    Open Registry Editor.
    On the File menu, click Export.
    In File name, enter a name for the registry file.
    Under Export range, do one of the following:
    To back up the entire registry, click All.
    To back up only a particular branch of the registry tree, click Selected branch and enter the name of the branch you want to export.
    Click Save.

    after backing up delete whatever you find suspicious then reboot and check if windows did not load properly then you back up the registry and try again...
    delete keys in safe mode for better authority

  6. #6
    meetdilip
    Guest

    Default can system restore replace registry settings

    i am not sure when this happened. actually i took broadband in nov. i used to get huge bills. i fixed a few problems before. i was using ie then. was a mistake. i will try registry back up. still if it already have those infected entries....

  7. #7
    meetdilip
    Guest

    Default a screenshot

    may be this will give clear picture
    Attached Images Attached Images

  8. #8
    meetdilip
    Guest

    Default screenshot

    also
    Attached Images Attached Images

  9. #9
    kirankumargb
    Guest

    Default

    which OS are you using ?
    the best is format your os and get a new os installed and then protect your system from getting infected....!

    in my system in EscDomains microsoft.com is the only site listed.... so i guess rest all are useless
    Last edited by kirankumargb; 03-10-09 at 12:55 PM. Reason: Automerged Doublepost

  10. #10
    meetdilip
    Guest

    Default Xp

    i am using windows XP SP2. i will try reinstalling.

  11. #11
    kirankumargb
    Guest

    Default

    Quote Originally Posted by meetdilip View Post
    i am using windows XP SP2. i will try reinstalling.
    DONT just re-install, format that drive and reinstall it...

  12. #12
    meetdilip
    Guest

    Default

    it works

  13. #13
    Bronze Member
    Join Date
    Dec 2008
    Age
    20
    Liked
    0 times
    Posts
    169

    Default

    Best option : Format & reinstall XP
    2nd option : Visit Trend Micro HouseCall - Free Online Virus and Spyware Scan - Trend Micro USA for free online scan & remove.
    3rd option : Download & install any security suite or some specific virus/malware remover ( if u know the name of the virus)

  14. #14
    meetdilip
    Guest

    Default Kooly noody is back again

    Hi ,

    My system was hanging at times. So I used CA Yahoo Antispy. It detected Kooly Noody. I chose remove options. Traces are still there. As instructed by Kiran in one of the earlier posts, I tried to reset internet setting. But it says the settings do not allow. Is there any alternate way for doing that? I have Avira + Adaware+ CCleaner + Spybot. All those scans failed to give a result. Can you help me with this.

    1. A specific Kooly Noody removal tool.

    2. Reset internet settings. I use IE6.

    I tried to find a solution, but in vain. Please help.
    Last edited by meetdilip; 04-22-09 at 04:21 PM.

  15. #15
    kirankumargb
    Guest

    Default

    here is the link to manually remove the code try and update if worked...!

    http://www.ehow.com/how_4896274_remo...y-spyware.html

  16. #16
    meetdilip
    Guest

    Default

    Thanks Kiran. I did it. But under internet settings, there are a lot of domains. I removed those under current user. But it seems it is also under local machine, users etc. Can I use IE 8 to reset the IE settings. Because IE 6 does not support it. I use a non genuine version of Windows XP. So if IE 8 has some detection or something. Please let me know what you think.

  17. #17
    Guardian Angel just4kix's Avatar
    Join Date
    Dec 2007
    Liked
    4 times
    Posts
    10,904

    Default

    On the whole, it seems to be best if you reformat the HDD and reinstall the OS. Or have you done it already?

  18. #18
    meetdilip
    Guest

    Default

    I used Control panel to reset the internet settings. I was unable to do it. Please check the screen shots. My installation has only one user and am logged in as administrator.



    Attached Images Attached Images
    • File Type: png 1.png (10.8 KB, 14 views)
    • File Type: png 2.png (41.9 KB, 14 views)

  19. #19
    meetdilip
    Guest

    Default

    Quote Originally Posted by just4kix View Post
    On the whole, it seems to be best if you reformat the HDD and reinstall the OS. Or have you done it already?
    Thanks Just4kix. I just tried formatting C till date. I wanted to avoid full format for a few more days. Till i get a new hard disk. I have some useful data in the present one, which is too costly (for me) to erase. It leaves me no option but to fight this some how.


    If someone can suggest any specific tools for Kooly Noody, it will be great help.
    Last edited by meetdilip; 04-22-09 at 10:53 PM.

  20. #20
    The One
    Guest

    Default

    @meetdilip

    Did you check this e-how article?

    How to Remove the KoolyNoody Spyware

  21. #21
    Guardian Angel just4kix's Avatar
    Join Date
    Dec 2007
    Liked
    4 times
    Posts
    10,904

    Default

    You can save your data somewhere. Plain data files, media files, etc. are not affected. But abandon all hope on EXE, DLL, etc.Your PC has been completely hijacked; probably you may have tried to install a keygen. Be it as it may, salvage whatever data you can, ignore all installables, and reinstall everything. Remember that you USB drives must have also been affected. This applies to installables burned on the CD/DVD also.

    Do the following:

    1. Reformat and reinstall OS. Do not connect to internet at all till said so.
    2. If you have a clean copy of AV then install it next.
    3. Now connect to internet and download the latest AV updates+upgrades. Disconnect from internet.
    4. Scan you USB drives for any virus/tojan/worm/etc.
    5. Install genuine/licensed software only.
    6. Buy a licensed copy of Net Nanny (only $25) that will prevent visits to porno+virus filled sites.
    I faced this problem when I was using pirated copy of Windows and freeware. That was 3 years ago. I have sworn off pirated stuff since then. People spend 40~50K on hardware. They pay Rs. 600 to Rs. 1000 pm for internet access. Some play online games and spend even more. But people are unwilling to spend less than 10K on genuine software and say that they cannot afford it.
    Last edited by just4kix; 04-23-09 at 11:22 AM. Reason: Somehow CR+LF got removed
    *** Never argue with an idiot. ***

    All my useful articles and Guides | My Movie Collection | My Blogs
    -------------------------------------------------------------------------------------------

  22. #22
    meetdilip
    Guest

    Default

    Quote Originally Posted by dhaneshv View Post
    @meetdilip

    Did you check this e-how article?

    How to Remove the KoolyNoody Spyware
    Yes. I did removed the reg keys. But there is a problem as you can see in the screen shots. I cannot reset my internet settings.

    @just4kix

    I totally agree with your views.

  23. #23
    The One
    Guest

    Default

    Yes. I also agree with what just4kix have said.
    Quote Originally Posted by just4kix View Post
    Buy a licensed copy of Net Nanny (only $25) that will prevent visits to porno+virus filled sites.
    But, there is no need of this, because the free McAfee Site Advisor or WOT plug-in for web browsers can solve that kind of problems and they are the best out there in the Internet for Parental Control (which is widely called so). Therefore, I don't see any need of buying one.

  24. #24
    meetdilip
    Guest

    Default Latest

    Just take a look what the Virus has done to my system. The system status was ok when I installed Tuneup Utilities 2009 last night. Now it is like this. I cannot change the settings even in TuneUp utities. Just wanted to share, that others can have some use on a later period.







    Attached Images Attached Images
    • File Type: png 1.png (29.2 KB, 11 views)
    • File Type: png 2.png (30.9 KB, 12 views)
    • File Type: png 3.png (27.4 KB, 11 views)
    • File Type: png 4.png (29.0 KB, 11 views)

  25. #25
    meetdilip
    Guest

    Default

    Tuneup utilities proved to be a better one than I imagined. I deleted every registry entry manually. Disconnected the internet. Went for a restart. Took tuneup utilities. Changed all these hostile setting. Now it seems everything is ok. It did reset the administrative right i lost for the internet explorer.

    Thanks Tuneup Utilities.

Page 1 of 2 12 LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. How often should I run a virus scan?
    By lockgold20 in forum Desktop Computer
    Replies: 6
    Last Post: 04-28-10, 05:58 PM
  2. How often should I run a virus scan?
    By lockgold20 in forum Computer Security
    Replies: 1
    Last Post: 02-10-10, 05:27 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •