Author Message

I've have Yaha,detected by Trend Pcillin.Tried to
quarintine,back-up files,delete.Didn't work.Infected .exe
files in the win32.Able to autoplay XP install disk,but
unable to access install to repair. Tried to re-format
hard drive ,but won't let,unable to stop hard drive
because in use? What should I try next? Thank you Scott
PS. Not worried about data loss.

Thu, 23 Jun 2005 02:34:58 GMT  
What should I try next?
Check out the instructions at http://www.sarc.com  for the registry edits
that are necessary.
Since .exe has been disabled it is necessary to go to the dos command prompt
and type      ren regedit.exe regedit.com
do an enter
type exit
and you are back in windows
Go up to run in the start list and type regedit.com
you will look through HKey Local Machine for software
click on the plus beside software and scroll down looking for classes
within classes look for EXEFILE
click on the + until you come to the word command
On the right hand side the data there has to be changed
In the right pane right click on the data to edit by typing in exactly
"%1" 1*
the above is quote percent one quote space one asterisk
ok, leave that area
Look in the HKey Local Machine\Software\Microsoft\Windows\CurrentVersion\Run
and in the right pane delete the value
WinServices C:\%System%\WinServices.exe

Exit the registry editor.

Go back to the dos prompt command and redo the renaming action
ren regedit.com regedit.exe

Executable files should work now  ....and if the virus checker did its thing
it removed the three files from your Windows folder which were
winservices.exe, tcpsvs32.exe and nav32_loader.exe


Thu, 23 Jun 2005 10:08:27 GMT  
 [ 2 post ] 

 Relevant Pages 

1. I-Worm/yaha.k

2. YAHA Virus


4. yaha virus

5. YAHA virus

6. YAHA worm

7. how do i get rid of yaha worm?

8. W32/Yaha.

9. yaha\g

10. got a pretty harmless virus(w32 yaha) but cant get rid of it..help!!!

11. please help!!!..w32 yaha.k virus wont give me access to 'system restore..


Powered by phpBB® Forum Software