Search:  In

 W32.Whybo - Description


 Browse by name

 
 | misc | a | b | c | d | e | f | g | h | i | j | k | l | m | n | o | p | q | r | s | t | u | v | w | x | y | z |

Description:
W32.Whybo is a virus that infects .exe files.


Alias:

Category:
Virus

Automatic Removal: Most effective removal tool is: Easy SpyRemover

Manual Removal:



Stop Runnin Processes:
%System%\IME\svchost.exe


Unregister DLLs:



Clean Registry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"Internt" = "%System%\internt.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"Program file" = "%System%\progmon.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\"CheckedValue" = "0"



Remove Files:
%System%\IME\svchost.exe
%System%\internt.exe
%System%\progmon.exe
%SystemDrive%:\setup.exe
[DRIVE LETTER]:\Program Files\Common Files\Microsoft Shared\[5 RANDOM LOWER CASE LETTERS].exe
[DRIVE LETTER]:\Program Files\Internet Explorer\Connection Wizard\[5 RANDOM LOWER CASE LETTERS].exe
[DRIVE LETTER]:\Program Files\Windows Media Player\[5 RANDOM LOWER CASE LETTERS].exe
[DRIVE LETTER]:\WINDOWS\addins\[5 RANDOM LOWER CASE LETTERS].exe
[DRIVE LETTER]:\WINDOWS\system32\[5 RANDOM LOWER CASE LETTERS].exe
[DRIVE LETTER]:\WINDOWS\system32\drivers\[5 RANDOM LOWER CASE LETTERS].exe
[DRIVE LETTER]:\WINDOWS\system32\dllcache\[5 RANDOM LOWER CASE LETTERS].exe
[DRIVE LETTER]:\WINDOWS\system32\IME\[5 RANDOM LOWER CASE LETTERS].exe
%SystemDrive%:\AutoRun.inf
%System%\svchost.ini
C:\pagefile.pif
%System%\DownList.ini
   


Latest Spyware Threats
    Comodo Trust Toolbar
    XP Antispyware 2009
    Antivirus 2010
    Freview
    RegistryGreat
    XPAntivirus
    Windows Antivirus 2008
    IE AntiVirus
    SpywareQuake 4
    Antivirus XP
    SecurePCCleaner
    Trojan.FakeAlert



Copyright © PcRepairCentral, 2005.