<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Techie Bubble &#187; Security</title>
	<atom:link href="http://www.techiebubble.com/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.techiebubble.com</link>
	<description>Technology in our everyday life</description>
	<lastBuildDate>Tue, 14 Apr 2009 23:54:12 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Remove Conficker/Downadup/Kido worm virus before April 1, 2009</title>
		<link>http://www.techiebubble.com/security/remove-conficker-downadup-kido-worm-virus-before-april-1-2009/</link>
		<comments>http://www.techiebubble.com/security/remove-conficker-downadup-kido-worm-virus-before-april-1-2009/#comments</comments>
		<pubDate>Sat, 28 Mar 2009 00:54:41 +0000</pubDate>
		<dc:creator>Ryman</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[anti-malware]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[Downadup]]></category>
		<category><![CDATA[removal]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.techiebubble.com/?p=44</guid>
		<description><![CDATA[Updated: March 31, 2009
Added domain keywords &#38; manual download of patches for Windows XP and Vista

The Conficker worm virus is spreading around the internet, and it&#8217;s ability to spread via network makes it much faster and harder to remove completely. I first encountered the virus on a friend&#8217;s laptop, which infected another friend&#8217;s digital camera [...]]]></description>
			<content:encoded><![CDATA[<p>Updated: March 31, 2009<br />
Added domain keywords &amp; manual download of patches for Windows XP and Vista</p>
<hr />
The <strong>Conficker worm</strong> virus is spreading around the internet, and it&#8217;s ability to spread via network makes it much faster and harder to remove completely. I first encountered the virus on a friend&#8217;s laptop, which infected another friend&#8217;s digital camera via USB. I also encountered this at the computers at the office. Incidentally as of this post, only two computers at the office within the network was not affected, mine (Windows XP SP3) and one of my officemate who is using Open Suse (Linux). I wasn&#8217;t going to post this, but then I got a news alert from one of my feeds, and it seems it already has infected 9 &#8211; 15 million computers around the world.</p>
<blockquote><p><strong>Conficker</strong>, also known as <strong>Downup</strong>, <strong>Downadup</strong> and <strong>Kido</strong>, is a computer worm that surfaced in October 2008 and targets the Microsoft Windows operating system. The worm exploits a known vulnerability in the Windows Server service used by Windows 2000, Windows XP, Windows Vista, Windows Server 2003, Windows Server 2008, and Windows 7 Beta. The latest variant will begin checking for a payload to download on April 1, 2009. [<a href="http://en.wikipedia.org/wiki/Conficker"rel="nofollow"  target="_blank">wiki</a>]</p></blockquote>
<p>The news report I got was from CNN regarding the<a href="http://edition.cnn.com/2009/TECH/03/24/conficker.computer.worm/index.html"rel="nofollow"  target="_blank"> <strong>Conficker C </strong>computer worm which is expected to activate on April Fool&#8217;s Day</a> (April 1, 2009).</p>
<blockquote><p>Those infections haven&#8217;t spawned many symptoms, but on April 1 a master computer is scheduled to gain control of these zombie machines, said Don DeBolt, director of threat research for CA, a New York-based IT and software company.</p>
<p>&#8230;</p>
<p>The program could delete all of the files on a person&#8217;s computer, use zombie PCs &#8212; those controlled by a master &#8212; to overwhelm and shut down Web sites or monitor a person&#8217;s keyboard strokes to collect private information like passwords or bank account information, experts said.</p></blockquote>
<p><a href="http://www.thetechherald.com/article.php/200911/3157/Conficker-Worm-fighting-back-a-new-variant-discovered-disables-security-measures"rel="nofollow"  target="_blank">The Tech Herald is on the same note regarding the Conficker</a>.</p>
<blockquote><p>“This worm, detected as Win32/Conficker.C, is getting ready for April Fool’s Day on 1 April, although it definitely won’t be fooling around. On that day, Conficker.C will commence its attempt to generate 50,000 URLs daily and try to access (download or report back to) 500 of them. It is a clever strategy, but the security industry is certainly on the lookout.”</p></blockquote>
<p><strong>Conficker A</strong> was reportedly released around November 2008. While <strong>Conficker B</strong> evolved around January 2009. <strong>Conficker C</strong> is the latest version of this worm which most systems now are already affected, and is said to activate on April 1, 2009.</p>
<p>I have already posted a similar topic a couple of days ago titled &#8220;<a href="http://www.techiebubble.com/security/how-to-remove-the-jwgkvsqvmx-worm-virus/">How to remove the jwgkvsq.vmx worm virus</a>&#8221; which was when I started to notice the virus in our network, it was the Conficker worm. I dismissed it as an ordinary virus. But it seems that it has been spreading around a lot lately. Now its security level is &#8216;highly dangerous&#8217;.</p>
<p><strong>Symptoms to check if your computer is infected with this:</strong></p>
<ul>
<li>Show all hidden files and folders are not working</li>
<li>Can&#8217;t access anti-virus websites like: Bitdefender.com Symantec.com, and patch sites like Microsoft.</li>
<li>The existence of a file named: <strong>jwgkvsq.vmx</strong> inside the RECYCLED folder.</li>
<li>Creates <strong>autorun.inf</strong> files on USB devices plugged in an infected machine. Also other viruses does this.</li>
<li>Account lockout policies being reset automatically.</li>
<li> Certain Microsoft Windows services such as Automatic Updates, Background Intelligent Transfer Service (BITS), Windows Defender and Error Reporting Services are automatically disabled.</li>
<li>Domain controllers respond slowly to client requests.</li>
<li>System network gets unusually congested. This can be checked with network traffic chart on Windows Task Manager.</li>
<li>Launches a brute force dictionary attack against administrator passwords to help it spread through ADMIN$ shares, making choice of sensible passwords advisable.</li>
</ul>
<p><strong>Remove the virus:</strong></p>
<p>Some of the well-known security companies came up with <strong>tools for removing the Conficker/Downandup worm virus</strong>. Removal tools can be freely downloaded from any of the following security sites:</p>
<ul>
<li><a href="http://www.microsoft.com/security/malwareremove/default.mspx"rel="nofollow"  target="_blank"> Microsoft</a></li>
<li><a href="http://www.bitdefender.com/VIRUS-1000462-en--Win32.Worm.Downadup.Gen.html"rel="nofollow"  target="_blank"> BitDefender</a></li>
<li><a href="http://download.eset.com/special/EConfickerRemover.exe"rel="nofollow"  target="_blank"> ESET</a></li>
<li><a href="http://www.symantec.com/security_response/writeup.jsp?docid=2008-112203-2408-99&amp;tabid=3"rel="nofollow"  target="_blank"> Symantec</a></li>
<li><a href="http://www.sophos.com/products/free-tools/conficker-removal-tool.html"rel="nofollow"  target="_blank"> Sophos</a></li>
<li><a href="http://support.kaspersky.com/faq/?qid=208279973 F-Secure http://www.f-secure.com/v-descs/worm_w32_downadup_al.shtml"rel="nofollow"  target="_blank"> Kaspersky Lab</a></li>
<li><a href="http://vil.nai.com/vil/stinger/"rel="nofollow"  target="_blank">McAfee</a> Anti-virus with updated detections can remove this by scanning your system.</li>
<li>AVG can also remove it via system scan, if you have it installed and updated.</li>
</ul>
<p><strong>How to remove the Conficker/Downandup worm virus?</strong></p>
<ol>
<li>Download Conficker/Downandup removal tools from the given sites above.</li>
<li>Disconnect from the internet, and remove any network cables at the back of your PC/laptop, and also remove any plugged-in USB devices.</li>
<li>Login as Administrator on your computer, or any account that has administrator privileges.</li>
<li>Run the removal tool. My recommendation is to use the removal tools from <em>BitDefender</em> (quick scan) and <em>Symantec</em> (thorough scan). But if you are not content, just run all the removal tools for greater detection.<em>Simple-case:</em> The removal tool will detect and remove the Conficker worm and &#8216;may&#8217; require that you restart your computer.<br />
<em>Extreme-case:</em> The removal tool won&#8217;t run because the virus is preventing it from running. Quick solution:</p>
<ol>
<li>Open task manager (CTRL+ATL+DEL)</li>
<li>Terminate (End) the process with these names: <strong>explorer.exe</strong> and <strong>svchost.exe</strong></li>
<li>A countdown timer will appear requiring you to restart your computer. DO NOT DO ANYTHING AT THIS POINT EXCEPT&#8230; Immediately run the BitDefender Tool (quick scan) so that it will remove the virus before your computer restarts.</li>
<li>If the tool won&#8217;t still run, &#8216;end process&#8217; all the <strong>svchost.exe</strong> and try running the removal tool again.</li>
</ol>
</li>
</ol>
<p>It only affects Windows system that aren&#8217;t patched with the latest update. <strong>Run autoupdate and patch your Windows</strong>. It is critical that these patches be installed:</p>
<p>Microsoft Security Bulletin MS08-067 – Critical<br />
Vulnerability in Server Service Could Allow Remote Code Execution (958644)<br />
<a href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx"rel="nofollow"  target="_blank">http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx</a> (<a href="http://download.microsoft.com/download/4/f/a/4fabe08e-5358-418b-81dd-d5038730b324/WindowsXP-KB958644-x86-ENU.exe"rel="nofollow" >download for XP</a>)</p>
<p>Microsoft Security Bulletin MS08-068 – Important<br />
Vulnerability in SMB Could Allow Remote Code Execution (957097)<br />
<a href="http://www.microsoft.com/technet/security/bulletin/ms08-068.mspx"rel="nofollow"  target="_blank">http://www.microsoft.com/technet/security/bulletin/ms08-068.mspx</a> (<a href="http://download.microsoft.com/download/4/b/c/4bcfd71b-1f5a-4f9c-8c57-0b7ba2aae684/WindowsXP-KB957097-x86-ENU.exe"rel="nofollow" >download for XP</a>)</p>
<p>Microsoft Security Bulletin MS09-001 &#8211; Critical<br />
Vulnerabilities in SMB Could Allow Remote Code Execution (958687)<br />
<a href="http://www.microsoft.com/technet/security/bulletin/ms09-001.mspx"rel="nofollow"  target="_blank">http://www.microsoft.com/technet/security/bulletin/ms09-001.mspx</a> (<a href="http://download.microsoft.com/download/B/9/7/B9798068-1B3B-4EE7-BC2A-2371C54B0ADD/WindowsXP-KB958687-x86-ENU.exe"rel="nofollow" >download for XP</a>)</p>
<p>For <strong>manual download of patches for Windows XP and Vista</strong> go to <a href="http://www.softwarepatch.com/windows/"rel="nofollow" >http://www.softwarepatch.com/windows/</a></p>
<p><strong>TAKE NOTE:</strong></p>
<p>The virus spreads via network, so plugging your computer/laptop again through the network the virus may infect it if your software isn&#8217;t patched.</p>
<p>The virus also spreads via autorun.inf on USB devices, plugging an infected USB device may infect your computer.</p>
<p>For questions regarding the removal of this virus and other inquiries regarding the topic feel free to leave a comment, and I&#8217;ll get back to you.</p>
<p>Extra resources you may find useful:<br />
<a href="http://www.downadup.com/remove-downadup.php"rel="nofollow"  target="_blank">Removing Downadup and Repairing</a> [downadup.com]</p>
<p>If your computer is infected, you won&#8217;t be able to visit sites (error timed out) with these keywords on their domain name:<br />
<span id="more-44"></span></p>
<ul>
<li>virus</li>
<li>spyware</li>
<li>malware</li>
<li>rootkit</li>
<li>defender</li>
<li>microsoft</li>
<li>symantec</li>
<li>norton</li>
<li>mcafee</li>
<li>trendmicro</li>
<li>sophos</li>
<li>panda</li>
<li>etrust</li>
<li>networkassociates</li>
<li>computerassociates</li>
<li>f-secure</li>
<li>kaspersky</li>
<li>jotti</li>
<li>f-prot</li>
<li>nod32</li>
<li>eset</li>
<li>grisoft</li>
<li>drweb</li>
<li>centralcommand</li>
<li>ahnlab</li>
<li>esafe</li>
<li>avast</li>
<li>avira</li>
<li>quickheal</li>
<li>comodo</li>
<li>clamav</li>
<li>ewido</li>
<li>fortinet</li>
<li>gdata</li>
<li>hacksoft</li>
<li>hauri</li>
<li>ikarus</li>
<li>k7computing</li>
<li>norman</li>
<li>pctools</li>
<li>prevx</li>
<li>rising</li>
<li>securecomputing</li>
<li>sunbelt</li>
<li>emsisoft</li>
<li>arcabit</li>
<li>cpsecure</li>
<li>spamhaus</li>
<li>castlecops</li>
<li>threatexpert</li>
<li>wilderssecurity</li>
<li>windowsupdate</li>
<li>nai.</li>
<li>ca.</li>
<li>avp.</li>
<li>avg.</li>
<li>vet.</li>
<li>bit9.</li>
<li>sans.</li>
<li>cert.</li>
</ul>
<h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://www.techiebubble.com/security/how-to-remove-the-acrobatcomexe-worm-virus/" title="How to remove the ACROBAT.COM.EXE worm virus">How to remove the ACROBAT.COM.EXE worm virus</a></li><li><a href="http://www.techiebubble.com/security/how-to-remove-the-jwgkvsqvmx-worm-virus/" title="How to remove the jwgkvsq.vmx worm virus">How to remove the jwgkvsq.vmx worm virus</a></li><li><a href="http://www.techiebubble.com/security/how-to-remove-the-lkhdexe-cqtvsexe-virus/" title="How to remove the lkhd.exe / cqtvs.exe virus">How to remove the lkhd.exe / cqtvs.exe virus</a></li></ul><hr />
<p><small>© Ryman for <a href="http://www.techiebubble.com">Techie Bubble</a>, 2009. |
<a href="http://www.techiebubble.com/security/remove-conficker-downadup-kido-worm-virus-before-april-1-2009/">Permalink</a> |
<a href="http://www.techiebubble.com/security/remove-conficker-downadup-kido-worm-virus-before-april-1-2009/#comments">5 comments</a><br/>
Post tags: <a href="http://www.techiebubble.com/tag/anti-malware/" rel="nofollow tag">anti-malware</a>, <a href="http://www.techiebubble.com/tag/anti-virus/" rel="nofollow tag">anti-virus</a>, <a href="http://www.techiebubble.com/tag/conficker/" rel="nofollow tag">Conficker</a>, <a href="http://www.techiebubble.com/tag/downadup/" rel="nofollow tag">Downadup</a>, <a href="http://www.techiebubble.com/tag/removal/" rel="nofollow tag">removal</a>, <a href="http://www.techiebubble.com/tag/virus/" rel="nofollow tag">virus</a>, <a href="http://www.techiebubble.com/tag/worm/" rel="nofollow tag">worm</a><br/>
This Feed is for personal non-commercial use only. If you are not reading this material in your Feed Reader, News Aggregator, or RSS Reader, then the site you are looking at is guilty of copyright infringement. Please contact infinity@eternalmoonlight.net so we can take legal action immediately.
</small></p>]]></content:encoded>
			<wfw:commentRss>http://www.techiebubble.com/security/remove-conficker-downadup-kido-worm-virus-before-april-1-2009/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>How to remove the lkhd.exe / cqtvs.exe virus</title>
		<link>http://www.techiebubble.com/security/how-to-remove-the-lkhdexe-cqtvsexe-virus/</link>
		<comments>http://www.techiebubble.com/security/how-to-remove-the-lkhdexe-cqtvsexe-virus/#comments</comments>
		<pubDate>Wed, 18 Mar 2009 07:51:19 +0000</pubDate>
		<dc:creator>Ryman</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[cqtvs.exe]]></category>
		<category><![CDATA[lkhd.exe]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[ydgp.exe]]></category>

		<guid isPermaLink="false">http://www.techiebubble.com/?p=39</guid>
		<description><![CDATA[Type: Trojan/Malware
It also spreads via USB drives.
If you found a file with the name lkhd.exe or cqtvs.exe residing on your computer, or is running on a process (task manager), or in a startup program, it maybe a virus.
It is a variant of YDGP.EXE virus.
To remove the lkhd.exe or cqtvs.exe virus?
Just download and run the Prevx [...]]]></description>
			<content:encoded><![CDATA[<p>Type: Trojan/Malware</p>
<p>It also spreads via USB drives.</p>
<p>If you found a file with the name <strong>lkhd.exe</strong> or <strong>cqtvs.exe</strong> residing on your computer, or is running on a process (task manager), or in a startup program, it maybe a virus.</p>
<p>It is a variant of <strong>YDGP.EXE</strong> virus.</p>
<p>To remove the lkhd.exe or cqtvs.exe virus?<br />
Just download and run the <a href="http://spywarefiles.prevx.com/RRJIBA27941874/YDGP.EXE.html"rel="nofollow"  target="_blank">Prevx CSI scanner</a>. It will remove any trace of the virus.</p>
<p>After downloading, installing, and running the program it will ask you for a purchase code to cleanup the infections it found. Don&#8217;t worry, you don&#8217;t have to pay, just navigate to the directory (in the report) where the infected file is located, and just delete it manually.</p>
<h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://www.techiebubble.com/security/remove-conficker-downadup-kido-worm-virus-before-april-1-2009/" title="Remove Conficker/Downadup/Kido worm virus before April 1, 2009">Remove Conficker/Downadup/Kido worm virus before April 1, 2009</a></li><li><a href="http://www.techiebubble.com/security/how-to-remove-the-acrobatcomexe-worm-virus/" title="How to remove the ACROBAT.COM.EXE worm virus">How to remove the ACROBAT.COM.EXE worm virus</a></li><li><a href="http://www.techiebubble.com/security/how-to-remove-the-jwgkvsqvmx-worm-virus/" title="How to remove the jwgkvsq.vmx worm virus">How to remove the jwgkvsq.vmx worm virus</a></li></ul><hr />
<p><small>© Ryman for <a href="http://www.techiebubble.com">Techie Bubble</a>, 2009. |
<a href="http://www.techiebubble.com/security/how-to-remove-the-lkhdexe-cqtvsexe-virus/">Permalink</a> |
<a href="http://www.techiebubble.com/security/how-to-remove-the-lkhdexe-cqtvsexe-virus/#comments">No comment</a><br/>
Post tags: <a href="http://www.techiebubble.com/tag/cqtvsexe/" rel="nofollow tag">cqtvs.exe</a>, <a href="http://www.techiebubble.com/tag/lkhdexe/" rel="nofollow tag">lkhd.exe</a>, <a href="http://www.techiebubble.com/tag/trojan/" rel="nofollow tag">trojan</a>, <a href="http://www.techiebubble.com/tag/virus/" rel="nofollow tag">virus</a>, <a href="http://www.techiebubble.com/tag/ydgpexe/" rel="nofollow tag">ydgp.exe</a><br/>
This Feed is for personal non-commercial use only. If you are not reading this material in your Feed Reader, News Aggregator, or RSS Reader, then the site you are looking at is guilty of copyright infringement. Please contact infinity@eternalmoonlight.net so we can take legal action immediately.
</small></p>]]></content:encoded>
			<wfw:commentRss>http://www.techiebubble.com/security/how-to-remove-the-lkhdexe-cqtvsexe-virus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to remove the ACROBAT.COM.EXE worm virus</title>
		<link>http://www.techiebubble.com/security/how-to-remove-the-acrobatcomexe-worm-virus/</link>
		<comments>http://www.techiebubble.com/security/how-to-remove-the-acrobatcomexe-worm-virus/#comments</comments>
		<pubDate>Wed, 18 Mar 2009 07:41:37 +0000</pubDate>
		<dc:creator>Ryman</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Acrobat.com.exe]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.techiebubble.com/?p=36</guid>
		<description><![CDATA[You know you have this kind of virus if it &#8220;Creates system tray popups, messages, errors and security warnings&#8221; every time you use your computer.
How to remove the acrobat.com.exe virus?
Just download and run the Prevx CSI scanner. It will remove any trace of the virus.
After downloading, installing, and running the program it will ask you [...]]]></description>
			<content:encoded><![CDATA[<p>You know you have this kind of virus if it &#8220;Creates system tray popups, messages, errors and security warnings&#8221; every time you use your computer.</p>
<p>How to remove the acrobat.com.exe virus?<br />
Just download and run the <a href="http://spywarefiles.prevx.com/spywarefiles.asp?FXC=FHCJ44857431"rel="nofollow"  target="_blank">Prevx CSI scanner</a>. It will remove any trace of the virus.</p>
<p>After downloading, installing, and running the program it will ask you for a purchase code to cleanup the infections it found. Don&#8217;t worry, you don&#8217;t have to pay, just navigate to the directory (in the report) where the infected file is located, and just delete it manually.</p>
<h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://www.techiebubble.com/security/remove-conficker-downadup-kido-worm-virus-before-april-1-2009/" title="Remove Conficker/Downadup/Kido worm virus before April 1, 2009">Remove Conficker/Downadup/Kido worm virus before April 1, 2009</a></li><li><a href="http://www.techiebubble.com/security/how-to-remove-the-jwgkvsqvmx-worm-virus/" title="How to remove the jwgkvsq.vmx worm virus">How to remove the jwgkvsq.vmx worm virus</a></li><li><a href="http://www.techiebubble.com/security/how-to-remove-the-lkhdexe-cqtvsexe-virus/" title="How to remove the lkhd.exe / cqtvs.exe virus">How to remove the lkhd.exe / cqtvs.exe virus</a></li></ul><hr />
<p><small>© Ryman for <a href="http://www.techiebubble.com">Techie Bubble</a>, 2009. |
<a href="http://www.techiebubble.com/security/how-to-remove-the-acrobatcomexe-worm-virus/">Permalink</a> |
<a href="http://www.techiebubble.com/security/how-to-remove-the-acrobatcomexe-worm-virus/#comments">2 comments</a><br/>
Post tags: <a href="http://www.techiebubble.com/tag/acrobatcomexe/" rel="nofollow tag">Acrobat.com.exe</a>, <a href="http://www.techiebubble.com/tag/virus/" rel="nofollow tag">virus</a>, <a href="http://www.techiebubble.com/tag/worm/" rel="nofollow tag">worm</a><br/>
This Feed is for personal non-commercial use only. If you are not reading this material in your Feed Reader, News Aggregator, or RSS Reader, then the site you are looking at is guilty of copyright infringement. Please contact infinity@eternalmoonlight.net so we can take legal action immediately.
</small></p>]]></content:encoded>
			<wfw:commentRss>http://www.techiebubble.com/security/how-to-remove-the-acrobatcomexe-worm-virus/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>How to remove the jwgkvsq.vmx worm virus</title>
		<link>http://www.techiebubble.com/security/how-to-remove-the-jwgkvsqvmx-worm-virus/</link>
		<comments>http://www.techiebubble.com/security/how-to-remove-the-jwgkvsqvmx-worm-virus/#comments</comments>
		<pubDate>Wed, 11 Mar 2009 05:32:07 +0000</pubDate>
		<dc:creator>Ryman</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[jwgkvsq.vmx]]></category>
		<category><![CDATA[network virus]]></category>
		<category><![CDATA[USB virus]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[W32/Confi]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.techiebubble.com/?p=28</guid>
		<description><![CDATA[The jwgkvsq.vmx is a worm-type virus, which spreads via USB/portable drives and through the network. It also makes autorun.inf file on your USB device as well as a hidden system folder called RECYCLER which contains the jwgkvsq.vmx file. I&#8217;m not sure if this is an old virus, but it seems it&#8217;s been spreading a lot [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>jwgkvsq.vmx</strong> is a worm-type virus, which spreads via USB/portable drives and through the network. It also makes autorun.inf file on your USB device as well as a hidden system folder called <strong>RECYCLER</strong> which contains the <strong>jwgkvsq.vmx</strong> file. I&#8217;m not sure if this is an old virus, but it seems it&#8217;s been spreading a lot lately. And most anti-virus doesn&#8217;t detect this, but for those who does, it can&#8217;t remove it.</p>
<p>It is also known as:</p>
<ul>
<li>W32/Confi</li>
<li>W32/Conficker.worm!inf</li>
<li>Win32/Conficker.B &#8211; CA</li>
</ul>
<p>It exploits Microsoft Windows vulnerability:<br />
<a href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx"rel="nofollow"  target="_blank">Microsoft Security Bulletin MS08-067 – Critical</a><br />
Vulnerability in Server Service Could Allow Remote Code Execution (958644)<br />
Published: October 23, 2008</p>
<p><strong>Symptoms:</strong></p>
<ul>
<li><strong>&#8216;Show hidden files and folders&#8217;</strong> doesn&#8217;t work. You can check this by going to a folder, then click Tools, then Folder Options, then View tab. Select the <strong>&#8216;Show hidden files and folders&#8217;</strong> then click Apply, then Ok. Open Folder Options again, if it reverted back to &#8216;Do not show hidden files and folders&#8217; then you have this virus.</li>
<li>Evey time you plug in a USB device on your computer, it creates an <strong>autorun.inf</strong> file, and a RECYCLER folder with the <strong>jwgkvsq.vmx</strong> virus file.</li>
<li>You can&#8217;t access anti-virus websites an other popular websites like microsoft.com or yahoo.com</li>
<li>Windows won&#8217;t boot into Safe Mode. This happens on extreme cases. When you try to boot into Safe Mode, your computer restarts/shuts down</li>
</ul>
<p><strong>Side-effects</strong></p>
<ul>
<li>Since this is a worm, system slowdown may (or may not) happen.</li>
<li>Quickly spreads through networked computers and USB devices. Which includes flash drives, portable external hard drives, mobile phones, mp3 players, and anything that can be plugged into a USB port.</li>
<li>Won&#8217;t let you access some websites.</li>
</ul>
<p>Now let&#8217;s go back to the topic. Remember that this guide will only help you remove the <strong>jwgkvsq.vmx</strong> virus.</p>
<p>Click through the link to continue&#8230;<br />
<span id="more-28"></span></p>
<p>Here is a quick step to remove this virus from your computer, and from your USB devices.</p>
<p><strong>Preparation:</strong></p>
<ul>
<li>Download <a href="http://www.symantec.com/content/en/us/global/removal_tool/threat_writeups/FixDownadup.exe"rel="nofollow"  target="_blank">FixDownadup.exe</a> from Symantec.com</li>
<li>Download <a href="http://download.bitdefender.com/resources/files/Download/en/anti-Downadup-EN.zip"rel="nofollow"  target="_blank">anti-Downadup-EN.zip</a> from BitDefender.com (just in case the first one doesn&#8217;t work).</li>
<li>Download <em>Process Explorer</em> and <em>AutoRuns</em> from <a href="http://technet.microsoft.com/en-us/sysinternals/default.aspx" rel="nofollow"  target="_blank">Sysinternals</a> (we may or may not use this).</li>
<li>Download <a href="http://www.moatsoft.com/MosoForceDelete.zip"rel="nofollow"  target="_blank">MoSo Force Delete</a> (just in case we need to delete something that can&#8217;t be deleted).</li>
</ul>
<p>Now let&#8217;s start&#8230;</p>
<p><strong>Removing the jwgkvsq.vmx virus from your computer</strong></p>
<ol>
<li>Disconnect your computer from the network, if it is connected. Removing the network cable from your PC should do the trick.</li>
<li>Just run the <em>FixDownadup.exe</em> we downloaded from Symantec. It should clean the virus of the PC. This works if the infection is in a low-level state. Meaning you have anti-virus software already running and the infection is isolated.</li>
<li>After scanning you should see a report popup, and an option to go to Microsoft website to patch your computer with a critical security update.</li>
<li>Restart your computer. When you&#8217;re back on the desktop, check your programs/softwares if it is still running.</li>
<li>Turn of System Restore to delete all entries, which sometimes contains remnants of the virus. To do this:
<ol type="a">
<li>Right-click My Computer, select Properties.</li>
<li>Click System Restore tab.</li>
<li>Check &#8216;Turn off System Restore on all drives&#8217;. Click Apply, then Ok.</li>
<li>Restart your computer.</li>
<li>Then, uncheck &#8216;Turn off System Restore on all drives&#8217; to enable it again.</li>
</ol>
</li>
</ol>
<p><strong>Removing the jwgkvsq.vmx virus from your USB device</strong></p>
<ol>
<li>First. Start your computer on Safe Mode
<ol type="a">
<li>Shut down your computer</li>
<li>Turn it back on, before the Windows loading screen comes up, press F8. Or just press it repeatedly after starting your computer</li>
<li>Select Safe Mode on the menu by pressing the arrow keys and hitting Enter.</li>
</ol>
</li>
<li>Plug your USB device. Notice that the <strong>autorun.inf</strong> won&#8217;t run in safe mode.</li>
<li>Enable the &#8216;Show hidden files and folders&#8217;. Instructions are listed on the Symptoms section above.</li>
<li>Delete <strong>autorun.inf</strong> file. It is usually located on the root of the USB drive.</li>
<li>Delete the hidden/system folder RECYCLER.
<ol type="a">
<li>If you can&#8217;t delete it, you have to disable it&#8217;s function (for external/portable hard drives). Right-click on the Recycle Bin icon on your desktop, then select Properties. Select &#8216;Configure drives independently&#8217;. Then tab to the external drive, and check &#8216;Do not move files to the Recycle Bin.&#8217; Hit Apply, then Ok&#8217;</li>
<li>If it is a flash drive or other USB device, use MoSo Force Delete, we&#8217;ve downloaded earlier on this guide.</li>
</ol>
</li>
</ol>
<p>Just in case the virus registered itself on the registry. Open the Run dialog box from the start menu, then type <strong>regedit</strong>. Then search for the file name <strong>jwgkvsq.vmx</strong>. If you found an entry, just press DEL to delete it.</p>
<p>If your computer is in a network, better check all the other computers connected to it. Also download and install the automatic update (Microsoft vulnerability) which I&#8217;ve posted at the beginning of this post.</p>
<p>In extreme cases, your computer won&#8217;t initiate Safe Mode and after using the removal tool above, your system may report a missing .dll file or something.</p>
<p>Credits (and for reference refer) to these two sites:<br />
<a href="http://tuxvoid.blogspot.com/2009/02/jwgkvsqvmx-wormvirus.html"rel="nofollow"  target="_blank">http://tuxvoid.blogspot.com/</a><br />
<a href="http://arpeex.blogspot.com/2009/02/problem-of-jwgkvsqvmx-has-been-resolved.html"rel="nofollow"  target="_blank">http://arpeex.blogspot.com/</a></p>
<p>For any additional support or inquiry regarding this problem, just leave a comment here, and I&#8217;ll reply as soon as I can.</p>
<h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://www.techiebubble.com/security/remove-conficker-downadup-kido-worm-virus-before-april-1-2009/" title="Remove Conficker/Downadup/Kido worm virus before April 1, 2009">Remove Conficker/Downadup/Kido worm virus before April 1, 2009</a></li><li><a href="http://www.techiebubble.com/security/how-to-remove-the-acrobatcomexe-worm-virus/" title="How to remove the ACROBAT.COM.EXE worm virus">How to remove the ACROBAT.COM.EXE worm virus</a></li><li><a href="http://www.techiebubble.com/security/how-to-remove-the-lkhdexe-cqtvsexe-virus/" title="How to remove the lkhd.exe / cqtvs.exe virus">How to remove the lkhd.exe / cqtvs.exe virus</a></li></ul><hr />
<p><small>© Ryman for <a href="http://www.techiebubble.com">Techie Bubble</a>, 2009. |
<a href="http://www.techiebubble.com/security/how-to-remove-the-jwgkvsqvmx-worm-virus/">Permalink</a> |
<a href="http://www.techiebubble.com/security/how-to-remove-the-jwgkvsqvmx-worm-virus/#comments">23 comments</a><br/>
Post tags: <a href="http://www.techiebubble.com/tag/jwgkvsqvmx/" rel="nofollow tag">jwgkvsq.vmx</a>, <a href="http://www.techiebubble.com/tag/network-virus/" rel="nofollow tag">network virus</a>, <a href="http://www.techiebubble.com/tag/usb-virus/" rel="nofollow tag">USB virus</a>, <a href="http://www.techiebubble.com/tag/virus/" rel="nofollow tag">virus</a>, <a href="http://www.techiebubble.com/tag/w32confi/" rel="nofollow tag">W32/Confi</a>, <a href="http://www.techiebubble.com/tag/worm/" rel="nofollow tag">worm</a><br/>
This Feed is for personal non-commercial use only. If you are not reading this material in your Feed Reader, News Aggregator, or RSS Reader, then the site you are looking at is guilty of copyright infringement. Please contact infinity@eternalmoonlight.net so we can take legal action immediately.
</small></p>]]></content:encoded>
			<wfw:commentRss>http://www.techiebubble.com/security/how-to-remove-the-jwgkvsqvmx-worm-virus/feed/</wfw:commentRss>
		<slash:comments>23</slash:comments>
		</item>
	</channel>
</rss>
