|What is the Pretty Park Worm?
|Pretty Park is a email worm similar to the Happy99.exe worm.
It comes in the form of an email attachment with the name
prettypark.exe, files32.exe, or prettyorg.exe. Windows users are
susceptible to the worm. Once the worm program is executed, it tries to
email itself automatically every 30 minutes (or 30 minutes after it is
loaded) to email addresses registered in your Internet address book.
tries to connect to an IRC server and join a specific IRC channel. The
worm sends information to IRC every 30 seconds to keep itself
connected, and to retrieve any commands from the IRC channel. Through
the IRC connection, the author of the worm could obtain system
information, including the computer name, product name, product
identifier, product key, registered owner, registered organization,
system root path, version, version number, ICQ identification numbers,
ICQ nicknames, victim's email address, and Dial Up Networking username
and passwords. In addition, being connected to IRC opens a security
hole in which the client can potentially be used to receive and execute
a file called files32.vxd in the C:\Windows\System
directory and modifies the following registry key located at
%* to files32.vxd "%1" %*
variant of the Pretty Park Worm also creates a similar change to the
following registry key.
Manual Removal Instructions for Pretty Park.exe
these instructions in the exact order, and as always, I claim no
responsibility for you not understanding the instructions completely
and wrecking havoc with your system. Changes to the registry should
only be done by someone who understands the consequences of a mistake
in the registry.
- On the
Windows taskbar, click Start > Run.
REGEDIT, then click OK.
the following Registry value:
files32.vxd "%1" %*
These seven characters are the following: double quote, percent sign,
the numeral one, double quote, space, percent sign, and asterisk. Don't
forget the space.
the above step for the following Registry Key
the File Command under the Start Menu, Find and Delete the
Windows Explorer or the Find Command under the Start Menu, find and
delete the \Windows\System\Files32.vxd file.
Automatic Removal of Pretty Park
Automatic Removal of PrettyPark and its variant,
Craig Schumugar's excellent Pretty Park Cleaner
Tools for Removing Spyware, Adware, and Malware
Spyware/Adware Removal Help
MSBlast.exe Worm Removal
Welchia (Dllhost.exe and SVCHost.exe) Worm Removal
Uninstall McAfee Instructions
Uninstall Norton Instructions
Uninstall Avast Instructions
Uninstall AVG Instructions
Uninstall Antivir Instructions
Uninstall Panda Instructions
How to Manually Run the Microsoft Malicious Software Removal Tool
Bloodhound.Exploit.6 Virus Removal
MyDoom Virus Removal
MiMail.C Virus Removal
Swen Worm Virus Removal
SoBig.F Worm Removal
Dumaru Virus Removal
BugBear.B Worm Removal
SoBig.E Worm Removal
Pop Up Ad Removal Info
KAK Worm Removal
MiMail.A Worm Removal
W95.MTX Virus Removal
Snow White Virus Removal
BadTrans Trojan Removal
Wininit Virus (Bymer Trojan)
Happy99 Worm Removal
VBS Netlog Worm Removal
Pretty Park Worm Removal
Sasser Worm Virus Removal
Backdoor SDBot.H Trojan Removal
Computer Security Information
Back Orifice Information
PC HELL Main Page
iPadastic - News, Tutorials, Help, Tips, and Hints for the iPad
Download Hoyle Games
including Casino 3D, Card, Board, and Solitaire games.