VBS Stages.A Virus
(Life_Stages.txt.shs file)
How to Detect it and Remove It
What is
the VBS.Stages worm?
How Does the Worm Activate? When someone opens the LIFE_STAGES.TXT.SHS file, it opens notepad and displays the following joke about the different stages of life for females and males. While the user is reading this joke, the worm installs itself into the infected computer. It creates the following registry entry, so that is runs at Windows startup. HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\ScanReg="C:\windows\wscript.exe c:\windows\system\scanreg.vbs" It drop the scanreg.vbs file into the c:\windows\system directory and creates registry entries to activate when ICQ is loaded. To spread via IRC channels, it creates the file SOUND32B.DLL called by MIRC. This allows the worm to spread via IRC channels, as well as email. It also sends the virus via email to all addresses in the infected computer's address book. Finally, it deletes the file REGEDIT.EXE and moves it to the Recycle Bin with the name RECYCLED.VXD. This makes it hard to remove the worm because you can't edit the windows registry. VBS.Stages.A also creates files with random names in the system and all available drives using the following fixed names: c:\WINDOWS\machine
name.acl Examples of
random names generated are the following: In the
creation of the random named SHS files, the virus uses the following
algorithm to determine a name: Random1 is
a selection of one of five choices: How to Clean/Delete the VBS.Stages worm You must locate a copy of the REGEDIT.EXE file from the original Windows disks or another computer to be able to edit the windows registry and remove the worm. You may also download the file FIXSTAGE.EXE from the Trend Micro website to correct the registry ad remove the files dropped by the worm. This will not delete the actual virus but it will correct most of the damage done to the system. The actual virus can be deleted by searching your system for file scanreg.vbs or quite frankly any other .vbs file type, and deleting it. VBS files are Visual Basic Scripts that may contain viruses. For more information on the Life_Stages worm, visit the Norton Anti Virus page for detailed manual removal directions as well as an automatic removal program Also visit my page on how to protect yourself from these email viruses
|
Tools for Removing Spyware, Adware, and Malware PC HELL Welchia (Dllhost.exe and SVCHost.exe) Worm Removal Uninstall Antivir Instructions How to Manually Run the Microsoft Malicious Software Removal Tool Bloodhound.Exploit.6 Virus Removal Backdoor SDBot.H Trojan Removal
iPadastic - News, Tutorials, Help, Tips, and Hints for the iPad Download Hoyle Games |
Recommended Software for PC Hell Visitors | |||||
Malwarebytes Anti-Malware |
iolo System Mechanic® |
Emsisoft Anti Malware |
|||
Search PCHELL.COM |
|