How to Clean W32 Yahlover Worm

Yahlover is a malicious worm parasite that spreads through Yahoo! Messenger and Autorun.ini files so that it may be automatically executed on your computer when auto-run is enabled. Once it has been executed, it spreads malicious links to all the members in your messenger buddy list. Some of the problems Yahlover worm causes include blocking the registry and rebooting your computer every time you attempt to open the command prompt. To completely remove Yahlover, remove all its registry entries and system files.

Instructions

    • 1

      Click the "Windows "Start" button and click "All Programs." Scroll up and select "Accessories." Scroll down and select "System Tools." Click "System Restore."

    • 2

      Click the "Create restore point" radio button and click "Next." Type a name for your restore point and click "Create." This will back up your computer system using a restore point you can come back to in case of errors.

    • 3

      Open the Task Manager by pressing "Ctrl," "Alt," and "Delete" together. Click the "Processes" tab. Scroll down and click "csrcs.exe." Click "End Process." Close the Task Manager.

    • 4

      Click the Windows "Start"button and click "Run" or "Start Search" (Windows Vista users).

    • 5

      Type "regedit" (without quotes) and press "Enter" to open the registry window. Press "F3" to open the registry search box.

    • 6

      Search for and delete the following registry entries:
      HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden = dword:00000000
      HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SuperHidden = dword:00000000
      HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden = dword:00000002
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue = dword:00000001
      HKLM\SOFTWARE\ESET\Nod\CurrentVersion\Modules\AMON\Settings\Config000\Settings\exc = <long hex value>
      HKLM\SOFTWARE\ESET\Nod\CurrentVersion\Modules\AMON\Settings\Config000\Settings\exc_num = dword:0000000c
      HKLM\SOFTWARE\ESET\Nod\CurrentVersion\Modules\AMON\Settings\Config000\Settings\media_network = dword:00000000
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\csrcs = "%System%\csrcs.exe"
      HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell = "Explorer.exe csrcs.exe"
      Exit the registry.

    • 7

      Click the Windows "Start" button and click "Search." Click "All Files and Folders" to open the search box. Click "More Advanced Options" and place a check on all the given options.

    • 8

      Search for and delete the following files: 21srg698.au3.tb, csrcs.exe

    • 9

      Empty the recycle bin and restart your computer.

Related Searches:

References

Comments

You May Also Like

  • How to Remove W32 Yahlover Worm

    W32/Yahlover is a virus from the worm family. These programs are able to mutate and replace their own code, making them difficult...

  • How to Remove W32 Autorun Worm

    W32 Autorun Worm, also known as W32/Autorun.Worm.aaan, is a computer worm that, like all computer worms, has the ability to replicate itself...

  • How to Remove the W32 Koobface Worm

    The W32 Koobface Worm (aka W32.Koobface) is a malicious parasite that spreads through social networking sites. Once installed, it communicates with other...

  • How to Remove the W32 Blaster Worm

    W32.Blaster.Worm is a parasite that affects DCOM RPC vulnerability on your computer. It affects Windows XP and prior Windows operating systems. Once...

  • W32 Worm Removal

    Malware can infect any computer and bring normal system functions to a halt. Some viruses can even target specific operating systems. The...

  • How to Remove Worm 32

    The Worm 32 infection is a severe security risk to your computer because it harms and alters your system and network settings....

  • How to Remove a W32 Randex F Worm

    The W32.Randex.F worm is an infection that attacks computers with weak administrative passwords, according to the Symantec website. The worm hacks into...

  • How to Clean a Worm Virus

    Computer worm viruses usually attempt to do one thing: spread. The worm virus will use weaknesses in the operating system, network and...

  • How to Get Rid of a Computer Virus

    Computer viruses come in many forms and can cause various kinds of damage to your system. Fortunately, most viruses are easily dealt...

Related Ads

Featured