ISSUE IS A WORM. HERE IS A DESCRIPTION AND WAY TO REMOVE THE PROBLEM AS
DESCRIBED ON THE TREND MICRO WEBSITE. I ALSO RECEOMEND USING HIJACK
THIS AND POSTING THE LOG FILE HERE FOR A FURTHER ANALYSIS.
QUICK LINKS
Understanding New Pattern Format
|
Malware type: Worm
Aliases: Worm.Win32.VB.ck
(Kaspersky), W32/YahLover.worm (McAfee), W32.Imaut.AA (Symantec),
Worm/VB.CK.24 (Avira), W32/Sohana-G (Sophos),
In the wild: Yes
Destructive: No
Language: English
Platform: Windows 98, ME, NT, 2000, XP, Server 2003
Encrypted: No
Overall risk rating:

Low
Reported infections:

Low
Damage potential:

Medium
Distribution potential:

High
Infection Channel 1 : Propagates via removable drives
Infection Channel 2 : Copies itself in all available physical drives
Description:
This worm may be downloaded unknowingly by a user when visiting malicious Web sites.
It drops copies of itself.
It creates registry entries to enable its automatic execution at
every system startup. It also drops copies of itself in the Windows
Common Startup folder to enable its automatic execution at every system
startup.
It creates and modifies registry entry as part of its installation routine.
It drops copies of itself in all physical drives and in all removable drives. It drops an AUTORUN.INF file to automatically execute dropped copies when the drives are accessed.
It accesses Web sites to download files. As a result, malicious
routines of the downloaded files are exhibited on the affected system.
Solution:
Identifying the Malware Files
- Scan your computer with your Trend Micro antivirus product.
- Note the path and file name of all files detected as WORM_VB.GAX.
Trend Micro customers need to download the latest virus pattern file before scanning their computer. Other users can use Housecall, the Trend Micro online threat scanner.
Terminating the Malware Program
Since this malware uses a file name that is also the file name of a
legitimate process, it is necessary to use third party process viewers
such as Process Explorer, to isolate the malware process itself.
If the process you are looking for is not in the list displayed by Process Explorer, proceed to the succeeding solution set.
- Download Process Explorer.
- Extract the contents of the compressed (ZIP) file to a location of your choice.
- Execute Process Explorer by double-clicking procexp.exe.
- In the Process Explorer window, locate the process:
%Windows%lsass.exe
(Note: %Windows% is the Windows folder, which is usually C:Windows or C:WINNT.)
- Right-click the malware process, and choose Properties.
- Check if the value for the Current Directory is the following:
- If yes, then right-click on the malware process, and click Kill Process Tree.
- Close Process Explorer.
*NOTE: On computers running all Windows platforms, if the
process you are looking for is not in the list displayed by Process
Explorer, continue with the next solution procedure, noting additional
instructions. If the malware process is in the list displayed by
Process Explorer, but you are unable to terminate it, restart your
computer in
safe mode.
Enabling The Registry Editor
This malware disables the Registry Editor. To restore the said system tool, perform the following instructions:
• On Windows 98 ME, NT, and 2000:
- Open Notepad. Click StartRun, type Notepad, then press Enter.
- Copy and paste the following:
REGEDIT4
[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPol iciesSystem]
"DisableRegistryTools" = dword:00000000
3.
- Save this file as C:RESTORE.REG.
- Click StartRun, type C:RESTORE.REG, then press Enter.
- Click Yes at the prompt of the message box
On Windows XP and Server 2003:
- Open the Run dialog box. Click StartRun, type Notepad, then press Enter.
- Copy and paste the following:
REG add HKCUSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem /v DisableRegistryTools /t REG_DWORD /d 0 /f
3.
- Save this file as C:RESTORE.REG.
- Click StartRun, type C:RESTORE.REG, then press Enter.
- Click Yes at the prompt of the message box.
Removing Autostart Entries from the Registry
This solution deletes/modifies registry keys/entries added/modified
by this malware. Before performing the steps below, make sure you know
how to back up the registry and how to restore it if a problem occurs.
Refer to this Microsoft article for more information about modifying your computer's registry.
- Open Registry Editor. Click StartRun, type REGEDIT, then press Enter.
- In the left panel, double-click the following:
HKEY_LOCAL_MACHINESoftwareMicrosoftWindows NTCurrentVersion
Winlogon - In the right panel, locate and delete the entry:
shell = "explorer.exe %Windows%systemlsass.exe" - Right-click on the value name and choose Modify. Change the value data of this entry to:
“Explorer.exe†- Still in the right panel, locate the entry:
Userinit = "userinit.exe,%Windows%systemlsass.exe" - Right-click on the value name and choose Modify. Change the value data of this entry to:
%System%userinit.exe
(Note: %System% is the Windows
system folder, which is usually C:WindowsSystem on Windows 98 and ME,
C:WINNTSystem32 on Windows NT and 2000, or C:WindowsSystem32 on
Windows XP and Server 2003.)
Restoring Registry Entries
- Still in the Registry Editor, in the left panel, double-click the following:
HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerMain - In the right panel, locate the entry:
Start Page = http://thecoolpics.net/ - Right-click on the value name and choose Modify. Change the value data of this entry to:
“User defined†- In the left panel, double-click the following:
HKEY_CURRENT_USER SoftwareMicrosoftWindowsCurrentVersion
ExplorerAdvanced - In the right panel, locate the entry:
Hidden = "2" - Right-click on the value name and choose Modify. Change the value data of this entry to:
“0†- In the right panel, locate the entry:
HideFileExt = "1" - Right-click on the value name and choose Modify. Change the value data of this entry to:
“0†- In the left panel, double-click the following:
HKEY_CURRENT_USERSoftwareYahoopagerView
YMSGR_buzz - In the right panel, locate the entry:
content url = http://thecoolpics.net/ - Right-click on the value name and choose Modify. Change the value data of this entry to:
http://tools.search.yahoo.com/ym/buzz - In the left panel, double-click the following:
HKEY_CURRENT_USERSoftwareYahoopagerView
YMSGR_Launchcast - In the right panel, locate the entry:
content url = http://thecoolpics.net/ - Right-click on the value name and choose Modify. Change the value data of this entry to:
http://radio.launch.yahoo.com/radio/play/playmessenger.as
Removing Other Malware Entries from the Registry
- Still in Registry Editor, in the left panel, double-click the following:
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersion
PoliciesExplorer - In the right panel, locate and delete the entry:
NoFolderOptions = "1" - Still in the right panel, locate and delete the entry:
NoRun = "1" - In the left panel, double-click the following:
HKEY_CURRENT_USER SoftwareMicrosoftWindowsCurrentVersion
PoliciesSYSTEM - In the right panel, locate and delete the entry:
DisableRegistryTools = "1" - Still in the right panel, locate and delete the entry:
DisableTaskMgr = "1" - In the left panel, double-click the following:
HKEY_CURRENT_USERSoftwarePoliciesMicrosoftInternet Explorer
Control Panel - In the right panel, locate and delete the entry:
Homepage = "1" - In the left panel, double-click the following:
HKEY_LOCAL_MACHINE SoftwareMicrosoftWindowsCurrentVersion
PoliciesExplorer - In the right panel, locate and delete the entry:
NoFolderOptions = "1" - In the left panel, double-click the following:
HKEY_LOCAL_MACHINESoftwarePoliciesMicrosoftWindows NT
SystemRestore - In the right panel, locate and delete the entry:
DisableConfig = "1" - Close the registry editor.
Deleting Malware-created AUTORUN.INF/s
- Right-click Start then click Search... or Find..., depending on the version of Windows you are running.
- In the Named input box, type:
AUTORUN.INF
- In the Look In drop-down list, select a drive, then press Enter.
- Select the file, then open using Notepad.
- Check if the following lines are present in the file:
[AutoRun]
Open=boot.exe
Shellexecute=boot.exe
ShellAutocommand=boot.exe
- If the lines are present, delete the file.
- Repeat steps 3 to 6 for AUTORUN.INF files in the remaining removable drives.
- Close Search Results.
Important Windows ME/XP Cleaning Instructions
Users running Windows ME and XP must disable System Restore to allow full scanning of infected computers.
Users running other Windows versions can proceed with the succeeding solution set(s).
Running Trend Micro Antivirus
If you are currently running in safe mode, please restart your computer normally before performing the following solution.
Scan your computer with Trend Micro antivirus and delete files detected as
WORM_VB.GAX. To do this, Trend Micro customers must download the latest virus pattern file and scan their computer. Other Internet users can use HouseCall, the Trend Micro online virus scanner.